[2025年06月] 検証済み Fortinet 試験問題集 NSE5_FMG-7.2 試験学習ガイド [Q23-Q44]

Share

[2025年06月] 検証済みFortinet試験問題集でNSE5_FMG-7.2試験学習ガイド

ベスト品質のFortinet NSE5_FMG-7.2試験解答リアル練習試験問題集で[2025]


NSE5_FMG-7.2は、Fortimanager 7.2を使用してFortinetデバイスを管理および構成する機能について候補者をテストします。この試験では、Fortimanagerシステムの構成、ポリシーとオブジェクト管理、デバイスの発見と登録、プロビジョニング、トラブルシューティングなど、さまざまなトピックについて説明します。候補者は、デバイスマネージャー、ポリシーマネージャー、セキュリティファブリックなどのFortimanager機能に関する知識を示す必要があります。成功した候補者は、Fortinetのセキュリティインフラストラクチャを効果的に管理および監視し、最新の脅威と脆弱性から保護するように構成されていることを確認します。

 

質問 # 23
Refer to the exhibit.

Given the configuration shown in the exhibit, which two statements are true? (Choose two.)

  • A. It allows two or more administrators to make configuration changes at the same time, in the same ADOM.
  • B. It disables concurrent read-write access to an ADOM.
  • C. It is used to validate administrator login attempts through external servers.
  • D. It allows the same administrator to lock more than one ADOM at the same time.

正解:B、D

解説:
Reference:https://docs.fortinet.com/document/fortimanager/6.0.4/administration-guide/86456/concurrentadom-ac


質問 # 24
An administrator has added all the devices in a Security Fabric group to FortiManager.
How does the administrator identify the root FortiGate?

  • A. By an at symbol (@) at the end of the device name
  • B. By an Asterisk (*) at the end of the device name
  • C. By a dollar symbol ($) at the end of the device name
  • D. Question mark(?) at the end of the device name

正解:B


質問 # 25
Which of the following statements are true regarding schedule backup of FortiManager? (Choose two.)

  • A. Can be configured from the CLI and GUI
  • B. Does not back up firmware images saved on FortiManager
  • C. Backs up all devices and the FortiGuard database.
  • D. Supports FTP, SCP, and SFTP

正解:B、D


質問 # 26
Refer to the exhibit.

Which two statements about the output are true? (Choose two.)

  • A. The latest history for the managed FortiGate does not match with the device-level database
  • B. The latest revision history for the managed FortiGate does match with the FortiGate running configuration
  • C. Configuration changes directly made on the FortiGate have been automatically updated to device-level
  • D. Configuration changes have been installed to FortiGate and represents FortiGate configuration has been changed

正解:A、B

解説:
database
Explanation:
STATUS: dev-db: modified; conf: in sync; cond: pending; dm: retrieved; conn: up
- dev-db: modified - This is the device setting status which indicates that configuration changes were made on FortiManager.
- conf: in sync - This is the sync status which shows that the latest revision history is in sync with Fortigate's configuration.
- cond: pending - This is the configuration status which says that configuration changes need to be installed.
Most probably a retrieve was done in the past (dm: retrieved) updating the revision history DB (conf: in sync) and FortiManager device level DB, now there is a new modification on FortiManager device level DB (dev-db: modified) which wasn't installed to FortiGate (cond: pending), hence; revision history DB is not aware of that modification and doesn't match device DB.
Conclusion:
- Revision DB does match FortiGate.
- No changes were installed to FortiGate yet.
- Device DB doesn't match Revision DB.
- No changes were done on FortiGate (auto-update) but configuration was retrieved instead After an Auto-Update or Retrieve:
device database = latest revision = FGT
Then after a manual change on FMG end (but no install yet):
latest revision = FGT (still) but now device database has been modified (is different).
After reverting to a previous revision in revision history:
device database = reverted revision != FGT


質問 # 27
Which two settings are required for FortiManager Management Extension Applications (MEA)? (Choose two.)

