NSE5_FMG-6.2試験問題を今すぐ試そう!最新の[2022年最新] 正解回答付き [Q12-Q35]

Share

NSE5_FMG-6.2試験問題を今すぐ試そう!最新の[2022年最新] 正解回答付き

練習できるNSE5_FMG-6.2には認定ガイド問題と解答とトレーニングを提供しています

質問 12
View the following exhibit.

Which statement is true regarding this failed installation log?

  • A. Policy ID 2 is installed without a source device
  • B. Policy ID 2 is installed in disabled state
  • C. Policy ID 2 will not be installed
  • D. Policy ID 2 is installed without a source address

正解: A

 

質問 13
Refer to the exhibit.

Which statement about the object named ALL is true?

  • A. FortiManager installed the object ALL with the updated value.
  • B. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate.
  • C. FortiManager updated the object ALL using the FortiManager value in its database.
  • D. FortiManager updated the object ALL using the FortiGate value in its database.

正解: D

 

質問 14
An administrator wants to delete an address object that is currently referenced in a firewall policy. Which one of the following statements is true?

  • A. FortiManager will not allow the administrator to delete a referenced address object
  • B. FortiManager will disable the status of the referenced firewall policy
  • C. FortiManager will replace the deleted address object with all address object in the referenced firewall policy
  • D. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy

正解: D

 

質問 15
When configuring FortiGuard on FortiManger. Which two statements are correct regarding Allow Push Update settings configured in the FortiGuard. Antivirus and IPS Settings? (Choose two)

  • A. FortiManager's built-in FDS service does not allow an administrator to override the default FortiManger IP address and port used by the FDN to send update messages.
  • B. If an urgent or critical FortiGuard Antivirus and/or IPS update becomes available, the FortiManger bult-in FDS will send push update notifications to each managed device.
  • C. FortiManager's built-in FDS service may not correctly receive push updates if the external facing IP address of any intermediary NAT device is dynamic.
  • D. If an urgent or critical FortiGuard Antivirus and/or IPS update becomes available, the FortiManger bult-in FDS will send push update notifications.

正解: C,D

 

質問 16
An administrator would like to create an SD-WAN default static route for a newly created SD-WAN using the FortiManager GUI. Both port1 and port2 are part of the SD-WAN member interfaces.
Which interface must the administrator select in the static route device drop-down list?

  • A. virtual-wan-link
  • B. port2
  • C. auto-discovery
  • D. port1

正解: A

 

質問 17
How are the points calculated when using FortiMeter to deploy FortiOS-VM? (Choose two.)

  • A. Based on the number of sessions on the mgmt interface of FortiOS-VM.
  • B. Based on the amount of traffic (per GB) passing through the FortiOS-VM.
  • C. Based on the traffic usage on port1 and port2 on FortiOS-VM.
  • D. Based on the FortiGuard service option enabled for FortiOS-VM.

正解: C,D

解説:
Point calculations are based off of traffic passing through the FortiOS-VM interfaces. Points are used per terabyte of traffic and there is an increased point cost as you increase the FortiGuard services in use.
4 pts/TB for a FortiOS-VM tagged as "FW"
10 pts/TB for a FortiOS-VM tagged as "FW + URL"
25 pts/TB for a FortiOS-VM tagged as "UTM"
Reference: https://docs.fortinet.com/uploaded/files/4057/fortinetvm_on-demand_1.pdf

 

質問 18
Which two statements are correct regarding synchronization between primary and secondary devices in a FortiManager HA duster? (Choose two)

  • A. Local logs and log configuration settings are synchronized in the HA cluster.
  • B. All device configurations including global databases are synchrorized in the HA cluster,
  • C. FortiGuard databases are downloaded separately by each cluster device.
  • D. FortiGuard databases are downloaded by the primary FortManager device and then synchronized with all secondary devices.

正解: B,C

 

質問 19
An administrator would like to create an SD-WAN default static route for a newly created SD-WAN using the FortiManager GUI.
Both port1 and port2 are part of the SD-WAN member interfaces. Which interface must the administrator select in the static route device drop-down list?

