NSE5_FMG-7.2 Practice Fortinet Verified Answers - Pass Your Exams For Sure! [2024]
Valid Way To Pass NSE 5 Network Security Analyst's NSE5_FMG-7.2 Exam
NEW QUESTION # 42
View the following exhibit.
What is the purpose of setting ADOM Mode to Advanced?
- A. The setting enables the ADOMs feature on FortiManager
- B. This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.
- C. The setting disables concurrent ADOM access and adds ADOM locking
- D. The setting allows automatic updates to the policy package configuration for a managed device
Answer: B
NEW QUESTION # 43
View the following exhibit:
How will FortiManager try to get updates for antivirus and IPS?
- A. From public FDNI server with highest index number only
- B. From the configured override server list only
- C. From the list of configured override servers with ability to fall back to public FDN servers
- D. From the default server fdsl.fortinet.com
Answer: C
NEW QUESTION # 44
Refer to the exhibit.
How will FortiManager try to get updates for antivirus and IPS?
- A. From the configured override server IP address 10.0.1.50 only
- B. From the list of configured override servers or public FDN servers
- C. From public FDNI server IP address with the fourth highest octet only
- D. From the default server fds1.fortinet.com
Answer: B
NEW QUESTION # 45
An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session.
What can prevent an admin account that has Super_User rights over the device from approving a workflow session?
- A. Student, who submitted the workflow session, must first self-approve the request
- B. Trainer is not a part of workflow approval group
- C. Trainer must close Student's workflow session before approving the request
- D. Trainer does not have full rights over this ADOM
Answer: B
NEW QUESTION # 46
Refer to the exhibit.
Given the configuration shown in the exhibit, which two statements are true? (Choose two.)
- A. FortiManager is in workflow mode.
- B. The FortiManager ADOM is locked by the administrator.
- C. An administrator can also lock the Local-FortiGate-1 policy package.
- D. The FortiManager ADOM workspace mode is set to Normal.
Answer: B,C
NEW QUESTION # 47
In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator sent a device registration to FortiManager from a remote FortiGate. Which one of the following statements is true?
- A. By default, the unregistered FortiGate will appear in the root ADOM.
- B. The FortiGate will be added automatically to the default ADOM named FortiGate.
- C. The FortiGate will be automatically added to the Training ADOM.
- D. The FortiManager administrator must add the unregistered device manually to the unregistered device
Answer: A
Explanation:
manually to the Training ADOM using the Add Device wizard
NEW QUESTION # 48
Refer to the exhibits.
Exhibit one.
Exhibit two.
An administrator created a new system template named Training with two new DNS addresses on FortiManager. During the installation preview stage, the administrator notices that many unset commands need to be pushed.
What can be the main reason for these unset commands?
- A. The DNS addresses in the default system settings are the same as the Training system template
- B. The Training system template has other default settings
- C. The ADOM is locked by another administrator
- D. The Training system template does not have assigned devices
Answer: B
NEW QUESTION # 49
Which two items are included in the FortiManager backup? (Choose two.)
- A. All devices
- B. FortiGuard database
- C. Global database
- D. Logs
Answer: A,C
Explanation:
Reference:https://kb.fortinet.com/kb/viewContent.do?externalId=FD34549
NEW QUESTION # 50
Refer to the exhibit.
A junior administrator is troubleshooting a FortiManager connectivity issue that rs occurring with managed FortiGate devices Given the FortiManager device manager settings shown in the exhibit what can you conclude from the exhibit?
- A. FortiManager test internet connectivity therefore, both devices appear to be down
- B. The administrator had restored the FortiManager configuration file
- C. The administrator must refresh both devices to restore connectivity
- D. The administrator can reclaim the FGFM tunnel to get both devices online
Answer: A
NEW QUESTION # 51
What will happen if FortiAnalyzer features are enabled on FortiManager?
- A. FortiManager will reboot
- B. FortiManager can be used only as a logging device.
- C. FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager
- D. FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices
Answer: A
NEW QUESTION # 52
An administrator run the reload failure command: diagnose test deploymanager reload config
<deviceid> on FortiManager. What does this command do?
- A. It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate.
- B. It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.
- C. It installs the provisioning template configuration on the specified FortiGate.
- D. It installs the latest configuration on the specified FortiGate and update the revision history database.
Answer: B
NEW QUESTION # 53
Refer to the exhibit.
An administrator has configured the command shown in the exhibit on FortiManager. A configuration change has been installed from FortiManager to the managed FortiGate that causes the FGFM tunnel to go down for more than 15 minutes.
What is the purpose of this command?
- A. It allows FortiGate to reboot and restore a previously working firmware image.
- B. It allows FortiGate to reboot and recover the previous configuration from its configuration file.
- C. It allows the FortiManager to revert and install a previous configuration revision on the managed FortiGate.
- D. It allows FortiGate to unset central management settings.
Answer: B
NEW QUESTION # 54
In the event that one of the secondary FortiManager devices fails, which action must be performed to return the FortiManager HA manual mode to a working state?
- A. Reconfigure the primary device to remove the peer IP of the failed device.
- B. The FortiManaqer HA state transition is transparent to administrators and does not require any reconfiguration.
- C. Reboot the failed device to remove its IP from the primary device.
- D. Manually promote one of the working secondary devices to the primary role, and reboot the old primary device to remove the peer IP of the failed device.
Answer: A
NEW QUESTION # 55
Which of the following statements are true regarding VPN Gateway configuration in VPN Manager? (Choose two.)
