(2024) NSE5_FMG-7.0 Exam Dumps, Practice Test Questions BUNDLE PACK
NSE 5 Network Security Analyst Certification NSE5_FMG-7.0 Sample Questions Reliable
NEW QUESTION # 10
An administrator would like to create an SD-WAN default static route for a newly created SD-WAN using the FortiManager GUI. Both port1 and port2 are part of the SD-WAN member interfaces.
Which interface must the administrator select in the static route device drop-down list?
- A. auto-discovery
- B. virtual-wan-link
- C. port2
- D. port1
Answer: B
NEW QUESTION # 11
An administrator has added all the devices in a Security Fabric group to FortiManager.
How does the administrator identify the root FortiGate?
- A. By an Asterisk (*) at the end of the device name
- B. By an at symbol (@) at the end of the device name
- C. By a Question NO : mark(?) at the end of the device name
- D. By a dollar symbol ($) at the end of the device name
Answer: A
NEW QUESTION # 12
Refer to the exhibit.
An administrator has created a firewall address object, Training which is used in the Local-FortiGate policy package.
When the installation operation is performed, which IP/Netmask will be installed on the Local-FortiGate, for the Training firewall address object?
- A. 192.168.0.1/24
- B. 10.200.1.0/24
- C. It will create a firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values.
- D. Local-FortiGate will automatically choose an IP/Netmask based on its network interface settings.
Answer: A
NEW QUESTION # 13
What does the diagnose dvm check-integrity command do? (Choose two.)
- A. Verifies and corrects duplicate VDOM entries
- B. Verifies and corrects database schemas in all object tables
- C. Internally upgrades existing ADOMs to the same ADON version in order to clean up and correct the ADOM syntax
- D. Verifies and corrects unregistered, registered, and deleted device states
Answer: A,D
Explanation:
6.2 Study Guide page 305 verify and correct parts of the device manager databases, including: - inconsistent device-to-group and group-to-ADOM memberships - unregistered, registered, and deleted device states - device lock statuses - duplicate VDOM entries
NEW QUESTION # 14
What will happen if FortiAnalyzer features are enabled on FortiManager?
- A. FortiManager will keep all the logs and reports on the FortiManager.
- B. FortiManager will install the logging configuration to the managed devices
- C. FortiManager will enable ADOMs to collect logs automatically from non-FortiGate devices.
- D. FortiManager can be used only as a logging device.
Answer: B
NEW QUESTION # 15
Which two statements about Security Fabric integration with FortiManager are true? (Choose two.)
- A. The Fabric View module enables you to generate the Security Fabric ratings for Security Fabric devices
- B. The Security Fabric license, group name and password are required for the FortiManager Security Fabric integration
- C. The Security Fabric settings are part of the device level settings
- D. The Fabric View module enables you to view the Security Fabric ratings for Security Fabric devices
Answer: C,D
NEW QUESTION # 16
An administrator configures a new firewall policy on FortiManager and has not yet pushed the changes to the managed FortiGate.
In which database will the configuration be saved?
- A. Device-level database
- B. ADOM-level database
- C. Configuration-level database
- D. Revision history database
Answer: B
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47942
NEW QUESTION # 17
View the following exhibit:
How will FortiManager try to get updates for antivirus and IPS?
- A. From the configured override server list only
- B. From the list of configured override servers with ability to fall back to public FDN servers
- C. From public FDNI server with highest index number only
- D. From the default server fdsl.fortinet.com
Answer: B
NEW QUESTION # 18
What is the purpose of the Policy Check feature on FortiManager?
- A. To find and merge duplicate policies in the policy package
- B. To find and provide recommendation for optimizing policies in a policy package
- C. To find and delete disabled firewall policies in the policy package
- D. To find and provide recommendation to combine multiple separate policy packages into one common policy package
Answer: B
NEW QUESTION # 19
In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator sent a device registration to FortiManager from a remote FortiGate. Which one of the following statements is true?
- A. By default, the unregistered FortiGate will appear in the root ADOM.
- B. The FortiGate will be automatically added to the Training ADOM.
- C. The FortiGate will be added automatically to the default ADOM named FortiGate.
- D. The FortiManager administrator must add the unregistered device manually to the unregistered device
Answer: A
Explanation:
manually to the Training ADOM using the Add Device wizard
NEW QUESTION # 20
View the following exhibit.
What is the purpose of setting ADOM Mode to Advanced?
- A. This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs.
- B. The setting allows automatic updates to the policy package configuration for a managed device
- C. The setting disables concurrent ADOM access and adds ADOM locking
- D. The setting enables the ADOMs feature on FortiManager
Answer: A
NEW QUESTION # 21
Which two items does an FGFM keepalive message include? (Choose two.)
- A. FortiGate configuration checksum
- B. FortiGate IPS version
- C. FortiGate uptime
- D. FortiGate license information
Answer: A,B
NEW QUESTION # 22
An administrator wants to delete an address object that is currently referenced in a firewall policy.
What can the administrator expect to happen?
- A. FortiManager will disable the status of the referenced firewall policy
- B. FortiManager will replace the deleted address object with all address object in the referenced firewall policy
- C. FortiManager will not allow the administrator to delete a referenced address object
- D. FortiManager will replace the deleted address object with the none address object in the referenced
firewall policy
Answer: D
NEW QUESTION # 23
Which of the following statements are true regarding VPN Manager? (Choose three.)
- A. Common IPsec settings need to be configured only once in a VPN Community for all managed gateways.
- B. VPN Manager automatically adds newly-registered devices to a VPN community.
- C. VPN Manager must be enabled on a per ADOM basis.
- D. VPN Manager can install common IPsec VPN settings on multiple FortiGate devices at the same time.
- E. VPN Manager automatically creates all the necessary firewall policies for traffic to be tunneled by IPsec.
Answer: A,C,D
NEW QUESTION # 24
An administrator's PC crashes before the administrator can submit a workflow session for approval. After the PC is restarted, the administrator notices that the ADOM was locked from the session before the crash.
How can the administrator unlock the ADOM?
- A. Log in using the same administrator account to unlock the ADOM.
- B. Log in as Super_User in order to unlock the ADOM.
- C. Delete the previous admin session manually through the FortiManager GUI or CLI.
- D. Restore the configuration from a previous backup.
Answer: C
NEW QUESTION # 25
View the following exhibit.
Given the configurations shown in the exhibit, what can you conclude from the installation targets in the Install On column?
- A. Policy seq#3 will be installed on the Trainer[NAT] VDOM only
- B. Policy seq#3 will be not installed on any managed device
- C. The Install On column value represents successful installation on the managed devices
- D. Policy seq#3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
Answer: D
NEW QUESTION # 26
......
Prepare for the Actual NSE 5 Network Security Analyst NSE5_FMG-7.0 Exam Practice Materials Collection: https://www.torrentexam.com/NSE5_FMG-7.0-exam-latest-torrent.html
NSE 5 Network Security Analyst Certified Official Practice Test NSE5_FMG-7.0: https://drive.google.com/open?id=1kRH0kT0LGDTuNpErIlbzjpfpygieBqmJ

