Prepare NSE5_FMG-7.2 Question Answers Free Update With 100% Exam Passing Guarantee [2024]
Dumps Real Fortinet NSE5_FMG-7.2 Exam Questions [Updated 2024]
The NSE5_FMG-7.2 exam is a part of the Fortinet Network Security Expert (NSE) certification program. The NSE program is a comprehensive training and certification program that is designed to provide IT professionals with the skills and knowledge to implement and manage Fortinet security solutions. The NSE program includes a series of exams that cover different aspects of Fortinet security solutions, from basic network security to advanced threat protection. The NSE5_FMG-7.2 exam is an important step in the NSE certification path for network security professionals who want to demonstrate their expertise in using FortiManager to manage and secure their network.
NEW QUESTION # 40
Which of the following statements are true regarding VPN Gateway configuration in VPN Manager? (Choose two.)
- A. Protected subnets are the subnets behind the device that you don't want to allow access to over the IPsec VPN
- B. Managed gateways are devices managed by FortiManager in the same ADOM
- C. Managed devices in other ADOMs must be treated as external gateways
- D. External gateways are third-party VPN gateway devices only
Answer: B,C
Explanation:
Reference:http://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG-FAZ/1
300_VPN_Manager/0800_IPsec_VPN_Gateway/0400_Create_mngd_gateway.htm
NEW QUESTION # 41
Refer to the exhibit.
You ate using the Quick install option to install configuration changes on the managed FortiGate Which two statements correctly describe the result? (Choose two)
- A. It installs all the changes in the device database first and the administrator must reinstall the changes on the FodiGate device
- B. It provides the option to preview only the policy package changes before installing them
- C. It install provisioning template changes on the FortiGate device
- D. It installs device-level changes on the FortiGate device without launching the Install Wizard
Answer: C,D
NEW QUESTION # 42
An administrator configures a new firewall policy on FortiManager and has not yet pushed the changes to the managed FortiGate.
In which database will the configuration be saved?
- A. Revision history database
- B. Configuration-level database
- C. ADOM-level database
- D. Device-level database
Answer: C
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47942
NEW QUESTION # 43
Refer to the exhibit.
Given the configuration shown in the exhibit, what can you conclude from the installation targets m the Install On column? (Choose two)
- A. Policy seq # 1 will be installed on the Remoto-FortiGate root[NAT] and Student[NAT] VDOMs only
- B. Policy 3 will be installed on all FortiGate devices and vdom belongs to the ADOM
- C. Policy seq # 3 will be skipped because no installation targets are specified
- D. Policy seq # 2 will not be installed on the Local-FortiGate root VDOM because there is no root VDOM in the Installation Target
- E. Policy seq # 3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
Answer: A,E
NEW QUESTION # 44
What will happen if FortiAnalyzer features are enabled on FortiManager?
- A. FortiManager will reboot
- B. FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager
- C. FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices
- D. FortiManager can be used only as a logging device.
Answer: A
Explanation:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1800_FAZ%20Features/0
NEW QUESTION # 45
Which configuration setting for FortiGate is part of an ADOM-level database on FortiManager?
- A. NSX-T Service Template
- B. Routing
- C. Security profiles
- D. SNMP
Answer: C
NEW QUESTION # 46
Refer to the exhibit.
Which two statements about the output are true? (Choose two.)
- A. The latest revision history for the managed FortiGate does match with the FortiGate running configuration
- B. Configuration changes have been installed to FortiGate and represents FortiGate configuration has been changed
- C. Configuration changes directly made on the FortiGate have been automatically updated to device-level database
- D. The latest history for the managed FortiGate does not match with the device-level database
Answer: A,D
Explanation:
STATUS: dev-db: modified; conf: in sync; cond: pending; dm: retrieved; conn: up- dev-db: modified - This is the device setting status which indicates that configuration changes were made on FortiManager.
- conf: in sync - This is the sync status which shows that the latest revision history is in sync with Fortigate's configuration.- cond: pending - This is the configuration status which says that configuration changes need to be installed.
