Fortinet NSE5_FMG-7.2 Fortinet NSE 5 – FortiManager 7.2 Online Training
Fortinet NSE5_FMG-7.2 Online Training
The questions for NSE5_FMG-7.2 were last updated at Jan 02,2025.
- Exam Code: NSE5_FMG-7.2
- Exam Name: Fortinet NSE 5 - FortiManager 7.2
- Certification Provider: Fortinet
- Latest update: Jan 02,2025
An administrator has assigned a global policy package to a new ADOM called ADOM1.
What will happen if the administrator tries to create a new policy package in ADOM1?
- A . When creating a new policy package, the administrator can select the option to assign the global policy package to the new policy package
- B . When a new policy package is created, the administrator needs to reapply the global policy package to ADOM1.
- C . When a new policy package is created, the administrator must assign the global policy package from the global ADOM.
- D . When the new policy package is created, FortiManager automatically assigns the global policy package to the new policy package.
What is the purpose of the Policy Check feature on FortiManager?
- A . To find and provide recommendation to combine multiple separate policy packages into one Common policy package
- B . To find and merge duplicate policies in the policy package
- C . To find and provide recommendation for optimizing policies in a policy package
- D . To find and delete disabled firewall policies in the policy package
Which two conditions trigger FortiManager to create a new revision history? (Choose two.)
- A . When configuration revision is reverted to previous revision in the revision history
- B . When FortiManager installs device-level changes to a managed device
- C . When FortiManager is auto-updated with configuration changes made directly on a managed device
- D . When changes to device-level database is made on FortiManager
When an installation is performed from FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?
- A . After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.
- B . FortiManager will revert and install a previous configuration revision on the managed FortiGate.
- C . FortiGate will reject the CLI commands that will cause the tunnel to go down.
- D . FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.
An administrator run the reload failure command: diagnose test deploymanager reload config
<deviceid> on FortiManager.
What does this command do?
- A . It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.
- B . It installs the latest configuration on the specified FortiGate and update the revision history database.
- C . It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate.
- D . It installs the provisioning template configuration on the specified FortiGate.
An administrator with the Super_User profile is unable to log in to FortiManager because of an authentication failure message.
Which troubleshooting step should you take to resolve the issue?
- A . Make sure FortiManager Access is enabled in the administrator profile
- B . Make sure Offline Mode is disabled
- C . Make sure the administrator IP address is part of the trusted hosts.
- D . Make sure ADOMs are enabled and the administrator has access to the Global ADOM
What are two outcomes of ADOM revisions? (Choose two.)
- A . ADOM revisions can significantly increase the size of the configuration backups.
- B . ADOM revisions can save the current size of the whole ADOM
- C . ADOM revisions can create System Checkpoints for the FortiManager configuration
- D . ADOM revisions can save the current state of all policy packages and objects for an ADOM
View the following exhibit.
If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)
- A . FortiGate is discovered by FortiManager through the FortiGate NATed IP address.
- B . FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management.
- C . During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
- D . If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
Which two settings must be configured for SD-WAN Central Management? (Choose two.)
- A . SD-WAN must be enabled on per-ADOM basis
- B . You can create multiple SD-WAN interfaces per VDOM
- C . When you configure an SD-WAN, you must specify at least two member interfaces.
- D . The first step in creating an SD-WAN using FortiManager is to create two SD-WAN firewall policies.
An administrator wants to delete an address object that is currently referenced in a firewall policy.
What can the administrator expect to happen?
- A . FortiManager will not allow the administrator to delete a referenced address object
- B . FortiManager will disable the status of the referenced firewall policy
- C . FortiManager will replace the deleted address object with the none address object in the Referenced firewall policy
- D . FortiManager will replace the deleted address object with all address object in the referenced firewall policy