[2025年最新] 高合格率な最新無料NSE5_FMG-7.2試験問題集アンサーを使おう
NSE5_FMG-7.2知能問題集PDF!Fortinet NSE5_FMG-7.2試験問セット
質問 # 22
An administrator has assigned a global policy package to custom ADOM1. Then the administrator creates a new policy package,Fortinet, in the custom ADOM1.
Which statement about the global policy package assignment to the newly-created policy packageFortinetis true?
- A. When a new policy package is created, you need to assign the global policy package from the global ADOM.
- B. When a new policy package is created, you can select the option to assign the global policies to the new package.
- C. When a new policy package is created, it automatically assigns the global policies to the new package.
- D. When a new policy package is created, you need to reapply the global policy package to the ADOM.
正解:C
解説:
Global Policy Package is applied at the ADOM level and you have the option to choose which ADOM policy packages you want to exclude (there is no option to choose Policy Packages to include).
質問 # 23
In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator sent a device registration to FortiManager from a remote FortiGate. Which one of the following statements is true?
- A. The FortiManager administrator must add the unregistered device manually to the unregistered device
- B. The FortiGate will be automatically added to the Training ADOM.
- C. By default, the unregistered FortiGate will appear in the root ADOM.
- D. The FortiGate will be added automatically to the default ADOM named FortiGate.
正解:C
解説:
manually to the Training ADOM using the Add Device wizard
質問 # 24
View the following exhibit.
When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)
- A. Provides the option to preview configuration changes prior to installing them
- B. Once initiated, the install process cannot be canceled and changes will be installed on the managed device
- C. Will not create new revision in the revision history
- D. Installs device-level changes to FortiGate without launching the Install Wizard
正解:B、D
質問 # 25
Refer to the exhibit.
A service provider administrator has assigned a global policy package to a managed customer ADOM named My_ADOM, which has four policy packages. The customer administrator has access onlytoMy_ADOM.
How can customer or service provider administrators remove both global header and footer policies from the policy package named Shared_Package?
- A. The customer administrator can unassign both global polices from My_ADOM.
- B. The service provider administrator can unassign both policies from the global ADOM.
- C. The customer administrator can unassign both polices by locking My_ADOM.
- D. The service provider administrator can unassign both global policies from My_ADOM.
正解:B
解説:
FortiManager_7.2_Study_Guide-Online.pdf page 17: In the global ADOM layer, you create header and footer policy rules. You can assing these policy rules to multiple ADOMs.
質問 # 26
Which two settings must be configured for SD-WAN Central Management? (Choose two.)
- A. When you configure an SD-WAN, you must specify at least two member interfaces.
- B. You can create multiple SD-WAN interfaces per VDOM
- C. SD-WAN must be enabled on per-ADOM basis
- D. The first step in creating an SD-WAN using FortiManager is to create two SD-WAN firewall policies.
正解:A、C
質問 # 27
Refer to the exhibit.
Which statement about the object named ALL is true?
- A. FortiManager updated the object ALL using the FortiManager value in its database.
- B. FortiManager updated the object ALL using the FortiGate value in its database.
- C. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate.
- D. FortiManager installed the object ALL with the updated value.
正解:B
質問 # 28
An administrator would like to review, approve, or reject all the firewall policy changes made by the junior administrators.
How should the Workspace mode be configured on FortiManager?
- A. Set to workflow and use the ADOM locking feature
- B. Set to disable and use the policy locking feature
- C. Set to read/write and use the policy locking feature
- D. Set to normal and use the policy locking feature
正解:A
質問 # 29
Refer to the exhibit.
A junior administrator is troubleshooting a FortiManager connectivity issue that rs occurring with managed FortiGate devices Given the FortiManager device manager settings shown in the exhibit what can you conclude from the exhibit?
- A. The administrator had restored the FortiManager configuration file
- B. The administrator must refresh both devices to restore connectivity
- C. The administrator can reclaim the FGFM tunnel to get both devices online
- D. FortiManager test internet connectivity therefore, both devices appear to be down
正解:D
質問 # 30
View the following exhibit.
When usingInstall Configoption to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)
- A. Provides the option to preview configuration changes prior to installing them
- B. Once initiated, the install process cannot be canceled and changes will be installed on the managed device
- C. Will not create new revision in the revision history
- D. Installs device-level changes to FortiGate without launching theInstall Wizard
正解:B、D
質問 # 31
Which three settings are the factory default settings on FortiManager? (Choose three.)
