[Oct 31, 2021] Free Fortinet NSE 5 NSE5_FMG-6.2 Exam Question
NSE5_FMG-6.2 dumps & Fortinet NSE 5 sure practice dumps
NEW QUESTION 14
View the following exhibit.
When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)
- A. Provides the option to preview configuration changes prior to installing them
- B. Will not create new revision in the revision history
- C. Installs device-level changes to FortiGate without launching the Install Wizard
- D. Once initiated, the install process cannot be canceled and changes will be installed on the managed device
Answer: C,D
NEW QUESTION 15
View the following exhibit. An administrator is importing a new device to FortiManager and has selected the shown options.
What will happen if the administrator makes the changes and installs the modified policy package on this managed FortiGate?
- A. The unused objects that are not tied to the firewall policies will remain as read-only locally on FortiGate
- B. The unused objects that are not tied to the firewall policies locally on FortiGate will be deleted
- C. The unused objects that are not tied to the firewall policies in policy package will be deleted from the FortiManager database
- D. The unused objects that are not tied to the firewall policies will be installed on FortiGate
Answer: B
Explanation:
Regardless of whether you choose to import only policy-dependent objects or all objects, the system will delete orphan (unused) object that are not tied to policies locally on FortiGate in the next installation.
NEW QUESTION 16
Which of the following items does an FGFM keepalive message include? (Choose two.)
- A. FortiGate license information
- B. FortiGate configuration checksum
- C. FortiGate uptime
- D. FortiGate IPS version
Answer: B,D
NEW QUESTION 17
Which of the following items does an FGFM keepalive message include? (Choose two.)
- A. FortiGate IPS version
- B. FortiGate license information
- C. FortiGate configuration checksum
- D. FortiGate uptime
Answer: B,C
Explanation:
FGFM Keepalive Messages configured on FortiManager. Only FortiGate sends a keepalive message to FortiManager, regardless of which device established the FGFM tunnel. FortiGate also sends a configuration checksum to confirm synchronization as a part of keepalive.
NEW QUESTION 18
Which of the following statements are true regarding schedule backup of FortiManager? (Choose two.)
- A. Supports FTP, SCP, and SFTP
- B. Backs up all devices and the FortiGuard database.
- C. Can be configured from the CLI and GUI
- D. Does not back up firmware images saved on FortiManager
Answer: A,D
NEW QUESTION 19
View the following exhibit. An administrator has created a firewall address object, Training, which is used in the Local-FortiGate policy package.
When the install operation is performed, which IP Netmask will be installed on the Local-FortiGate, for the Training firewall address object?
- A. 10.0.1.0/24
- B. 192.168.0.1/24
- C. Local-FortiGate will automatically choose an IP Network based on its network interface settings.
- D. It will create firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values
Answer: A
Explanation:
In the example, the dynamic address object LocalLan refers to the internal network address of the managed firewalls. The object has a default value of
192.168.1.0/24. The mapping rules are defined per device. For Remote-FortiGate, the address object LocalLan referes to 10.10.11.0/24. The devices in the ADOM that do not have dynamic mapping for LocalLan have a default value of 192.168.1.0/24.
NEW QUESTION 20
Refer to the exhibits.
Exhibit one.
Exhibit two.
An administrator created a new system template named Training with two new DNS addresses on FortiManager. During the installation preview stage, the administrator notices that many unset commands need to be pushed.
What can be the main reason for these unset commands?
- A. The Training system template does not have assigned devices
- B. The DNS addresses in the default system settings are the same as the Training system template
- C. The Training system template has other default settings
- D. The ADOM is locked by another administrator
Answer: C
NEW QUESTION 21
What is the purpose of the Policy Check feature on FortiManager?
- A. To find and provide recommendation for optimizing policies in a policy package
- B. To find and provide recommendation to combine multiple separate policy packages into one common policy package
- C. To find and delete disabled firewall policies in the policy package
- D. To find and merge duplicate policies in the policy package
Answer: D
Explanation:
The policy check tool allows you to check all policy packages within an ADOM to ensure consistency and eliminate conflicts that may prevent your devices from passing traffic. This allows you to optimize your policy sets and potentially reduce the size of your databases. The check will verify:
1. Object duplication: two objects that have identical definitions
2. Object shadowing: a higher priority object completely encompasses another object of the same type
3. Object overlap: one object partially overlaps another object of the same type
4. Object orphaning: an object has been defined but has not been used anywhere.
Reference: https://docs.fortinet.com/uploaded/files/2905/FortiManager-5.4.0-Administration-Guide.pdf
NEW QUESTION 22
View the following exhibit, which shows the Download Import Report:
Why it is failing to import firewall policy ID 2?
- A. Policy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager
- B. The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association locally on the FortiGate
- C. Policy ID 2 does not have ADOM Interface mapping configured on FortiManager
- D. Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.
