Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: big75certs

Free and Premium Fortinet NSE6_FMG_AD-7.6 Dumps Questions Answers

Fortinet NSE 6 - FortiManager 7.6 Administrator Questions and Answers

Question 1

Which two conditions trigger FortiManager to create a new revision history? (Choose two.)

Options:

A.

When FortiManager installs device-level changes on a managed device

B.

When changes to the device-level database are made on FortiManager

C.

When FortiManager is auto-updated with configuration changes made directly on a managed device

D.

When a provisioning template is assigned to a managed device on the device-level database

Buy Now
Question 2

A FortiManager administrator has moved a FortiGate device to a new ADOM, but they cannot see the policy or object configurations for that FortiGate.

What should the administrator do to see the policy or object configurations?

Options:

A.

Use ADOM shared objects to restore all missing data.

B.

Reset the device and add it to the new ADOM again.

C.

Import the policy package manually using the Import Configuration wizard.

D.

Use ADOM sync to restore the missing configurations.

Question 3

Refer to the exhibit.

What percentage of the available RAM is being used by the process in charge of downloading the web and email filter databases from the public FortiGuard servers?

Options:

A.

1.5

B.

3.1

C.

4.1

D.

2.9

Question 4

Refer to the exhibits.

Which IP/netmask will be present in the LAN firewall address object on the Remote-Firewall?

Options:

A.

172.16.0.0/255.255.255.0

B.

10.0.0.0/255.255.255.0

C.

192.168.1.0/255.255.255.0

D.

172.16.10.0/255.255.255.0

Question 5

An administrator configures a new BGP peer in the FortiManager device-level database of FortiGate. They reinstall the policy package to the managed FortiGate device without any errors. However, when the administrator logs in to FortiGate, they do not see the BGP configuration changes.

What is the most likely reason why FortiManager did not push the BGP peer changes to FortiGate?

Options:

A.

The administrator must run a sanity check on FortiManager to make sure the database is not corrupted.

B.

Fortigate has a BGP template assigned on the FortiManager database.

C.

The administrator must use the Install Wizard and select Install device settings only to push BGP settings

D.

The FortiGate firmware version is different from the FortiManager ADOM version.

Question 6

Which two statements about the integrity of databases on FortiManager are correct? Choose two answers.

Options:

A.

Scheduled backups run database integrity commands automatically.

B.

The diagnose dvm check-integrity command attempts to fix a corrupted file system.

C.

The diagnose cdb check adom-integrity command can correct issues related to locked devices.

D.

You should fix all database integrity issues before performing a script.

E.

Not following the correct upgrade path may cause inconsistencies in the databases.

Question 7

Refer to Exhibit:

Which two actions will occur if you run the script using the Remote FortiGate Directly via CLI option? Choose two answers

Options:

A.

FortiManager will provide a preview of CLI commands before executing this script on a managed FortiGate.

B.

FortiManager will create a new revision history.

C.

FortiGate will auto-updated the FortiManager device-level database.

D.

You will have to install these changes using the Install Wizard.

Question 8

What is the best explanation of how FortiManager helps with mass provisioning?

Options:

A.

It upgrades the OS of each FortiGate device.

B.

It provides local FortiGuard Distribution Server (FDS) services to the network.

C.

It uses templates to configure the same settings on many devices simultaneously.

D.

It sends email alerts when new devices connect.

Question 9

An administrator has assigned a global policy package to a new ADOM named ADOM1.

What will happen if the administrator tries to create a new policy package in ADOM1?

Options:

A.

The administrator will be able to select the option to assign the global policy package to the new policy package.

B.

FortiManager will automatically assign the global policy package to the new policy package.

C.

FortiManager will automatically install policies on the policy package in ADOM1.

D.

The administrator will have to assign the global policy package from the global ADOM.

Question 10

If one of the secondary FortiManager devices fails, which action must be performed to return the FortiManager HA manual mode to a working state?

Options:

A.

The FortiManager high availability HA state transition is transparent to administrators and does not require any reconfiguration.

B.

Run a sanity check on the failed device to make sure HA heartbeat packets are using TCP port 5199.

C.

Manually promote one of the working secondary devices to the primary role.

D.

Remove the peer IP of the failed device on the primary device.

Question 11

An administrator receives the import report after importing policies into the policy package layer.

Based on the import report, how did FortiManager handle the profile-protocol-options object named default?

Options:

A.

FortiManager deleted the duplicate value from its database.

B.

FortiManager created a new service category in its database.

C.

