Weekend Sale - Special 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75onlydt

NSE6_FMG_AD-7.6 Questions and Answers

Question # 6

After correcting a policy package configuration issue, you want to prevent administrators from repeating the mistake that caused the issue.

Which FortiManager approach best meets this need?

A.

Configure an TCL script to run locally on FortiManager for each FortiGate.

B.

Restrict administrators with an administration profile from viewing the revision history to limit who can make changes.

C.

Enable the change note to require administrators to add a note whenever they change object configurations.

D.

Enable a workflow requiring approval before installing policy packages on any FortiGate.

Full Access
Question # 7

Refer to the exhibits.

Question # 7

Question # 7

Question # 7

An administrator must replace the source LAN interface in policy ID 2 on their FortiGateRugged-70F.

However, when they try to install the policy package, they receive the error shown in the exhibit.

What should the administrator do to resolve the error?

A.

Use the API to assign a system template interface for FortiGateRugged-70F model.

B.

Use a metadata variable to dynamically assign an interface when this error occurs.

C.

Create a per-device mapping for the LAN interface.

D.

Replace LAN with lan1, which is supported by FortiGateRugged-70F models.

Full Access
Question # 8

Refer to the exhibit.

Question # 8

What are two results from the configuration shown in the exhibit? (Choose two.)

A.

Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out.

B.

The administrator can lock policy blocks and FortiManager global ADOM.

C.

The same administrator can lock more than one ADOM at the same time.

D.

The administrator must have access to the ADOM to approve changes.

Full Access
Question # 9

Refer to Exhibits:

Question # 9

Question # 9

An administrator has observed the performance status outputs on an HA cluster for 55 seconds.

Which FortiGate is the primary?

A.

HQ-NGFW-2 with the parameter memory-failover-threshold setting

B.

HQ-NGFW-2 with the parameter priority setting

C.

HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting

D.

HQ-NGFW-1 with the parameter override setting

Full Access
Question # 10

Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

A.

When FortiManager installs device-level changes on a managed device

B.

When changes to the device-level database are made on FortiManager

C.

When FortiManager is auto-updated with configuration changes made directly on a managed device

D.

When a provisioning template is assigned to a managed device on the device-level database

Full Access
Question # 11

Refer to the exhibits.

Question # 11

An administrator added BR1-FGT-1 to FortiManager and started importing the policy package. During the process, they saw that they need to choose values from FortiGate or FortiManager.

Which conclusion is most clearly supported by the exhibits?

A.

BR1-FGT-1 does not support the SSL/SSH profile with HTTPS on port 443.

B.

The administrator must match the FortiOS firmware version with the FortiManager ADOM firmware version to resolve the conflict status.

C.

The default Firewall Profile-Protocol-Options object is the only profile that does not significantly affect any configuration changes on either FortiManager or FortiGate.

D.

FortiManager has a different FortiGuard database compared to FortiGate BR1-FGT-1 for the QUIC protocol.

Full Access
Question # 12

Refer to the following configuration. FortiManager # config system global global# set workspace-mode normal global# end FortiManager # What are two results from the configuration shown in the exhibit? Choose two answers

A.

The same administrator can lock more than one ADOM at the same time.

B.

Multiple administrators can lock and work on separate ADOMs at the same time.

C.

All changes must be approved before they can be installed on a device.

D.

Concurrent read-write access to an ADOM is disabled.

Full Access
Question # 13

Push updates are failing on a FortiGate device located behind a network address translation (NAT) device?

Which two settings should the administrator check to correct this problem? (Choose two.)

A.

Make sure the NAT device IP address and the correct ports are configured on FortiManager.

B.

Make sure FortiGuard updates and web service are enabled on the FortiGuard service interface.

C.

Make sure the virtual IP address and the correct ports are configured on the NAT device.

D.

Make sure the Bind to IP address option on the FortiGuard service interface is set to the virtual IP address from the NAT device.

Full Access
Question # 14

What is the purpose of ADOM revisions?

A.

ADOM revisions find unused, duplicate, and unnecessary firewall policies and objects.

B.

ADOM revisions show specific changes in a policy package when it is installed.

C.

ADOM revisions compare previous snapshots of the Policy Package and ADOM-level objects with the device-level database.

D.

ADOM revisions save the current state of all policy packages and objects for an ADOM.

Full Access
Question # 15

Refer to the exhibits.

Question # 15

Question # 15

An administrator has been asked to install the same policies from a central policy package onto the BR1-FGT-1 firewall.

The administrator added BR1-FGT-1 as a target in the central policy package installation.

What should the administrator do when reinstalling the central policy package on the BR1-FGT-1 firewall?

A.

Assign only one policy package to the firewall because FortiManager does not allow more than one policy package assigned per device at the same time.

B.

Import the policy package to change the unknown status and synchronize the policy package.

C.

Use the install wizard to install the central policy package on the BR1-FGT-1 firewall.

D.

First resolve the modified status in the configuration and provisioning templates to allow a smooth installation.

Full Access
Question # 16

Which output is displayed right after moving the ISFW device from one ADOM to another?

A)

Question # 16

B)

Question # 16

C)

Question # 16

D)

Question # 16

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Full Access
Question # 17

What are two expected results when both FortiManager and FortiGate are behind network address translation NAT devices? Choose two answers

A.

FortiGate is discovered by FortiManager through the FortiGate NATed IP address.

B.

During discovery, the FortiManager NATed IP address is not set by default on FortiGate.

C.

FortiGate can announce itself to FortiManager only if the FortiManager non-NATed IP address is configured on FortiGate under central management.

D.

If the FortiGate–FortiManager communication protocol FGFM tunnel is torn down, FortiManager will try to reestablish the FGFM tunnel.

Full Access
Question # 18

An administrator assigned the Training global policy package to the Branches policy package in ADOM1. Later, the administrator created a new policy package named Remotes on ADOM1.

What should the administrator do to sync the Training global policy package with the Remotes policy package in ADOM1?

A.

Manually add and assign the Remotes policy package to the Training global policy package

B.

Use the automatically install policies to ADOM devices method to sync from the Training global policy package to the Remotes policy package

C.

Assign the Training global policy package to the Remotes policy package

D.

Unassign the Training policy package and reassign it to all policy packages within ADOM1

Full Access
Question # 19

Refer to the exhibit.

Question # 19

Which two statements about the output are true? (Choose two.)

A.

The latest revision history for the managed FortiGate does not match the device-level database.

B.

Configuration changes have been installed on FortiGate, updating policy and device-level database.

C.

The latest revision history for the managed FortiGate does match the FortiManager policy database.

D.

The system template default will override device-level database configurations.

Full Access