[Jun 15, 2024] Fortinet NSE5_FMG-7.2 Real Exam Questions and Answers FREE [Q51-Q76]

Share

[Jun 15, 2024] Fortinet NSE5_FMG-7.2 Real Exam Questions and Answers FREE

Pass Fortinet NSE5_FMG-7.2 Exam Info and Free Practice Test

NEW QUESTION # 51
Refer to the following exhibit:

Which of the following statements are true based on this configuration? (Choose two.)

  • A. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out
  • B. The same administrator can lock more than one ADOM at the same time
  • C. Unlocking an ADOM will submit configuration changes automatically to the approval administrator
  • D. Unlocking an ADOM will install configuration automatically on managed devices

Answer: A,B

Explanation:
Reference:http://help.fortinet.com/fmgr/cli/5-6-2/Document/0800_AD0Ms/200_Configuring+.htm


NEW QUESTION # 52
What does thediagnose dvm check-integritycommand do? (Choose two.)

  • A. Verifies and corrects database schemas in all object tables
  • B. Internally upgrades existing ADOMs to the same ADON version in order to clean up and correct the ADOM syntax
  • C. Verifies and corrects duplicate VDOM entries
  • D. Verifies and corrects unregistered, registered, and deleted device states

Answer: C,D

Explanation:
6.2 Study Guide page 305verify and correct parts of the device manager databases, including:- inconsistent device-to-group and group-to-ADOM memberships- unregistered, registered, and deleted device states- device lock statuses- duplicate VDOM entries


NEW QUESTION # 53
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)

  • A. TheFabric Viewmodule enables you to view the Security Fabric ratings for Security Fabric devices
  • B. The Security Fabric license, group name and password are required for the FortiManager Security Fabric integration
  • C. TheFabric Viewmodule enables you to generate the Security Fabric ratings for Security Fabric devices
  • D. The Security Fabric settings are part of the device level settings

Answer: A,D


NEW QUESTION # 54
Refer to the exhibit.

An administrator logs into the FortiManager GUI and sees the panes shown in the exhibit.
Which two reasons can explain why the FortiAnalyzer feature panesdo notappear? (Choose two.)

  • A. FortiAnalyzer features are not enabled on FortiManager.
  • B. The administrator IP address is not a part of the trusted hosts configured on FortiManager interfaces.
  • C. The administrator logged in using the unsecure protocol HTTP, so the view is restricted.
  • D. The administrator profile does not have full access privileges like theSuper_Userprofile.

Answer: A,D


NEW QUESTION # 55
Refer to the exhibit.

Which statement is true about the FortiManager ADOM policy tab based on the API request?

  • A. The API command has requested the policy tab permissions information only.
  • B. The API command has applied to customer with ID: 200.
  • C. The API command has failed when requesting policy tab permissions information.
  • D. The API command has enabled both central NAT and interface policy on the policy tab.

Answer: D


NEW QUESTION # 56
Refer to the following exhibit:

Which of the following statements are true based on this configuration? (Choose two.)

  • A. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out
  • B. The same administrator can lock more than one ADOM at the same time
  • C. Unlocking an ADOM will submit configuration changes automatically to the approval administrator
  • D. Unlocking an ADOM will install configuration automatically on managed devices

Answer: A,B


NEW QUESTION # 57
View the following exhibit.

Which of the following statements are true based on this configuration setting? (Choose two.)

  • A. This setting will enable the ADOMs feature on FortiManager.
  • B. This setting is applied globally to all ADOMs.
  • C. This setting will allow assigning different VDOMs from the same FortiGate to different ADOMs.
  • D. This setting will allow automatic updates to the policy package configuration for a managed device.

Answer: B,C


NEW QUESTION # 58
Refer to the exhibit.

On FortiManager, an administrator created a new system template named Training with two new DNS addresses. During the installation preview stage, the administrator notices that central-management settings need to be purged.
What can be the main reason for the central-management purge command?

  • A. The Remote-FortiGate device does not have any DNS server-list configured in the central-management settings.
  • B. The Training system template has a default FortiGuard widget.
  • C. The ADOM is locked by another administrator.
  • D. The DNS addresses in the default system settings are the same as the Training system template.

Answer: A


NEW QUESTION # 59
Refer to the exhibit.

