All Obstacles During NSE5_FMG-7.2 Exam Preparation with NSE5_FMG-7.2 Real Test Questions
Fully Updated Free Actual Fortinet NSE5_FMG-7.2 Exam Questions
NEW QUESTION # 36
View the following exhibit.
Which one of the following statements is true regarding the object named ALL?
- A. FortiManager updated the object ALL using FortiGate's value in its database
- B. FortiManager installed the object ALL with the updated value.
- C. FortiManager updated the object ALL using FortiManager's value in its database
- D. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate.
Answer: A
NEW QUESTION # 37
View the following exhibit, which shows theDownload Import Report:
Why it is failing to import firewall policy ID 2?
- A. Policy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager
- B. The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association locally on the FortiGate
- C. Policy ID 2 does not have ADOM Interface mapping configured on FortiManager
- D. Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.
Answer: B
Explanation:
FortiManager_6.4_Study_Guide-Online - page 331 & 332
NEW QUESTION # 38
View the following exhibit.
An administrator is importing a new device to FortiManager and has selected the shown options. What will happen if the administrator makes the changes and installs the modified policy package on this managed FortiGate?
- A. The unused objects that are not tied to the firewall policies locally on FortiGate will be deleted
- B. The unused objects that are not tied to the firewall policies in policy package will be deleted from the FortiManager database
- C. The unused objects that are not tied to the firewall policies will remain as read-only locally on FortiGate
- D. The unused objects that are not tied to the firewall policies will be installed on FortiGate
Answer: A
Explanation:
Reference:https://community.fortinet.com/t5/FortiManager/Import-all-objects-Versus-Import-only-policy-depend
NEW QUESTION # 39
In the event that the primary FortiManager fails, which of the following actions must be performed to return the FortiManager HA to a working state?
- A. Reboot one of the secondary devices to promote it automatically to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- B. Manually promote one of the secondary devices to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- C. FortiManager HA state transition is transparent to administrators and does not require any reconfiguration.
- D. Secondary device with highest priority will automatically be promoted to the primary role, and manually reconfigure all other secondary devices to point to the new primary device
Answer: B
Explanation:
FortiManager_6.4_Study_Guide-Online - page 346
FortiManager HA doesn't support IP takeover where an HA state transition is transparent to administrators. If a failure of the primary occurs, the administrator must take corrective action to resolve the problem that may include invoking the state transition. If the primary device fails, the administrator must do the following in order to return the FortiManager HA to a working state:
1. Manually reconfigure one of the secondary devices to become the primary device
2. Reconfigure all other secondary devices to point to the new primary device
NEW QUESTION # 40
An administrator with theSuper_Userprofile is unable to log in to FortiManager because of an authentication failure message.
Which troubleshooting step should you take to resolve the issue?
- A. Make sure Offline Mode is disabled
- B. Make sure the administrator IP address is part of the trusted hosts.
- C. Make sure FortiManager Access is enabled in the administrator profile
- D. Make sure ADOMs are enabled and the administrator has access to the Global ADOM
Answer: B
Explanation:
Even if a user entered the correct userid/password, the FMG denies access if a user is logging in from an untrusted source IP subnets.
Reference:https://docs.fortinet.com/document/fortimanager/6.0.3/administration-guide/107347/trusted-hosts
NEW QUESTION # 41
An administrator configures a new firewall policy on FortiManager and has not yet pushed the changes to the managed FortiGate.
In which database will the configuration be saved?
- A. Revision history database
- B. Configuration-level database
- C. Device-level database
- D. ADOM-level database
Answer: D
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47942
NEW QUESTION # 42
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)
- A. TheFabric Viewmodule enables you to view the Security Fabric ratings for Security Fabric devices
- B. The Security Fabric settings are part of the device level settings
- C. TheFabric Viewmodule enables you to generate the Security Fabric ratings for Security Fabric devices
- D. The Security Fabric license, group name and password are required for the FortiManager Security Fabric integration
Answer: A,B
NEW QUESTION # 43
An administrator is in the process of moving the system template profile between ADOMs by running the following command:
execute improfile import-profile ADOM2 3547 /tmp/myfile
Where does the administrator import the file from?
- A. ADOM2 object database
- B. File system
- C. ADOM1
- D. ADOM2
Answer: B
NEW QUESTION # 44
Refer to the exhibit.
