QuestionQ1
Centralized managementRefer to the exhibit.

An administrator has assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview, they see settings that they did not change and are uncertain about those changes.
Based on the exhibit, which two actions will occur if they proceed with the installation?
- A FortiGate HQ-NGFW-1 can use FortiManager firmware templates to upgrade firmware and ratings.
- B FortiGate HQ-NGFW-1 can contact the FortiManager acting as FortiGuard Distribution Server (FDS) to download FortiGuard updates.
- C FortiGate HQ-NGFW-1 will use the root_CA3 certificate in firewall address objects or policies.
- D FortiManager will install the CA certificate named root_CA3 to authenticate FortiGate-to-FortiManager communication protocol (FGFM) tunnel connections with FortiGate HQ- NGFW-1.
QuestionQ2
Centralized managementRefer to the exhibit.

FortiManager is deployed behind a network address translation (NAT) device, and the administrator configured the FortiManager NATed IP address in the FortiManager system administration settings.
What result is expected during discovery?
- A FortiManager sets both the 100.65.0.120 IP address and 10.0.13.120 IP address on FortiGate.
- B FortiManager sets both the 100.65.0.120 IP address and 100.65.0.101 IP address on FortiGate.
- C FortiManager sets the 100.65.0.101 IP address on FortiGate.
- D FortiManager sets the 100.65.0.120 IP address on FortiGate.
Community Discussion
QuestionQ3
Centralized managementAn administrator observes that the policy package status for HQ-NGFW-1 is Never Installed.
What can be concluded from this status?
- A The policy package was never imported to the revision history after HQ-NGFW-1 was registered on FortiManager.
- B The policies have not yet been retrieved from the HQ-NGFW-1 device-level database of FortiManager.
- C The firewall policies exist only in the HQ-NGFW-1 device-level database, and no policy package has been assigned to the firewall.
- D The firewall policies were created or changed in the ADOM, and they need to be installed on the managed HQ-NGFW-1 for the first time.
Community Discussion
QuestionQ4
Rules and routingRefer to the exhibit.

What conclusion can be drawn from the downloaded import report?
- A FortiManager does not support per-device mapping for firewall addresses.
- B The administrator will see a new policy package named Remote-FortiGate_root in the FortiManager ADOM database.
- C ortiManager will change the configuration of REMOTE_SUBNET to match the interface mapping coming in from Remote-FortiGate.
- D As a result of this policy import process, FortiManager will create a new firewall address called REMOTE_SUBNET in the ADOM database.
Community Discussion
QuestionQ5
Centralized managementWhich output appears immediately after moving the ISFW device from one ADOM to another?
- A

- B

- C

- D















Community Discussion