You ate using the Quick install option to install configuration changes on the managed FortiGate Which two statements correctly describe the result? (Choose two)

  • A. It install provisioning template changes on the FortiGate device
  • B. It installs all the changes in the device database first and the administrator must reinstall the changes on the FodiGate device
  • C. It installs device-level changes on the FortiGate device without launching the Install Wizard
  • D. It provides the option to preview only the policy package changes before installing them

Answer: A,C


NEW QUESTION # 60
View the following exhibit.

Given the configurations shown in the exhibit, what can you conclude from the installation targets in the Install Oncolumn?

  • A. Policy seq#3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
  • B. The Install On column value represents successful installation on the managed devices
  • C. Policy seq#3 will be installed on the Trainer[NAT] VDOM only
  • D. Policy seq#3 will be not installed on any managed device

Answer: A


NEW QUESTION # 61
What will be the result of reverting to a previous revision version in the revision history?

  • A. It will tag the device settings status asAuto-Update
  • B. It will install configuration changes to managed device automatically
  • C. It will modify the device-level database
  • D. It will generate a new versionIDand remove all other revision history versions

Answer: C


NEW QUESTION # 62
Refer to the exhibit.

Which two statements about an ADOM set inNormalmode on FortiManager are true? (Choose two.)

  • A. FortiManager automatically installs the configuration difference in revisions on the managed FortiGate
  • B. It allows making configuration changes for managed devices on FortiManager panes
  • C. You cannot assign the same ADOM to multiple administrators
  • D. It supports the FortiManager script feature

Answer: B,D

Explanation:
"FortiGate units in the ADOM will query their own configuration every 5 seconds. If there has been a configuration change, the FortiGate unit will send a diff revision on the change to the FortiManager using the FGFM protocol."


NEW QUESTION # 63
Refer to the exhibit.

An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.
After the installation operation is performed, which IP/netmask will be shown on FortiManager for this firewall address object without specify Per-Device Mapping?

  • A. 0.0.0.0/0.
  • B. 192.168.1.0/24.
  • C. The FortiManager replaces the address object to none.
  • D. 10.0.5.0/24.

Answer: B

Explanation:
In the scenario you described, an administrator has created a firewall address object used in multiple policy packages for multiple FortiGate devices within an Administrative Domain (ADOM) on FortiManager. The question concerns the display of this object's IP/netmask in FortiManager after installation, assuming no per-device mapping is specified.
Given the screenshot and the description of the situation, the answer is **C. 192.168.1.0/24**. When you create a firewall address object in FortiManager without specifying per-device mapping, FortiManager uses the generic settings of the object as defined. In the screenshot, the IP/Netmask is set to 192.168.1.0/255.255.255.0, and since there is no per-device variation defined or required in your query, this setting remains as shown in the object's configuration.


NEW QUESTION # 64
Which two items does an FGFM keepalive message include? (Choose two.)

  • A. FortiGate license information
  • B. FortiGate configuration checksum
  • C. FortiGate IPS version
  • D. FortiGate uptime

Answer: B,C

Explanation:
Reference:https://docs.fortinet.com/document/fortimanager/6.2.0/fortigate-fortimanager-communications-protoc


NEW QUESTION # 65
What are two outcomes of ADOM revisions? (Choose two.)

  • A. ADOM revisions can save the current size of the whole ADOM
  • B. ADOM revisions can create System Checkpoints for the FortiManager configuration
  • C. ADOM revisions can save the current state of all policy packages and objects for an ADOM
  • D. ADOM revisions can significantly increase the size of the configuration backups.

Answer: C,D


NEW QUESTION # 66
An administrator run the reload failure command: diagnose test deploymanager reload config
<deviceid> on FortiManager. What does this command do?

  • A. It installs the latest configuration on the specified FortiGate and update the revision history database.
  • B. It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate.
  • C. It installs the provisioning template configuration on the specified FortiGate.
  • D. It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.

Answer: D


NEW QUESTION # 67
Which two statements about the scheduled backup of FortiManager are true? (Choose two.)

  • A. It can be configured using the CLI and GUI.
  • B. It backs up all devices and the FortiGuard database.
  • C. It supports FTP, SCP, and SFTP.
  • D. It does not back up firmware images saved on FortiManager.

Answer: C,D

Explanation:
Reference:https://docs.ansible.com/ansible/latest/collections/fortinet/fortimanager/fmgr_system_backup_allsettin


NEW QUESTION # 68
Refer to the exhibits.
Exhibit one.

Exhibit two.

