About the Exam

This proctored exam evaluates knowledge of FortiManager devices, including FortiManager configuration and operation. It covers operational scenarios, system configuration, device registration, and troubleshooting. It is intended for network and security analysts responsible for centralized administration of multiple FortiGate devices using FortiManager.

Exam Topics

  • SD-WAN setup20%
  • Rules and routing20%
  • Centralized management20%
  • Advanced IPsec20%
  • SD-WAN troubleshooting20%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated October 15, 2025 at 7:28 AM

Topic filter
Retired questions
Question sort

QuestionQ1

Centralized management

Refer to the exhibit.

Question Image

An administrator has assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview, they see settings that they did not change and are uncertain about those changes.

Based on the exhibit, which two actions will occur if they proceed with the installation?

Choose two
  • A FortiGate HQ-NGFW-1 can use FortiManager firmware templates to upgrade firmware and ratings.
  • B FortiGate HQ-NGFW-1 can contact the FortiManager acting as FortiGuard Distribution Server (FDS) to download FortiGuard updates.
  • C FortiGate HQ-NGFW-1 will use the root_CA3 certificate in firewall address objects or policies.
  • D FortiManager will install the CA certificate named root_CA3 to authenticate FortiGate-to-FortiManager communication protocol (FGFM) tunnel connections with FortiGate HQ- NGFW-1.
Explanation

An additional central-management server configured with server-type update rating allows the FortiGate to use FortiManager as a FortiGuard Distribution Server for FortiGuard updates and rating requests. Installing the root_CA3 CA certificate provides the trust anchor used to authenticate FGFM tunnel communications between the FortiGate and FortiManager. FortiOS documents that the central-management CA certificate is used by the FGFM protocol and that the server list supplies update and rating services.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Centralized management

Refer to the exhibit.

Question Image

FortiManager is deployed behind a network address translation (NAT) device, and the administrator configured the FortiManager NATed IP address in the FortiManager system administration settings.

What result is expected during discovery?

  • A FortiManager sets both the 100.65.0.120 IP address and 10.0.13.120 IP address on FortiGate.
  • B FortiManager sets both the 100.65.0.120 IP address and 100.65.0.101 IP address on FortiGate.
  • C FortiManager sets the 100.65.0.101 IP address on FortiGate.
  • D FortiManager sets the 100.65.0.120 IP address on FortiGate.
Explanation

The mgmt-addr setting supplies FortiManager’s fixed public-facing address for FGFM when FortiManager is behind NAT. A configured value of 100.65.0.120 is therefore set as the FortiManager address on the FortiGate, allowing the FortiGate to initiate its management tunnel through the NAT device.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Centralized management

An administrator observes that the policy package status for HQ-NGFW-1 is Never Installed.

What can be concluded from this status?

  • A The policy package was never imported to the revision history after HQ-NGFW-1 was registered on FortiManager.
  • B The policies have not yet been retrieved from the HQ-NGFW-1 device-level database of FortiManager.
  • C The firewall policies exist only in the HQ-NGFW-1 device-level database, and no policy package has been assigned to the firewall.
  • D The firewall policies were created or changed in the ADOM, and they need to be installed on the managed HQ-NGFW-1 for the first time.
Explanation

A Never Installed status means a policy package is assigned to the managed firewall but was not produced by importing that firewall’s policy and has not yet been installed to it. The ADOM-managed policies therefore require their initial installation on the firewall.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Rules and routing

Refer to the exhibit.

Question Image

What conclusion can be drawn from the downloaded import report?

  • A FortiManager does not support per-device mapping for firewall addresses.
  • B The administrator will see a new policy package named Remote-FortiGate_root in the FortiManager ADOM database.
  • C ortiManager will change the configuration of REMOTE_SUBNET to match the interface mapping coming in from Remote-FortiGate.
  • D As a result of this policy import process, FortiManager will create a new firewall address called REMOTE_SUBNET in the ADOM database.
Explanation

Import Configuration creates a policy package that reflects the FortiGate configuration. The report identifies that package as Remote-FortiGate_root. REMOTE_SUBNET fails interface-binding validation, so it is not successfully created or modified by this import.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Centralized management

Which output appears immediately after moving the ISFW device from one ADOM to another?

  • A
  • B
  • C
  • D
Explanation

Policy packages belong to an ADOM and do not follow a device that is moved, so in the destination ADOM the device has no linked policy package and its package state reports pkg:[never-installed] with no package name. The device database itself is preserved by the move, so diagnose dvm device list continues to show dev-db: not modified, conf: in sync, and dm: installed. States such as unknown, imported, or out-of-sync are displayed against a named package and can therefore appear only after a policy package in the new ADOM has been linked to the device through assignment, import, or installation.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home