ExamGecko
Home Home / Fortinet / NSE5_FMG-7.2

Fortinet NSE5_FMG-7.2 Practice Test - Questions Answers, Page 10

Question list
Search
Search

Related questions











What is the purpose of the Policy Check feature on FortiManager?

A.
It provides recommendations for optimizing policies in a policy package.
A.
It provides recommendations for optimizing policies in a policy package.
Answers
B.
It provides recommendations to combine similar policy packages within an ADOM into one single policy package.
B.
It provides recommendations to combine similar policy packages within an ADOM into one single policy package.
Answers
C.
It compares the policy packages with the revision history, and updates policy packages in the ADOM database.
C.
It compares the policy packages with the revision history, and updates policy packages in the ADOM database.
Answers
D.
It merges and creates dynamic mappings for duplicate objects used in a policy package.
D.
It merges and creates dynamic mappings for duplicate objects used in a policy package.
Answers
Suggested answer: A

Refer to the exhibit.

Given the configuration shown in the exhibit, which two statements are true? (Choose two.)

A.
The FortiManager ADOM workspace mode is set to Normal.
A.
The FortiManager ADOM workspace mode is set to Normal.
Answers
B.
An administrator can also lock the Local-FortiGate-1 policy package.
B.
An administrator can also lock the Local-FortiGate-1 policy package.
Answers
C.
The FortiManager ADOM is locked by the administrator.
C.
The FortiManager ADOM is locked by the administrator.
Answers
D.
FortiManager is in workflow mode.
D.
FortiManager is in workflow mode.
Answers
Suggested answer: A, B

Explanation:

https://docs.fortinet.com/document/fortimanager/7.2.4/administration-guide/397419/lock-an-individual-policy

Refer to the exhibit.

What can you conclude from the failed installation log shown in the exhibit?

A.
Policy ID 2 will not be installed.
A.
Policy ID 2 will not be installed.
Answers
B.
Policy ID 2 is installed in the disabled state.
B.
Policy ID 2 is installed in the disabled state.
Answers
C.
Policy ID 2 is installed without a source address.
C.
Policy ID 2 is installed without a source address.
Answers
D.
Policy ID 2 is installed without the remote user student.
D.
Policy ID 2 is installed without the remote user student.
Answers
Suggested answer: D

Refer to the exhibit.

A service provider administrator has assigned a global policy package to a managed customer ADOM named My_ADOM, which has four policy packages. The customer administrator has access onlytoMy_ADOM.

How can customer or service provider administrators remove both global header and footer policies from the policy package named Shared_Package?

A.
The service provider administrator can unassign both policies from the global ADOM.
A.
The service provider administrator can unassign both policies from the global ADOM.
Answers
B.
The service provider administrator can unassign both global policies from My_ADOM.
B.
The service provider administrator can unassign both global policies from My_ADOM.
Answers
C.
The customer administrator can unassign both polices by locking My_ADOM.
C.
The customer administrator can unassign both polices by locking My_ADOM.
Answers
D.
The customer administrator can unassign both global polices from My_ADOM.
D.
The customer administrator can unassign both global polices from My_ADOM.
Answers
Suggested answer: B

Refer to the exhibit.

An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.

After the installation operation is performed, which IP/netmask will be shown on FortiManager for this firewall address object without specify Per-Device Mapping?

A.
The FortiManager replaces the address object to none.
A.
The FortiManager replaces the address object to none.
Answers
B.
0.0.0.0/0.
B.
0.0.0.0/0.
Answers
C.
192.168.1.0/24.
C.
192.168.1.0/24.
Answers
D.
10.0.5.0/24.
D.
10.0.5.0/24.
Answers
Suggested answer: C

Explanation:

In the scenario you described, an administrator has created a firewall address object used in multiple policy packages for multiple FortiGate devices within an Administrative Domain (ADOM) on FortiManager. The question concerns the display of this object's IP/netmask in FortiManager after installation, assuming no per-device mapping is specified.

Given the screenshot and the description of the situation, the answer is **C. 192.168.1.0/24**. When you create a firewall address object in FortiManager without specifying per-device mapping, FortiManager uses the generic settings of the object as defined. In the screenshot, the IP/Netmask is set to 192.168.1.0/255.255.255.0, and since there is no per-device variation defined or required in your query, this setting remains as shown in the object's configuration.


