Pre-Winter Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet NSE6_FMG_AD-7.6 Fortinet NSE 6 - FortiManager 7.6 Administrator Exam Practice Test

Demo: 19 questions
Total 65 questions

Fortinet NSE 6 - FortiManager 7.6 Administrator Questions and Answers

Question 1

Which output is displayed right after moving the ISFW device from one ADOM to another?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 2

Refer to the exhibit.

How does FortiManager get antivirus and IPS updates? Choose one answer

Options:

A.

It uses all URLs in the list that contain the fds host name.

B.

It gets updates from the server with IP address 10.0.1.50.

C.

It connects to all servers marked as FortiGuard Distribution Network through Internet FDNI sources.

D.

It connects to the public FortiGuard servers listed in the configuration

Question 3

Refer to the exhibits.

An administrator has been asked to install the same policies from a central policy package onto the BR1-FGT-1 firewall.

The administrator added BR1-FGT-1 as a target in the central policy package installation.

What should the administrator do when reinstalling the central policy package on the BR1-FGT-1 firewall?

Options:

A.

Assign only one policy package to the firewall because FortiManager does not allow more than one policy package assigned per device at the same time.

B.

Import the policy package to change the unknown status and synchronize the policy package.

C.

Use the install wizard to install the central policy package on the BR1-FGT-1 firewall.

D.

First resolve the modified status in the configuration and provisioning templates to allow a smooth installation.

Question 4

An administrator wants to configure and manage multiple objects in the FortiManager database and give access to other users who work in the same database.

To stay in control of the changes made to firewall policies by other team members, the administrator needs a setup where all modifications go through a central check before they can be installed.

How can the administrator create this setup?

Options:

A.

Enable the prompt asking the administrator to accept firewall policies changes before saving.

B.

Enable the workspace (for all ADOMs) to control all changes made by any administrator.

C.

Enable device lock and the advanced mode feature in the ADOM.

D.

Enable workflow mode and the ADOM lock feature.

Question 5

Refer to Exhibits:

An administrator has observed the performance status outputs on an HA cluster for 55 seconds.

Which FortiGate is the primary?

Options:

A.

HQ-NGFW-2 with the parameter memory-failover-threshold setting

B.

HQ-NGFW-2 with the parameter priority setting

C.

HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting

D.

HQ-NGFW-1 with the parameter override setting

Question 6

What are two expected results when both FortiManager and FortiGate are behind network address translation NAT devices? Choose two answers

Options:

A.

FortiGate is discovered by FortiManager through the FortiGate NATed IP address.

B.

During discovery, the FortiManager NATed IP address is not set by default on FortiGate.

C.

FortiGate can announce itself to FortiManager only if the FortiManager non-NATed IP address is configured on FortiGate under central management.

D.

If the FortiGate–FortiManager communication protocol FGFM tunnel is torn down, FortiManager will try to reestablish the FGFM tunnel.

Question 7

What are two outcomes of ADOM revisions? Choose two answers.

Options:

A.

ADOM revisions can save the current state of the entire ADOM.

B.

ADOM revisions do not increase the size of configuration backups.

C.

ADOM revisions can save the current state of all policy packages and objects for an ADOM.

D.

ADOM revisions appear in the Install Policy and Package Settings section of the install wizard.

Question 8

Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

Options:

A.

When FortiManager installs device-level changes on a managed device

B.

When changes to the device-level database are made on FortiManager

C.

When FortiManager is auto-updated with configuration changes made directly on a managed device

D.

When a provisioning template is assigned to a managed device on the device-level database

Question 9

Refer to the exhibit.

An administrator created two new meta fields in FortiManager.

Which operation can you perform with these parameters?

Options:

A.

You can add them to objects as custom attributes.

B.

You can export them to be used in other ADOMs.

C.

You can use them as variables in scripts.

D.

You can invoke them using the $ character.

Question 10

An administrator suspects that the Collector Agent is not forwarding login events to FortiGate.

What is the most effective troubleshooting step?

Options:

A.

Verify if DC agent is enabled on the FortiGate.

