Fortinet NSE 5 - FortiManager 7.6 Administrator FCP_FMG_AD-7.6 Exam Questions

Page: 1 / 14
Total 65 questions
Question 1

Refer to Exhibit:

Which two actions will occur if you run the script using the Remote FortiGate Directly via CLI option? Choose two answers



Answer : B, C

The correct answers are B and C. The FortiManager 7.6 Administrator Study Guide explicitly states: ''Scripts that you run directly on remote devices also cause automatic updates and create a revision history.'' This exact extract proves both results: FortiManager creates a new revision history and the device status becomes Auto-Updated, meaning the FortiGate change is automatically reflected in the FortiManager device-level database.

The lab guide also distinguishes this from database-targeted scripts by stating: ''You must perform an installation if you run a script on a device database, policy package, or ADOM database.'' That wording excludes Remote FortiGate Directly via CLI, so D is incorrect.

A is also incorrect because direct remote execution does not use the install preview workflow; preview and validation are tied to Install Wizard operations, not direct CLI execution.

=========


Question 2

Which FortiGate configuration settings is part of an ADOM-level database on FortiManager?



Answer : B

The best verified answer is B. The FortiManager 7.6 Administrator Study Guide shows that the ADOM Layer contains Policy and Objects, and specifically states: ''Policy & Objects: Centralize the management of firewall policies, objects, and security profiles, among others.'' Because security-related policy settings belong to the Policy and Objects layer, they are part of the ADOM-level database.

By contrast, Routing and SNMP are treated as device-level settings. The lab guide shows Routing under the device/network configuration view, and SNMP as a setting in the system template that ''pushes configuration changes to the device level.''

Also, provisioning templates such as NSX-T service are listed as having precedence over device-layer configurations, which further indicates they are not the Policy and Objects ADOM database answer here.

=========


Question 3

What can you conclude from the failed installation log shown in the exhibit?



Answer : D

The correct answer is D. The lab guide explains that when an installation fails, the installation log shows the commands that the managed device received and accepted, as well as the commands that the managed device did not accept.

From the exhibit, FortiGate accepted the policy creation commands for policy ID 2 such as set srcintf port3, set dstintf port1, set srcaddr all, set dstaddr all, set action accept, and set schedule always. However, the line set users student failed with ''entry not found in datasource'' and ''value parse error before 'student'''. That shows the user reference was not accepted, while the rest of the policy commands were processed. Therefore, policy ID 2 is still created, but without the remote user student. This rules out A, B, and C.

=========


Question 4

Which two statements about the integrity of databases on FortiManager are correct? Choose two answers.



Answer : A, E

The correct answers are A and E. The study guide explicitly states under Database Integrity that scheduled backups ''Automatically executes database integrity commands'' and ''Does not automatically make corrections''. That exactly verifies A.

It also states in Best Practices---Database Integrity: ''Always follow the proper upgrade path'' and ''If you don't, it may cause inconsistencies in the database.'' That exactly verifies E.

B is incorrect because diagnose dvm check-integrity verifies and corrects device manager database issues such as device states, memberships, lock statuses, and duplicate VDOM entries, not a corrupted file system. C is incorrect because locked device status issues are listed under diagnose dvm check-integrity, not diagnose cdb check adom-integrity. D is not a stated FortiManager best practice in the uploaded guide.


Question 5

An administrator created a new global policy package that includes both header policies and footer policies. What two things must the administrator know before deploying the global policy package to ADOM2? Choose two answers



Answer : A, B

FortiManager global policies and objects are shared across ADOMs, but they are not applied automatically to every package. The study guide states that when you create a global policy package, you can choose the ADOMs you want to apply it to, and you can even pick specific policy packages in individual ADOMs. That directly validates B.

A is also correct because the lab guide explicitly says you can promote ADOM objects to global objects by right-clicking an ADOM object and selecting Promote to Global.

C is incorrect because when Automatically Install Policies to ADOM Devices is enabled, FortiManager installs without giving you a preview/accept step first; the lab warns to use it only when you are sure of the changes.

D is incorrect because FortiManager imports device policies into an ADOM policy package, not into the global package for synchronization.


Question 6

An administrator assigned the Training global policy package to the Branches policy package in ADOM1. Later, the administrator created a new policy package named Remotes on ADOM1.

What should the administrator do to sync the Training global policy package with the Remotes policy package in ADOM1?



Answer : C

The correct answer is C. The FortiManager 7.6 Administrator Study Guide explicitly says: ''You must explicitly assign global policy packages to specific ADOMs'' and ''you can even pick specific policy packages in individual ADOMs that you want to apply the global policies to.'' The study guide also explains the assignment workflow: ''This slide shows the steps to assign a global policy package to an ADOM policy package'' and ''First, add the required ADOMs as targets. Second, assign the global policy package to the ADOMs.''

Because Remotes is a newly created policy package, it does not inherit the earlier assignment automatically. The administrator must explicitly assign the Training global policy package to the Remotes policy package. Automatic install does not create that assignment, and unassigning all packages is unnecessary.


Question 7

Refer to the exhibit.

What percentage of the available RAM is being used by the process in charge of downloading the web and email filter databases from the public FortiGuard servers?



Answer : D

The correct answer is D. The FortiManager 7.6 Administrator Study Guide gives the exact extract under Web Filter and Email Filter: ''fgdlinkd --- Responsible for downloading web filter and email filter databases''. The same study guide section explains that the execute top command displays real-time CPU and RAM usage, and the %MEM column shows the memory percentage used by each process.

In the exhibit, the line for fgdlinkd shows %MEM 2.9. Therefore, the process responsible for downloading the web and email filter databases is using 2.9% of RAM. That matches option D exactly. The other values belong to different processes, such as fgdsvr and other FortiGuard-related daemons, but not the downloader process identified in the study guide.

=========


Page:    1 / 14   
Total 65 questions