WorksheetsNSE5 - FortiManager 7.2 (2)
Total questions: 33
Worksheet time: 17mins
Name
Class
Date
1.
You are moving managed FortiGate devices from one ADOM to a new ADOM.
Which statement correctly describes the expected result?
a)
The shared device settings will be installed automatically.
b)
Any unused objects from a previous ADOM are moved to the new ADOM automatically.
c)
The shared policy package will not be moved to the new ADOM.
d)
Policy packages will be imported into the new ADOM automatically.
2.
What is the purpose of ADOM revisions?*
a)
To save the FortiManager configuration in the System Checkpoints
b)
To revert individual policy packages and device-level settings for a managed FortiGate
c)
To save the current state of the whole ADOM
d)
To save the current state of all policy packages and objects for an ADOM
3.
Which two statements about the scheduled backup of FortiManager are true? (Choose two.)
a)
It can be configured using the CLI and GUI.
b)
It does not back up firmware images saved on FortiManager.
c)
It backs up all devices and the FortiGuard database.
d)
It supports FTP, SCP, and SFTP.
4.
An administrator has enabled Service Access on FortiManager.
What is the purpose of Service Access on the FortiManager interface?
a)
It allows administrative access to FortiManager.
b)
It allows FortiManager to determine the connection status of managed devices.
c)
It allows third-party applications to gain read/write access to FortiManager.
d)
It allows FortiManager to respond to requests for FortiGuard services from FortiGate devices.
5.
Refer to the exhibit.
If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)
a)
During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
b)
If the FGFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
c)
FortiGate is discovered by FortiManager through the FortiGate NATed IP address.
d)
FortiGate can announce itself to FortiManager only if the FortiManager non-NATed IP address is configured on FortiGate under central management.
6.
Refer to the exhibit.
An administrator would like to create three ADOMs on FortiManager with different access levels based on departments.
What two conclusions can you draw from the design shown in the exhibit? (Choose two.)*
a)
Admin A can access VDOM2 and VDOM3 with the super user profile.
b)
The FortiManager policies and objects database can be shared between the Financial and HR ADOMs.
c)
The administrator must set the FortiManager ADOM mode to Advanced.
d)
The administrator must configure FortiManager in workspace mode.
7.
Refer to the exhibit.
According to the error message, why is FortiManager failing to add the FortiAnalyzer device?
a)
The administrator must use the correct user name and password of the FortiAnalyzer device.
b)
The administrator must turn off the Use Legacy Device login and add the FortiAnalyzer device to the same network as FortiManager.
c)
The administrator must use the Add Model Device section and discover the FortiAnalyzer device.
d)
The administrator must select the FortiManager administrative access checkbox on the FortiAnalyzer management interface.
8.
Refer to the exhibit.
An administrator is importing a new device to FortiManager and has selected the options shown in the exhibit.
What will happen if the administrator makes the changes and installs the modified policy package on this managed FortiGate?
a)
The unused objects that are not tied to the firewall policies locally on FortiGate will be deleted.
b)
The unused objects that are not tied to the firewall policies in the policy package will be deleted from the FortiManager database.
c)
The unused objects that are not tied to the firewall policies will remain as read-only locally on FortiGate.
d)
The unused objects that are not tied to the firewall policies will be installed on FortiGate.
9.
Push updates are failing on a FortiGate device that is located behind a NAT device.
Which two settings should the administrator check? (Choose two.)
a)
That the virtual IP address and correct ports are set on the NAT device
b)
That the override server IP address is set on FortiManager and the NAT device
c)
That the external IP address on the NAT device is set to DHCP and configured with the virtual IP
d)
That the NAT device IP address and correct ports are configured on FortiManager
10.
An administrator has assigned a global policy package with All Policy Packages option selected to a new ADOM called ADOM1.
What will happen if the administrator tries to create a new policy package in ADOM1?
a)
When a new policy package is created, the administrator must import the global policy package to ADOM1.
b)
When the new policy package is created, FortiManager automatically assigns the global policy package to the new policy package.
c)
When a new policy package is created, the administrator must assign the global policy package from the global ADOM.
d)
When creating a new policy package, the administrator can select the option to assign the global policy package to the new policy package.
11.
Refer to the exhibit.
