[Jan-2022] Updated Fortinet NSE5_FMG-6.2 Dumps – PDF & Online Engine
NSE5_FMG-6.2.pdf - Questions Answers PDF Sample Questions Reliable
NEW QUESTION 42
Refer to the exhibit.
You are using the Quick Install option to install configuration changes on the managed FortiGate.
Which two statements correctly describe the result? (Choose two.)
- A. It will not create a new revision in the revision history
- B. It installs device-level changes to FortiGate without launching the Install Wizard
- C. It provides the option to preview configuration changes prior to installing them
- D. It cannot be canceled once initiated and changes will be installed on the managed device
Answer: B,D
NEW QUESTION 43
What configuration setting for FortiGate is part of a device-level database on FortiManager?
- A. Firewall policies
- B. VIP and IP Pools
- C. Routing
- D. Security profiles
Answer: C
Explanation:
The device-level database includes configuration details related to device-level settings, such as interfaces, DNS, routing, and more.
The ADOM-level database includes configuration details related to firewall policies, objects, and security profiles.
NEW QUESTION 44
Refer to the exhibit. Given the configurations shown in the exhibit, what can you conclude from the installation targets in the Install On column?
- A. The Install On column value represents successful installations on the managed devices.
- B. Policy seq.# 3 will be installed on all managed devices and VDOMs that are listed under Installation Targets.
- C. Policy seq.# 3 will be installed on the Trainer[NAT] VDOM only.
- D. Policy seq.# 3 will not be installed on any managed device.
Answer: B
NEW QUESTION 45
An administrator has assigned a global policy package to custom ADOM1. Then the administrator creates a new policy package, Fortinet, in the custom ADOM1.
Which statement about the global policy package assignment to the newly-created policy package Fortinet is true?
- A. When a new policy package is created, it automatically assigns the global policies to the new package.
- B. When a new policy package is created, you need to reapply the global policy package to the ADOM.
- C. When a new policy package is created, you can select the option to assign the global policies to the new package.
- D. When a new policy package is created, you need to assign the global policy package from the global ADOM.
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION 46
Refer to the exhibit. Which two statements about an ADOM set in Normal mode on FortiManager are true? (Choose two.)
- A. It supports the FortiManager script feature
- B. It allows making configuration changes for managed devices on FortiManager panes
- C. FortiManager automatically installs the configuration difference in revisions on the managed FortiGate
- D. You cannot assign the same ADOM to multiple administrators
Answer: B,C
NEW QUESTION 47
Refer to the exhibit. You are using the Quick Install option to install configuration changes on the managed FortiGate.
Which two statements correctly describe the result? (Choose two.)
- A. It will not create a new revision in the revision history
- B. It installs device-level changes to FortiGate without launching the Install Wizard
- C. It provides the option to preview configuration changes prior to installing them
- D. It cannot be canceled once initiated and changes will be installed on the managed device
Answer: B,D
NEW QUESTION 48
View the following exhibit.
Which one of the following statements is true regarding the object named ALL?
- A. FortiManager updated the object ALL using FortiManager's value in its database
- B. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate.
- C. FortiManager installed the object ALL with the updated value.
- D. FortiManager updated the object ALL using FortiGate's value in its database
Answer: D
NEW QUESTION 49
What is the purpose of the Policy Check feature on FortiManager?
- A. To find and provide recommendation for optimizing policies in a policy package
- B. To find and provide recommendation to combine multiple separate policy packages into one common policy package
- C. To find and delete disabled firewall policies in the policy package
- D. To find and merge duplicate policies in the policy package
Answer: D
Explanation:
The policy check tool allows you to check all policy packages within an ADOM to ensure consistency and eliminate conflicts that may prevent your devices from passing traffic. This allows you to optimize your policy sets and potentially reduce the size of your databases. The check will verify:
1. Object duplication: two objects that have identical definitions
2. Object shadowing: a higher priority object completely encompasses another object of the same type
3. Object overlap: one object partially overlaps another object of the same type
4. Object orphaning: an object has been defined but has not been used anywhere.
Reference: https://docs.fortinet.com/uploaded/files/2905/FortiManager-5.4.0-Administration-Guide.pdf
NEW QUESTION 50
What does the diagnose dvm check-integrity command do? (Choose two.)
- A. Verifies and corrects unregistered, registered, and deleted device states
- B. Verifies and corrects duplicate VDOM entries
- C. Verifies and corrects database schemas in all object tables
- D. Internally upgrades existing ADOMs to the same ADON version in order to clean up and correct the ADOM syntax
Answer: A,B
Explanation:
6.2 Study Guide page 305
verify and correct parts of the device manager databases, including:
- inconsistent device-to-group and group-to-ADOM memberships
- unregistered, registered, and deleted device states
- device lock statuses
- duplicate VDOM entries
NEW QUESTION 51
View the following exhibit.
Based on the configuration setting, which one of the following statements is true?
- A. The setting disables concurrent ADOM access and adds ADOM locking
- B. The setting allows automatic updates to the policy package configuration for a managed device
- C. The setting enables the ADOMs feature on FortiManager
- D. This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.
Answer: D
NEW QUESTION 52
Refer to the exhibit. If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)
- A. If the FGFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
- B. During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
- C. FortiGate can announce itself to FortiManager only if the FortiManager non-NATed IP address is configured on FortiGate under central management.
- D. FortiGate is discovered by FortiManager through the FortiGate NATed IP address.
