NSE5_FMG-6.2 Practice Dumps - Verified By Test4Cram Updated 85 Questions [Q36-Q53]

Share

NSE5_FMG-6.2 Practice Dumps - Verified By Test4Cram Updated 85 Questions

Updated NSE5_FMG-6.2  Exam Dumps - PDF Questions and Testing Engine

NEW QUESTION 36
Setting workspace-mode to normal, as shown in the exhibit, allows what on FortiManager? (Choose two) config system global set workspace-mode normal end

  • A. Restricted concurrent access
  • B. ADOM locking
  • C. VDOM locking
  • D. Unrestricted concurrent access

Answer: A,B

 

NEW QUESTION 37
View the following exhibit:

How will FortiManager try to get updates for antivirus and IPS?

  • A. From public FDNI server with highest index number only
  • B. From the default server fdsl.fortinet.com
  • C. From the list of configured override servers with ability to fall back to public FDN servers
  • D. From the configured override server list only

Answer: C

 

NEW QUESTION 38
Which of the following conditions trigger FortiManager to create a new revision history? (Choose two.)

  • A. When FortiManager is auto-updated with configuration changes made directly on a managed device
  • B. When changes to device-level database is made on FortiManager
  • C. When configuration revision is reverted to previous revision in the revision history
  • D. When FortiManager installs device-level changes to a managed device

Answer: A,D

Explanation:
When a new configuration is installed, FortiManager compares the latest revision history running on the device with the changes made on FortiManager.
FortiManager then creates a new revision in the revision history and installs these changes on the managed device. Modifying configuration directly on a managed device creates automatically new revision.

 

NEW QUESTION 39
View the following exhibit.

When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)

  • A. Provides the option to preview configuration changes prior to installing them
  • B. Will not create new revision in the revision history
  • C. Installs device-level changes to FortiGate without launching the Install Wizard
  • D. Once initiated, the install process cannot be canceled and changes will be installed on the managed device

Answer: C,D

 

NEW QUESTION 40
View the following exhibit.

What of the following statements are true regarding the output? (Choose two.)

  • A. The latest revision history for the managed FortiGate does match with the FortiGate running configuration
  • B. Configuration changes directly made on the FortiGate have been automatically updated to device-level database
  • C. The latest history for the managed FortiGate does not match with the device-level database
  • D. Configuration changes have been installed to FortiGate and represents FortiGate configuration has been changed

Answer: A,B

Explanation:
This example shows that FortiGate configuration is in sync with the latest running revision history. However, change have been made to device-level settings.
Once the changes are installed on FortiGate, it will show db: unmodified and cond:OK.

 

NEW QUESTION 41
View the following exhibit, which shows the Download Import Report:

Why it is failing to import firewall policy ID 2?

  • A. Policy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager
  • B. The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association locally on the FortiGate
  • C. Policy ID 2 does not have ADOM Interface mapping configured on FortiManager
  • D. Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.

Answer: B

Explanation:
FortiManager can create a dynamic mapping for an address object, if the address object name is the same, but contains a different value locally. However, there is one restriction - the associated interface cannot be different. This is because, at the ADOM level, this address object might be used by other policy packages, which might not have same interfaces." Address object name in this case is "REMOTE_SUBNET". The interface binding has 2 different interfaces 'ANY' and
'Port6'. They cannot be different.

 

NEW QUESTION 42
An administrator run the reload failure command: diagnose test deploymanager reload config <deviceid> on FortiManager. What does this command do?

  • A. It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate.
  • B. It installs the latest configuration on the specified FortiGate and update the revision history database.
  • C. It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.
  • D. It installs the provisioning template configuration on the specified FortiGate.

Answer: C

Explanation:
diagnose test deploymanager reloadconf: Reload configuration from the FortiGate
https://docs-fortinet.com/uploaded/files/3874/FortiManager%205.6.0%20CLI%20Reference.pdf

 

NEW QUESTION 43
Which of the following items does an FGFM keepalive message include? (Choose two.)

  • A. FortiGate IPS version
  • B. FortiGate license information
  • C. FortiGate configuration checksum
  • D. FortiGate uptime

Answer: B,C

Explanation:
FGFM Keepalive Messages configured on FortiManager. Only FortiGate sends a keepalive message to FortiManager, regardless of which device established the FGFM tunnel. FortiGate also sends a configuration checksum to confirm synchronization as a part of keepalive.

 

NEW QUESTION 44
A FortiGate device is imported to FortiManager using the settings given in the exhibit.