An administrator logs into the FortiManager GUI and sees the panes shown in the exhibit.
Which two reasons can explain why the FortiAnalyzer feature panesdo notappear? (Choose two.)
- A. The administrator profile does not have full access privileges like theSuper_Userprofile.
- B. The administrator logged in using the unsecure protocol HTTP, so the view is restricted.
- C. FortiAnalyzer features are not enabled on FortiManager.
- D. The administrator IP address is not a part of the trusted hosts configured on FortiManager interfaces.
Answer: A,C
NEW QUESTION # 45
What will happen if FortiAnalyzer features are enabled on FortiManager?
- A. FortiManager will enable ADOMs to collect logs automatically from non-FortiGate devices.
- B. FortiManager can be used only as a logging device.
- C. FortiManager will keep all the logs and reports on the FortiManager.
- D. FortiManager will install the logging configuration to the managed devices
Answer: D
NEW QUESTION # 46
An administrator would like to create an SD-WAN default static route for a newly created SD-WAN using the FortiManager GUI. Both port1 and port2 are part of the SD-WAN member interfaces.
Which interface must the administrator select in the static route device drop-down list?
- A. port1
- B. port2
- C. virtual-wan-link
- D. auto-discovery
Answer: C
NEW QUESTION # 47
What does a policy package status ofModifiedindicate?
- A. The Policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager
- B. FortiManager is unable to determine the policy package status
- C. The Policy package configuration has been changed on FortiManager and changes have not yet been installed on the managed device.
- D. The policy package was never imported after a device was registered on FortiManager
Answer: D
NEW QUESTION # 48
What will be the result of reverting to a previous revision version in the revision history?
- A. It will tag the device settings status asAuto-Update
- B. It will modify the device-level database
- C. It will install configuration changes to managed device automatically
- D. It will generate a new versionIDand remove all other revision history versions
Answer: B
NEW QUESTION # 49
View the following exhibit.
Given the configurations shown in the exhibit, what can you conclude from the installation targets in the Install Oncolumn?
- A. Policy seq#3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
- B. Policy seq#3 will be installed on the Trainer[NAT] VDOM only
- C. The Install On column value represents successful installation on the managed devices
- D. Policy seq#3 will be not installed on any managed device
Answer: A
NEW QUESTION # 50
Refer to the exhibit.
A junior administrator is troubleshooting a FortiManager connectivity issue that rs occurring with managed FortiGate devices Given the FortiManager device manager settings shown in the exhibit what can you conclude from the exhibit?
- A. The administrator can reclaim the FGFM tunnel to get both devices online
- B. The administrator must refresh both devices to restore connectivity
- C. FortiManager test internet connectivity therefore, both devices appear to be down
- D. The administrator had restored the FortiManager configuration file
Answer: C
NEW QUESTION # 51
An administrator has enabledService Accesson FortiManager.
What is the purpose ofService Accesson the FortiManager interface?
- A. Allows FortiManager to automatically configure a default route
- B. Allows FortiManager to run real-time debugs on the managed devices
- C. Allows FortiManager to download IPS packages
- D. Allows FortiManager to respond to request for FortiGuard services from FortiGate devices
Answer: D
Explanation:
FortiManager 6.2 Study guide page 350
NEW QUESTION # 52
Refer to the exhibit.
How will FortiManager try to get updates for antivirus and IPS?
- A. From the configured override server IP address 10.0.1.50 only
- B. From public FDNI server IP address with the fourth highest octet only
- C. From the list of configured override servers or public FDN servers
- D. From the default server fds1.fortinet.com
Answer: C
NEW QUESTION # 53
Which two conditions trigger FortiManager to create a new revision history? (Choose two.)
- A. When FortiManager is auto-updated with configuration changes made directly on a managed device
- B. When changes to the device-level database are made on FortiManager
- C. When a configuration revision is reverted to a previous revision in the revision history
- D. When FortiManager installs device-level changes on a managed device
Answer: B,D
NEW QUESTION # 54
What does a policy package status ofConflictindicate?
- A. The policy package reports inconsistencies and conflicts during aPolicy Consistency Check.
- B. The policy package configuration has been changed on both FortiManager and the managed device independently.
- C. The policy package does not have a FortiGate as the installation target.
