[Q39-Q61] 2024 Updated NSE5_FMG-7.2 PDF for the NSE5_FMG-7.2 Tests Free Updated Today!

Share

2024 Updated NSE5_FMG-7.2 PDF for the NSE5_FMG-7.2 Tests Free Updated Today!

Fully Updated Dumps PDF - Latest NSE5_FMG-7.2 Exam Questions and Answers

NEW QUESTION # 39
What will be the result of reverting to a previous revision version in the revision history?

  • A. It will tag the device settings status asAuto-Update
  • B. It will modify the device-level database
  • C. It will generate a new versionIDand remove all other revision history versions
  • D. It will install configuration changes to managed device automatically

Answer: B


NEW QUESTION # 40
Refer to the exhibit.

On FortiManager, an administrator created a new system template namedTrainingwith two new DNS addresses. During the installation preview stage, the administrator notices that central-management settings need to be purged.
What can be the main reason for the central-management purge command?

  • A. The DNS addresses in the default system settings are the same as the Training system template.
  • B. The ADOM is locked by another administrator.
  • C. The Remote-FortiGate device does not have any DNS server-list configured in the central-management settings.
  • D. The Training system template has a default FortiGuard widget.

Answer: C


NEW QUESTION # 41
What is the advantage of using FortiManager to manage PortiAnalyzer?

  • A. It allows FortiManager to store all managed FortiGate device logs
  • B. It allows FortiManager to fun reports based on FortiAnalyzer
  • C. It allows FortiManager to act as a collector and FortiAnalyzer device
  • D. It allows FortiManager to manage all FortiGate devices

Answer: C


NEW QUESTION # 42
View the following exhibit:

An administrator used the value shown in the exhibit when importing a Local-FortiGate into FortiManager.
What name will be used to display the firewall policy for port1?

  • A. port1 on FortiGate and WAN on FortiManager
  • B. WAN zone on FortiGate and WAN zone on FortiManager
  • C. port1 on both FortiGate and FortiManager
  • D. WAN zone on FortiGate and WAN interface on FortiManager

Answer: A


NEW QUESTION # 43
What does thediagnose dvm check-integritycommand do? (Choose two.)

  • A. Verifies and corrects database schemas in all object tables
  • B. Internally upgrades existing ADOMs to the same ADON version in order to clean up and correct the ADOM syntax
  • C. Verifies and corrects duplicate VDOM entries
  • D. Verifies and corrects unregistered, registered, and deleted device states

Answer: C,D

Explanation:
6.2 Study Guide page 305verify and correct parts of the device manager databases, including:- inconsistent device-to-group and group-to-ADOM memberships- unregistered, registered, and deleted device states- device lock statuses- duplicate VDOM entries


NEW QUESTION # 44
An administrator with theSuper_Userprofile is unable to log in to FortiManager because of an authentication failure message.
Which troubleshooting step should you take to resolve the issue?

  • A. Make sure the administrator IP address is part of the trusted hosts.
  • B. Make sure ADOMs are enabled and the administrator has access to the Global ADOM
  • C. Make sure Offline Mode is disabled
  • D. Make sure FortiManager Access is enabled in the administrator profile

Answer: A

Explanation:
Even if a user entered the correct userid/password, the FMG denies access if a user is logging in from an untrusted source IP subnets.
Reference:https://docs.fortinet.com/document/fortimanager/6.0.3/administration-guide/107347/trusted-hosts


NEW QUESTION # 45
What are two outcomes of ADOM revisions? (Choose two.)

  • A. ADOM revisions can save the current state of all policy packages and objects for an ADOM
  • B. ADOM revisions can create System Checkpoints for the FortiManager configuration
  • C. ADOM revisions can save the current size of the whole ADOM
  • D. ADOM revisions can significantly increase the size of the configuration backups.

Answer: A,D

Explanation:
Reference:https://docs2.fortinet.com/document/fortimanager/6.0.0/best-practices/101837/adom-revisions


NEW QUESTION # 46
View the following exhibit.