- A. The Port1 interface IP address is 192.168.1.99/24.
- B. FortiAnalvzer features are disabled.
- C. Management Extension applications are enabled.
- D. The administrative domain is disabled.
- E. The FortiManager setup wizard is disabled.
正解:A、B、D
質問 # 32
Refer to the exhibit.
According to the error message why is FortiManager failing to add the FortiAnalyzer device?
- A. The administrator must turn off the Use Legacy Device login and add the FortiAnalyzer device to the same network as Forti-Manager
- B. The administrator must use the Add Model Device section and discover the FortiAnalyzer device
- C. The administrator must use the correct user name and password of the FortiAnalyzer device
- D. The administrator must select the Forti-Manager administrative access checkbox on the FortiAnalyzer management interface
正解:A
質問 # 33
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)
- A. The Fabric View module enables you to view the Security Fabric ratings for Security Fabric devices
- B. The Security Fabric settings are part of the device level settings
- C. The Fabric View module enables you to generate the Security Fabric ratings for Security Fabric devices
- D. The Security Fabric license, group name and password are required for the FortiManager Security Fabric integration
正解:A、B
質問 # 34
Refer to the exhibit.
Given the configuration shown in the exhibit, what can you conclude from the installation targets m the Install On column? (Choose two)
- A. Policy 3 will be installed on all FortiGate devices and vdom belongs to the ADOM
- B. Policy seq # 2 will not be installed on the Local-FortiGate root VDOM because there is no root VDOM in the Installation Target
- C. Policy seq # 1 will be installed on the Remoto-FortiGate root[NAT] and Student[NAT] VDOMs only
- D. Policy seq # 3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
- E. Policy seq # 3 will be skipped because no installation targets are specified
正解:C、D
質問 # 35
Refer to the exhibit.
Given the configuration shown in the exhibit, what are two results from this configuration? (Choose two.)
- A. The same administrator can lock more than one ADOM at the same time. Most Voted
- B. Two or more administrators can make configuration changes at the same time, in the same ADOM.
- C. You can validate administrator login attempts through external servers.
- D. Concurrent read-write access to an ADOM is disabled. Most Voted
正解:A、D
質問 # 36
Refer to the exhibit.
An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.
After the installation operation is performed, which IP/netmask will be shown on FortiManager for this firewall address object without specify Per-Device Mapping?
- A. 0.0.0.0/0.
- B. 192.168.1.0/24.
- C. The FortiManager replaces the address object to none.
- D. 10.0.5.0/24.
正解:B
解説:
In the scenario you described, an administrator has created a firewall address object used in multiple policy packages for multiple FortiGate devices within an Administrative Domain (ADOM) on FortiManager. The question concerns the display of this object's IP/netmask in FortiManager after installation, assuming no per-device mapping is specified.
Given the screenshot and the description of the situation, the answer is **C. 192.168.1.0/24**. When you create a firewall address object in FortiManager without specifying per-device mapping, FortiManager uses the generic settings of the object as defined. In the screenshot, the IP/Netmask is set to 192.168.1.0/255.255.255.0, and since there is no per-device variation defined or required in your query, this setting remains as shown in the object's configuration.
質問 # 37
An administrator would like to authorize a newly-installed AP using AP Manager. What steps does the administrator need to perform to authorize an AP?
- A. Changes to the AP's state must be performed directly on the managed FortiGate.
- B. Authorize the new AP using AP Manager and install the device level settings on the managed FortiGate.
- C. Authorize the new AP using AP Manager and wait until the change is updated on the FortiAP. Changes to the AP's state do not require installation.
- D. Authorize the new AP using AP Manager and install the policy package changes on the managed FortiGate.
正解:B
質問 # 38
An administrator is replacing a failed device on FortiManager by running the following command:
execute device replace sn <devname> <serialnum>.
Which device name and serial number must the administrator use?
- A. The device name of the failed device and serial number of the new device
- B. The device name and serial number of the failed device
- C. The device name of the new device and serial number of the failed device
- D. The device name and serial number of the new device
正解:A
解説:
To replace the faulty device with the new device, take the following steps:
1. Note the device name of the original FortiGate.
If the replacement device is already listed as unregistered, then you will need to delete it from the unregistered device list in the root ADOM.
2. Add the serial number of the replacement FortiGate.
After the replace command is executed, FortiManager updates the serial number in its database.
3. Verify that the new device serial number is associated with the faulty device in FortiManager.
You can do this using the CLI or the System Information widget of FortiGate.