Answer: B
Explanation:
FortiManager can create a dynamic mapping for an address object, if the address object name is the same, but contains a different value locally. However, there is one restriction - the associated interface cannot be different. This is because, at the ADOM level, this address object might be used by other policy packages, which might not have same interfaces." Address object name in this case is "REMOTE_SUBNET". The interface binding has 2 different interfaces 'ANY' and
'Port6'. They cannot be different.
NEW QUESTION 23
As a result of enabling FortiAnalyzer features on FortiManager, which of the following statements is true?
- A. FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager
- B. FortiManager can be used only as a logging device.
- C. FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices
- D. FortiManager will reboot
Answer: D
NEW QUESTION 24
Refer to the exhibit. Given the configurations shown in the exhibit, what can you conclude from the installation targets in the Install On column?
- A. The Install On column value represents successful installations on the managed devices.
- B. Policy seq.# 3 will be installed on all managed devices and VDOMs that are listed under Installation Targets.
- C. Policy seq.# 3 will be installed on the Trainer[NAT] VDOM only.
- D. Policy seq.# 3 will not be installed on any managed device.
Answer: B
NEW QUESTION 25
What does a policy package status of Modified indicate?
- A. FortiManager is unable to determine the policy package status
- B. The policy package was never imported after a device was registered on FortiManager
- C. Policy package configuration has been changed on FortiManager and changes have not yet been installed on the managed device.
- D. Policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager
Answer: C
Explanation:
http://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1200_Policy%20and%20Objects/0800_Managing%20policy%20packages/2200_Policy%
20Package%20Installation%20targets.htm
NEW QUESTION 26
Refer to the exhibit. Which statement is correct?
- A. FortiManager will delete service category General from its ADOM object database.
- B. FortiManager will update its object database for service category General with the object value from FortiGate.
- C. FortiManager will keep its existing object value for service category General in the ADOM object database and will consider it a duplicate entry.
- D. A FortiManager administrator must select view details to modify and match the value between FortiGate and FortiManager.
Answer: B
NEW QUESTION 27
What are the factory default settings on FortiManager? (Choose three.)
- A. Reports and Event Monitor panes are enabled
- B. Password is fortinet
- C. port1 interface IP address is 192.168.1.99/24
- D. Username is admin
- E. FortiAnalyzer features are disabled
Answer: C,D,E
NEW QUESTION 28
View the following exhibit:
Which of the following statements are true if the scripts is executed using Remote FortiGate Directly (via CLI) option? (Choose two.)
- A. You must install these changes using Install Wizard
- B. FortiManager will create a new revision history.
- C. FortiGate will auto-update the FortiManager's device-level database.
- D. FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate.
Answer: B,C
NEW QUESTION 29
An administrator run the reload failure command: diagnose test deploymanager reload config
<deviceid> on FortiManager. What does this command do?
- A. It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate.
- B. It installs the latest configuration on the specified FortiGate and update the revision history database.
- C. It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.
- D. It installs the provisioning template configuration on the specified FortiGate.
Answer: C
NEW QUESTION 30
An administrator wants to delete an address object that is currently referenced in a firewall policy. Which one of the following statements is true?
- A. FortiManager will replace the deleted address object with all address object in the referenced firewall policy
- B. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy
- C. FortiManager will disable the status of the referenced firewall policy
- D. FortiManager will not allow the administrator to delete a referenced address object
Answer: B
NEW QUESTION 31
Which of the following are FortiManager features? (Choose two)
- A. Cloud-based Management
- B. Administrative Domains
- C. Virtual Domains
- D. Centralized Management
Answer: B,D
Explanation:
Explanation
NEW QUESTION 32
How are the points calculated when using FortiMeter to deploy FortiOS-VM? (Choose two.)
- A. Based on the traffic usage on port1 and port2 on FortiOS-VM.
- B. Based on the amount of traffic (per GB) passing through the FortiOS-VM.
- C. Based on the number of sessions on the mgmt interface of FortiOS-VM.
- D. Based on the FortiGuard service option enabled for FortiOS-VM.
Answer: A,D
Explanation:
Point calculations are based off of traffic passing through the FortiOS-VM interfaces. Points are used per terabyte of traffic and there is an increased point cost as you increase the FortiGuard services in use.
4 pts/TB for a FortiOS-VM tagged as "FW"
10 pts/TB for a FortiOS-VM tagged as "FW + URL"
25 pts/TB for a FortiOS-VM tagged as "UTM"
Reference: https://docs.fortinet.com/uploaded/files/4057/fortinetvm_on-demand_1.pdf
NEW QUESTION 33
In the event that the primary FortiManager fails, which of the following actions must be performed to return the FortiManager HA to a working state?
- A. Manually promote one of the secondary devices to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- B. Reboot one of the secondary devices to promote it automatically to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- C. Secondary device with highest priority will automatically be promoted to the primary role, and manually reconfigure all other secondary devices to point to the new primary device
- D. FortiManager HA state transition is transparent to administrators and does not require any reconfiguration.
Answer: A
NEW QUESTION 34
......
Fortinet NSE5_FMG-6.2 Actual Questions and Braindumps: https://www.vceprep.com/NSE5_FMG-6.2-latest-vce-prep.html