Refer to the exhibit showing a Download Import Report.

Why is it failing to import firewall policy ID 1?

A.
Policy ID 1 is configured from the interface any to port6. FortiManager rejects the request to import this policy because the any interface does not exist on FortiManager.
A.
Policy ID 1 is configured from the interface any to port6. FortiManager rejects the request to import this policy because the any interface does not exist on FortiManager.
Answers
B.
The address object used in policy ID 1 already exists in the ADOM database with any as the interface association, and conflicts with the address object interface association locally on FortiGate.
B.
The address object used in policy ID 1 already exists in the ADOM database with any as the interface association, and conflicts with the address object interface association locally on FortiGate.
Answers
C.
Policy ID 1 does not have the ADOM Interface mapping configured on FortiManager.
C.
Policy ID 1 does not have the ADOM Interface mapping configured on FortiManager.
Answers
D.
Policy ID 1 for this managed FortiGate already exists on FortiManager in the policy package named Remote-FortiGate.
D.
Policy ID 1 for this managed FortiGate already exists on FortiManager in the policy package named Remote-FortiGate.
Answers
Suggested answer: B

Refer to the exhibit.

An administrator wants to create a policy on the Staging ADOM in backup mode, and install it on the FortiGate device in the same ADOM.

How can the administrator perform this task?

A.
The administrator must use the Policy & Objects section to create a policy first.
A.
The administrator must use the Policy & Objects section to create a policy first.
Answers
B.
The administrator must use the I ortiManager script.
B.
The administrator must use the I ortiManager script.
Answers
C.
The administrator must disable the FortiManager offline mode first.
C.
The administrator must disable the FortiManager offline mode first.
Answers
D.
The administrator must change the ADOM mode to Advanced to bring the FortiManager online.
D.
The administrator must change the ADOM mode to Advanced to bring the FortiManager online.
Answers
Suggested answer: D

An administrator has enabled Service Access on FortiManager. What is the purpose of Service Access on the FortiManager interface?

A.
It allows FortiManager to respond to requests for FortiGuard services from FortiGate devices.
A.
It allows FortiManager to respond to requests for FortiGuard services from FortiGate devices.
Answers
B.
It allows FortiManager to determine the connection status of managed devices.
B.
It allows FortiManager to determine the connection status of managed devices.
Answers
C.
It allows administrative access to FortiManager.
C.
It allows administrative access to FortiManager.
Answers
D.
It allows third-party applications to gain read/write access to FortiManager.
D.
It allows third-party applications to gain read/write access to FortiManager.
Answers
Suggested answer: A

Refer to the exhibit.

Given the configuration shown in the exhibit, what are two results from this configuration? (Choose two.)

A.

Two or more administrators can make configuration changes at the same time, in the same ADOM.

A.

Two or more administrators can make configuration changes at the same time, in the same ADOM.

Answers
B.

The same administrator can lock more than one ADOM at the same time. Most Voted

B.

The same administrator can lock more than one ADOM at the same time. Most Voted

Answers
C.

Concurrent read-write access to an ADOM is disabled. Most Voted

C.

Concurrent read-write access to an ADOM is disabled. Most Voted

Answers
D.

You can validate administrator login attempts through external servers.

D.

You can validate administrator login attempts through external servers.

Answers
Suggested answer: B, C

What does a policy package status of Never Installed indicate?

A.

The policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager.

A.

The policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager.

Answers
B.

FortiManager is unable to determine the policy package status.

B.

FortiManager is unable to determine the policy package status.

Answers
C.

The policy configuration has been changed on FortiManager and changes have not yet been installed on the managed device.

C.

The policy configuration has been changed on FortiManager and changes have not yet been installed on the managed device.

Answers
D.

The policy package was never imported after a device was registered on FortiManager

D.

The policy package was never imported after a device was registered on FortiManager

Answers
Suggested answer: D

Explanation:

Never Installed: There is no policy package for this unit. Either policies and objects have not been imported yet or no policy package has been assigned for this unit. https://community.fortinet.com/t5/FortiManager/Technical-Tip-FortiManager-policy-package-installation-and/ta-p/195923

Total 103 questions
Go to page: of 11