Latest [Jun 02, 2024] 100% Passing Guarantee - Brilliant NSE5_FMG-7.0 Exam Questions PDF
NSE5_FMG-7.0 Certification – Valid Exam Dumps Questions Study Guide! (Updated 82 Questions)
Fortinet NSE5_FMG-7.0 certification exam is a vendor-specific exam that is part of Fortinet’s Network Security Expert (NSE) program. NSE5_FMG-7.0 exam consists of 60 multiple-choice questions that are designed to test the candidate’s knowledge of FortiManager 7.0 and its various features and functionality. Candidates are given 90 minutes to complete the exam and must achieve a passing score of 70% or higher to earn the certification.
NEW QUESTION # 21
What does the diagnose dvm check-integrity command do? (Choose two.)
- A. Verifies and corrects unregistered, registered, and deleted device states
- B. Verifies and corrects duplicate VDOM entries
- C. Verifies and corrects database schemas in all object tables
- D. Internally upgrades existing ADOMs to the same ADON version in order to clean up and correct the ADOM
syntax
Answer: A,B
Explanation:
6.2 Study Guide page 305 verify and correct parts of the device manager databases, including: - inconsistent device-to-group and group-to-ADOM memberships - unregistered, registered, and deleted device states - device lock statuses - duplicate VDOM entries
NEW QUESTION # 22
Which of the following statements are true regarding VPN Manager? (Choose three.)
- A. Common IPsec settings need to be configured only once in a VPN Community for all managed gateways.
- B. VPN Manager must be enabled on a per ADOM basis.
- C. VPN Manager can install common IPsec VPN settings on multiple FortiGate devices at the same time.
- D. VPN Manager automatically adds newly-registered devices to a VPN community.
- E. VPN Manager automatically creates all the necessary firewall policies for traffic to be tunneled by IPsec.
Answer: A,B,C
NEW QUESTION # 23
What is the purpose of the Policy Check feature on FortiManager?
- A. To find and merge duplicate policies in the policy package
- B. To find and provide recommendation for optimizing policies in a policy package
- C. To find and delete disabled firewall policies in the policy package
- D. To find and provide recommendation to combine multiple separate policy packages into one common
policy package
Answer: B
NEW QUESTION # 24
An administrator would like to create an SD-WAN using central management in the Training ADOM.
To create an SD-WAN using central management, which two steps must be completed? (Choose two.)
- A. Remove all the interface references such as routes or policies that will be a part of SD-WAN member interfaces
- B. Configure and install the SD-WAN firewall policy and SD-WAN static route before installing the SD-WAN template settings
- C. Specify a gateway address when you create a default SD-WAN static route
- D. Enable SD-WAN central management in the Training ADOM
Answer: A,D
NEW QUESTION # 25
An administrator would like to review, approve, or reject all the firewall policy changes made by the junior administrators.
How should the Workspace mode be configured on FortiManager?
- A. Set to workflow and use the ADOM locking feature
- B. Set to normal and use the policy locking feature
- C. Set to read/write and use the policy locking feature
- D. Set to disable and use the policy locking feature
Answer: A
NEW QUESTION # 26
View the following exhibit.
If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)
- A. FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management.
- B. FortiGate is discovered by FortiManager through the FortiGate NATed IP address.
- C. During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
- D. If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
Answer: B,C
Explanation:
Fortimanager can discover FortiGate through a NATed FortiGate IP address. If a FortiManager NATed IP address is configured on FortiGate, then FortiGate can announce itself to FortiManager. FortiManager will not attempt to re-establish the FGFM tunnel to the FortiGate NATed IP address, if the FGFM tunnel is interrupted. Just like it was in the NATed FortiManager scenario, the FortiManager NATed IP address in this scenario is not configured under FortiGate central management configuration.
NEW QUESTION # 27
What does the diagnose dvm check-integrity command do? (Choose two.)
- A. Verifies and corrects unregistered, registered, and deleted device states
- B. Verifies and corrects duplicate VDOM entries
- C. Verifies and corrects database schemas in all object tables
- D. Internally upgrades existing ADOMs to the same ADON version in order to clean up and correct the ADOM syntax
Answer: A,B
Explanation:
6.2 Study Guide page 305 verify and correct parts of the device manager databases, including: - inconsistent device-to-group and group-to-ADOM memberships - unregistered, registered, and deleted device states - device lock statuses - duplicate VDOM entries
NEW QUESTION # 28
Refer to the exhibit.
