Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

Note! Fortinet has retired the NSE5_FMG-7.0 Exam and replaced it with the NSE5_FMG-7.2 Exam. Contact us through Live Chat or email us for more information.

NSE5_FMG-7.0 Fortinet NSE 5 - FortiManager 7.0 Questions and Answers

Questions 4

Which two items are included in the FortiManager backup? (Choose two.)

Options:

A.

FortiGuard database

B.

Global database

C.

Logs

D.

All devices

Buy Now
Questions 5

An administrator has assigned a global policy package to custom ADOM1. Then the administrator creates a new policy package, Fortinet, in the custom ADOM1.

Which statement about the global policy package assignment to the newly-created policy package Fortinet is true?

Options:

A.

When a new policy package is created, it automatically assigns the global policies to the new package.

B.

When a new policy package is created, you need to assign the global policy package from the global

ADOM.

C.

When a new policy package is created, you need to reapply the global policy package to the ADOM.

D.

When a new policy package is created, you can select the option to assign the global policies to the new package.

Buy Now
Questions 6

Refer to the exhibit.

NSE5_FMG-7.0 Question 6

An administrator has configured the command shown in the exhibit on FortiManager. A configuration change has been installed from FortiManager to the managed FortiGate that causes the FGFM tunnel to go down for more than 15 minutes.

What is the purpose of this command?

Options:

A.

It allows FortiGate to unset central management settings.

B.

It allows FortiGate to reboot and recover the previous configuration from its configuration file.

C.

It allows the FortiManager to revert and install a previous configuration revision on the managed FortiGate.

D.

It allows FortiGate to reboot and restore a previously working firmware image.

Buy Now
Questions 7

Refer to the exhibit.

NSE5_FMG-7.0 Question 7

Which two statements about an ADOM set in Normal mode on FortiManager are true? (Choose two.)

Options:

A.

It supports the FortiManager script feature

B.

It allows making configuration changes for managed devices on FortiManager panes

C.

FortiManager automatically installs the configuration difference in revisions on the managed FortiGate

D.

You cannot assign the same ADOM to multiple administrators

Buy Now
Questions 8

View the following exhibit:

NSE5_FMG-7.0 Question 8

An administrator used the value shown in the exhibit when importing a Local-FortiGate into FortiManager. What name will be used to display the firewall policy for port1?

Options:

A.

port1 on FortiGate and WAN on FortiManager

B.

port1 on both FortiGate and FortiManager

C.

WAN zone on FortiGate and WAN zone on FortiManager

D.

WAN zone on FortiGate and WAN interface on FortiManager

Buy Now
Questions 9

Refer to the exhibit.

NSE5_FMG-7.0 Question 9

An administrator is about to add the FortiGate device to FortiManager using the discovery process FortiManager is operating behind a NAT device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings

What is the expected result?

Options:

A.

During discovery FortiManager sets trie FortiManager NATed IP address on FortiGate

B.

During discovery FortiManager sets both tie FortiManager NATed IP address and NAT device IP address on FortiGate

C.

During discovery FortiManager sets the NATed device IP address on FortiGate

D.

During discovery FortiManager uses only the FortiGate serial number to establish the connection

Buy Now
Questions 10

Refer to the exhibit.

NSE5_FMG-7.0 Question 10

You ate using the Quick install option to install configuration changes on the managed FortiGate

Which two statements correctly describe the result? (Choose two)

Options:

A.

It installs device-level changes on the FortiGate device without launching the Install Wizard

B.

It installs all the changes in the device database first and the administrator must reinstall the changes on the FodiGate device

C.

It provides the option to preview only the policy package changes before installing them

D.

It install provisioning template changes on the FortiGate device

Buy Now
Questions 11

In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator authorized the FortiGate device on FortiManager using the Fortinet Security Fabric.

Given the administrator's actions, which statement correctly describes the expected result?

Options:

A.

The FortiManager administrator must add the authorized device to the Training ADOM using the Add Device wizard only.

B.

The authorized FortiGate will be automatically added to the Training ADOM.

C.

The authorized FortiGate will appear in the root ADOM.

D.

The authorized FortiGate can be added to the Training ADOM using FortiGate Fabric Connectors.

Buy Now
Questions 12

Which two settings are required for FortiManager Management Extension Applications (MEA)? (Choose two.)

Options:

A.

When you configure MEA, you must open TCP or UDP port 540.

B.

You must open the ports to the Fortinet registry

C.