4. Send a request from the replacement device to register it with FortiManager Reference [Page 283] - https://ebin.pub/fortinet-fortimanager-study-guide-for-fortimanager-72.html
質問 # 39
View the following exhibit.
If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)
- A. FortiGate is discovered by FortiManager through the FortiGate NATed IP address.
- B. FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management.
- C. If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
- D. During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
正解:A、D
解説:
Fortimanager can discover FortiGate through a NATed FortiGate IP address. If a FortiManager NATed IP address is configured on FortiGate, then FortiGate can announce itself to FortiManager. FortiManager will not attempt to re-establish the FGFM tunnel to the FortiGate NATed IP address, if the FGFM tunnel is interrupted. Just like it was in the NATed FortiManager scenario, the FortiManager NATed IP address in this scenario is not configured under FortiGate central management configuration.
質問 # 40
Which of the following statements are true regarding schedule backup of FortiManager? (Choose two.)
- A. Can be configured from the CLI and GUI
- B. Supports FTP, SCP, and SFTP
- C. Does not back up firmware images saved on FortiManager
- D. Backs up all devices and the FortiGuard database.
正解:B、C
質問 # 41
View the following exhibit.
Which one of the following statements is true regarding the object named ALL?
- A. FortiManager updated the object ALL using FortiManager's value in its database
- B. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate.
- C. FortiManager installed the object ALL with the updated value.
- D. FortiManager updated the object ALL using FortiGate's value in its database
正解:D
質問 # 42
An administrator would like to review, approve, or reject all the firewall policy changes made by the junior administrators.
How should the Workspace mode be configured on FortiManager?
- A. Set to workflow and use the ADOM locking feature
- B. Set to disable and use the policy locking feature
- C. Set to read/write and use the policy locking feature
- D. Set to normal and use the policy locking feature
正解:A
解説:
Reference:https://help.fortinet.com/fmgr/50hlp/52/5-2-0/FMG_520_Online_Help/200_What's-New.03.03.html
質問 # 43
Refer to the exhibit.
Which statement about the object named ALL is true?
- A. FortiManager updated the object ALL using the FortiManager value in its database.
- B. FortiManager updated the object ALL using the FortiGate value in its database.
- C. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate.
- D. FortiManager installed the object ALL with the updated value.
正解:B
質問 # 44
Refer to the exhibit.
Which two statements about an ADOM set inNormalmode on FortiManager are true? (Choose two.)
- A. It supports the FortiManager script feature
- B. You cannot assign the same ADOM to multiple administrators
- C. FortiManager automatically installs the configuration difference in revisions on the managed FortiGate
- D. It allows making configuration changes for managed devices on FortiManager panes
正解:A、D
解説:
"FortiGate units in the ADOM will query their own configuration every 5 seconds. If there has been a configuration change, the FortiGate unit will send a diff revision on the change to the FortiManager using the FGFM protocol."
質問 # 45
An administrator has assigned a global policy package to a new ADOM called ADOM1. What will happen if the administrator tries to create a new policy package in ADOM1?
- A. When a new policy package is created, the administrator needs to reapply the global policy package to ADOM1.
- B. When the new policy package is created, FortiManager automatically assigns the global policy package to the new policy package.
- C. When a new policy package is created, the administrator must assign the global policy package from the global ADOM.
- D. When creating a new policy package, the administrator can select the option to assign the global policy package to the new policy package
正解:D
解説:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-2/FortiManager_Admin_Guide/1200_Policy%20and%20O
質問 # 46
An administrator, Trainer, who is assigned theSuper_Userprofile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session.
What can prevent an admin account that hasSuper_Userrights over the device from approving a workflow session?
- A. Trainer must close Student's workflow session before approving the request
- B. Trainer does not have full rights over this ADOM
- C. Trainer is not a part of workflow approval group
- D. Student, who submitted the workflow session, must first self-approve the request
正解:C
解説:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG-FAZ/0800_ADOMs/1800_Workflow/0600_Work
質問 # 47
......
Fortinet NSE5_FMG-7.2問題集PDFを使ってベストオプションを目指そう:https://www.passtest.jp/Fortinet/NSE5_FMG-7.2-shiken.html
2025年最新のNSE5_FMG-7.2サンプル問題は頼もしいNSE5_FMG-7.2テストエンジン:https://drive.google.com/open?id=1kUuwDKrGfKyAeUAaWSdF758bvVsfoDcW