Latest NSE5_FMG-7.0 Exam Dumps Fortinet Exam from Training Expert ExamTorrent [Q41-Q61]

Share

Latest NSE5_FMG-7.0 Exam Dumps Fortinet Exam from Training Expert ExamTorrent

Pass Fortinet Fortinet NSE 5 - FortiManager 7.0 PDF Dumps | Recently Updated 82 Questions


The FortiManager 7.0 platform is a powerful tool for managing and administering Fortinet’s network security solutions. It provides centralized management and configuration of Fortinet’s security devices, including firewalls, VPNs, and intrusion prevention systems. The Fortinet NSE5_FMG-7.0 certification exam is designed to test the candidate’s knowledge of the platform and ensure that they are capable of configuring and managing it effectively.


Fortinet NSE5_FMG-7.0 exam covers a wide range of topics related to FortiManager 7.0, including device registration, configuration management, policy management, software management, and troubleshooting. NSE5_FMG-7.0 exam also covers topics such as device discovery, device groups, and device templates. NSE5_FMG-7.0 exam is designed to test the candidate's ability to manage a large number of FortiGate devices using FortiManager 7.0.

 

NEW QUESTION # 41
An administrator has assigned a global policy package to a new ADOM called ADOM1. What will happen if the administrator tries to create a new policy package in ADOM1?

  • A. When the new policy package is created, FortiManager automatically assigns the global policy package to the new policy package.
  • B. When a new policy package is created, the administrator needs to reapply the global policy package to ADOM1.
  • C. When creating a new policy package, the administrator can select the option to assign the global policy package to the new policy package
  • D. When a new policy package is created, the administrator must assign the global policy package from the global ADOM.

Answer: A


NEW QUESTION # 42
An administrator would like to create an SD-WAN using central management. What steps does the
administrator need to perform to create an SD-WAN using central management?

  • A. Enable SD-WAN central management in the ADOM, add member interfaces, create a static route and SDWAN firewall policies.
  • B. Remove all the interface references such as routes or policies
  • C. First create an SD-WAN firewall policy, add member interfaces to the SD-WAN template and create a static route
  • D. You must specify a gateway address when you create a default static route

Answer: A


NEW QUESTION # 43
In the event that the primary FortiManager fails, which of the following actions must be performed to return the FortiManager HA to a working state?

  • A. Manually promote one of the secondary devices to the primary role, and reconfigure all other secondary devices to point to the new primary device.
  • B. FortiManager HA state transition is transparent to administrators and does not require any reconfiguration.
  • C. Secondary device with highest priority will automatically be promoted to the primary role, and manually reconfigure all other secondary devices to point to the new primary device
  • D. Reboot one of the secondary devices to promote it automatically to the primary role, and reconfigure all other secondary devices to point to the new primary device.

Answer: A

Explanation:
FortiManager_6.4_Study_Guide-Online - page 346
FortiManager HA doesn't support IP takeover where an HA state transition is transparent to administrators. If a failure of the primary occurs, the administrator must take corrective action to resolve the problem that may include invoking the state transition. If the primary device fails, the administrator must do the following in order to return the FortiManager HA to a working state:
1. Manually reconfigure one of the secondary devices to become the primary device
2. Reconfigure all other secondary devices to point to the new primary device


NEW QUESTION # 44
Refer to the exhibit.

An administrator has created a firewall address object, Training which is used in the Local-FortiGate policy package.
When the installation operation is performed, which IP/Netmask will be installed on the Local-FortiGate, for the Training firewall address object?

  • A. 10.200.1.0/24
  • B. It will create a firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values.
  • C. Local-FortiGate will automatically choose an IP/Netmask based on its network interface settings.
  • D. 192.168.0.1/24

Answer: D


NEW QUESTION # 45
Refer to the exhibits.
Exhibit one.

Exhibit two.

An administrator created a new system template named Training with two new DNS addresses on FortiManager. During the installation preview stage, the administrator notices that many unset commands need to be pushed.
What can be the main reason for these unset commands?

  • A. The Training system template does not have assigned devices
  • B. The DNS addresses in the default system settings are the same as the Training system template
  • C. The ADOM is locked by another administrator
  • D. The Training system template has other default settings

Answer: D


NEW QUESTION # 46
Refer to the exhibit.

Which two statements are true if the script is executed using the Device Database option? (Choose two.)

  • A. The script history will show successful installation of the script on the remote FortiGate
  • B. The successful execution of a script on the Device Database will create a new revision history
  • C. The Device Settings Status will be tagged as Modified
  • D. You must install these changes using the Install Wizard to a managed device

Answer: C,D


NEW QUESTION # 47
Refer to the exhibit.

Which two statements are true if the script is executed using the Device Database option? (Choose two.)

  • A. The script history will show successful installation of the script on the remote FortiGate
  • B. The successful execution of a script on the Device Database will create a new revision history
  • C. The Device Settings Status will be tagged as Modified
  • D. You must install these changes using the Install Wizard to a managed device

Answer: C,D


NEW QUESTION # 48
An administrator would like to authorize a newly-installed AP using AP Manager. What steps does the administrator need to perform to authorize an AP?

  • A. Changes to the AP's state must be performed directly on the managed FortiGate.
  • B. Authorize the new AP using AP Manager and wait until the change is updated on the FortiAP. Changes to the AP's state do not require installation.
  • C. Authorize the new AP using AP Manager and install the device level settings on the managed FortiGate.
  • D. Authorize the new AP using AP Manager and install the policy package changes on the managed FortiGate.