Answer: B,D
Explanation:
Fortimanager can discover FortiGate through a NATed FortiGate IP address. If a FortiManager NATed IP address is configured on FortiGate, then FortiGate can announce itself to FortiManager. FortiManager will not attempt to re-establish the FGFM tunnel to the FortiGate NATed IP address, if the FGFM tunnel is interrupted. Just like it was in the NATed FortiManager scenario, the FortiManager NATed IP address in this scenario is not configured under FortiGate central management configuration.
NEW QUESTION 53
An administrator's PC crashes before the administrator can submit a workflow session for approval. After the PC is restarted, the administrator notices that the ADOM was locked from the session before the crash.
How can the administrator unlock the ADOM?
- A. Restore the configuration from a previous backup.
- B. Log in using the same administrator account to unlock the ADOM.
- C. Log in as Super_User in order to unlock the ADOM.
- D. Delete the previous admin session manually through the FortiManager GUI or CLI.
Answer: B
NEW QUESTION 54
Which two statements regarding device management on FortiManager are true? (Choose two.)
- A. FortiGate in transparent mode configurations are not counted toward the device count on FortiManager.
- B. The maximum number of managed devices for each ADOM is 500.
- C. FortiGate devices in an HA cluster that has five VDOMs are counted as five separate devices.
- D. FortiGate devices in HA cluster devices are counted as a single device.
Answer: C,D
NEW QUESTION 55
View the following exhibit.
Which of the following statements are true if FortiManager and FortiGate are behind the NAT devices? (Choose two.)
- A. During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
- B. If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
- C. FortiGate is discovered by FortiManager through the FortiGate NATed IP address.
- D. FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management.
Answer: C,D
NEW QUESTION 56
Refer to the exhibit. An administrator has configured the command shown in the exhibit on FortiManager. A configuration change has been installed from FortiManager to the managed FortiGate that causes the FGFM tunnel to go down for more than 15 minutes.
What is the purpose of this command?
- A. It allows FortiGate to reboot and recover the previous configuration from its configuration file.
- B. It allows FortiGate to reboot and restore a previously working firmware image.
- C. It allows FortiGate to unset central management settings.
- D. It allows the FortiManager to revert and install a previous configuration revision on the managed FortiGate.
Answer: A
NEW QUESTION 57
An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student.
However, Trainer is unable to approve the approving a workflow session?
- A. Trainer must close Student's workflow session before approving the request
- B. Trainer is not a part of workflow approval group
- C. Trainer does not have full rights over this ADOM
- D. Student, who submitted the workflow session, must first self-approve the request
Answer: B
Explanation:
An administrator must be part of an approval group, and have rights over the ADOM in which the session was created, in order to approve a session. Being part of the 'Super_Admin' profile is not enough to approve a session.
NEW QUESTION 58
View the following exhibit.
When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)
- A. Provides the option to preview configuration changes prior to installing them
- B. Will not create new revision in the revision history
- C. Installs device-level changes to FortiGate without launching the Install Wizard
- D. Once initiated, the install process cannot be canceled and changes will be installed on the managed device
Answer: C,D
NEW QUESTION 59
Which of the following statements are true regarding schedule backup of FortiManager? (Choose two.)
- A. Supports FTP, SCP, and SFTP
- B. Backs up all devices and the FortiGuard database.
- C. Can be configured from the CLI and GUI
- D. Does not back up firmware images saved on FortiManager
Answer: A,D
NEW QUESTION 60
Which two statements are correct regarding synchronization between primary and secondary devices in a FortiManager HA duster? (Choose two)
- A. All device configurations including global databases are synchrorized in the HA cluster,
- B. FortiGuard databases are downloaded separately by each cluster device.
- C. Local logs and log configuration settings are synchronized in the HA cluster.
- D. FortiGuard databases are downloaded by the primary FortManager device and then synchronized with all secondary devices.
Answer: A,B
NEW QUESTION 61
An administrator wants to delete an address object that is currently referenced in a firewall policy.
What can the administrator expect to happen?
- A. FortiManager will replace the deleted address object with the all address object in the referenced firewall policy.
- B. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy.
- C. FortiManager will not allow the administrator to delete a referenced address object.
- D. FortiManager will disable the status of the referenced firewall policy.
Answer: B
NEW QUESTION 62
Refer to the exhibit.
Given the configuration shown in the exhibit, which two statements are true? (Choose two.)
- A. It disables concurrent read-write access to an ADOM.
- B. It allows the same administrator to lock more than one ADOM at the same time.
- C. It is used to validate administrator login attempts through external servers.
- D. It allows two or more administrators to make configuration changes at the same time, in the same ADOM.
Answer: A,B
Explanation:
Reference:
https://docs.fortinet.com/document/fortimanager/6.0.4/administration-guide/86456/concurrentadom-access
NEW QUESTION 63
When statement correct compares FortiManager physical and virtual appliances?
- A. Physical and virtual FortiManager appliances use model types and licenses respectively, to differentiate managed device and storage capacity limits.
- B. Physical and virtual FortiManager appliances may manage unlimited devices and have unrestricted storage.
- C. Physical and virtual FortiManager appliances have an unrestricted daily logging rate.
- D. Physical and virtual FortiManager appliances use licenses to increase managed device and storage capacity limits.
Answer: A
NEW QUESTION 64
......
Fortinet NSE5_FMG-6.2 Dumps PDF Are going to be The Best Score: https://www.troytecdumps.com/NSE5_FMG-6.2-troytec-exam-dumps.html