Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

FCP_FMG_AD-7.6 Fortinet NSE 5 - FortiManager 7.6 Administrator Questions and Answers

Questions 4

Refer to the exhibits.

FCP_FMG_AD-7.6 Question 4

FCP_FMG_AD-7.6 Question 4

FCP_FMG_AD-7.6 Question 4

An administrator needs to push a FortiToken Mobile to assign it to HR_user in the HQ-NGFW-1.

However, when installing the policy package, they receive the following error message:

FCP_FMG_AD-7.6 Question 4

Why is the administrator not able to install the FortiToken on the HQ-NGFW-1 firewall?

Options:

A.

The administrator must use a user local meta field to assign FortiToken.

B.

The administrator must use a valid FortiToken that exists on HQ-NGFW-1.

C.

The administrator must use a metadata variable to assign the same FortiToken to multiple users in FortiManager.

D.

The administrator must use per-device mapping to assign the FortiToken to HQ-NGFW-1.

Buy Now
Questions 5

Company policy dictates that any time a change is made to a policy package on FortiManager an ADOM revision is created before the change installed, and that revision is held for a minimum of 90 days.

Over the past three months, each installed change has resulted in several unused policies and duplicate objects.

The FortiManager administrator plans to upgrade the FortiGate devices and then upgrade the FortiManager ADOM from version 7.4 to 7.6.

Which action can the administrator take to avoid slow ADOM upgrades?

Options:

A.

Check and repair the global configuration database before upgrading.

B.

Export firewall policies to Excel, delete them on the ADOM. then reimport them after upgrading the ADOM.

C.

Find unused firmware templates, then delete them before upgrading.

D.

Limit ADOM revisions before upgrading.

Buy Now
Questions 6

Refer to the exhibits.

FCP_FMG_AD-7.6 Question 6

FCP_FMG_AD-7.6 Question 6

An administrator has been asked to install the same policies from a central policy package onto the BR1-FGT-1 firewall.

The administrator added BR1-FGT-1 as a target in the central policy package installation.

What should the administrator do when reinstalling the central policy package on the BR1-FGT-1 firewall?

Options:

A.

Assign only one policy package to the firewall because FortiManager does not allow more than one policy package assigned per device at the same time.

B.

Import the policy package to change the unknown status and synchronize the policy package.

C.

Use the install wizard to install the central policy package on the BR1-FGT-1 firewall.

D.

First resolve the modified status in the configuration and provisioning templates to allow a smooth installation.

Buy Now
Questions 7

Refer to the exhibit.

FCP_FMG_AD-7.6 Question 7

Which two results occur if you run the script using the Device Database option? (Choose two.)

Options:

A.

The device Config Status is tagged as Modified.

B.

The script history shows the successful installation of the script on the remote FortiGate.

C.

The successful execution of a script on the Device Database creates a new revision history.

D.

The administrator must install these changes on a managed device using the Install Wizard.

Buy Now
Questions 8

An administrator assigned the Training global policy package to the Branches policy package in ADOM1. Later, the administrator created a new policy package named Remotes on ADOM1.

What should the administrator do to sync the Training global policy package with the Remotes policy package in ADOM1?

Options:

A.

Manually add and assign the Remotes policy package to the Training global policy package

B.

Use the automatically install policies to ADOM devices method to sync from the Training global policy package to the Remotes policy package

C.

Assign the Training global policy package to the Remotes policy package

D.

Unassign the Training policy package and reassign it to all policy packages within ADOM1

Buy Now
Questions 9

An administrator notices that CLI scripts are failing on some FortiGate devices because they use different FortiOS versions.

Which two actions should the administrator take to fix the failing CLI scripts? Choose two answers.

Options:

A.

Create separate ADOMs for each FortiOS version.

B.

Disable CLI scripts for devices using older firmware.

C.

Modify the CLI scripts to include conditional commands based on FortiOS version.

D.

Create version-specific CLI script groups and assign them to the appropriate devices.

Buy Now
Questions 10

An administrator has assigned a global policy package to a new ADOM named ADOM1.

What will happen if the administrator tries to create a new policy package in ADOM1?

Options:

A.

The administrator will be able to select the option to assign the global policy package to the new policy package.

B.

FortiManager will automatically assign the global policy package to the new policy package.

C.

FortiManager will automatically install policies on the policy package in ADOM1.

D.

The administrator will have to assign the global policy package from the global ADOM.

Buy Now
Questions 11

Refer to the exhibit.

FCP_FMG_AD-7.6 Question 11

An administrator added a FortiGate device to FortiManager with the default object settings at the ADOM layer.

What can you conclude from the import policy package process of the HQ-NGFW- 1 device?

Options:

A.

The administrator must select Per Platform for all interfaces to correctly detect all interfaces from HQ-NGFW-1.

B.

The administrator must manually create the port4 interface on the ADOM layer to avoid import policy errors.