FortiManager did not update its database with the value.

D.

FortiManager updated the duplicate value in the FortiGate database.

Question 12

The administrator uses FortiManager to push a CLI script using the Remote FortiGate Directly (via CLI) option to configure an IPsec VPN. However, when running the script, the administrator receives the following error:

config vpn ipsec phase2-interface [parameter(s) invalid. detail: object mismatch]

What must the administrator do to resolve the script error and successfully apply the IPsec configuration?

Options:

A.

Add the end command after finishing the IPsec phase 1-interface configuration block.

B.

Use IPsec templates to deploy provisioning templates.

C.

Add a second config vpn ipsec phase2-interface block without linking it to phase1.

D.

Run the script using the policy package or ADOM database method.

Question 13

Refer to the exhibit.

An administrator has assigned the default system template to install all devices with the FortiAnalyzer IP address 10.0.13.12. However, not all FortiGate devices can reach FortiAnalyzer using the default interface. Some devices may use the LAN interface, while others may use the WAN interface. How can the administrator change the source interface for FortiGate devices using the default system template? Choose one answer

Options:

A.

Use per-device dynamic object configurations at the ADOM level and apply them in the template.

B.

Configure a metadata variable at the ADOM level and use it in the template.

C.

Create a different system template for each FortiGate, if the configuration is different.

D.

Create a meta field on FortiManager system settings of type Device and use it in the template.

Question 14

Refer to the exhibits.

What can you conclude, based on the configuration shown in the exhibit? Choose one answer

Options:

A.

The administrator needs to retrieve the Local-FortiGate configuration to sync with the Security Fabric group, Training.

B.

Policy sequence #1 will be installed on the internal segmentation firewall ISFW device root NAT and Trainer NAT VDOMs.

C.

Policy sequence #3 must have devices or VDOMs listed in the Install On column; otherwise, it will cause errors.

D.

The global policy package will be added to the top of the ISFW policy package.

Question 15

An administrator assigned the Training global policy package to the Branches policy package in ADOM1. Later, the administrator created a new policy package named Remotes on ADOM1.

What should the administrator do to sync the Training global policy package with the Remotes policy package in ADOM1?

Options:

A.

Manually add and assign the Remotes policy package to the Training global policy package

B.

Use the automatically install policies to ADOM devices method to sync from the Training global policy package to the Remotes policy package

C.

Assign the Training global policy package to the Remotes policy package

D.

Unassign the Training policy package and reassign it to all policy packages within ADOM1

Question 16

Refer to the exhibits.

An administrator has been asked to install the same policies from a central policy package onto the BR1-FGT-1 firewall.

The administrator added BR1-FGT-1 as a target in the central policy package installation.

What should the administrator do when reinstalling the central policy package on the BR1-FGT-1 firewall?

Options:

A.

Assign only one policy package to the firewall because FortiManager does not allow more than one policy package assigned per device at the same time.

B.

Import the policy package to change the unknown status and synchronize the policy package.

C.

Use the install wizard to install the central policy package on the BR1-FGT-1 firewall.

D.

First resolve the modified status in the configuration and provisioning templates to allow a smooth installation.

Question 17

FortiGate is integrated with FortiAnalyzer and FortiManager.

When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log recording on FortiAnalyzer and FortiManager?

Options:

A.

Policy ID

B.

Log ID

C.

Universally Unique Identifier

D.

Sequence ID

Question 18

Refer to Exhibits:

An administrator has observed the performance status outputs on an HA cluster for 55 seconds.

Which FortiGate is the primary?

Options:

A.

HQ-NGFW-2 with the parameter memory-failover-threshold setting

B.

HQ-NGFW-2 with the parameter priority setting

C.

HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting

D.

HQ-NGFW-1 with the parameter override setting

Question 19

Refer to the exhibit.

An administrator assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview, they noticed some settings they did not modify and are unsure about the changes.

Based on the exhibit, which two things will happen if they continue with the installation? (Choose two.)

Options:

A.

FortiGate HQ-NGFW-1 can use FortiManager firmware templates to upgrade firmware and ratings.

B.

FortiGate HQ-NGFW-1 can contact the FortiManager acting as FortiGuard Distribution Server (FDS) to download FortiGuard updates.

C.

FortiGate HQ-NGFW-1 will use the root_CA3 certificate in firewall address objects or policies.

D.

FortiManager will install the CA certificate named root_CA3 to authenticate FortiGate-to-FortiManager communication protocol (FGFM) tunnel connections with FortiGate HQ- NGFW-1.