Authentic Best resources for NSE5_FMG-7.0 Test Engine Practice Exam
[2023] NSE5_FMG-7.0 PDF Questions - Perfect Prospect To Go With Prep4sureGuide Practice Exam
NEW QUESTION # 40
Which two items are included in the FortiManager backup? (Choose two.)
- A. FortiGuard database
- B. Logs
- C. Global database
- D. All devices
Answer: C,D
NEW QUESTION # 41
What are two outcomes of ADOM revisions? (Choose two.)
- A. ADOM revisions can save the current size of the whole ADOM
- B. ADOM revisions can create System Checkpoints for the FortiManager configuration
- C. ADOM revisions can save the current state of all policy packages and objects for an ADOM
- D. ADOM revisions can significantly increase the size of the configuration backups.
Answer: C,D
NEW QUESTION # 42
View the following exhibit:
How will FortiManager try to get updates for antivirus and IPS?
- A. From the list of configured override servers with ability to fall back to public FDN servers
- B. From the configured override server list only
- C. From the default server fdsl.fortinet.com
- D. From public FDNI server with highest index number only
Answer: A
NEW QUESTION # 43
An administrator has enabled Service Access on FortiManager.
What is the purpose of Service Access on the FortiManager interface?
- A. Allows FortiManager to automatically configure a default route
- B. Allows FortiManager to respond to request for FortiGuard services from FortiGate devices
- C. Allows FortiManager to run real-time debugs on the managed devices
- D. Allows FortiManager to download IPS packages
Answer: B
NEW QUESTION # 44
An administrator with the Super_User profile is unable to log in to FortiManager because of an authentication failure message.
Which troubleshooting step should you take to resolve the issue?
- A. Make sure FortiManager Access is enabled in the administrator profile
- B. Make sure the administrator IP address is part of the trusted hosts.
- C. Make sure Offline Mode is disabled
- D. Make sure ADOMs are enabled and the administrator has access to the Global ADOM
Answer: B
Explanation:
Even if a user entered the correct userid/password, the FMG denies access if a user is logging in from an untrusted source IP subnets.
Topic 1, Main Questions Pool B
NEW QUESTION # 45
When an installation is performed from FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?
- A. FortiManager will revert and install a previous configuration revision on the managed FortiGate.
- B. After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.
- C. FortiGate will reject the CLI commands that will cause the tunnel to go down.
- D. FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.
Answer: A
Explanation:
The configuration change will break the fgfm connection, causing the FortiGate unit to attempt to reconnect for 900 seconds. If the FortiGate cannot reconnect, it will rollback to its previous configuration.
NEW QUESTION # 46
View the following exhibit:
Which two statements are true if the script is executed using the Remote FortiGate Directly (via CLI) option? (Choose two.)
- A. FortiManager will create a new revision history.
- B. FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate.
- C. You must install these changes using Install Wizard
- D. FortiGate will auto-update the FortiManager's device-level database.
Answer: A,D
NEW QUESTION # 47
An administrator would like to review, approve, or reject all the firewall policy changes made by the junior
administrators.
How should the Workspace mode be configured on FortiManager?
- A. Set to disable and use the policy locking feature
- B. Set to workflow and use the ADOM locking feature
- C. Set to read/write and use the policy locking feature
- D. Set to normal and use the policy locking feature
Answer: B
NEW QUESTION # 48
View the following exhibit.
When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)
- A. Installs device-level changes to FortiGate without launching the Install Wizard
- B. Once initiated, the install process cannot be canceled and changes will be installed on the managed device
- C. Provides the option to preview configuration changes prior to installing them
- D. Will not create new revision in the revision history
Answer: A,B
NEW QUESTION # 49
In the event that the primary FortiManager fails, which of the following actions must be performed to return the FortiManager HA to a working state?
- A. FortiManager HA state transition is transparent to administrators and does not require any reconfiguration.
- B. Secondary device with highest priority will automatically be promoted to the primary role, and manually reconfigure all other secondary devices to point to the new primary device
- C. Manually promote one of the secondary devices to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- D. Reboot one of the secondary devices to promote it automatically to the primary role, and reconfigure all other secondary devices to point to the new primary device.
Answer: C
Explanation:
FortiManager_6.4_Study_Guide-Online - page 346
FortiManager HA doesn't support IP takeover where an HA state transition is transparent to administrators. If a failure of the primary occurs, the administrator must take corrective action to resolve the problem that may include invoking the state transition. If the primary device fails, the administrator must do the following in order to return the FortiManager HA to a working state:
1. Manually reconfigure one of the secondary devices to become the primary device
2. Reconfigure all other secondary devices to point to the new primary device
NEW QUESTION # 50
An administrator's PC crashes before the administrator can submit a workflow session for approval. After the PC is restarted, the administrator notices that the ADOM was locked from the session before the crash.