  • A. The administrator must have the super user profile.
  • B. When you configure MEA, you must open TCP or UDP port 540.
  • C. You must create a MEA special policy on FortiManager using the super user profile
  • D. You must open the ports to the Fortinet registry

正解:A、C


質問 # 28
Refer to the exhibit.

Given the configuration shown in the exhibit, which two statements are true? (Choose two.)

  • A. The FortiManager ADOM workspace mode is set to Normal.
  • B. FortiManager is in workflow mode.
  • C. The FortiManager ADOM is locked by the administrator.
  • D. An administrator can also lock the Local-FortiGate-1 policy package.

正解:C、D


質問 # 29
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)

  • A. The Fabric View module enables you to generate the Security Fabric ratings for Security Fabric devices
  • B. The Security Fabric settings are part of the device level settings
  • C. The Security Fabric license, group name and password are required for the FortiManager Security Fabric integration
  • D. The Fabric View module enables you to view the Security Fabric ratings for Security Fabric devices

正解:B、D


質問 # 30
View the following exhibit.

Which of the following statements are true based on this configuration setting? (Choose two.)

  • A. This setting will allow automatic updates to the policy package configuration for a managed device.
  • B. This setting will allow assigning different VDOMs from the same FortiGate to different ADOMs.
  • C. This setting is applied globally to all ADOMs.
  • D. This setting will enable the ADOMs feature on FortiManager.

正解:B、C


質問 # 31
Which of the following statements are true regarding VPN Manager? (Choose three.)

  • A. VPN Manager automatically creates all the necessary firewall policies for traffic to be tunneled by IPsec.
  • B. VPN Manager can install common IPsec VPN settings on multiple FortiGate devices at the same time.
  • C. Common IPsec settings need to be configured only once in a VPN Community for all managed gateways.
  • D. VPN Manager automatically adds newly-registered devices to a VPN community.
  • E. VPN Manager must be enabled on a per ADOM basis.

正解:B、C、E


質問 # 32
Push updates are failing on a FortiGate device that is located behind a NAT device Which two settings should the administrator check? (Choose two.)

  • A. That the NAT device IP address and correct ports are configured on FortiManager
  • B. That the override server IP address is set on FortiManager and the NAT device
  • C. That the external IP address on the NAT device is set to DHCP and configured with the virtual IP
  • D. That the virtual IP address and correct ports are set on the NAT device

正解:A、C


質問 # 33
Refer to the exhibit.

Given the configuration shown in the exhibit, what can you conclude from the installation targets m the Install On column? (Choose two)

  • A. Policy 3 will be installed on all FortiGate devices and vdom belongs to the ADOM
  • B. Policy seq # 3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
  • C. Policy seq # 3 will be skipped because no installation targets are specified
  • D. Policy seq # 1 will be installed on the Remoto-FortiGate root[NAT] and Student[NAT] VDOMs only
  • E. Policy seq # 2 will not be installed on the Local-FortiGate root VDOM because there is no root VDOM in the Installation Target

正解:B、D


質問 # 34
Refer to the exhibit.

Given the configuration shown in the exhibit, which two statements are true? (Choose two.)

  • A. It allows two or more administrators to make configuration changes at the same time, in the same ADOM.
  • B. It is used to validate administrator login attempts through external servers.
  • C. It allows the same administrator to lock more than one ADOM at the same time.
  • D. It disables concurrent read-write access to an ADOM.

正解:A、C


質問 # 35
Refer to the exhibit.

An administrator has configured the command shown in the exhibit on FortiManager. A configuration change has been installed from FortiManager to the managed FortiGate that causes the FGFM tunnel to go down for more than 15 minutes.
What is the purpose of this command?

  • A. It allows FortiGate to reboot and restore a previously working firmware image.
  • B. It allows FortiGate to unset central management settings.
  • C. It allows the FortiManager to revert and install a previous configuration revision on the managed FortiGate.
  • D. It allows FortiGate to reboot and recover the previous configuration from its configuration file.

正解:D


質問 # 36
View the following exhibit.

If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)

  • A. FortiGate is discovered by FortiManager through the FortiGate NATed IP address.
  • B. During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
  • C. If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
  • D. FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management.

