On FortiManager, an administrator creates a new system template named Training with two new DNS addresses. During the installation-preview stage, the administrator notices that central-management settings must be purged.
What is the primary reason for the central-management purge command?
AThe Remote-FortiGate device does not have any DNS server-list configured in the central-management settings.
BThe DNS addresses in the default system settings are the same as the Training system template.
CThe ADOM is locked by another administrator.
DThe Training system template has a default FortiGuard widget.
0
Community Discussion
No comments yet. Be the first to start the discussion!
Where does the administrator import the file from?
AFile system
BADOM1
CADOM2 object database
DADOM2
An administrator has enabled Service Access on FortiManager.
What is the purpose of Service Access on a FortiManager interface?
AIt allows FortiManager to determine the connection status of managed devices.
BIt allows administrative access to FortiManager.
CIt allows third-party applications to gain read/write access to FortiManager.
DIt allows FortiManager to respond to requests for FortiGuard services from FortiGate devices.
Refer to the exhibit.
Which statement is correct about the FortiManager ADOM policy tab based on the API request?
AThe API command has enabled both central NAT and interface policy on the policy tab.
BThe API command has requested the policy tab permissions information only.
CThe API command has failed when requesting policy tab permissions information.
DThe API command has applied to customer with ID: 200.
Which two settings are necessary for FortiManager Management Extension Applications (MEA)?
Choose two
AYou must create an MEA special policy on FortiManager using the super user profile.
BYou must open the ports to the Fortinet registry.
CWhen you configure MEA, you must open TCP or UDP port 540.
DThe administrator must have the super user profile.
An administrator is replacing a failed device in FortiManager by using the following command: execute device replace sn <devname> <serialnum>.
Which device name and serial number must the administrator provide?
AThe device name of the new device and serial number of the failed device
BThe device name and serial number of the failed device
CThe device name of the failed device and serial number of the new device
DThe device name and serial number of the new device
Refer to the exhibit.
Based on the error message, why is FortiManager unable to add the FortiAnalyzer device?
AThe administrator must use the correct user name and password of the FortiAnalyzer device.
BThe administrator must turn off the Use Legacy Device login and add the FortiAnalyzer device to the same network as FortiManager.
CThe administrator must use the Add Model Device section and discover the FortiAnalyzer device.
DThe administrator must select the FortiManager administrative access checkbox on the FortiAnalyzer management interface.
Refer to the exhibit.
What occurs if the script is run with the Device Database option?
Choose two
AYou must install these changes using the Install Wizard to a managed device.
BThe script history will show successful installation of the script on the remote FortiGate.
CThe successful execution of a script on the Device Database will create a new revision history.
DThe Device Settings Status will be tagged as Modified.
Refer to the exhibit.
How does FortiManager attempt to obtain antivirus and IPS updates?
AFrom the list of configured override servers or public FDN servers
BFrom the default server fds1.fortinet.com
CFrom the configured override server IP address 10.0.1.50 only
DFrom public FDNI server IP address with the fourth highest octet only
An administrator has created a global policy package containing header and footer policies and assigned it to an ADOM.
Which two outcomes result from this action?
Choose two
AYou must manually move the header and footer policies after the policy assignment.
BAfter you assign the global policy package to an ADOM, the policy package is hidden from the ADOM and cannot be viewed.
CIf you assign an additional global policy package to the same ADOM, FortiManager removes previously assigned policies.
DYou can edit or delete all the global objects in the global ADOM.
An administrator has enabled workspace mode and wants to delete an address object that is currently referenced by a firewall policy.
Which two outcomes can the administrator expect?
Choose two
AFortiManager will temporarily change the status of the referenced firewall policy.
BFortiManager will disable the status of the address object.
CFortiManager will replace the deleted address object with the none address object in the referenced firewall policy.
DFortiManager will not allow the administrator to delete a referenced address object until the ADOM is locked.
Refer to the exhibit.
An administrator signs in to the FortiManager GUI and sees the panes displayed in the exhibit.
Which two reasons could explain why the FortiAnalyzer feature panes are not displayed?
Choose two
AThe administrator workflow is enabled on the ADOM.
BFortiAnalyzer features are not enabled on FortiManager.
CThe admin session requires approval before administrator can see the FortiAnalyzer feature panes.
DThe administrator profile does not have full access privileges like the Super_User profile.
Which two of the following items are included in a FortiManager backup?
Choose two
AFortiGuard database
BFirmware images
CFlash configuration
DAll devices
An administrator, Trainer, who has been assigned the Super_User profile, is attempting to approve a workflow session submitted by another administrator, Student. However, Trainer cannot approve the workflow session.
What could stop an admin account with Super_User rights over the device from approving a workflow session?
ATrainer must first create their own workflow session to approve student session.
BTrainer is not a part of workflow approval group.
CTrainer must close Student’s workflow session before approving the request.
DTrainer does not have full rights over this ADOM.
An administrator creates a new OSPF route in FortiManager but has not yet pushed the changes to the managed FortiGate device.
In which database is the configuration saved?
ARevision history database
BADOM-level database
CConfiguration-level database
DDevice-level database
An administrator wants to review, approve, or reject every firewall-policy change made by junior administrators.
How should the FortiManager workspace-mode settings be configured?
ASet to normal and using the approval group feature
BSet to read/write and using the policy locking feature
CSet to workflow and using the ADOM locking feature
DSet to workspace and using the policy locking feature
Refer to the exhibit.
What is the purpose of configuring ADOM Mode as Advanced?
AThis setting enables the ADOMs feature on FortiManager.
BThis setting allows you to manage FortiGate chassis models.
CThis setting disables concurrent ADOM access and adds ADOM locking.
DThis setting allows you to assign a VDOM from a single device to a different ADOM.
An administrator executes the reload-failure command diagnose test deploymanager reloadconf <deviceid> on FortiManager.
What does this command do?
AIt reloads the policy package from the FortiManager to FortiGate.
BIt installs the latest configuration on the specified FortiGate and updates the revision history database.
CIt downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.
DIt compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate.
Refer to the following exhibit.
If both FortiManager and FortiGate are behind NAT devices, which two results are expected?
Choose two
ADuring discovery, the FortiManager NATed IP address is not set by default on FortiGate.
BIf the FGFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
CFortiGate is discovered by FortiManager through the FortiGate NATed IP address.
DFortiGate can announce itself to FortiManager only if the FortiManager non-NATed IP address is configured on FortiGate under central management.
Push updates are failing for a FortiGate device located behind a NAT device.
Which two settings should the administrator verify?
Choose two
AThat the virtual IP address and correct ports are set on the NAT device
BThat the override server IP address is set on FortiManager and the NAT device
CThat the external IP address on the NAT device is set to DHCP and configured with the virtual IP
DThat the NAT device IP address and correct ports are configured on FortiManager
Refer to the exhibit.
An administrator created a firewall address object named Local, which is used in the Remote-FortiGate policy package. When the installation operation is performed, which IP/Netmask is installed on Remote-FortiGate for the Local firewall address object?
A192.168.5.0/24
BRemote-FortiGate will automatically choose an IP/netmask based on its network interface settings.
C10.0.2.0/24
DIt will create the Local and Remote-Local firewall address objects on Remote-FortiGate with 192.168.5.0/24 and 10.0.2.0/24 values.
Community Discussion