Get Instant Access to NSE5_FMG-7.2 Practice Exam Questions [Q31-Q48]

Share

Get Instant Access to NSE5_FMG-7.2 Practice Exam Questions

Reliable Study Materials & Testing Engine for NSE5_FMG-7.2 Exam Success!

NEW QUESTION # 31
An administrator would like to create an SD-WAN using central management in theTrainingADOM.
To create an SD-WAN using central management, which two steps must be completed? (Choose two.)

  • A. Configure and install the SD-WAN firewall policy and SD-WAN static route before installing the SD-WAN template settings
  • B. Enable SD-WAN central management in theTrainingADOM
  • C. Specify a gateway address when you create a default SD-WAN static route
  • D. Remove all the interface references such as routes or policies that will be a part of SD-WAN member interfaces

Answer: B,D

Explanation:
Reference:https://docs.fortinet.com/document/fortigate/6.0.0/cookbook/676493/removing-existing-configuration


NEW QUESTION # 32
What will happen if FortiAnalyzer features are enabled on FortiManager?

  • A. FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices
  • B. FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager
  • C. FortiManager will reboot
  • D. FortiManager can be used only as a logging device.

Answer: C

Explanation:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1800_FAZ%20Features/0


NEW QUESTION # 33
View the following exhibit:

An administrator used the value shown in the exhibit when importing a Local-FortiGate into FortiManager.
What name will be used to display the firewall policy for port1?

  • A. WAN zone on FortiGate and WAN interface on FortiManager
  • B. port1 on FortiGate and WAN on FortiManager
  • C. port1 on both FortiGate and FortiManager
  • D. WAN zone on FortiGate and WAN zone on FortiManager

Answer: B


NEW QUESTION # 34
An administrator run the reload failure command:diagnose test deploymanager reload config
<deviceid>on FortiManager. What does this command do?

  • A. It installs the provisioning template configuration on the specified FortiGate.
  • B. It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate.
  • C. It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.
  • D. It installs the latest configuration on the specified FortiGate and update the revision history database.

Answer: C

Explanation:
Reference:https://community.fortinet.com/t5/FortiManager/Technical-Note-Retrieve-configuration-file-using-CL


NEW QUESTION # 35
Which two statements about the scheduled backup of FortiManager are true? (Choose two.)

  • A. It supports FTP, SCP, and SFTP.
  • B. It backs up all devices and the FortiGuard database.
  • C. It can be configured using the CLI and GUI.
  • D. It does not back up firmware images saved on FortiManager.

Answer: A,D

Explanation:
Reference:https://docs.ansible.com/ansible/latest/collections/fortinet/fortimanager/fmgr_system_backup_allsettin


NEW QUESTION # 36
What is the purpose of thePolicy Checkfeature on FortiManager?

  • A. To find and provide recommendation for optimizing policies in a policy package
  • B. To find and merge duplicate policies in the policy package
  • C. To find and delete disabled firewall policies in the policy package
  • D. To find and provide recommendation to combine multiple separate policy packages into one common policy package

Answer: A

Explanation:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-2/FortiManager_Admin_Guide/1200_Policy%20and%20O


NEW QUESTION # 37
An administrator wants to delete an address object that is currently referenced in a firewall policy.
What can the administrator expect to happen?

  • A. FortiManager will disable the status of the referenced firewall policy
  • B. FortiManager will not allow the administrator to delete a referenced address object
  • C. FortiManager will replace the deleted address object with thenoneaddress object in the referenced firewall policy
  • D. FortiManager will replace the deleted address object withalladdress object in the referenced firewall policy

Answer: C

Explanation:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-2/FortiManager_Admin_Guide/1200_Policy%20and%20O


NEW QUESTION # 38
Refer to the exhibit.

Given the configuration shown in the exhibit, what can you conclude from the installation targets m the Install On column? (Choose two)

  • A. Policy seq # 3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
  • B. Policy seq # 2 will not be installed on the Local-FortiGate root VDOM because there is no root VDOM in the Installation Target
  • C. Policy 3 will be installed on all FortiGate devices and vdom belongs to the ADOM
  • D. Policy seq # 3 will be skipped because no installation targets are specified
  • E. Policy seq # 1 will be installed on the Remoto-FortiGate root[NAT] and Student[NAT] VDOMs only

Answer: A,E


NEW QUESTION # 39
Refer to the exhibits.
Exhibit one.

Exhibit two.

An administrator created a new system template namedTrainingwith two new DNS addresses on FortiManager. During the installation preview stage, the administrator notices that many unset commands need to be pushed.
What can be the main reason for these unset commands?