  • A. virtual-wan-link
  • B. port2
  • C. auto-discovery
  • D. port1

正解: A

 

質問 20
Refer to the exhibit.

Which two statements about an ADOM set in Normal mode on FortiManager are true? (Choose two.)

  • A. FortiManager automatically installs the configuration difference in revisions on the managed FortiGate
  • B. It supports the FortiManager script feature
  • C. You cannot assign the same ADOM to multiple administrators
  • D. It allows making configuration changes for managed devices on FortiManager panes

正解: A,D

 

質問 21
View the following exhibit:

How will FortiManager try to get updates for antivirus and IPS?

  • A. From the list of configured override servers with ability to fall back to public FDN servers
  • B. From the configured override server list only
  • C. From the default server fdsl.fortinet.com
  • D. From public FDNI server with highest index number only

正解: A

 

質問 22
A FortiGate device is imported to FortiManager using the settings given in the exhibit.

An administrator subsequently modifies and installs the policy package.
Which two statements are correct regarding the scenario? (Choose two)

  • A. The orphan (unused) objects that are not tied to policies locally on the FortiGate will not be deleted on install.
  • B. The FortiManager did not import unused objects to the ADOM object database. These objects cannot be used by referencing in the policies on FortiManager and installing to the managed devices.
  • C. The orphan (unused) objects that are not tied to policies locally on the FortiGate will be deleted on install.
  • D. The FortiManager imported all unused objects to the ADOM object database. These objects can be used by referencing in the policies on FortiManager and installing to the managed devices.

正解: B,C

 

質問 23
View the following exhibit. When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true?
(Choose two.)

  • A. Provides the option to preview configuration changes prior to installing them
  • B. Installs device-level changes to FortiGate without launching the Install Wizard
  • C. Will not create new revision in the revision history
  • D. Once initiated, the install process cannot be canceled and changes will be installed on the managed device

正解: B,D

解説:
The Install Config option allows you to perform a quick installation of device-level settings without launching the Install Wizard. When you use this option, you cannot preview the changes prior to committing. Administrator should be certain of the changes before using this install option, because the install can't be cancelled after the process is initiated.

 

質問 24
Which two statements are correct for configuration changes made by FortiManager scripts? (Choose two)

  • A. When run on managed devices directly, changes are automatically installed to the managed FortiGate devices.
  • B. When run on the device database, you can install changes to the managed FortiGate devices using the installation wizard.
  • C. When run on the device database, changes are automatically installed to the managed FortiGate devices.
  • D. When run on managed devices directly, you can install changes to the managed FortiGate devices using the installation wizard.

正解: A,B

解説:
A script can make many changes to a managed device and are useful for bulk configuration changes and consistency across multiple managed devices. Scripts can be run in three different ways:
Device Database: By default, a script can be executed on the device database. It is recommended you run the changes on the device database (default setting), as this allows you to check what configuration changes you will send to the managed device. Once scripts are run on the device database you can then install these changes to a managed device using the installation wizard.
Policy Package, ADOM database: A script can be run here to create ADOM level objects that will be applied to your managed devices and can then be installed using the installation wizard.
Remote FortiGate Directly (via CLI): A script can be executed directly on the device and you don't need to install these changes using the installation wizard. As the changes are directly installed on the managed device, no option is provided to verify and check the configuration changes through FortiManager.

 

質問 25
Refer to the exhibit.

Which two statements about the output are true? (Choose two.)

  • A. Configuration changes directly made on FortiGate have been automatically updated to the device-level database.
  • B. The latest revision history for the managed FortiGate does match with the FortiGate running configuration.
  • C. The latest revision history for the managed FortiGate does not match with the device-level database.
  • D. Configuration changes have been installed on FortiGate, which means the FortiGate configuration has been changed.

正解: B,C

 

質問 26
View the following exhibit. An administrator has created a firewall address object, Training, which is used in the Local-FortiGate policy package.
When the install operation is performed, which IP Netmask will be installed on the Local-FortiGate, for the Training firewall address object?

