Pre-Summer Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

FCP_FMG_AD-7.6 Sample Questions Answers

Questions 4

Refer to the exhibit.

Which two results occur if you run the script using the Device Database option? (Choose two.)

Options:

A.

The device Config Status is tagged as Modified.

B.

The script history shows the successful installation of the script on the remote FortiGate.

C.

The successful execution of a script on the Device Database creates a new revision history.

D.

The administrator must install these changes on a managed device using the Install Wizard.

Buy Now
Questions 5

An administrator notices that CLI scripts are failing on some FortiGate devices because they use different FortiOS versions.

Which two actions should the administrator take to fix the failing CLI scripts? Choose two answers.

Options:

A.

Create separate ADOMs for each FortiOS version.

B.

Disable CLI scripts for devices using older firmware.

C.

Modify the CLI scripts to include conditional commands based on FortiOS version.

D.

Create version-specific CLI script groups and assign them to the appropriate devices.

Buy Now
Questions 6

Refer to the exhibits.

An administrator has been asked to install the same policies from a central policy package onto the BR1-FGT-1 firewall.

The administrator added BR1-FGT-1 as a target in the central policy package installation.

What should the administrator do when reinstalling the central policy package on the BR1-FGT-1 firewall?

Options:

A.

Assign only one policy package to the firewall because FortiManager does not allow more than one policy package assigned per device at the same time.

B.

Import the policy package to change the unknown status and synchronize the policy package.

C.

Use the install wizard to install the central policy package on the BR1-FGT-1 firewall.

D.

First resolve the modified status in the configuration and provisioning templates to allow a smooth installation.

Buy Now
Questions 7

A service provider administrator has assigned a global policy package to a managed customer ADOM named My_ADOM. The customer administrator has access only to My_ADOM.

How can the customer administrator edit the global header policy of the global policy package?

Options:

A.

The customer administrator can edit the header policy by using workspace mode on the global ADOM.

B.

The customer administrator can edit the header policy by using workflow mode on the global ADOM and My_ADOM.

C.

The service provider administrator can unlock the global policy from the global ADOM to authorize changes to the customer administrator.

D.

The customer administrator cannot edit the global header policy; only the service provider administrator can make changes from the global ADOM.

Buy Now
Questions 8

Which two statements about the integrity of databases on FortiManager are correct? Choose two answers.

Options:

A.

Scheduled backups run database integrity commands automatically.

B.

The diagnose dvm check-integrity command attempts to fix a corrupted file system.

C.

The diagnose cdb check adom-integrity command can correct issues related to locked devices.

D.

You should fix all database integrity issues before performing a script.

E.

Not following the correct upgrade path may cause inconsistencies in the databases.

Buy Now
Questions 9

A FortiManager administrator has moved a FortiGate device to a new ADOM, but they cannot see the policy or object configurations for that FortiGate.

What should the administrator do to see the policy or object configurations?

Options:

A.

Use ADOM shared objects to restore all missing data.

B.

Reset the device and add it to the new ADOM again.

C.

Import the policy package manually using the Import Configuration wizard.

D.

Use ADOM sync to restore the missing configurations.

Buy Now
Questions 10

Refer to the exhibit.

Which two statements about the output are true? (Choose two.)

Options:

A.

The latest revision history for the managed FortiGate does not match the device-level database.

B.

Configuration changes have been installed on FortiGate, updating policy and device-level database.

C.

The latest revision history for the managed FortiGate does match the FortiManager policy database.

D.

The system template default will override device-level database configurations.

Buy Now
Questions 11

What are two expected results when both FortiManager and FortiGate are behind network address translation NAT devices? Choose two answers

Options:

A.

FortiGate is discovered by FortiManager through the FortiGate NATed IP address.

B.

During discovery, the FortiManager NATed IP address is not set by default on FortiGate.

C.

FortiGate can announce itself to FortiManager only if the FortiManager non-NATed IP address is configured on FortiGate under central management.

D.

If the FortiGate–FortiManager communication protocol FGFM tunnel is torn down, FortiManager will try to reestablish the FGFM tunnel.

Buy Now
Questions 12

Refer to the exhibits.

An administrator needs to push a FortiToken Mobile to assign it to HR_user in the HQ-NGFW-1.

However, when installing the policy package, they receive the following error message:

Why is the administrator not able to install the FortiToken on the HQ-NGFW-1 firewall?

Options:

A.

The administrator must use a user local meta field to assign FortiToken.

B.