Answer: C


NEW QUESTION # 49
Which three settings are the factory default settings on FortiManager? (Choose three.)

  • A. FortiAnalyzer features are disabled
  • B. Password is fortinet
  • C. Reports and Event Monitor panes are enabled
  • D. port1 interface IP address is 192.168.1.99/24
  • E. Username is admin

Answer: A,D,E


NEW QUESTION # 50
When an installation is performed from FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?

  • A. After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.
  • B. FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.
  • C. FortiGate will reject the CLI commands that will cause the tunnel to go down.
  • D. FortiManager will revert and install a previous configuration revision on the managed FortiGate.

Answer: D

Explanation:
The configuration change will break the fgfm connection, causing the FortiGate unit to attempt to reconnect for 900 seconds. If the FortiGate cannot reconnect, it will rollback to its previous configuration.


NEW QUESTION # 51
Refer to the exhibit.

Which statement about the object named ALL is true?

  • A. FortiManager updated the object ALL using the FortiManager value in its database.
  • B. FortiManager created the object ALL as a unique entity in its database, which can be only used by this
    managed FortiGate.
  • C. FortiManager updated the object ALL using the FortiGate value in its database.
  • D. FortiManager installed the object ALL with the updated value.

Answer: C


NEW QUESTION # 52
Refer to the exhibit.

A junior administrator is troubleshooting a FortiManager connectivity issue that rs occurring with managed FortiGate devices Given the FortiManager device manager settings shown in the exhibit what can you conclude from the exhibit?

  • A. FortiManager test internet connectivity therefore, both devices appear to be down
  • B. The administrator can reclaim the FGFM tunnel to get both devices online
  • C. The administrator had restored the FortiManager configuration file
  • D. The administrator must refresh both devices to restore connectivity

Answer: A


NEW QUESTION # 53
Which of the following statements are true regarding VPN Gateway configuration in VPN Manager? (Choose two.)

  • A. External gateways are third-party VPN gateway devices only
  • B. Managed devices in other ADOMs must be treated as external gateways
  • C. Protected subnets are the subnets behind the device that you don't want to allow access to over the IPsec VPN
  • D. Managed gateways are devices managed by FortiManager in the same ADOM

Answer: B,D


NEW QUESTION # 54
An administrator configures a new firewall policy on FortiManager and has not yet pushed the changes to the
managed FortiGate.
In which database will the configuration be saved?

  • A. Device-level database
  • B. Configuration-level database
  • C. Revision history database
  • D. ADOM-level database

Answer: D

Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47942


NEW QUESTION # 55
What is the purpose of ADOM revisions?

  • A. To create System Checkpoints for the FortiManager configuration.
  • B. To save the current state of all policy packages and objects for an ADOM.
  • C. To revert individual policy packages and device-level settings for a managed FortiGate by reverting to a specific ADOM revision
  • D. To save the current state of the whole ADOM.

Answer: B

Explanation:
Fortimanager 6.4 Study guide page 198


NEW QUESTION # 56
Refer to the exhibit.

An administrator logs into the FortiManager GUI and sees the panes shown in the exhibit.
Which two reasons can explain why the FortiAnalyzer feature panes do not appear? (Choose two.)

  • A. FortiAnalyzer features are not enabled on FortiManager.
  • B. The administrator profile does not have full access privileges like the Super_User profile.
  • C. The administrator IP address is not a part of the trusted hosts configured on FortiManager interfaces.
  • D. The administrator logged in using the unsecure protocol HTTP, so the view is restricted.

Answer: A,B


NEW QUESTION # 57
View the following exhibit:

How will FortiManager try to get updates for antivirus and IPS?

  • A. From public FDNI server with highest index number only
  • B. From the default server fdsl.fortinet.com
  • C. From the configured override server list only
  • D. From the list of configured override servers with ability to fall back to public FDN servers

Answer: D


NEW QUESTION # 58
View the following exhibit.

Which one of the following statements is true regarding the object named ALL?

  • A. FortiManager updated the object ALL using FortiManager's value in its database
  • B. FortiManager updated the object ALL using FortiGate's value in its database
  • C. FortiManager created the object ALL as a unique entity in its database, which can be only used by this
    managed FortiGate.
  • D. FortiManager installed the object ALL with the updated value.

Answer: B


NEW QUESTION # 59
Which two statements regarding device management on FortiManager are true? (Choose two.)

  • A. FortiGate in transparent mode configurations are not counted toward the device count on FortiManager.
  • B. FortiGate devices in HA cluster devices are counted as a single device.
  • C. FortiGate devices in an HA cluster that has five VDOMs are counted as five separate devices.
  • D. The maximum number of managed devices for each ADOM is 500.

Answer: B,C


NEW QUESTION # 60
An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session.
What can prevent an admin account that has Super_User rights over the device from approving a workflow session?

  • A. Trainer does not have full rights over this ADOM
  • B. Student, who submitted the workflow session, must first self-approve the request
  • C. Trainer must close Student's workflow session before approving the request
  • D. Trainer is not a part of workflow approval group

Answer: D


NEW QUESTION # 61
......

Updated Test Engine to Practice NSE5_FMG-7.0 Dumps & Practice Exam: https://prep4sure.examtorrent.com/NSE5_FMG-7.0-exam-papers.html