- A. External gateways are third-party VPN gateway devices only
- B. Protected subnets are the subnets behind the device that you don't want to allow access to over the IPsec VPN
- C. Managed gateways are devices managed by FortiManager in the same ADOM
- D. Managed devices in other ADOMs must be treated as external gateways
Answer: C,D
Explanation:
Reference:http://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG-FAZ/1
300_VPN_Manager/0800_IPsec_VPN_Gateway/0400_Create_mngd_gateway.htm
NEW QUESTION # 56
View the following exhibit.
When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)
- A. Will not create new revision in the revision history
- B. Once initiated, the install process cannot be canceled and changes will be installed on the managed device
- C. Provides the option to preview configuration changes prior to installing them
- D. Installs device-level changes to FortiGate without launching the Install Wizard
Answer: B,D
NEW QUESTION # 57
In the event that the primary FortiManager fails, which of the following actions must be performed to return the FortiManager HA to a working state?
- A. Secondary device with highest priority will automatically be promoted to the primary role, and manually reconfigure all other secondary devices to point to the new primary device
- B. Reboot one of the secondary devices to promote it automatically to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- C. Manually promote one of the secondary devices to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- D. FortiManager HA state transition is transparent to administrators and does not require any reconfiguration.
Answer: C
Explanation:
FortiManager_6.4_Study_Guide-Online - page 346
FortiManager HA doesn't support IP takeover where an HA state transition is transparent to administrators. If a failure of the primary occurs, the administrator must take corrective action to resolve the problem that may include invoking the state transition. If the primary device fails, the administrator must do the following in order to return the FortiManager HA to a working state:
1. Manually reconfigure one of the secondary devices to become the primary device
2. Reconfigure all other secondary devices to point to the new primary device
NEW QUESTION # 58
An administrator with theSuper_Userprofile is unable to log in to FortiManager because of an authentication failure message.
Which troubleshooting step should you take to resolve the issue?
- A. Make sure FortiManager Access is enabled in the administrator profile
- B. Make sure ADOMs are enabled and the administrator has access to the Global ADOM
- C. Make sure the administrator IP address is part of the trusted hosts.
- D. Make sure Offline Mode is disabled
Answer: C
Explanation:
Even if a user entered the correct userid/password, the FMG denies access if a user is logging in from an untrusted source IP subnets.
Reference:https://docs.fortinet.com/document/fortimanager/6.0.3/administration-guide/107347/trusted-hosts
NEW QUESTION # 59
Which two statements regarding device management on FortiManager are true? (Choose two.)
- A. The maximum number of managed devices for each ADOM is 500.
- B. FortiGate devices in HA cluster devices are counted as a single device.
- C. FortiGate devices in an HA cluster that has five VDOMs are counted as five separate devices.
- D. FortiGate in transparent mode configurations are not counted toward the device count on FortiManager.
Answer: B,C
NEW QUESTION # 60
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)
- A. The Security Fabric settings are part of the device level settings
- B. The Security Fabric license, group name and password are required for the FortiManager Security Fabric integration
- C. TheFabric Viewmodule enables you to view the Security Fabric ratings for Security Fabric devices
- D. TheFabric Viewmodule enables you to generate the Security Fabric ratings for Security Fabric devices
Answer: A,C
NEW QUESTION # 61
Refer to the following exhibit:
Which of the following statements are true based on this configuration? (Choose two.)
- A. The same administrator can lock more than one ADOM at the same time
- B. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out
- C. Unlocking an ADOM will install configuration automatically on managed devices
- D. Unlocking an ADOM will submit configuration changes automatically to the approval administrator
Answer: A,B
NEW QUESTION # 62
An administrator configures a new firewall policy on FortiManager and has not yet pushed the changes to the managed FortiGate.
In which database will the configuration be saved?
- A. Configuration-level database
- B. ADOM-level database
- C. Device-level database
- D. Revision history database
Answer: B
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47942
NEW QUESTION # 63
What is the purpose of the Policy Check feature on FortiManager?
- A. To find and merge duplicate policies in the policy package
- B. To find and provide recommendation to combine multiple separate policy packages into one common policy package
- C. To find and delete disabled firewall policies in the policy package
- D. To find and provide recommendation for optimizing policies in a policy package
Answer: D
NEW QUESTION # 64
Refer to the exhibit.
You ate using the Quick install option to install configuration changes on the managed FortiGate Which two statements correctly describe the result? (Choose two)
- A. It installs device-level changes on the FortiGate device without launching the Install Wizard
- B. It install provisioning template changes on the FortiGate device
- C. It provides the option to preview only the policy package changes before installing them
- D. It installs all the changes in the device database first and the administrator must reinstall the changes on the FodiGate device
Answer: A,B
NEW QUESTION # 65
Which two items are included in the FortiManager backup? (Choose two.)
- A. All devices
- B. FortiGuard database
- C. Global database
- D. Logs
Answer: A,C
NEW QUESTION # 66
......
Fortinet NSE5_FMG-7.2 exam is designed to test the knowledge and skills of IT professionals in managing and configuring FortiManager 7.2. FortiManager is a centralized management solution for Fortinet devices, allowing IT teams to efficiently manage and monitor their network infrastructure. NSE5_FMG-7.2 exam is ideal for IT professionals who are responsible for managing Fortinet devices in their organization.
Fortinet NSE5_FMG-7.2 Pre-Exam Practice Tests | ExamcollectionPass: https://www.examcollectionpass.com/Fortinet/NSE5_FMG-7.2-practice-exam-dumps.html
NSE5_FMG-7.2 practice test questions, answers, explanations: https://drive.google.com/open?id=1FvvI7dVC5WsjbiS7xBghEIdy3HTsFcVi