  • A. 192.168.0.1/24
  • B. Local-FortiGate will automatically choose an IP Network based on its network interface settings.
  • C. 10.0.1.0/24
  • D. It will create firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values

正解: C

解説:
In the example, the dynamic address object LocalLan refers to the internal network address of the managed firewalls. The object has a default value of
192.168.1.0/24. The mapping rules are defined per device. For Remote-FortiGate, the address object LocalLan referes to 10.10.11.0/24. The devices in the ADOM that do not have dynamic mapping for LocalLan have a default value of 192.168.1.0/24.

 

質問 27
What does a policy package status of Modified indicate?

  • A. Policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager
  • B. The policy package was never imported after a device was registered on FortiManager
  • C. FortiManager is unable to determine the policy package status
  • D. Policy package configuration has been changed on FortiManager and changes have not yet been installed on the managed device.

正解: D

解説:
http://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1200_Policy%20and%20Objects/0800_Managing%20policy%20packages/2200_Policy%
20Package%20Installation%20targets.htm

 

質問 28
When installation is performed from the FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?

  • A. FortiGate will reject the CLI commands that will cause the tunnel to go down.
  • B. After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.
  • C. FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.
  • D. FortiManager will revert and install a previous configuration revision on the managed FortiGate.

正解: B

 

質問 29
An administrator has added all the devices in a Security Fabric group to FortiManager.
How does the administrator identify the root FortiGate?

  • A. By an Asterisk (*) at the end of the device name
  • B. By an at symbol (@) at the end of the device name
  • C. By a question no mark(?) at the end of the device name
  • D. By a dollar symbol ($) at the end of the device name

正解: A

 

質問 30
View the following exhibit. Which of the following statements are true based on this configuration setting? (Choose two.)

  • A. This setting is applied globally to all ADOMs.
  • B. This setting will enable the ADOMs feature on FortiManager.
  • C. This setting will allow automatic updates to the policy package configuration for a managed device.
  • D. This setting will allow assigning different VDOMs from the same FortiGate to different ADOMs.

正解: A,D

 

質問 31
View the following exhibit.

Based on the configuration setting, which one of the following statements is true?

  • A. The setting enables the ADOMs feature on FortiManager
  • B. The setting allows automatic updates to the policy package configuration for a managed device
  • C. This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.
  • D. The setting disables concurrent ADOM access and adds ADOM locking

正解: C

 

質問 32
What does a policy package status of Conflict indicate?

  • A. The policy package does not have a FortiGate as the installation target.
  • B. The policy package configuration has been changed on both FortiManager and the managed device independently.
  • C. The policy package reports inconsistencies and conflicts during a Policy Consistency Check.
  • D. The policy configuration has never been imported after a device was registered on FortiManager.

正解: C

 

質問 33
Refer to the exhibit.

An administrator has created a firewall address object which is used in multiple policy packages for multiple FortiGate devices in an ADOM.
When the installation operation is performed, which IP/Netmask will be installed on managed devices for this firewall address object?

  • A. If no dynamic mapping is defined for other FortiGate devices, the object will not be installed
  • B. 10.200.1.0/24 on Remote-FortiGate
  • C. The FortiManager administrator can choose the value for the firewall address object in the Install Wizard for Remote-FortiGate
  • D. 192.168.0.1/24 on Remote-FortiGate

正解: B

 

質問 34
An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the approving a workflow session?

  • A. Trainer is not a part of workflow approval group
  • B. Student, who submitted the workflow session, must first self-approve the request
  • C. Trainer must close Student's workflow session before approving the request
  • D. Trainer does not have full rights over this ADOM

正解: A

 

質問 35
......

試験準備には欠かさない!トップクラスのFortinet NSE5_FMG-6.2試験アプリ学習ガイド練習問題最新版:https://www.passtest.jp/Fortinet/NSE5_FMG-6.2-shiken.html