The administrator must use a valid FortiToken that exists on HQ-NGFW-1.

C.

The administrator must use a metadata variable to assign the same FortiToken to multiple users in FortiManager.

D.

The administrator must use per-device mapping to assign the FortiToken to HQ-NGFW-1.

Buy Now
Questions 13

The administrator uses FortiManager to push a CLI script using the Remote FortiGate Directly (via CLI) option to configure an IPsec VPN. However, when running the script, the administrator receives the following error:

config vpn ipsec phase2-interface [parameter(s) invalid. detail: object mismatch]

What must the administrator do to resolve the script error and successfully apply the IPsec configuration?

Options:

A.

Add the end command after finishing the IPsec phase 1-interface configuration block.

B.

Use IPsec templates to deploy provisioning templates.

C.

Add a second config vpn ipsec phase2-interface block without linking it to phase1.

D.

Run the script using the policy package or ADOM database method.

Buy Now
Questions 14

If one of the secondary FortiManager devices fails, which action must be performed to return the FortiManager HA manual mode to a working state?

Options:

A.

The FortiManager high availability HA state transition is transparent to administrators and does not require any reconfiguration.

B.

Run a sanity check on the failed device to make sure HA heartbeat packets are using TCP port 5199.

C.

Manually promote one of the working secondary devices to the primary role.

D.

Remove the peer IP of the failed device on the primary device.

Buy Now
Questions 15

An administrator must create a policy and install it on a FortiGate device within an ADOM in backup mode.

How can the administrator perform this task?

Options:

A.

Use the Install Wizard located on the device manager.

B.

Enable workflow mode to allow policy creation and approval.

C.

Make sure the ADOM and FortiGate firmware versions match and use the ADOM policy package.

D.

Use a FortiManager script to apply the configuration changes.

Buy Now
Questions 16

An administrator has a FortiGate-HQ device with VDOMs—root, HR and Facilities, currently managed under the FortiManager ADOM—Site1. They try to move VDOM HR to the FortiManager ADOM—Site2, but it does not work.

Why is the administrator not able to move FortiGate-HQ VDOM HR to FortiManager ADOM—Site2?

Options:

A.

The FortiGate-HQ must be managed under the FortiManager ADOM—root to allow moving its VDOMs to different ADOMs.

B.

The administrator must have full access in the device layer of FortiGate-HQ VDOM-root before they can VDOMs to different ADOMs.

C.

FortiManager must be in ADOM normal mode, which does not allow VDOMs to be managed separately.

D.

The administrator must delete the FortiGate-HQ device from FortiManager and add it again using the Add Device wizard before moving the VDOM.

Buy Now
Questions 17

An administrator created a new ADOM named Training for FortiGate devices only. Then, the administrator added the root FortiGate device of a Security Fabric group to the Training ADOM. Which statement correctly describes the expected result for the downstream devices in the Security Fabric, given the actions taken by the administrator? Choose one answer

Options:

A.

The downstream devices are automatically authorized.

B.

The downstream devices will appear in the Managed FortiGate section of the root ADOM.

C.

The downstream devices show as unauthorized in the root ADOM.

D.

The downstream devices must be added using the Add Device wizard.

Buy Now
Questions 18

What allows FortiManager to run CLI scripts on FortiGate devices without prompting for SSH authentication each time?

Options:

A.

FortiGate devices using the legacy login method.

B.

The secure management tunnel between FortiManager and FortiGate devices.

C.

The script using the Remote FortiGate Directly via CLI option.

D.

The script on the FortiManager device database.

Buy Now
Questions 19

Refer to the exhibit.

An administrator has assigned the default system template to install all devices with the FortiAnalyzer IP address 10.0.13.12. However, not all FortiGate devices can reach FortiAnalyzer using the default interface. Some devices may use the LAN interface, while others may use the WAN interface. How can the administrator change the source interface for FortiGate devices using the default system template? Choose one answer

Options:

A.

Use per-device dynamic object configurations at the ADOM level and apply them in the template.

B.

Configure a metadata variable at the ADOM level and use it in the template.

C.

Create a different system template for each FortiGate, if the configuration is different.

D.

Create a meta field on FortiManager system settings of type Device and use it in the template.

Buy Now
Exam Code: FCP_FMG_AD-7.6
Exam Name: Fortinet NSE 5 - FortiManager 7.6 Administrator
Last Update: May 15, 2026
Questions: 65
$57.75  $164.99
$43.75  $124.99
$36.75  $104.99
buy now FCP_FMG_AD-7.6