If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)

  • A. FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management.
  • B. During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
  • C. If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
  • D. FortiGate is discovered by FortiManager through the FortiGate NATed IP address.

Answer: B,D

Explanation:
Fortimanager can discover FortiGate through a NATed FortiGate IP address. If a FortiManager NATed IP address is configured on FortiGate, then FortiGate can announce itself to FortiManager. FortiManager will not attempt to re-establish the FGFM tunnel to the FortiGate NATed IP address, if the FGFM tunnel is interrupted.
Just like it was in the NATed FortiManager scenario, the FortiManager NATed IP address in this scenario is not configured under FortiGate central management configuration.


NEW QUESTION # 47
An administrator would like to authorize a newly-installed AP using AP Manager. What steps does the administrator need to perform to authorize an AP?

  • A. Changes to the AP's state must be performed directly on the managed FortiGate.
  • B. Authorize the new AP using AP Manager and install the device level settings on the managed FortiGate.
  • C. Authorize the new AP using AP Manager and wait until the change is updated on the FortiAP. Changes to the AP's state do not require installation.
  • D. Authorize the new AP using AP Manager and install the policy package changes on the managed FortiGate.

Answer: B


NEW QUESTION # 48
Which of the following statements are true regarding schedule backup of FortiManager? (Choose two.)

  • A. Can be configured from the CLI and GUI
  • B. Does not back up firmware images saved on FortiManager
  • C. Backs up all devices and the FortiGuard database.
  • D. Supports FTP, SCP, and SFTP

Answer: B,D


NEW QUESTION # 49
Refer to the exhibit.

An administrator is about to add the FortiGate device to FortiManager using the discovery process FortiManager is operating behind a NAT device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings What is the expected result?

  • A. During discovery FortiManager uses only the FortiGate serial number to establish the connection
  • B. During discovery FortiManager sets the NATed device IP address on FortiGate
  • C. During discovery FortiManager sets trie FortiManager NATed IP address on FortiGate
  • D. During discovery FortiManager sets both tie FortiManager NATed IP address and NAT device IP address on FortiGate

Answer: B


NEW QUESTION # 50
In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator authorized the FortiGate device on FortiManager using the Fortinet Security Fabric.
Given the administrator's actions, which statement correctly describes the expected result?

  • A. The authorized FortiGate will appear in the root ADOM.
  • B. The authorized FortiGate will be automatically added to the Training ADOM.
  • C. The authorized FortiGate can be added to the Training ADOM using FortiGate Fabric Connectors.
  • D. The FortiManager administrator must add the authorized device to the Training ADOM using the Add Device wizard only.

Answer: A


NEW QUESTION # 51
An administrator would like to create an SD-WAN using central management in theTrainingADOM.
To create an SD-WAN using central management, which two steps must be completed? (Choose two.)

  • A. Enable SD-WAN central management in theTrainingADOM
  • B. Remove all the interface references such as routes or policies that will be a part of SD-WAN member interfaces
  • C. Specify a gateway address when you create a default SD-WAN static route
  • D. Configure and install the SD-WAN firewall policy and SD-WAN static route before installing the SD-WAN template settings

Answer: A,B

Explanation:
Reference:https://docs.fortinet.com/document/fortigate/6.0.0/cookbook/676493/removing-existing-configuration


NEW QUESTION # 52
View the following exhibit.

An administrator is importing a new device to FortiManager and has selected the shown options. What will happen if the administrator makes the changes and installs the modified policy package on this managed FortiGate?

  • A. The unused objects that are not tied to the firewall policies in policy package will be deleted from the FortiManager database
  • B. The unused objects that are not tied to the firewall policies will remain as read-only locally on FortiGate
  • C. The unused objects that are not tied to the firewall policies locally on FortiGate will be deleted
  • D. The unused objects that are not tied to the firewall policies will be installed on FortiGate

Answer: C

Explanation:
Reference:https://community.fortinet.com/t5/FortiManager/Import-all-objects-Versus-Import-only-policy-depend


NEW QUESTION # 53
Which two settings must be configured for SD-WAN Central Management? (Choose two.)

