Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert FCP_FMG_AD-7.6 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Company policy dictates that any time a change is made to a policy package on FortiManager an ADOM revision is created before the change installed, and that revision is held for a minimum of 90 days.

Over the past three months, each installed change has resulted in several unused policies and duplicate objects.

The FortiManager administrator plans to upgrade the FortiGate devices and then upgrade the FortiManager ADOM from version 7.4 to 7.6.

Which action can the administrator take to avoid slow ADOM upgrades?

Options:

A.

Check and repair the global configuration database before upgrading.


B.

Export firewall policies to Excel, delete them on the ADOM. then reimport them after upgrading the ADOM.


C.

Find unused firmware templates, then delete them before upgrading.


D.

Limit ADOM revisions before upgrading.


Expert Solution
Questions # 12:

Refer to the exhibits.

Question # 12

Question # 12

An administrator has been asked to install the same policies from a central policy package onto the BR1-FGT-1 firewall.

The administrator added BR1-FGT-1 as a target in the central policy package installation.

What should the administrator do when reinstalling the central policy package on the BR1-FGT-1 firewall?

Options:

A.

Assign only one policy package to the firewall because FortiManager does not allow more than one policy package assigned per device at the same time.


B.

Import the policy package to change the unknown status and synchronize the policy package.


C.

Use the install wizard to install the central policy package on the BR1-FGT-1 firewall.


D.

First resolve the modified status in the configuration and provisioning templates to allow a smooth installation.


Expert Solution
Questions # 13:

What is the purpose of ADOM revisions?

Options:

A.

ADOM revisions find unused, duplicate, and unnecessary firewall policies and objects.


B.

ADOM revisions show specific changes in a policy package when it is installed.


C.

ADOM revisions compare previous snapshots of the Policy Package and ADOM-level objects with the device-level database.


D.

ADOM revisions save the current state of all policy packages and objects for an ADOM.


Expert Solution
Questions # 14:

Refer to the exhibits.

Question # 14

Question # 14

Question # 14

An administrator must replace the source LAN interface in policy ID 2 on their FortiGateRugged-70F.

However, when they try to install the policy package, they receive the error shown in the exhibit.

What should the administrator do to resolve the error?

Options:

A.

Use the API to assign a system template interface for FortiGateRugged-70F model.


B.

Use a metadata variable to dynamically assign an interface when this error occurs.


C.

Create a per-device mapping for the LAN interface.


D.

Replace LAN with lan1, which is supported by FortiGateRugged-70F models.


Expert Solution
Questions # 15:

Refer to the exhibit.

Question # 15

FortiManager is operating behind a network address translation (NAT) device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings.

What is the expected result during discovery?

Options:

A.

FortiManager sets both the 100.65.0.120 IP address and 10.0.13.120 IP address on FortiGate.


B.

FortiManager sets both the 100.65.0.120 IP address and 100.65.0.101 IP address on FortiGate.


C.

FortiManager sets the 100.65.0.101 IP address on FortiGate.


D.

FortiManager sets the 100.65.0.120 IP address on FortiGate.


Expert Solution
Questions # 16:

An administrator suspects that the Collector Agent is not forwarding login events to FortiGate.

What is the most effective troubleshooting step?

Options:

A.

Verify if DC agent is enabled on the FortiGate.


B.

Restart the domain controller to refresh authentication services.


C.

Verify if FortiGate is set to use LDAP authentication instead of FSSO.


D.

Check if TCP port 8000 is open between the collector agent and FortiGate.


Expert Solution
Questions # 17:

An administrator upgrades FortiManager with workspace mode per ADOM enabled to the latest version but notices that the ADOM versions did not change.

Why were the ADOMs not upgraded?

Options:

A.

The administrator did not run the database integrity check before performing the upgrade.


B.

FortiManager does not automatically upgrade ADOMs after a firmware upgrade.


C.

A FortiManager process task is stuck and blocking the ADOM upgrade, so the administrator must fix it.


D.

A user had all ADOMs locked before the upgrade, which stopped them from being upgraded.


Expert Solution
Questions # 18:

An administrator has assigned a global policy package to a new ADOM named ADOM1.

What will happen if the administrator tries to create a new policy package in ADOM1?

Options:

A.

The administrator will be able to select the option to assign the global policy package to the new policy package.


B.

FortiManager will automatically assign the global policy package to the new policy package.


C.

FortiManager will automatically install policies on the policy package in ADOM1.


D.

The administrator will have to assign the global policy package from the global ADOM.


Expert Solution
Questions # 19:

What allows FortiManager to run CLI scripts on FortiGate devices without prompting for SSH authentication each time?

Options:

A.

FortiGate devices using the legacy login method.


B.

The secure management tunnel between FortiManager and FortiGate devices.


C.

The script using the Remote FortiGate Directly via CLI option.


D.

The script on the FortiManager device database.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions