良質なNSE5_FMG-7.2のPDF問題集でNSE5_FMG-7.2試験問題を試せます
一番最新のFortinet NSE5_FMG-7.2試験問題集PDF2025年更新
質問 # 19
Refer to the exhibit.
A junior administrator is troubleshooting a FortiManager connectivity issue that rs occurring with managed FortiGate devices Given the FortiManager device manager settings shown in the exhibit what can you conclude from the exhibit?
- A. The administrator can reclaim the FGFM tunnel to get both devices online
- B. FortiManager test internet connectivity therefore, both devices appear to be down
- C. The administrator had restored the FortiManager configuration file
- D. The administrator must refresh both devices to restore connectivity
正解:A
質問 # 20
Refer to the exhibit.
Given the configuration shown in the exhibit, which two statements are true? (Choose two.)
- A. It disables concurrent read-write access to an ADOM.
- B. It allows the same administrator to lock more than one ADOM at the same time.
- C. It allows two or more administrators to make configuration changes at the same time, in the same ADOM.
- D. It is used to validate administrator login attempts through external servers.
正解:A、B
解説:
Reference:https://docs.fortinet.com/document/fortimanager/6.0.4/administration-guide/86456/concurrentadom-ac
質問 # 21
Refer to the exhibit.
Given the configuration shown in the exhibit, what can you conclude from the installation targets m the Install On column? (Choose two)
- A. Policy seq # 3 will be skipped because no installation targets are specified
- B. Policy seq # 3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
- C. Policy seq # 1 will be installed on the Remoto-FortiGate root[NAT] and Student[NAT] VDOMs only
- D. Policy seq # 2 will not be installed on the Local-FortiGate root VDOM because there is no root VDOM in the Installation Target
- E. Policy 3 will be installed on all FortiGate devices and vdom belongs to the ADOM
正解:B、C
質問 # 22
Refer to the exhibit.
Which two statements about the output are true? (Choose two.)
- A. The latest revision history for the managed FortiGate does match with the FortiGate running configuration
- B. The latest history for the managed FortiGate does not match with the device-level database
- C. Configuration changes have been installed to FortiGate and represents FortiGate configuration has been changed
- D. Configuration changes directly made on the FortiGate have been automatically updated to device-level database
正解:A、B
解説:
STATUS: dev-db: modified; conf: in sync; cond: pending; dm: retrieved; conn: up- dev-db: modified - This is the device setting status which indicates that configuration changes were made on FortiManager.
- conf: in sync - This is the sync status which shows that the latest revision history is in sync with Fortigate's configuration.- cond: pending - This is the configuration status which says that configuration changes need to be installed.
Most probably a retrieve was done in the past (dm: retrieved) updating the revision history DB (conf: in sync) and FortiManager device level DB, now there is a new modification on FortiManager device level DB (dev-db: modified) which wasn't installed to FortiGate (cond: pending), hence; revision history DB is not aware of that modification and doesn't match device DB.
Conclusion:- Revision DB does match FortiGate.- No changes were installed to FortiGate yet.- Device DB doesn't match Revision DB.- No changes were done on FortiGate (auto-update) but configuration was retrieved instead After an Auto-Update or Retrieve:device database = latest revision = FGT Then after a manual change on FMG end (but no install yet):latest revision = FGT (still) but now device database has been modified (is different).
After reverting to a previous revision in revision history:device database = reverted revision != FGT
質問 # 23
An administrator has assigned a global policy package to custom ADOM1. Then the administrator creates a new policy package Fortinet in the custom ADOM1. What will happen to the Fortinet policy package when it is created?
- A. You need to reapply the global poky package to the ADOM
- B. You need to assign the global policy package from the global ADOM
- C. You can select the option to assign the global polices
- D. it automatically assigns the global policies
正解:D
質問 # 24
An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session.
What can prevent an admin account that has Super_User rights over the device from approving a workflow session?
- A. Trainer does not have full rights over this ADOM
- B. Trainer must close Student's workflow session before approving the request
- C. Student, who submitted the workflow session, must first self-approve the request
- D. Trainer is not a part of workflow approval group
正解:D
質問 # 25
Refer to the exhibit.
Which statement is true about the FortiManager ADOM policy tab based on the API request?
- A. The API command has enabled both central NAT and interface policy on the policy tab.
- B. The API command has failed when requesting policy tab permissions information.
- C. The API command has requested the policy tab permissions information only.