You must create a MEA special policy on FortiManager using the super user profile

D.

The administrator must have the super user profile.

Buy Now
Questions 13

View the following exhibit.

NSE5_FMG-7.0 Question 13

When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)

Options:

A.

Once initiated, the install process cannot be canceled and changes will be installed on the managed device

B.

Will not create new revision in the revision history

C.

Installs device-level changes to FortiGate without launching the Install Wizard

D.

Provides the option to preview configuration changes prior to installing them

Buy Now
Questions 14

What does the diagnose dvm check-integrity command do? (Choose two.)

Options:

A.

Internally upgrades existing ADOMs to the same ADON version in order to clean up and correct the ADOM

syntax

B.

Verifies and corrects unregistered, registered, and deleted device states

C.

Verifies and corrects database schemas in all object tables

D.

Verifies and corrects duplicate VDOM entries

Buy Now
Questions 15

View the following exhibit.

NSE5_FMG-7.0 Question 15

An administrator has created a firewall address object, Training, which is used in the Local-FortiGate policy package. When the install operation is performed, which IP Netmask will be installed on the Local-FortiGate, for the Training firewall address object?

Options:

A.

10.0.1.0/24

B.

It will create firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values

C.

192.168.0.1/24

D.

Local-FortiGate will automatically choose an IP Network based on its network interface settings.

Buy Now
Questions 16

Which three settings are the factory default settings on FortiManager? (Choose three.)

Options:

A.

Username is admin

B.

Password is fortinet

C.

FortiAnalyzer features are disabled

D.

Reports and Event Monitor panes are enabled

E.

port1 interface IP address is 192.168.1.99/24

Buy Now
Questions 17

View the following exhibit, which shows the Download Import Report:

NSE5_FMG-7.0 Question 17

Why it is failing to import firewall policy ID 2?

Options:

A.

The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association locally on the FortiGate

B.

Policy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager

C.

Policy ID 2 does not have ADOM Interface mapping configured on FortiManager

D.

Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.

Buy Now
Questions 18

Which two items does an FGFM keepalive message include? (Choose two.)

Options:

A.

FortiGate uptime

B.

FortiGate license information

C.

FortiGate IPS version

D.

FortiGate configuration checksum

Buy Now
Questions 19

An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session.

What can prevent an admin account that has Super_User rights over the device from approving a workflow session?

NSE5_FMG-7.0 Question 19

Options:

A.

Trainer is not a part of workflow approval group

B.

Trainer does not have full rights over this ADOM

C.

Trainer must close Student’s workflow session before approving the request

D.

Student, who submitted the workflow session, must first self-approve the request

Buy Now
Questions 20

View the following exhibit:

NSE5_FMG-7.0 Question 20

Which two statements are true if the script is executed using the Remote FortiGate Directly (via CLI) option? (Choose two.)

Options:

A.

You must install these changes using Install Wizard

B.

FortiGate will auto-update the FortiManager’s device-level database.

C.

FortiManager will create a new revision history.

D.

FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate.

Buy Now
Questions 21

View the following exhibit.

NSE5_FMG-7.0 Question 21

If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)

Options:

A.

FortiGate is discovered by FortiManager through the FortiGate NATed IP address.

B.

FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on

FortiGate under central management.

C.

During discovery, the FortiManager NATed IP address is not set by default on FortiGate.

D.

If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.

Buy Now
Questions 22

View the following exhibit.

NSE5_FMG-7.0 Question 22

What is the purpose of setting ADOM Mode to Advanced?

Options:

A.

The setting allows automatic updates to the policy package configuration for a managed device

B.

The setting enables the ADOMs feature on FortiManager

C.

This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.

D.

The setting disables concurrent ADOM access and adds ADOM locking

Buy Now
Questions 23

An administrator has assigned a global policy package to a new ADOM called ADOM1. What will happen if the administrator tries to create a new policy package in ADOM1?

Options:

A.

When creating a new policy package, the administrator can select the option to assign the global policy

package to the new policy package

B.

When a new policy package is created, the administrator needs to reapply the global policy package to

ADOM1.

C.

When a new policy package is created, the administrator must assign the global policy package from the global ADOM.

D.

When the new policy package is created, FortiManager automatically assigns the global policy package to the new policy package.

Buy Now
Exam Code: NSE5_FMG-7.0
Exam Name: Fortinet NSE 5 - FortiManager 7.0
Last Update: Jul 13, 2025
Questions: 79