How can the administrator unlock the ADOM?
- A. Log in as Super_User in order to unlock the ADOM.
- B. Delete the previous admin session manually through the FortiManager GUI or CLI.
- C. Restore the configuration from a previous backup.
- D. Log in using the same administrator account to unlock the ADOM.
Answer: B
NEW QUESTION # 51
What does a policy package status of Conflict indicate?
- A. The policy configuration has never been imported after a device was registered on FortiManager.
- B. The policy package reports inconsistencies and conflicts during a Policy Consistency Check.
- C. The policy package configuration has been changed on both FortiManager and the managed device independently.
- D. The policy package does not have a FortiGate as the installation target.
Answer: C
NEW QUESTION # 52
When an installation is performed from FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?
- A. After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.
- B. FortiManager will revert and install a previous configuration revision on the managed FortiGate.
- C. FortiGate will reject the CLI commands that will cause the tunnel to go down.
- D. FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.
Answer: A
Explanation:
The configuration change will break the fgfm connection, causing the FortiGate unit to attempt to reconnect for 900 seconds. If the FortiGate cannot reconnect, it will rollback to its previous configuration.
NEW QUESTION # 53
Which configuration setting for FortiGate is part of an ADOM-level database on FortiManager?
- A. NSX-T Service Template
- B. Security profiles
- C. Routing
- D. SNMP
Answer: C
NEW QUESTION # 54
Which two items does an FGFM keepalive message include? (Choose two.)
- A. FortiGate configuration checksum
- B. FortiGate uptime
- C. FortiGate IPS version
- D. FortiGate license information
Answer: A,C
NEW QUESTION # 55
View the following exhibit.
Which of the following statements are true based on this configuration setting? (Choose two.)
- A. This setting is applied globally to all ADOMs.
- B. This setting will allow automatic updates to the policy package configuration for a managed device.
- C. This setting will allow assigning different VDOMs from the same FortiGate to different ADOMs.
- D. This setting will enable the ADOMs feature on FortiManager.
Answer: A,C
NEW QUESTION # 56
Refer to the exhibits.
Exhibit one.
Exhibit two.
An administrator created a new system template named Training with two new DNS addresses on FortiManager. During the installation preview stage, the administrator notices that many unset commands need to be pushed.
What can be the main reason for these unset commands?
- A. The Training system template does not have assigned devices
- B. The ADOM is locked by another administrator
- C. The DNS addresses in the default system settings are the same as the Training system template
- D. The Training system template has other default settings
Answer: D
NEW QUESTION # 57
View the following exhibit.
What is the purpose of setting ADOM Mode to Advanced?
- A. The setting enables the ADOMs feature on FortiManager
- B. This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.
- C. The setting disables concurrent ADOM access and adds ADOM locking
- D. The setting allows automatic updates to the policy package configuration for a managed device
Answer: B
NEW QUESTION # 58
In the event that the primary FortiManager fails, which of the following actions must be performed to return the FortiManager HA to a working state?
- A. FortiManager HA state transition is transparent to administrators and does not require any reconfiguration.
- B. Manually promote one of the secondary devices to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- C. Secondary device with highest priority will automatically be promoted to the primary role, and manually
reconfigure all other secondary devices to point to the new primary device - D. Reboot one of the secondary devices to promote it automatically to the primary role, and reconfigure all other secondary devices to point to the new primary device.
Answer: B
Explanation:
FortiManager_6.4_Study_Guide-Online - page 346
FortiManager HA doesn't support IP takeover where an HA state transition is transparent to administrators. If a failure of the primary occurs, the administrator must take corrective action to resolve the problem that may include invoking the state transition. If the primary device fails, the administrator must do the following in order to return the FortiManager HA to a working state:
1. Manually reconfigure one of the secondary devices to become the primary device
2. Reconfigure all other secondary devices to point to the new primary device
NEW QUESTION # 59
......
Fortinet NSE5_FMG-7.0 (Fortinet NSE 5 - FortiManager 7.0) Certification Exam is a professional certification program designed for individuals who specialize in managing and maintaining FortiManager 7.0, a centralized management solution for Fortinet’s Security Fabric. NSE5_FMG-7.0 exam is designed to validate the knowledge and skills required to effectively configure and manage FortiManager 7.0, as well as to troubleshoot common issues and optimize the platform for maximum performance.
Best updated resource for NSE5_FMG-7.0 Online Practice Exam: https://www.prep4sureguide.com/NSE5_FMG-7.0-prep4sure-exam-guide.html
Realistic Practice NSE5_FMG-7.0 Fortinet NSE 5 - FortiManager 7.0 Exam Braindumps: https://drive.google.com/open?id=111Vu8sej1tLLO_i1VsCYaX3SD6k2y_fQ