- D. The API command has applied to customer with ID: 200.
正解:A
質問 # 26
Refer to the exhibit.
An administrator is about to add the FortiGate device to FortiManager using the discovery process FortiManager is operating behind a NAT device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings What is the expected result?
- A. During discovery FortiManager uses only the FortiGate serial number to establish the connection
- B. During discovery FortiManager sets both tie FortiManager NATed IP address and NAT device IP address on FortiGate
- C. During discovery FortiManager sets the NATed device IP address on FortiGate
- D. During discovery FortiManager sets trie FortiManager NATed IP address on FortiGate
正解:C
質問 # 27
Which two statements regarding device management on FortiManager are true? (Choose two.)
- A. FortiGate devices in HA cluster devices are counted as a single device.
- B. FortiGate in transparent mode configurations are not counted toward the device count on FortiManager.
- C. The maximum number of managed devices for each ADOM is 500.
- D. FortiGate devices in an HA cluster that has five VDOMs are counted as five separate devices.
正解:A、D
質問 # 28
Refer to the exhibit.
An administrator logs into the FortiManager GUI and sees the panes shown in the exhibit.
Which two reasons can explain why the FortiAnalyzer feature panes do not appear? (Choose two.)
- A. The administrator logged in using the unsecure protocol HTTP, so the view is restricted.
- B. The administrator IP address is not a part of the trusted hosts configured on FortiManager interfaces.
- C. The administrator profile does not have full access privileges like the Super_User profile.
- D. FortiAnalyzer features are not enabled on FortiManager.
正解:C、D
質問 # 29
Refer to the exhibit.
Which two statements about an ADOM set inNormalmode on FortiManager are true? (Choose two.)
- A. It supports the FortiManager script feature
- B. It allows making configuration changes for managed devices on FortiManager panes
- C. FortiManager automatically installs the configuration difference in revisions on the managed FortiGate
- D. You cannot assign the same ADOM to multiple administrators
正解:A、B
解説:
"FortiGate units in the ADOM will query their own configuration every 5 seconds. If there has been a configuration change, the FortiGate unit will send a diff revision on the change to the FortiManager using the FGFM protocol."
質問 # 30
Refer to the exhibit.
How will FortiManager try to get updates for antivirus and IPS?
- A. From public FDNI server IP address with the fourth highest octet only
- B. From the list of configured override servers or public FDN servers
- C. From the default server fds1.fortinet.com
- D. From the configured override server IP address 10.0.1.50 only
正解:B
質問 # 31
Refer to the exhibit.
A junior administrator is troubleshooting a FortiManager connectivity issue that rs occurring with managed FortiGate devices Given the FortiManager device manager settings shown in the exhibit what can you conclude from the exhibit?
- A. FortiManager test internet connectivity therefore, both devices appear to be down
- B. The administrator had restored the FortiManager configuration file
- C. The administrator can reclaim the FGFM tunnel to get both devices online
- D. The administrator must refresh both devices to restore connectivity
正解:A
質問 # 32
View the following exhibit.
An administrator has created a firewall address object, Training, which is used in the Local-FortiGate policy package. When the install operation is performed, which IP Netmask will be installed on the Local-FortiGate, for the Training firewall address object?
- A. 10.0.1.0/24
- B. 192.168.0.1/24
- C. It will create firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values
- D. Local-FortiGate will automatically choose an IP Network based on its network interface settings.
正解:A
質問 # 33
Refer to the exhibit.
Given the configuration shown in the exhibit, how did FortiManager handle the service category named General?
- A. FortiManager ignored the firewall service category General and updated the FortiGate duplicate value in the FortiGate database.
- B. FortiManager ignored the firewall service category General but created a new service category in its database.
- C. FortiManager ignored the firewall service category general and deleted the duplicate value In Its database
- D. FortiManager ignored the firewall service category General and did not update Its database with the value
正解:D
質問 # 34
Refer to the exhibit.
You ate using the Quick install option to install configuration changes on the managed FortiGate Which two statements correctly describe the result? (Choose two)
- A. It install provisioning template changes on the FortiGate device
- B. It installs device-level changes on the FortiGate device without launching the Install Wizard
- C. It provides the option to preview only the policy package changes before installing them
- D. It installs all the changes in the device database first and the administrator must reinstall the changes on the FodiGate device
正解:A、B
質問 # 35
Refer to the exhibit.
An administrator has created a firewall address object,Trainingwhich is used in the Local-FortiGate policy package.