- D. The policy configuration has never been imported after a device was registered on FortiManager.
Answer: B
NEW QUESTION # 55
Refer to the exhibit.
An administrator would like to create three ADOMs on FortiManager with different access levels based on departments.
What two conclusions can you draw from the design shown in the exhibit? (Choose two.)
- A. The FortiManager policies and objects database can be shared between the Financial and HR ADOMs.
- B. The administrator must configure FortiManager in workspace mode.
- C. The administrator must set the FortiManager ADOM mode to Advanced.
- D. Admin A can access VDOM2 and VDOM3 with the super user profile.
Answer: A,C
NEW QUESTION # 56
Which two statements about the scheduled backup of FortiManager are true? (Choose two.)
- A. It can be configured using the CLI and GUI.
- B. It backs up all devices and the FortiGuard database.
- C. It supports FTP, SCP, and SFTP.
- D. It does not back up firmware images saved on FortiManager.
Answer: C,D
Explanation:
Reference:https://docs.ansible.com/ansible/latest/collections/fortinet/fortimanager/fmgr_system_backup_allsettin
NEW QUESTION # 57
What will happen if FortiAnalyzer features are enabled on FortiManager?
- A. FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices
- B. FortiManager can be used only as a logging device.
- C. FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager
- D. FortiManager will reboot
Answer: D
Explanation:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1800_FAZ%20Features/0
NEW QUESTION # 58
What is the purpose of ADOM revisions?
- A. To revert individual policy packages and device-level settings for a managed FortiGate by reverting to a specific ADOM revision
- B. To save the current state of all policy packages and objects for an ADOM.
- C. To createSystem Checkpointsfor the FortiManager configuration.
- D. To save the current state of the whole ADOM.
Answer: B
Explanation:
Fortimanager 6.4 Study guide page 198
NEW QUESTION # 59
You are moving managed FortiGate devices from one ADOM to a new ADOM.
Which statement correctly describes the expected result?
- A. Policy packages will be imported into the new ADOM automaticallyD
- B. The shared policy package will not be moved to the new ADOM
- C. Any pending device settings will be installed automatically
- D. Any unused objects from a previous ADOM are moved to the new ADOM automatically
Answer: B
Explanation:
Reference:https://community.fortinet.com/t5/FortiManager/Technical-Note-How-to-move-objects-to-new-ADOM
NEW QUESTION # 60
What does thediagnose dvm check-integritycommand do? (Choose two.)
- A. Internally upgrades existing ADOMs to the same ADON version in order to clean up and correct the ADOM syntax
- B. Verifies and corrects duplicate VDOM entries
- C. Verifies and corrects database schemas in all object tables
- D. Verifies and corrects unregistered, registered, and deleted device states
Answer: B,D
Explanation:
6.2 Study Guide page 305verify and correct parts of the device manager databases, including:- inconsistent device-to-group and group-to-ADOM memberships- unregistered, registered, and deleted device states- device lock statuses- duplicate VDOM entries
NEW QUESTION # 61
......
Fortinet NSE5_FMG-7.2 certification exam is an excellent way for IT professionals to demonstrate their expertise in managing and maintaining Fortinet security solutions. Fortinet NSE 5 - FortiManager 7.2 certification exam is vendor-neutral, globally recognized, and covers essential topics that are directly relevant to IT professionals' day-to-day work. To take the exam, IT professionals must have experience working with FortiManager 7.2, a solid understanding of network security concepts and technologies, and ideally, have completed the Fortinet NSE 4 certification program.
Fortinet NSE5_FMG-7.2 certification exam covers a range of topics, including FortiManager deployment, device registration, configuration management, and device group management. It also covers advanced topics such as policy packages, device templates, and troubleshooting. By passing NSE5_FMG-7.2 exam, network professionals can demonstrate their proficiency in managing and configuring FortiManager devices, and can gain recognition as a certified Fortinet NSE5_FMG-7.2 professional. Fortinet NSE 5 - FortiManager 7.2 certification can enhance their career prospects and make them a valuable asset to any organization that uses Fortinet products for their network security needs.
Validate your NSE5_FMG-7.2 Exam Preparation with NSE5_FMG-7.2 Practice Test: https://killexams.practicevce.com/Fortinet/NSE5_FMG-7.2-practice-exam-dumps.html