Real Fortinet NSE5_FMG-7.0 Exam Questions Study Guide [Q40-Q59]

Share

Real Fortinet NSE5_FMG-7.0 Exam Questions Study Guide

Updated and Accurate NSE5_FMG-7.0 Questions for passing the exam Quickly


The Fortinet NSE5_FMG-7.0 certification exam is a challenging and rewarding certification that validates a candidate's ability to manage Fortinet security infrastructure using FortiManager. This certification is ideal for security professionals who want to enhance their skills and advance their careers in the cybersecurity industry.

 

NEW QUESTION # 40
An administrator has added all the devices in a Security Fabric group to FortiManager.
How does the administrator identify the root FortiGate?

  • A. By an at symbol (@) at the end of the device name
  • B. By a dollar symbol ($) at the end of the device name
  • C. By a
  • D. By an Asterisk (*) at the end of the device name

Answer: D


NEW QUESTION # 41
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)

  • A. The Fabric View module enables you to view the Security Fabric ratings for Security Fabric devices
  • B. The Security Fabric license, group name and password are required for the FortiManager Security Fabric
    integration
  • C. The Security Fabric settings are part of the device level settings
  • D. The Fabric View module enables you to generate the Security Fabric ratings for Security Fabric devices

Answer: A,C


NEW QUESTION # 42
What is the purpose of the Policy Check feature on FortiManager?

  • A. To find and delete disabled firewall policies in the policy package
  • B. To find and merge duplicate policies in the policy package
  • C. To find and provide recommendation to combine multiple separate policy packages into one common policy package
  • D. To find and provide recommendation for optimizing policies in a policy package

Answer: D


NEW QUESTION # 43
View the following exhibit, which shows the Download Import Report:

Why it is failing to import firewall policy ID 2?

  • A. Policy ID 2 does not have ADOM Interface mapping configured on FortiManager
  • B. Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.
  • C. The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association locally on the FortiGate
  • D. Policy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager

Answer: C

Explanation:
FortiManager_6.4_Study_Guide-Online - page 331 & 332


NEW QUESTION # 44
View the following exhibit.

Which one of the following statements is true regarding the object named ALL?

  • A. FortiManager updated the object ALL using FortiGate's value in its database
  • B. FortiManager updated the object ALL using FortiManager's value in its database
  • C. FortiManager installed the object ALL with the updated value.
  • D. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate.

Answer: A


NEW QUESTION # 45
Refer to the exhibit.

You are using the Quick Install option to install configuration changes on the managed FortiGate.
Which two statements correctly describe the result? (Choose two.)

  • A. It provides the option to preview configuration changes prior to installing them
  • B. It will not create a new revision in the revision history
  • C. It installs device-level changes to FortiGate without launching the Install Wizard
  • D. It cannot be canceled once initiated and changes will be installed on the managed device

Answer: C,D

Explanation:
FortiManager_6.4_Study_Guide-Online - page 164
The Install Config option allows you to perform a quick installation of device-level settings without launching the Install Wizard. When you use this option, you cannot preview the changes prior to committing. Administrator should be certain of the changes before using this install option, because the install can't be cancelled after the process is initiated.


NEW QUESTION # 46
Which two items does an FGFM keepalive message include? (Choose two.)

  • A. FortiGate uptime
  • B. FortiGate configuration checksum
  • C. FortiGate license information
  • D. FortiGate IPS version

Answer: B,D


NEW QUESTION # 47
In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator sent a device registration to FortiManager from a remote FortiGate. Which one of the following statements is true?

  • A. The FortiManager administrator must add the unregistered device manually to the unregistered device
  • B. The FortiGate will be automatically added to the Training ADOM.
  • C. The FortiGate will be added automatically to the default ADOM named FortiGate.
  • D. By default, the unregistered FortiGate will appear in the root ADOM.

Answer: D

Explanation:
manually to the Training ADOM using the Add Device wizard


NEW QUESTION # 48
An administrator run the reload failure command: diagnose test deploymanager reload config
<deviceid> on FortiManager. What does this command do?

  • A. It installs the provisioning template configuration on the specified FortiGate.
  • B. It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.
  • C. It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate.
  • D. It installs the latest configuration on the specified FortiGate and update the revision history database.

Answer: B


NEW QUESTION # 49
Which two items are included in the FortiManager backup? (Choose two.)

  • A. Global database
  • B. Logs
  • C. FortiGuard database
  • D. All devices

Answer: A,D


NEW QUESTION # 50
View the following exhibit.

What is the purpose of setting ADOM Mode to Advanced?

  • A. The setting disables concurrent ADOM access and adds ADOM locking
  • B. The setting enables the ADOMs feature on FortiManager
  • C. This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.
  • D. The setting allows automatic updates to the policy package configuration for a managed device

Answer: C


NEW QUESTION # 51
Refer to the exhibit.

Which two statements about the output are true? (Choose two.)