正解:A、B

解説:
Fortimanager can discover FortiGate through a NATed FortiGate IP address. If a FortiManager NATed IP address is configured on FortiGate, then FortiGate can announce itself to FortiManager. FortiManager will not attempt to re-establish the FGFM tunnel to the FortiGate NATed IP address, if the FGFM tunnel is interrupted. Just like it was in the NATed FortiManager scenario, the FortiManager NATed IP address in this scenario is not configured under FortiGate central management configuration.


質問 # 37
Refer to the following exhibit:

Which of the following statements are true based on this configuration? (Choose two.)

  • A. Unlocking an ADOM will submit configuration changes automatically to the approval administrator
  • B. Unlocking an ADOM will install configuration automatically on managed devices
  • C. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out
  • D. The same administrator can lock more than one ADOM at the same time

正解:C、D

解説:
Reference:http://help.fortinet.com/fmgr/cli/5-6-2/Document/0800_AD0Ms/200_Configuring+.htm


質問 # 38
Refer to the exhibit.

Which two statements are true if the script is executed using theDevice Databaseoption? (Choose two.)

  • A. TheDevice Settings Statuswill be tagged asModified
  • B. The successful execution of a script on theDevice Databasewill create a new revision history
  • C. You must install these changes using theInstall Wizardto a managed device
  • D. The script history will show successful installation of the script on the remote FortiGate

正解:A、C


質問 # 39
An administrator wants to delete an address object that is currently referenced in a firewall policy.
What can the administrator expect to happen?

  • A. FortiManager will replace the deleted address object with all address object in the referenced firewall policy
  • B. FortiManager will not allow the administrator to delete a referenced address object
  • C. FortiManager will disable the status of the referenced firewall policy
  • D. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy

正解:D


質問 # 40
Refer to the exhibit.

An administrator would like to create three ADOMs on FortiManager with different access levels based on departments.
What two conclusions can you draw from the design shown in the exhibit? (Choose two.)

  • A. Admin A can access VDOM2 and VDOM3 with the super user profile.
  • B. The FortiManager policies and objects database can be shared between the Financial and HR ADOMs.
  • C. The administrator must configure FortiManager in workspace mode.
  • D. The administrator must set the FortiManager ADOM mode to Advanced.

正解:B、D


質問 # 41
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)

  • A. The Security Fabric settings are part of the device level settings
  • B. TheFabric Viewmodule enables you to generate the Security Fabric ratings for Security Fabric devices
  • C. The Security Fabric license, group name and password are required for the FortiManager Security Fabric integration
  • D. TheFabric Viewmodule enables you to view the Security Fabric ratings for Security Fabric devices

正解:A、D


質問 # 42
When an installation is performed from FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?

  • A. FortiManager will revert and install a previous configuration revision on the managed FortiGate.
  • B. FortiGate will reject the CLI commands that will cause the tunnel to go down.
  • C. After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.
  • D. FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.

正解:C

解説:
The configuration change will break the fgfm connection, causing the FortiGate unit to attempt to reconnect for 900 seconds. If the FortiGate cannot reconnect, it will rollback to its previous configuration.


質問 # 43
Refer to the exhibit.

An administrator is about to add the FortiGate device to FortiManager using the discovery process FortiManager is operating behind a NAT device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings What is the expected result?

  • A. During discovery FortiManager sets the NATed device IP address on FortiGate
  • B. During discovery FortiManager sets trie FortiManager NATed IP address on FortiGate
  • C. During discovery FortiManager uses only the FortiGate serial number to establish the connection
  • D. During discovery FortiManager sets both tie FortiManager NATed IP address and NAT device IP address on FortiGate

正解:A


質問 # 44
......

正真正銘のベスト材料NSE5_FMG-7.2:https://www.passtest.jp/Fortinet/NSE5_FMG-7.2-shiken.html

NSE5_FMG-7.2テストエンジン練習試験:https://drive.google.com/open?id=1jZgtfcyT9Hmna0YI87TOqvbT_i78hxm4