[2024年03月26日] 最新をゲットせよ!NSE5_FMG-7.2認定練習テスト問題と試験問題集
リアルNSE5_FMG-7.2試験問題集解答で有効なNSE5_FMG-7.2問題集PDF
Fortinet NSE5_FMG -7.2(Fortinet NSE 5 -Fortimanager 7.2)試験は、Fortimanagerの構成、管理、維持の専門知識を実証したいIT専門家の認定試験です。この試験は、複数のFortinetデバイスを管理し、さまざまなネットワーク全体でセキュリティポリシーを実装する際に候補者のスキルと知識をテストするように設計されています。
Fortinet NSE5_FMG-7.2試験は、ネットワークセキュリティに特化したITプロフェッショナル向けにFortinetが提供する認定試験です。この試験は、Fortinetのネットワークセキュリティ管理ソリューションであるFortiManager 7.2での作業経験を持つ個人を対象としています。試験は、複数のFortinetデバイス全体でのセキュリティポリシーの管理と管理能力を候補者の知識とスキルを検証することを目的としています。
Fortinet NSE5_FMG-7.2の試験は、グローバルに認められているベンダー中立的な認証資格です。この試験は、FortiManager管理、デバイス登録、デバイス管理、ポリシーやオブジェクト管理、構成管理など、幅広いトピックをカバーしています。この試験は、中央管理プラットフォームを通じて、複数のデバイスを効率的かつ効果的に管理できるかどうかをテストするために設計されています。
質問 # 29
What does a policy package status ofModifiedindicate?
- A. The policy package was never imported after a device was registered on FortiManager
- B. The Policy package configuration has been changed on FortiManager and changes have not yet been installed on the managed device.
- C. FortiManager is unable to determine the policy package status
- D. The Policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager
正解:A
質問 # 30
Refer to the exhibit.
An administrator has created a firewall address object,Trainingwhich is used in the Local-FortiGate policy package.
When the installation operation is performed, which IP/Netmask will be installed on the Local-FortiGate, for theTrainingfirewall address object?
- A. Local-FortiGate will automatically choose an IP/Netmask based on its network interface settings.
- B. It will create a firewall address group on Local-FortiGate with192.168.0.1/24and10.0.1.0/24object values.
- C. 192.168.0.1/24
- D. 10.200.1.0/24
正解:C
質問 # 31
Which two settings are required for FortiManager Management Extension Applications (MEA)? (Choose two.)
- A. You must create a MEA special policy on FortiManager using the super user profile
- B. You must open the ports to the Fortinet registry
- C. The administrator must have the super user profile.
- D. When you configure MEA, you must open TCP or UDP port 540.
正解:A、C
質問 # 32
Refer to the exhibit.
Given the configuration shown in the exhibit, how did FortiManager handle the service category named General?
- A. FortiManager ignored the firewall service category General and did not update Its database with the value
- B. FortiManager ignored the firewall service category general and deleted the duplicate value In Its database
- C. FortiManager ignored the firewall service category General but created a new service category in its database.
- D. FortiManager ignored the firewall service category General and updated the FortiGate duplicate value in the FortiGate database.
正解:A
質問 # 33
Refer to the exhibit.
Which statement is true about the FortiManager ADOM policy tab based on the API request?
- A. The API command has failed when requesting policy tab permissions information.
- B. The API command has applied to customer with ID: 200.
- C. The API command has enabled both central NAT and interface policy on the policy tab.
- D. The API command has requested the policy tab permissions information only.
正解:C
質問 # 34
What does a policy package status ofModifiedindicate?
- A. The policy package was never imported after a device was registered on FortiManager
- B. The Policy package configuration has been changed on FortiManager and changes have not yet been installed on the managed device.
- C. FortiManager is unable to determine the policy package status
- D. The Policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager
正解:A
解説:
Reference:http://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_A
dmin_Guide/1200_Policy%20and%20Objects/0800_Managing%20policy%20packages/2200_Policy%20Packag
質問 # 35
An administrator would like to review, approve, or reject all the firewall policy changes made by the junior administrators.
How should the Workspace mode be configured on FortiManager?
- A. Set to workflow and use the ADOM locking feature
- B. Set to normal and use the policy locking feature
- C. Set to read/write and use the policy locking feature
- D. Set to disable and use the policy locking feature
正解:A
解説:
Reference:https://help.fortinet.com/fmgr/50hlp/52/5-2-0/FMG_520_Online_Help/200_What's-New.03.03.html
質問 # 36
View the following exhibit, which shows theDownload Import Report:
Why it is failing to import firewall policy ID 2?
- A. Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.
- B. The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association locally on the FortiGate
- C. Policy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager
- D. Policy ID 2 does not have ADOM Interface mapping configured on FortiManager
正解:B
解説:
FortiManager_6.4_Study_Guide-Online - page 331 & 332
質問 # 37
View the following exhibit.
What is the purpose of settingADOM ModetoAdvanced?
- A. The setting allows automatic updates to the policy package configuration for a managed device
- B. This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.
- C. The setting disables concurrent ADOM access and adds ADOM locking
- D. The setting enables the ADOMs feature on FortiManager
正解:B
解説:
Reference:https://docs.fortinet.com/document/fortianalyzer/7.0.0/administration-guide/66530/adom-device-mode
質問 # 38
Which two items does an FGFM keepalive message include? (Choose two.)