  • A. The latest revision history for the managed FortiGate does match with the FortiGate running configuration
  • B. Configuration changes directly made on the FortiGate have been automatically updated to device-level
  • C. Configuration changes have been installed to FortiGate and represents FortiGate configuration has been changed
  • D. The latest history for the managed FortiGate does not match with the device-level database

Answer: A,D

Explanation:
database
Explanation:
STATUS: dev-db: modified; conf: in sync; cond: pending; dm: retrieved; conn: up - dev-db: modified - This is the device setting status which indicates that configuration changes were made on FortiManager. - conf: in sync - This is the sync status which shows that the latest revision history is in sync with Fortigate's configuration. - cond: pending - This is the configuration status which says that configuration changes need to be installed.
Most probably a retrieve was done in the past (dm: retrieved) updating the revision history DB (conf: in sync) and FortiManager device level DB, now there is a new modification on FortiManager device level DB (dev-db: modified) which wasn't installed to FortiGate (cond: pending), hence; revision history DB is not aware of that modification and doesn't match device DB.
Conclusion: - Revision DB does match FortiGate. - No changes were installed to FortiGate yet. - Device DB doesn't match Revision DB. - No changes were done on FortiGate (auto-update) but configuration was retrieved instead
After an Auto-Update or Retrieve: device database = latest revision = FGT
Then after a manual change on FMG end (but no install yet): latest revision = FGT (still) but now device database has been modified (is different).
After reverting to a previous revision in revision history: device database = reverted revision != FGT


NEW QUESTION # 52
An administrator would like to create an SD-WAN using central management. What steps does the administrator need to perform to create an SD-WAN using central management?

  • A. Remove all the interface references such as routes or policies
  • B. You must specify a gateway address when you create a default static route
  • C. First create an SD-WAN firewall policy, add member interfaces to the SD-WAN template and create a static route
  • D. Enable SD-WAN central management in the ADOM, add member interfaces, create a static route and SDWAN firewall policies.

Answer: D


NEW QUESTION # 53
Which of the following statements are true regarding VPN Gateway configuration in VPN Manager? (Choose two.)

  • A. Managed devices in other ADOMs must be treated as external gateways
  • B. External gateways are third-party VPN gateway devices only
  • C. Protected subnets are the subnets behind the device that you don't want to allow access to over the IPsec
    VPN
  • D. Managed gateways are devices managed by FortiManager in the same ADOM

Answer: A,D


NEW QUESTION # 54
Refer to the exhibit.

According to the error message why is FortiManager failing to add the FortiAnalyzer device?

  • A. The administrator must use the Add Model Device section and discover the FortiAnaJyzer device
  • B. The administrator must turn off the Use Legacy Device login and add the FortiAnaJyzer device to the same network as Forti-Manager
  • C. The administrator must select the Forti-Manager administrative access checkbox on the FortiAnalyzer management interface
  • D. The administrator must use the correct user name and password of the FortiAnalyzer device

Answer: C


NEW QUESTION # 55
What does a policy package status of Conflict indicate?

  • A. The policy configuration has never been imported after a device was registered on FortiManager.
  • B. The policy package reports inconsistencies and conflicts during a Policy Consistency Check.
  • C. The policy package configuration has been changed on both FortiManager and the managed device independently.
  • D. The policy package does not have a FortiGate as the installation target.

Answer: C


NEW QUESTION # 56
Refer to the exhibit.

An administrator has created a firewall address object, Training which is used in the Local-FortiGate policy package.
When the installation operation is performed, which IP/Netmask will be installed on the Local-FortiGate, for the Training firewall address object?

  • A. It will create a firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values.
  • B. 192.168.0.1/24
  • C. Local-FortiGate will automatically choose an IP/Netmask based on its network interface settings.
  • D. 10.200.1.0/24

Answer: B


NEW QUESTION # 57
An administrator with the Super_User profile is unable to log in to FortiManager because of an authentication failure message.
Which troubleshooting step should you take to resolve the issue?

  • A. Make sure FortiManager Access is enabled in the administrator profile
  • B. Make sure the administrator IP address is part of the trusted hosts.
  • C. Make sure ADOMs are enabled and the administrator has access to the Global ADOM
  • D. Make sure Offline Mode is disabled

Answer: B

Explanation:
Even if a user entered the correct userid/password, the FMG denies access if a user is logging in from an untrusted source IP subnets.
Topic 1, Main Questions Pool B


NEW QUESTION # 58
What are two outcomes of ADOM revisions? (Choose two.)

  • A. ADOM revisions can save the current size of the whole ADOM
  • B. ADOM revisions can significantly increase the size of the configuration backups.
  • C. ADOM revisions can save the current state of all policy packages and objects for an ADOM
  • D. ADOM revisions can create System Checkpoints for the FortiManager configuration

Answer: B,C


NEW QUESTION # 59
......

Prepare Important Exam with NSE5_FMG-7.0 Exam Dumps: https://pass4sures.freepdfdump.top/NSE5_FMG-7.0-valid-torrent.html