When the installation operation is performed, which IP/Netmask will be installed on the Local-FortiGate, for theTrainingfirewall address object?
- A. 192.168.0.1/24
- B. 10.200.1.0/24
- C. Local-FortiGate will automatically choose an IP/Netmask based on its network interface settings.
- D. It will create a firewall address group on Local-FortiGate with192.168.0.1/24and10.0.1.0/24object values.
正解:A
質問 # 36
Refer to the exhibit.
How will FortiManager try to get updates for antivirus and IPS?
- A. From public FDNI server IP address with the fourth highest octet only
- B. From the list of configured override servers or public FDN servers
- C. From the default server fds1.fortinet.com
- D. From the configured override server IP address 10.0.1.50 only
正解:B
質問 # 37
Which two conditions trigger FortiManager to create a new revision history? (Choose two.)
- A. When FortiManager installs device-level changes on a managed device
- B. When changes to the device-level database are made on FortiManager
- C. When a configuration revision is reverted to a previous revision in the revision history
- D. When FortiManager is auto-updated with configuration changes made directly on a managed device
正解:A、B
質問 # 38
Refer to the exhibit.
An administrator would like to create three ADOMs on FortiManager with different access levels based on departments.
What two conclusions can you draw from the design shown in the exhibit? (Choose two.)
- A. The FortiManager policies and objects database can be shared between the Financial and HR ADOMs.
- B. Admin A can access VDOM2 and VDOM3 with the super user profile.
- C. The administrator must configure FortiManager in workspace mode.
- D. The administrator must set the FortiManager ADOM mode to Advanced.
正解:A、D
質問 # 39
An administrator is replacing a failed device on FortiManager by running the following command:
execute device replace sn <devname> <serialnum>.
Which device name and serial number must the administrator use?
- A. The device name and serial number of the failed device
- B. The device name and serial number of the new device
- C. The device name of the new device and serial number of the failed device
- D. The device name of the failed device and serial number of the new device
正解:D
質問 # 40
An administrator wants to delete an address object that is currently referenced in a firewall policy.
What can the administrator expect to happen?
- A. FortiManager will disable the status of the referenced firewall policy
- B. FortiManager will replace the deleted address object with all address object in the referenced firewall policy
- C. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy
- D. FortiManager will not allow the administrator to delete a referenced address object
正解:C
質問 # 41
An administrator has enabledService Accesson FortiManager.
What is the purpose ofService Accesson the FortiManager interface?
- A. Allows FortiManager to automatically configure a default route
- B. Allows FortiManager to run real-time debugs on the managed devices
- C. Allows FortiManager to download IPS packages
- D. Allows FortiManager to respond to request for FortiGuard services from FortiGate devices
正解:D
解説:
FortiManager 6.2 Study guide page 350
質問 # 42
An administrator has assigned a global policy package to custom ADOM1. Then the administrator creates a new policy package,Fortinet, in the custom ADOM1.
Which statement about the global policy package assignment to the newly-created policy packageFortinetis true?
- A. When a new policy package is created, you need to reapply the global policy package to the ADOM.
- B. When a new policy package is created, you can select the option to assign the global policies to the new package.
- C. When a new policy package is created, you need to assign the global policy package from the global ADOM.
- D. When a new policy package is created, it automatically assigns the global policies to the new package.
正解:D
解説:
Global Policy Package is applied at the ADOM level and you have the option to choose which ADOM policy packages you want to exclude (there is no option to choose Policy Packages to include).
質問 # 43
......
Fortinet NSE5_FMG-7.2(Fortinet NSE 5 - FortiManager 7.2)認定試験は、Fortinetセキュリティソリューションを管理および維持する責任を持つ個人のスキルと知識を認定するために設計されています。FortiManagerは、組織がセキュリティオペレーションを合理化し、セキュリティ管理タスクを簡素化することができるセントラルセキュリティ管理プラットフォームです。認定試験は、FortiManagerの構成と管理における専門知識を証明したいセキュリティ専門家を対象としています。
100%無料NSE 5 Network Security Analyst NSE5_FMG-7.2問題集PDFお試しサンプル認定ガイドカバー率:https://www.passtest.jp/Fortinet/NSE5_FMG-7.2-shiken.html
PDF試験材料は2025年最新の実際に出るNSE5_FMG-7.2問題集:https://drive.google.com/open?id=1jZgtfcyT9Hmna0YI87TOqvbT_i78hxm4