An administrator subsequently modifies and installs the policy package.
Which two statements are correct regarding the scenario? (Choose two)

  • A. The FortiManager imported all unused objects to the ADOM object database. These objects can be used by referencing in the policies on FortiManager and installing to the managed devices.
  • B. The orphan (unused) objects that are not tied to policies locally on the FortiGate will not be deleted on install.
  • C. The orphan (unused) objects that are not tied to policies locally on the FortiGate will be deleted on install.
  • D. The FortiManager did not import unused objects to the ADOM object database. These objects cannot be used by referencing in the policies on FortiManager and installing to the managed devices.

Answer: C,D

 

NEW QUESTION 45
Refer to the exhibit.

An administrator logs into the FortiManager GUI and sees the panes shown in the exhibit.
Which two reasons can explain why the FortiAnalyzer feature panes do not appear? (Choose two.)

  • A. The administrator IP address is not a part of the trusted hosts configured on FortiManager interfaces.
  • B. The administrator profile does not have full access privileges like the Super_User profile.
  • C. The administrator logged in using the unsecure protocol HTTP, so the view is restricted.
  • D. FortiAnalyzer features are not enabled on FortiManager.

Answer: A,D

 

NEW QUESTION 46
An administrator wants to delete an address object that is currently referenced in a firewall policy.
What can the administrator expect to happen?

  • A. FortiManager will replace the deleted address object with the all address object in the referenced firewall policy.
  • B. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy.
  • C. FortiManager will not allow the administrator to delete a referenced address object.
  • D. FortiManager will disable the status of the referenced firewall policy.

Answer: B

 

NEW QUESTION 47
What configuration setting for FortiGate is part of a device-level database on FortiManager?

  • A. Firewall policies
  • B. VIP and IP Pools
  • C. Routing
  • D. Security profiles

Answer: C

 

NEW QUESTION 48
Refer to the exhibit.

An administrator has created a firewall address object which is used in multiple policy packages for multiple FortiGate devices in an ADOM.
When the installation operation is performed, which IP/Netmask will be installed on managed devices for this firewall address object?

  • A. 10.200.1.0/24on Remote-FortiGate
  • B. If no dynamic mapping is defined for other FortiGate devices, the object will not be installed
  • C. The FortiManager administrator can choose the value for the firewall address object in the Install Wizard for Remote-FortiGate
  • D. 192.168.0.1/24on Remote-FortiGate

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 49
As a result of enabling FortiAnalyzer features on FortiManager, which of the following statements is true?

  • A. FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager
  • B. FortiManager can be used only as a logging device.
  • C. FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices
  • D. FortiManager will reboot

Answer: D

 

NEW QUESTION 50
Refer to the exhibit.

Which two statements about an ADOM set in Normal mode on FortiManager are true? (Choose two.)

  • A. It supports the FortiManager script feature
  • B. It allows making configuration changes for managed devices on FortiManager panes
  • C. FortiManager automatically installs the configuration difference in revisions on the managed FortiGate
  • D. You cannot assign the same ADOM to multiple administrators

Answer: B,C

 

NEW QUESTION 51
What is the purpose of the Policy Check feature on FortiManager?

  • A. To find and provide recommendation for optimizing policies in a policy package
  • B. To find and provide recommendation to combine multiple separate policy packages into one common policy package
  • C. To find and delete disabled firewall policies in the policy package
  • D. To find and merge duplicate policies in the policy package

Answer: D

Explanation:
The policy check tool allows you to check all policy packages within an ADOM to ensure consistency and eliminate conflicts that may prevent your devices from passing traffic. This allows you to optimize your policy sets and potentially reduce the size of your databases. The check will verify:
1. Object duplication: two objects that have identical definitions
2. Object shadowing: a higher priority object completely encompasses another object of the same type
3. Object overlap: one object partially overlaps another object of the same type
4. Object orphaning: an object has been defined but has not been used anywhere.
Reference: https://docs.fortinet.com/uploaded/files/2905/FortiManager-5.4.0-Administration-Guide.pdf

 

NEW QUESTION 52
When a FortiManager HA primary device fails, which two statements are correct for promoting a secondary device to the primary role? (Choose two)

  • A. The FortiManager HA suports IP takeover where an HA state transition does not require manual intervention.
  • B. Must manually reconfigure one of the secondary devices to become the master device.
  • C. Reboot is required when promoting from secondary to primary.
  • D. All other secondary devices must be reconfigured to point to new primary device.

Answer: B,D

 

NEW QUESTION 53
......

New (2021) Fortinet NSE5_FMG-6.2  Exam Dumps: https://www.test4cram.com/NSE5_FMG-6.2_real-exam-dumps.html