An administrator has created a firewall address object, Training which is used in the Local-FortiGate policy package.
When the installation operation is performed, which IP/Netmask will be installed on the Local-FortiGate, for the Training firewall address object?
- A. 10.200.1.0/24
- B. It will create a firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values.
- C. Local-FortiGate will automatically choose an IP/Netmask based on its network interface settings.
- D. 192.168.0.1/24
Answer: D
NEW QUESTION # 29
View the following exhibit.
What is the purpose of setting ADOM Mode to Advanced?
- A. The setting disables concurrent ADOM access and adds ADOM locking
- B. This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.
- C. The setting allows automatic updates to the policy package configuration for a managed device
- D. The setting enables the ADOMs feature on FortiManager
Answer: B
NEW QUESTION # 30
Which two items are included in the FortiManager backup? (Choose two.)
- A. FortiGuard database
- B. Global database
- C. Logs
- D. All devices
Answer: B,D
NEW QUESTION # 31
Refer to the exhibit.
An administrator logs into the FortiManager GUI and sees the panes shown in the exhibit.
Which two reasons can explain why the FortiAnalyzer feature panes do not appear? (Choose two.)
- A. The administrator profile does not have full access privileges like the Super_User profile.
- B. FortiAnalyzer features are not enabled on FortiManager.
- C. The administrator IP address is not a part of the trusted hosts configured on FortiManager interfaces.
- D. The administrator logged in using the unsecure protocol HTTP, so the view is restricted.
Answer: A,B
NEW QUESTION # 32
Refer to the exhibit.
Which two statements about an ADOM set in Normal mode on FortiManager are true? (Choose two.)
- A. FortiManager automatically installs the configuration difference in revisions on the managed FortiGate
- B. It supports the FortiManager script feature
- C. You cannot assign the same ADOM to multiple administrators
- D. It allows making configuration changes for managed devices on FortiManager panes
Answer: B,D
Explanation:
"FortiGate units in the ADOM will query their own configuration every 5 seconds. If there has been a configuration change, the FortiGate unit will send a diff revision on the change to the FortiManager using the FGFM protocol."
NEW QUESTION # 33
Which three settings are the factory default settings on FortiManager? (Choose three.)
- A. Reports and Event Monitor panes are enabled
- B. Password is fortinet
- C. port1 interface IP address is 192.168.1.99/24
- D. FortiAnalyzer features are disabled
- E. Username is admin
Answer: C,D,E
NEW QUESTION # 34
An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session.
What can prevent an admin account that has Super_User rights over the device from approving a workflow session?
- A. Trainer is not a part of workflow approval group
- B. Student, who submitted the workflow session, must first self-approve the request
- C. Trainer must close Student's workflow session before approving the request
- D. Trainer does not have full rights over this ADOM
Answer: A
NEW QUESTION # 35
When an installation is performed from FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?
- A. FortiManager will revert and install a previous configuration revision on the managed FortiGate.
- B. FortiGate will reject the CLI commands that will cause the tunnel to go down.
- C. FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.
- D. After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.
Answer: D
NEW QUESTION # 36
Which two items does an FGFM keepalive message include? (Choose two.)
- A. FortiGate configuration checksum
- B. FortiGate IPS version
- C. FortiGate uptime
- D. FortiGate license information
Answer: A,B
NEW QUESTION # 37
......
Fortinet NSE5_FMG-7.0 certification is intended for professionals who are responsible for managing the security infrastructure of their organization's network. Fortinet NSE 5 - FortiManager 7.0 certification validates the candidate's understanding of FortiManager's capabilities and provides a competitive edge in the job market. Fortinet NSE 5 - FortiManager 7.0 certification also provides a pathway for professionals to advance their career in network security by becoming Fortinet NSE 6 certified.
NSE5_FMG-7.0 are Available for Instant Access: https://exams4sure.briandumpsprep.com/NSE5_FMG-7.0-prep-exam-braindumps.html