B.

Restart the domain controller to refresh authentication services.

C.

Verify if FortiGate is set to use LDAP authentication instead of FSSO.

D.

Check if TCP port 8000 is open between the collector agent and FortiGate.

Question 11

Refer to Exhibit:

Which two actions will occur if you run the script using the Remote FortiGate Directly via CLI option? Choose two answers

Options:

A.

FortiManager will provide a preview of CLI commands before executing this script on a managed FortiGate.

B.

FortiManager will create a new revision history.

C.

FortiGate will auto-updated the FortiManager device-level database.

D.

You will have to install these changes using the Install Wizard.

Question 12

Refer to the exhibit.

What can you conclude from the downloaded import report?

Options:

A.

FortiManager does not support per-device mapping for firewall addresses.

B.

The administrator will see a new policy package named Remote-FortiGate_root in the FortiManager ADOM database.

C.

FortiManager will change the configuration of REMOTE_SUBNET to match the interface mapping coming in from Remote-FortiGate.

D.

As a result of this policy import process, FortiManager will create a new firewall address called REMOTE_SUBNET in the ADOM database.

Question 13

An administrator notices that CLI scripts are failing on some FortiGate devices because they use different FortiOS versions.

Which two actions should the administrator take to fix the failing CLI scripts? Choose two answers.

Options:

A.

Create separate ADOMs for each FortiOS version.

B.

Disable CLI scripts for devices using older firmware.

C.

Modify the CLI scripts to include conditional commands based on FortiOS version.

D.

Create version-specific CLI script groups and assign them to the appropriate devices.

Question 14

Which is recommended when you are managing a high volume of logs in your network?

Options:

A.

Store logs on FortiManager and use FortiView.

B.

Add and manage FortiAnalyzer from FortiManager.

C.

Enable advanced ADOM mode on FortiManager.

D.

Forward logs from FortiAnalyzer to FortiManager daily.

Question 15

What allows FortiManager to run CLI scripts on FortiGate devices without prompting for SSH authentication each time?

Options:

A.

FortiGate devices using the legacy login method.

B.

The secure management tunnel between FortiManager and FortiGate devices.

C.

The script using the Remote FortiGate Directly via CLI option.

D.

The script on the FortiManager device database.

Question 16

An administrator has assigned a global policy package to a new ADOM named ADOM1.

What will happen if the administrator tries to create a new policy package in ADOM1?

Options:

A.

The administrator will be able to select the option to assign the global policy package to the new policy package.

B.

FortiManager will automatically assign the global policy package to the new policy package.

C.

FortiManager will automatically install policies on the policy package in ADOM1.

D.

The administrator will have to assign the global policy package from the global ADOM.

Question 17

Refer to the exhibit.

If the monitored interface for the primary FortiManager device fails, what must you do to maintain high availability (HA)?

Options:

A.

The FortiManager HA failover is transparent to administrators and does not require any additional action.

B.

Manually promote one of the working secondary devices to the primary role: and reboot the original primary device to remove the peer IP address of the failed device.

C.

Reconfigure the primary device to remove the peer IP address of the failed device from its configuration.

D.

Check the integrity database of the primary device to force a secondary device to become the new primary with all active interfaces.

Question 18

Refer to the exhibit.

An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.

After the installation operation is performed, which IP/netmask will be installed on Remote-Firewall [VDOM1] for the LAN firewall address object?

Options:

A.

21.21.2.5/255.255.255.255

B.

172.16.5.20/255.255.255.255

C.

172.16.5.0/255.255.255.0

D.

10.10.10.5/255.255.255.255

Question 19

A FortiManager administrator opens the revision history and choose to revert to a previous version.

What will this action do to the current device configuration?

Options:

A.

It will trigger an unknown device-level database status, and the administrator will have to import a policy package to sync.

B.

It will trigger a conflict status if it is using any provisioning template, and the administrator will have to install changes.

C.

It will revert both configurations: device-level database and policy layer database.

D.

It will modify the device-level database.

Demo: 19 questions
Total 65 questions