Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

NSE6_FMG_AD-7.6 Fortinet NSE 6 - FortiManager 7.6 Administrator Questions and Answers

Questions 4

Refer to the exhibit.

NSE6_FMG_AD-7.6 Question 4

An administrator has assigned the default system template to install all devices with the FortiAnalyzer IP address 10.0.13.12. However, not all FortiGate devices can reach FortiAnalyzer using the default interface. Some devices may use the LAN interface, while others may use the WAN interface. How can the administrator change the source interface for FortiGate devices using the default system template? Choose one answer

Options:

A.

Use per-device dynamic object configurations at the ADOM level and apply them in the template.

B.

Configure a metadata variable at the ADOM level and use it in the template.

C.

Create a different system template for each FortiGate, if the configuration is different.

D.

Create a meta field on FortiManager system settings of type Device and use it in the template.

Buy Now
Questions 5

What are two expected results when both FortiManager and FortiGate are behind network address translation NAT devices? Choose two answers

Options:

A.

FortiGate is discovered by FortiManager through the FortiGate NATed IP address.

B.

During discovery, the FortiManager NATed IP address is not set by default on FortiGate.

C.

FortiGate can announce itself to FortiManager only if the FortiManager non-NATed IP address is configured on FortiGate under central management.

D.

If the FortiGate–FortiManager communication protocol FGFM tunnel is torn down, FortiManager will try to reestablish the FGFM tunnel.

Buy Now
Questions 6

An administrator is copying a system template profile between ADOMs by running the following command:

execute fmprofile export-profile ADOM 3547 /tmp/Backup_File

output dump to file: [/tmp/Backup_File]

Where does this command export the system template profile from?

Options:

A.

FortiManager /tmp/Backup_File folder

B.

FortiManager ADOM policy database

C.

ADOM device database

D.

FortiManager configuration backup file

Buy Now
Questions 7

After correcting a policy package configuration issue, you want to prevent administrators from repeating the mistake that caused the issue.

Which FortiManager approach best meets this need?

Options:

A.

Configure an TCL script to run locally on FortiManager for each FortiGate.

B.

Restrict administrators with an administration profile from viewing the revision history to limit who can make changes.

C.

Enable the change note to require administrators to add a note whenever they change object configurations.

D.

Enable a workflow requiring approval before installing policy packages on any FortiGate.

Buy Now
Questions 8

Refer to the exhibits.

NSE6_FMG_AD-7.6 Question 8

What can you conclude, based on the configuration shown in the exhibit? Choose one answer

Options:

A.

The administrator needs to retrieve the Local-FortiGate configuration to sync with the Security Fabric group, Training.

B.

Policy sequence #1 will be installed on the internal segmentation firewall ISFW device root NAT and Trainer NAT VDOMs.

C.

Policy sequence #3 must have devices or VDOMs listed in the Install On column; otherwise, it will cause errors.

D.

The global policy package will be added to the top of the ISFW policy package.

Buy Now
Questions 9

Refer to the exhibit.

NSE6_FMG_AD-7.6 Question 9

Which two statements about the output are true? (Choose two.)

Options:

A.

The latest revision history for the managed FortiGate does not match the device-level database.

B.

Configuration changes have been installed on FortiGate, updating policy and device-level database.

C.

The latest revision history for the managed FortiGate does match the FortiManager policy database.

D.

The system template default will override device-level database configurations.

Buy Now
Questions 10

What can you conclude from the failed installation log shown in the exhibit?

NSE6_FMG_AD-7.6 Question 10

Options:

A.

Policy ID 2 is installed in the disabled state.

B.

Policy ID 2 will not be installed.

C.

Policy ID 2 is installed without a source address.

D.

Policy ID 2 is installed without the remote user student.

Buy Now
Questions 11

Push updates are failing on a FortiGate device located behind a network address translation (NAT) device?

Which two settings should the administrator check to correct this problem? (Choose two.)

Options:

A.

Make sure the NAT device IP address and the correct ports are configured on FortiManager.

B.

Make sure FortiGuard updates and web service are enabled on the FortiGuard service interface.

C.

Make sure the virtual IP address and the correct ports are configured on the NAT device.

D.

Make sure the Bind to IP address option on the FortiGuard service interface is set to the virtual IP address from the NAT device.

Buy Now
Questions 12

Refer to the exhibits.

NSE6_FMG_AD-7.6 Question 12

NSE6_FMG_AD-7.6 Question 12

An administrator needed to recover all the configurations related to the user, Support. The configurations were saved in configuration revision ID 9.

The administrator reverted the configuration using the Configuration Revision History window and received the CLI output shown in the exhibit.

What can you conclude from the CLI output?