- A. FortiGate license information
- B. FortiGate configuration checksum
- C. FortiGate uptime
- D. FortiGate IPS version
正解:B、D
解説:
Reference:https://docs.fortinet.com/document/fortimanager/6.2.0/fortigate-fortimanager-communications-protoc
質問 # 39
An administrator has enabledService Accesson FortiManager.
What is the purpose ofService Accesson the FortiManager interface?
- A. Allows FortiManager to automatically configure a default route
- B. Allows FortiManager to run real-time debugs on the managed devices
- C. Allows FortiManager to respond to request for FortiGuard services from FortiGate devices
- D. Allows FortiManager to download IPS packages
正解:C
解説:
FortiManager 6.2 Study guide page 350
質問 # 40
An administrator configures a new firewall policy on FortiManager and has not yet pushed the changes to the managed FortiGate.
In which database will the configuration be saved?
- A. Configuration-level database
- B. Revision history database
- C. ADOM-level database
- D. Device-level database
正解:C
解説:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47942
質問 # 41
Refer to the exhibit.
An administrator logs into the FortiManager GUI and sees the panes shown in the exhibit.
Which two reasons can explain why the FortiAnalyzer feature panesdo notappear? (Choose two.)
- A. The administrator logged in using the unsecure protocol HTTP, so the view is restricted.
- B. The administrator IP address is not a part of the trusted hosts configured on FortiManager interfaces.
- C. The administrator profile does not have full access privileges like theSuper_Userprofile.
- D. FortiAnalyzer features are not enabled on FortiManager.
正解:C、D
質問 # 42
Refer to the exhibits.
Exhibit one.
Exhibit two.
An administrator created a new system template namedTrainingwith two new DNS addresses on FortiManager. During the installation preview stage, the administrator notices that many unset commands need to be pushed.
What can be the main reason for these unset commands?
- A. The ADOM is locked by another administrator
- B. The DNS addresses in the default system settings are the same as theTrainingsystem template
- C. TheTrainingsystem template has other default settings
- D. TheTrainingsystem template does not have assigned devices
正解:C
質問 # 43
Which two conditions trigger FortiManager to create a new revision history? (Choose two.)
- A. When changes to device-level database is made on FortiManager
- B. When FortiManager installs device-level changes to a managed device
- C. When configuration revision is reverted to previous revision in the revision history
- D. When FortiManager is auto-updated with configuration changes made directly on a managed device
正解:B、D
解説:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1000_Device%20Manage
質問 # 44
In the event that the primary FortiManager fails, which of the following actions must be performed to return the FortiManager HA to a working state?
- A. FortiManager HA state transition is transparent to administrators and does not require any reconfiguration.
- B. Manually promote one of the secondary devices to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- C. Reboot one of the secondary devices to promote it automatically to the primary role, and reconfigure all other secondary devices to point to the new primary device.
- D. Secondary device with highest priority will automatically be promoted to the primary role, and manually reconfigure all other secondary devices to point to the new primary device
正解:B
解説:
FortiManager_6.4_Study_Guide-Online - page 346
FortiManager HA doesn't support IP takeover where an HA state transition is transparent to administrators. If a failure of the primary occurs, the administrator must take corrective action to resolve the problem that may include invoking the state transition. If the primary device fails, the administrator must do the following in order to return the FortiManager HA to a working state:
1. Manually reconfigure one of the secondary devices to become the primary device
2. Reconfigure all other secondary devices to point to the new primary device
質問 # 45
An administrator created a header and footer global policy package and assigned it to an ADOM.
What are two outcomes from this action? (Choose two.)
- A. If you assign an additional global policy package to the same ADOM, FortiManaqer removes previously assigned policies.
- B. After you assign the global policy package to an ADOM, the policy package is hidden from the ADOM and cannot be viewed.
- C. You must manually move the header and footer policies after the policy assignment.
- D. You can edit or delete all the global objects in the global ADOM.
正解:C、D
質問 # 46
View the following exhibit.
When usingInstall Configoption to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)
- A. Provides the option to preview configuration changes prior to installing them
- B. Once initiated, the install process cannot be canceled and changes will be installed on the managed device
- C. Installs device-level changes to FortiGate without launching theInstall Wizard
- D. Will not create new revision in the revision history
正解:B、C
質問 # 47
Refer to the exhibit.
Given the configuration shown in the exhibit, what can you conclude from the installation targets m the Install On column? (Choose two)
- A. Policy 3 will be installed on all FortiGate devices and vdom belongs to the ADOM
- B. Policy seq # 3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
- C. Policy seq # 2 will not be installed on the Local-FortiGate root VDOM because there is no root VDOM in the Installation Target
- D. Policy seq # 3 will be skipped because no installation targets are specified
- E. Policy seq # 1 will be installed on the Remoto-FortiGate root[NAT] and Student[NAT] VDOMs only
正解:B、E
質問 # 48
......
NSE5_FMG-7.2試験問題集でPDF問題とテストエンジン:https://www.passtest.jp/Fortinet/NSE5_FMG-7.2-shiken.html
最新NSE5_FMG-7.2試験問題集には合格保証付きます:https://drive.google.com/open?id=1UUuRvMIy902mjq5nNe5gcqpVopr6UPUv