Which statement is true about the FortiManager ADOM policy tab based on the API request?
a)
The API command has enabled both central NAT and interface policy on the policy tab.
b)
The API command has requested the policy tab permissions information only.
c)
The API command has failed when requesting policy tab permissions information.
d)
The API command has applied to customer with ID: 200.
12.
An administrator is replacing a failed device on FortiManager by running the following command: execute device replace sn <devname> <serialnum>. Which device name and serial number must the administrator use?
a)
The device name of the new device and serial number of the failed device
b)
The device name and serial number of the failed device
c)
The device name of the failed device and serial number of the new device
d)
The device name and serial number of the new device
13.
Refer to the exhibit.
Given the configuration shown in the exhibit, what are two results from this configuration? (Choose two.)
a)
Two or more administrators can make configuration changes at the same time, in the same ADOM.
b)
The same administrator can lock more than one ADOM at the same time.
c)
Concurrent read-write access to an ADOM is disabled.
d)
You can validate administrator login attempts through external servers.
14.
An administrator configures a new OSPF route on FortiManager and has not yet pushed the changes to the managed FortiGate device.
In which database will the configuration be saved?
a)
Revision history database
b)
ADOM-level database
c)
Configuration-level database
d)
Device-level database
15.
What are two outcomes of ADOM revisions? (Choose two.)*
a)
ADOM revisions can save the current state of the whole ADOM.
b)
ADOM revisions can save the current state of all policy packages and objects for an ADOM.
c)
ADOM revisions can significantly increase the size of the configuration backups.
d)
ADOM revisions can create System Checkpoints for the FortiManager configuration.
16.
Refer to the exhibit.
What is the purpose of setting ADOM Mode to Advanced?
a)
This setting enables the ADOMs feature on FortiManager.
b)
This setting allows you to manage FortiGate chassis models.
c)
This setting disables concurrent ADOM access and adds ADOM locking.
d)
This setting allows you to assign a VDOM from a single device to a different ADOM.
17.
Refer to the exhibit.
How will FortiManager try to get updates for antivirus and IPS?
a)
From the list of configured override servers or public FDN servers
b)
From the default server fds1.fortinet.com
c)
From the configured override server IP address 10.0.1.50 only
d)
From public FDNI server IP address with the fourth highest octet only
18.
Refer to the exhibit.
Given the configuration shown in the exhibit, what can you conclude from the installation targets in the Install On column? (Choose two.)
a)
Policy 3 will be installed on all FortiGate devices and vdom belongs to the ADOM.
b)
Policy seq.# 3 will be skipped because no installation targets are specified.
c)
Policy seq.# 3 will be installed on all managed devices and VDOMs that are listed under Installation Targets.
d)
Policy seq.# 2 will not be installed on the Local-FortiGate root VDOM because there is no root VDOM in the Installation Target.
e)
Policy seq # 1 will be installed on the Remote-FortiGate root[NAT] and Student[NAT] VDOMs only.
19.
What is the advantage of using FortiManager to manage FortiAnalyzer?
a)
It allows FortiManager to manage all FortiGate devices.
b)
It allows FortiManager to run reports based on FortiAnalyzer.
c)
It allows FortiManager to store all managed FortiGate device logs.
d)
It allows FortiManager to act as a collector and FortiAnalyzer device.
20.
Refer to the exhibit.
What can you conclude from the failed installation log shown in the exhibit?
a)
Policy ID 2 will not be installed.
b)
Policy ID 2 is installed in the disabled state.
c)
Policy ID 2 is installed without a source address.
d)
Policy ID 2 is installed without the remote user student.
21.
Refer to the exhibit.
A junior administrator is troubleshooting a FortiManager connectivity issue that is occurring with managed FortiGate devices.
Given the FortiManager device manager settings shown in the exhibit, what can you conclude from the exhibit?
a)
FortiManager lost internet connectivity, therefore, both devices appear to be down.
b)
The administrator must refresh both devices to restore connectivity.
c)
The administrator had restored the FortiManager configuration file.
d)
The administrator can reclaim the FGFM tunnel to get both devices online.
22.
Which configuration setting for FortiGate is part of an ADOM-level database on FortiManager?
a)
Routing
b)
NSX-T Service Template
c)
SNMP
d)
Security profiles
23.
Refer to the exhibit.
An administrator logs in to the FortiManager GUI and sees the panes shown in the exhibit.