An administrator created a new system template namedTrainingwith two new DNS addresses on FortiManager. During the installation preview stage, the administrator notices that many unset commands need to be pushed.
What can be the main reason for these unset commands?

  • A. TheTrainingsystem template does not have assigned devices
  • B. The DNS addresses in the default system settings are the same as theTrainingsystem template
  • C. The ADOM is locked by another administrator
  • D. TheTrainingsystem template has other default settings

Answer: D


NEW QUESTION # 69
View the following exhibit:

Which two statements are true if the script is executed using the Remote FortiGate Directly (via CLI) option? (Choose two.)

  • A. FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate.
  • B. You must install these changes using Install Wizard
  • C. FortiGate will auto-update the FortiManager's device-level database.
  • D. FortiManager will create a new revision history.

Answer: C,D


NEW QUESTION # 70
Refer to the exhibit.

You are using theQuick Installoption to install configuration changes on the managed FortiGate.
Which two statements correctly describe the result? (Choose two.)

  • A. It will not create a new revision in the revision history
  • B. It provides the option to preview configuration changes prior to installing them
  • C. It installs device-level changes to FortiGate without launching theInstall Wizard
  • D. It cannot be canceled once initiated and changes will be installed on the managed device

Answer: C,D

Explanation:
FortiManager_6.4_Study_Guide-Online - page 164
The Install Config option allows you to perform a quick installation of device-level settings without launching the Install Wizard. When you use this option, you cannot preview the changes prior to committing.
Administrator should be certain of the changes before using this install option, because the install can't be cancelled after the process is initiated.


NEW QUESTION # 71
View the following exhibit.

Which statement is true regarding this failed installation log?

  • A. Policy ID 2 is installed without a source address
  • B. Policy ID 2 will not be installed
  • C. Policy ID 2 is installed without a source device
  • D. Policy ID 2 is installed in disabled state

Answer: B


NEW QUESTION # 72
Refer to the exhibits.
Exhibit one.

Exhibit two.

An administrator created a new system template named Training with two new DNS addresses on FortiManager. During the installation preview stage, the administrator notices that many unset commands need to be pushed.
What can be the main reason for these unset commands?

  • A. The Training system template has other default settings
  • B. The ADOM is locked by another administrator
  • C. The DNS addresses in the default system settings are the same as the Training system template
  • D. The Training system template does not have assigned devices

Answer: A


NEW QUESTION # 73
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)

  • A. The Fabric View module enables you to view the Security Fabric ratings for Security Fabric devices
  • B. The Fabric View module enables you to generate the Security Fabric ratings for Security Fabric devices
  • C. The Security Fabric license, group name and password are required for the FortiManager Security Fabric integration
  • D. The Security Fabric settings are part of the device level settings

Answer: A,D


NEW QUESTION # 74
Which of the following statements are true regarding reverting to previous revision version from the revision history? (Choose two.)

  • A. To push these changes to a managed device, it required an install operation to the managed FortiGate.
  • B. It will modify device-level database
  • C. Reverting to a previous revision history will generate a new versionIDand remove all other history versions.
  • D. Reverting to a previous revision history will tag the device settings status asAuto-Update.

Answer: A,B


NEW QUESTION # 75
Refer to the exhibit.

According to the error message why is FortiManager failing to add the FortiAnalyzer device?

  • A. The administrator must turn off the Use Legacy Device login and add the FortiAnalyzer device to the same network as Forti-Manager
  • B. The administrator must use the correct user name and password of the FortiAnalyzer device
  • C. The administrator must use the Add Model Device section and discover the FortiAnalyzer device
  • D. The administrator must select the Forti-Manager administrative access checkbox on the FortiAnalyzer management interface

Answer: A


NEW QUESTION # 76
......


Earning the Fortinet NSE5_FMG-7.2 certification validates your expertise in FortiManager 7.2 and proves that you have the skills and knowledge necessary to manage and secure complex networks. Fortinet NSE 5 - FortiManager 7.2 certification is recognized globally and can help you advance your career in network administration and security. With the demand for Fortinet products and services increasing, the Fortinet NSE5_FMG-7.2 certification can open up numerous job opportunities for you.

 

Latest NSE5_FMG-7.2 Exam Dumps Fortinet Exam: https://realexamcollection.examslabs.com/Fortinet/NSE-5-Network-Security-Analyst/best-NSE5_FMG-7.2-exam-dumps.html