  • A. You can create multiple SD-WAN interfaces per VDOM
  • B. When you configure an SD-WAN, you must specify at least two member interfaces.
  • C. SD-WAN must be enabled on per-ADOM basis
  • D. The first step in creating an SD-WAN using FortiManager is to create two SD-WAN firewall policies.

Answer: B,C


NEW QUESTION # 54
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)

  • A. TheFabric Viewmodule enables you to view the Security Fabric ratings for Security Fabric devices
  • B. The Security Fabric license, group name and password are required for the FortiManager Security Fabric integration
  • C. TheFabric Viewmodule enables you to generate the Security Fabric ratings for Security Fabric devices
  • D. The Security Fabric settings are part of the device level settings

Answer: A,D


NEW QUESTION # 55
View the following exhibit.

Given the configurations shown in the exhibit, what can you conclude from the installation targets in the Install Oncolumn?

  • A. Policy seq#3 will be installed on the Trainer[NAT] VDOM only
  • B. Policy seq#3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
  • C. The Install On column value represents successful installation on the managed devices
  • D. Policy seq#3 will be not installed on any managed device

Answer: B


NEW QUESTION # 56
Refer to the exhibit.

According to the error message why is FortiManager failing to add the FortiAnalyzer device?

  • A. The administrator must turn off the Use Legacy Device login and add the FortiAnalyzer device to the same network as Forti-Manager
  • B. The administrator must use the Add Model Device section and discover the FortiAnalyzer device
  • C. The administrator must select the Forti-Manager administrative access checkbox on the FortiAnalyzer management interface
  • D. The administrator must use the correct user name and password of the FortiAnalyzer device

Answer: A


NEW QUESTION # 57
Which configuration setting for FortiGate is part of a device-level database on FortiManager?

  • A. VIP and IP Pools
  • B. Security profiles
  • C. Routing
  • D. Firewall policies

Answer: B

Explanation:
The FortiManager stores the FortiGate configuration details in two distinct databases. The device-level database includes configuration details related to device-level settings, such as interfaces, DNS, routing, and more. The ADOM-level database includes configuration details related to firewall policies, objects, and security profiles.


NEW QUESTION # 58
Refer to the exhibit.

Given the configuration shown in the exhibit, how did FortiManager handle the service category named General?

  • A. FortiManager ignored the firewall service category General and updated the FortiGate duplicate value in the FortiGate database.
  • B. FortiManager ignored the firewall service category general and deleted the duplicate value In Its database
  • C. FortiManager ignored the firewall service category General but created a new service category in its database.
  • D. FortiManager ignored the firewall service category General and did not update Its database with the value

Answer: D


NEW QUESTION # 59
Refer to the following exhibit:

Which of the following statements are true based on this configuration? (Choose two.)

  • A. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out
  • B. Unlocking an ADOM will submit configuration changes automatically to the approval administrator
  • C. Unlocking an ADOM will install configuration automatically on managed devices
  • D. The same administrator can lock more than one ADOM at the same time

Answer: A,D

Explanation:
Reference:http://help.fortinet.com/fmgr/cli/5-6-2/Document/0800_AD0Ms/200_Configuring+.htm


NEW QUESTION # 60
What will happen if FortiAnalyzer features are enabled on FortiManager?

  • A. FortiManager will reboot
  • B. FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager
  • C. FortiManager can be used only as a logging device.
  • D. FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices

Answer: A

Explanation:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1800_FAZ%20Features/0


NEW QUESTION # 61
......

Free NSE5_FMG-7.2 Exam Questions NSE5_FMG-7.2 Actual Free Exam Questions: https://testprep.dumpsvalid.com/NSE5_FMG-7.2-brain-dumps.html