  • A. The ADOM is locked by another administrator
  • B. The DNS addresses in the default system settings are the same as theTrainingsystem template
  • C. TheTrainingsystem template does not have assigned devices
  • D. TheTrainingsystem template has other default settings

Answer: D


NEW QUESTION # 40
Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

  • A. When configuration revision is reverted to previous revision in the revision history
  • B. When FortiManager installs device-level changes to a managed device
  • C. When changes to device-level database is made on FortiManager
  • D. When FortiManager is auto-updated with configuration changes made directly on a managed device

Answer: B,D


NEW QUESTION # 41
View the following exhibit, which shows theDownload Import Report:

Why it is failing to import firewall policy ID 2?

  • A. Policy ID 2 does not have ADOM Interface mapping configured on FortiManager
  • B. Policy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager
  • C. The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association locally on the FortiGate
  • D. Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.

Answer: C

Explanation:
FortiManager_6.4_Study_Guide-Online - page 331 & 332


NEW QUESTION # 42
Which of the following statements are true regarding VPN Gateway configuration in VPN Manager? (Choose two.)

  • A. Protected subnets are the subnets behind the device that you don't want to allow access to over the IPsec VPN
  • B. Managed devices in other ADOMs must be treated as external gateways
  • C. Managed gateways are devices managed by FortiManager in the same ADOM
  • D. External gateways are third-party VPN gateway devices only

Answer: B,C

Explanation:
Reference:http://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG-FAZ/1
300_VPN_Manager/0800_IPsec_VPN_Gateway/0400_Create_mngd_gateway.htm


NEW QUESTION # 43
Refer to the following exhibit:

Which of the following statements are true based on this configuration? (Choose two.)

  • A. Unlocking an ADOM will submit configuration changes automatically to the approval administrator
  • B. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out
  • C. The same administrator can lock more than one ADOM at the same time
  • D. Unlocking an ADOM will install configuration automatically on managed devices

Answer: B,C

Explanation:
Reference:http://help.fortinet.com/fmgr/cli/5-6-2/Document/0800_AD0Ms/200_Configuring+.htm


NEW QUESTION # 44
Refer to the exhibit.

An administrator has configured the command shown in the exhibit on FortiManager. A configuration change has been installed from FortiManager to the managed FortiGate that causes the FGFM tunnel to go down for more than 15 minutes.
What is the purpose of this command?

  • A. It allows the FortiManager to revert and install a previous configuration revision on the managed FortiGate.
  • B. It allows FortiGate to reboot and restore a previously working firmware image.
  • C. It allows FortiGate to reboot and recover the previous configuration from its configuration file.
  • D. It allows FortiGate to unset central management settings.

Answer: C

Explanation:
Reference:https://docs.fortinet.com/document/fortimanager/6.2.0/fortigate-fortimanager-communicationsprotoco


NEW QUESTION # 45
Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

  • A. When configuration revision is reverted to previous revision in the revision history
  • B. When FortiManager installs device-level changes to a managed device
  • C. When changes to device-level database is made on FortiManager
  • D. When FortiManager is auto-updated with configuration changes made directly on a managed device

Answer: B,D

Explanation:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1000_Device%20Manage


NEW QUESTION # 46
Which of the following statements are true regarding reverting to previous revision version from the revision history? (Choose two.)

  • A. Reverting to a previous revision history will generate a new versionIDand remove all other history versions.
  • B. It will modify device-level database
  • C. Reverting to a previous revision history will tag the device settings status asAuto-Update.
  • D. To push these changes to a managed device, it required an install operation to the managed FortiGate.

Answer: B,D


NEW QUESTION # 47
An administrator with theSuper_Userprofile is unable to log in to FortiManager because of an authentication failure message.
Which troubleshooting step should you take to resolve the issue?

  • A. Make sure ADOMs are enabled and the administrator has access to the Global ADOM
  • B. Make sure FortiManager Access is enabled in the administrator profile
  • C. Make sure Offline Mode is disabled
  • D. Make sure the administrator IP address is part of the trusted hosts.

Answer: D

Explanation:
Even if a user entered the correct userid/password, the FMG denies access if a user is logging in from an untrusted source IP subnets.
Reference:https://docs.fortinet.com/document/fortimanager/6.0.3/administration-guide/107347/trusted-hosts


NEW QUESTION # 48
......

Validate your Skills with Updated NSE5_FMG-7.2 Exam Questions & Answers and Test Engine: https://www.practicedump.com/NSE5_FMG-7.2_actualtests.html

Tested & Approved NSE5_FMG-7.2 Study Materials Download: https://drive.google.com/open?id=1_GU_CJzUBDugOMHQnY1HoATqnfmUuXli