C.

FortiManager will create LAN, port4, and port6 as normalized interfaces at the ADOM layer.

D.

FortiGate may not work as expected when the administrator does not import all objects.

Buy Now
Questions 12

Refer to the exhibits.

FCP_FMG_AD-7.6 Question 12

An administrator added BR1-FGT-1 to FortiManager and started importing the policy package. During the process, they saw that they need to choose values from FortiGate or FortiManager.

Which conclusion is most clearly supported by the exhibits?

Options:

A.

BR1-FGT-1 does not support the SSL/SSH profile with HTTPS on port 443.

B.

The administrator must match the FortiOS firmware version with the FortiManager ADOM firmware version to resolve the conflict status.

C.

The default Firewall Profile-Protocol-Options object is the only profile that does not significantly affect any configuration changes on either FortiManager or FortiGate.

D.

FortiManager has a different FortiGuard database compared to FortiGate BR1-FGT-1 for the QUIC protocol.

Buy Now
Questions 13

Refer to the exhibits.

FCP_FMG_AD-7.6 Question 13

FCP_FMG_AD-7.6 Question 13

FCP_FMG_AD-7.6 Question 13

An administrator must replace the source LAN interface in policy ID 2 on their FortiGateRugged-70F.

However, when they try to install the policy package, they receive the error shown in the exhibit.

What should the administrator do to resolve the error?

Options:

A.

Use the API to assign a system template interface for FortiGateRugged-70F model.

B.

Use a metadata variable to dynamically assign an interface when this error occurs.

C.

Create a per-device mapping for the LAN interface.

D.

Replace LAN with lan1, which is supported by FortiGateRugged-70F models.

Buy Now
Questions 14

Refer to the exhibit.

FCP_FMG_AD-7.6 Question 14

What are two results from the configuration shown in the exhibit? Choose two answers.

Options:

A.

The same administrator can lock more than one ADOM at the same time.

B.

Multiple administrators can lock and work on separate ADOMs at the same time.

C.

All changes must be approved before they can be installed on a device.

D.

Concurrent read-write access to an ADOM is disabled.

Buy Now
Questions 15

An administrator configures a new BGP peer in the FortiManager device-level database of FortiGate. They reinstall the policy package to the managed FortiGate device without any errors. However, when the administrator logs in to FortiGate, they do not see the BGP configuration changes.

What is the most likely reason why FortiManager did not push the BGP peer changes to FortiGate?

Options:

A.

The administrator must run a sanity check on FortiManager to make sure the database is not corrupted.

B.

Fortigate has a BGP template assigned on the FortiManager database.

C.

The administrator must use the Install Wizard and select Install device settings only to push BGP settings

D.

The FortiGate firmware version is different from the FortiManager ADOM version.

Buy Now
Questions 16

A FortiManager administrator opens the revision history and choose to revert to a previous version.

What will this action do to the current device configuration?

Options:

A.

It will trigger an unknown device-level database status, and the administrator will have to import a policy package to sync.

B.

It will trigger a conflict status if it is using any provisioning template, and the administrator will have to install changes.

C.

It will revert both configurations: device-level database and policy layer database.

D.

It will modify the device-level database.

Buy Now
Questions 17

Refer to the exhibits.

FCP_FMG_AD-7.6 Question 17

FCP_FMG_AD-7.6 Question 17

An administrator needed to recover all the configurations related to the user, Support. The configurations were saved in configuration revision ID 9.

The administrator reverted the configuration using the Configuration Revision History window and received the CLI output shown in the exhibit.

What can you conclude from the CLI output?

Options:

A.

The administrator set the flag to 0 to prevent configuration overrides.

B.

The administrator reinstalled the policy package.

C.

The administrator needs to retrieve the device to correctly detect the FortiGate firmware version.

D.

The administrator installed only the device-level configuration.

Buy Now
Questions 18

Refer to the exhibit.

FCP_FMG_AD-7.6 Question 18

An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.

After the installation operation is performed, which IP/netmask will be installed on Remote-Firewall [VDOM1] for the LAN firewall address object?

Options:

A.

21.21.2.5/255.255.255.255

B.

172.16.5.20/255.255.255.255

C.

172.16.5.0/255.255.255.0

D.

10.10.10.5/255.255.255.255

Buy Now
Questions 19

What allows FortiManager to run CLI scripts on FortiGate devices without prompting for SSH authentication each time?

Options:

A.

FortiGate devices using the legacy login method.

B.

The secure management tunnel between FortiManager and FortiGate devices.

C.

The script using the Remote FortiGate Directly via CLI option.

D.

The script on the FortiManager device database.

Buy Now
Exam Code: FCP_FMG_AD-7.6
Exam Name: Fortinet NSE 5 - FortiManager 7.6 Administrator
Last Update: Apr 30, 2026
Questions: 65

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99