Options:

A.

The administrator set the flag to 0 to prevent configuration overrides.

B.

The administrator reinstalled the policy package.

C.

The administrator needs to retrieve the device to correctly detect the FortiGate firmware version.

D.

The administrator installed only the device-level configuration.

Buy Now
Questions 13

What is the purpose of ADOM revisions?

Options:

A.

ADOM revisions find unused, duplicate, and unnecessary firewall policies and objects.

B.

ADOM revisions show specific changes in a policy package when it is installed.

C.

ADOM revisions compare previous snapshots of the Policy Package and ADOM-level objects with the device-level database.

D.

ADOM revisions save the current state of all policy packages and objects for an ADOM.

Buy Now
Questions 14

Refer to the exhibit.

NSE6_FMG_AD-7.6 Question 14

An administrator assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview, they noticed some settings they did not modify and are unsure about the changes.

Based on the exhibit, which two things will happen if they continue with the installation? (Choose two.)

Options:

A.

FortiGate HQ-NGFW-1 can use FortiManager firmware templates to upgrade firmware and ratings.

B.

FortiGate HQ-NGFW-1 can contact the FortiManager acting as FortiGuard Distribution Server (FDS) to download FortiGuard updates.

C.

FortiGate HQ-NGFW-1 will use the root_CA3 certificate in firewall address objects or policies.

D.

FortiManager will install the CA certificate named root_CA3 to authenticate FortiGate-to-FortiManager communication protocol (FGFM) tunnel connections with FortiGate HQ- NGFW-1.

Buy Now
Questions 15

An administrator has a FortiGate-HQ device with VDOMs—root, HR and Facilities, currently managed under the FortiManager ADOM—Site1. They try to move VDOM HR to the FortiManager ADOM—Site2, but it does not work.

Why is the administrator not able to move FortiGate-HQ VDOM HR to FortiManager ADOM—Site2?

Options:

A.

The FortiGate-HQ must be managed under the FortiManager ADOM—root to allow moving its VDOMs to different ADOMs.

B.

The administrator must have full access in the device layer of FortiGate-HQ VDOM-root before they can VDOMs to different ADOMs.

C.

FortiManager must be in ADOM normal mode, which does not allow VDOMs to be managed separately.

D.

The administrator must delete the FortiGate-HQ device from FortiManager and add it again using the Add Device wizard before moving the VDOM.

Buy Now
Questions 16

Refer to the exhibit.

NSE6_FMG_AD-7.6 Question 16

What can you conclude from the downloaded import report?

Options:

A.

FortiManager does not support per-device mapping for firewall addresses.

B.

The administrator will see a new policy package named Remote-FortiGate_root in the FortiManager ADOM database.

C.

FortiManager will change the configuration of REMOTE_SUBNET to match the interface mapping coming in from Remote-FortiGate.

D.

As a result of this policy import process, FortiManager will create a new firewall address called REMOTE_SUBNET in the ADOM database.

Buy Now
Questions 17

Refer to the exhibit.

NSE6_FMG_AD-7.6 Question 17

Which two statements about the configuration shown in the exhibit are true? Choose two answers.

Options:

A.

An administrator can lock the Local-FortiGate_root policy package.

B.

The administrator created a snapshot of the Remote-FortiGate policy package.

C.

The FortiManager ADOM workspace mode is set to normal.

D.

The FortiManager is in workflow mode.

Buy Now
Questions 18

Company policy dictates that any time a change is made to a policy package on FortiManager an ADOM revision is created before the change installed, and that revision is held for a minimum of 90 days.

Over the past three months, each installed change has resulted in several unused policies and duplicate objects.

The FortiManager administrator plans to upgrade the FortiGate devices and then upgrade the FortiManager ADOM from version 7.4 to 7.6.

Which action can the administrator take to avoid slow ADOM upgrades?

Options:

A.

Check and repair the global configuration database before upgrading.

B.

Export firewall policies to Excel, delete them on the ADOM. then reimport them after upgrading the ADOM.

C.

Find unused firmware templates, then delete them before upgrading.

D.

Limit ADOM revisions before upgrading.

Buy Now
Questions 19

What is the best explanation of how FortiManager helps with mass provisioning?

Options:

A.

It upgrades the OS of each FortiGate device.

B.

It provides local FortiGuard Distribution Server (FDS) services to the network.

C.

It uses templates to configure the same settings on many devices simultaneously.

D.

It sends email alerts when new devices connect.

Buy Now
Exam Code: NSE6_FMG_AD-7.6
Exam Name: Fortinet NSE 6 - FortiManager 7.6 Administrator
Last Update: Sep 2, 2026
Questions: 65

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99