Which two reasons can explain why the FortiAnalyzer feature panes do not appear? (Choose two.)
a)
The administrator workflow is enabled on the ADOM.
b)
FortiAnalyzer features are not enabled on FortiManager.
c)
The admin session requires approval before administrator can see the FortiAnalyzer feature panes.
d)
The administrator profile does not have full access privileges like the Super_User profile.
24.
An administrator runs the Policy Check feature on FortiManager ADOM.
What will be the result?
a)
It will find and provide recommendations to combine multiple separate policy packages into one common policy package.
b)
It will find and merge duplicate policies in the policy package.
c)
It will find and provide recommendations for optimizing policies in a policy package.
d)
It will find and delete disabled firewall policies in the policy package.
25.
Refer to the exhibit.
What will happen if the script is run using the Remote FortiGate Directly (via CLI) option? (Choose two.)
a)
FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate.
b)
FortiManager will create a new revision history.
c)
FortiGate will auto-update the FortiManager device-level database.
d)
You must install these changes using the Install Wizard.
26.
Refer to the exhibit.
Given the configuration shown in the exhibit, how did FortiManager handle the service category named General?
a)
FortiManager ignored the firewall service category General and updated the FortiGate duplicate value in the FortiGate database.
b)
FortiManager ignored the firewall service category General and did not update its database with the value.
c)
FortiManager ignored the firewall service category General and deleted the duplicate value in its database.
d)
FortiManager ignored the firewall service category General but created a new service category in its database.
27.
Refer to the exhibit showing a Download Import Report.
Why is it failing to import firewall policy ID 1?
a)
Policy ID 1 for this managed FortiGate already exists on FortiManager in the policy package named Remote-FortiGate.
b)
The address object used in policy ID 1 already exists in the ADOM database with any as the interface association, and conflicts with the address object interface association locally on FortiGate.
c)
Policy ID 1 is configured from the interface any to port6. FortiManager rejects the request to import this policy because the any interface does not exist on FortiManager.
d)
Policy ID 1 does not have the ADOM Interface mapping configured on FortiManager.
28.
What does a policy package status of Never Installed indicate?*
a)
The policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager.
b)
FortiManager is unable to determine the policy package status.
c)
The policy configuration has been changed on FortiManager and changes have not yet been installed on the managed device.
d)
The policy package was never imported after a device was registered on FortiManager.
29.
Refer to the exhibit.
An administrator is about to add the FortiGate device to FortiManager using the discovery process. FortiManager is operating behind a NAT device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings.
What is the expected result?
a)
During discovery, FortiManager uses only the FortiGate serial number to establish the connection.
b)
During discovery, FortiManager sets the FortiManager NATed IP address on FortiGate.
c)
During discovery, FortiManager sets the NATed device IP address on FortiGate.
d)
During discovery, FortiManager sets both the FortiManager NATed IP address and NAT device IP address on FortiGate.
30.
An administrator is in the process of moving the system template profile between ADOMs by running the following command: execute fmprofile import-profile ADOM2 3547 /tmp/myfile
Where does the administrator import the file from?
a)
File system
b)
ADOM1
c)
ADOM2 object database
d)
ADOM2
31.
What will be the result of reverting to a previous revision version in the revision history?
a)
It will generate a new version ID and remove all other revision history versions.
b)
It will install configuration changes to managed device automatically.
c)
It will tag the device settings status as Auto-Update.
d)
It will modify the device-level database.
32.
In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices only. The administrator authorized the FortiGate device on FortiManager using the Fortinet Security Fabric.
Given the administrator’s actions, which statement correctly describes the expected result?
a)
The FortiManager administrator must add the authorized device to the Training ADOM using the Add Device wizard only.
b)
The authorized FortiGate will appear in the root ADOM.
c)
The authorized FortiGate can be added to the Training ADOM using FortiGate Fabric Connectors.
d)
The authorized FortiGate will be automatically added to the Training ADOM.
33.
Refer to the exhibit.
Given the configuration shown in the exhibit, what are two results from this configuration? (Choose two.)
a)
Unlocking an ADOM will submit configuration changes automatically to the approval administrator.
b)
Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out.
c)
The same administrator can lock more than one ADOM at the same time.
d)
Unlocking an ADOM will install configuration changes automatically on managed devices.
100 %