Most probably a retrieve was done in the past (dm: retrieved) updating the revision history DB (conf: in sync) and FortiManager device level DB, now there is a new modification on FortiManager device level DB (dev-db: modified) which wasn't installed to FortiGate (cond: pending), hence; revision history DB is not aware of that modification and doesn't match device DB.
Conclusion:- Revision DB does match FortiGate.- No changes were installed to FortiGate yet.- Device DB doesn't match Revision DB.- No changes were done on FortiGate (auto-update) but configuration was retrieved instead After an Auto-Update or Retrieve:device database = latest revision = FGT Then after a manual change on FMG end (but no install yet):latest revision = FGT (still) but now device database has been modified (is different).
After reverting to a previous revision in revision history:device database = reverted revision != FGT
NEW QUESTION # 47
Which two statements about the scheduled backup of FortiManager are true? (Choose two.)
- A. It backs up all devices and the FortiGuard database.
- B. It does not back up firmware images saved on FortiManager.
- C. It supports FTP, SCP, and SFTP.
- D. It can be configured using the CLI and GUI.
Answer: B,C
NEW QUESTION # 48
Refer to the exhibit.
How will FortiManager try to get updates for antivirus and IPS?
- A. From the configured override server IP address 10.0.1.50 only
- B. From public FDNI server IP address with the fourth highest octet only
- C. From the list of configured override servers or public FDN servers
- D. From the default server fds1.fortinet.com
Answer: C
NEW QUESTION # 49
An administrator would like to create an SD-WAN using central management in the Training ADOM.
To create an SD-WAN using central management, which two steps must be completed? (Choose two.)
- A. Configure and install the SD-WAN firewall policy and SD-WAN static route before installing the SD-WAN template settings
- B. Specify a gateway address when you create a default SD-WAN static route
- C. Remove all the interface references such as routes or policies that will be a part of SD-WAN member interfaces
- D. Enable SD-WAN central management in the Training ADOM
Answer: C,D
NEW QUESTION # 50
Which two settings must be configured for SD-WAN Central Management? (Choose two.)
- A. SD-WAN must be enabled on per-ADOM basis
- B. When you configure an SD-WAN, you must specify at least two member interfaces.
- C. You can create multiple SD-WAN interfaces per VDOM
- D. The first step in creating an SD-WAN using FortiManager is to create two SD-WAN firewall policies.
Answer: A,B
NEW QUESTION # 51
Refer to the exhibit.
An administrator would like to create three ADOMs on FortiManager with different access levels based on departments.
What two conclusions can you draw from the design shown in the exhibit? (Choose two.)
- A. The administrator must configure FortiManager in workspace mode.
- B. The administrator must set the FortiManager ADOM mode to Advanced.
- C. The FortiManager policies and objects database can be shared between the Financial and HR ADOMs.
- D. Admin A can access VDOM2 and VDOM3 with the super user profile.
Answer: B,C
NEW QUESTION # 52
View the following exhibit.
If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)
- A. FortiGate is discovered by FortiManager through the FortiGate NATed IP address.
- B. FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management.
- C. During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
- D. If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
Answer: A,C
Explanation:
Fortimanager can discover FortiGate through a NATed FortiGate IP address. If a FortiManager NATed IP address is configured on FortiGate, then FortiGate can announce itself to FortiManager. FortiManager will not attempt to re-establish the FGFM tunnel to the FortiGate NATed IP address, if the FGFM tunnel is interrupted. Just like it was in the NATed FortiManager scenario, the FortiManager NATed IP address in this scenario is not configured under FortiGate central management configuration.
NEW QUESTION # 53
View the following exhibit.
Which of the following statements are true based on this configuration setting? (Choose two.)
- A. This setting will allow assigning different VDOMs from the same FortiGate to different ADOMs.
- B. This setting will enable the ADOMs feature on FortiManager.
- C. This setting will allow automatic updates to the policy package configuration for a managed device.
- D. This setting is applied globally to all ADOMs.
Answer: A,D
NEW QUESTION # 54
An administrator would like to create an SD-WAN default static route for a newly created SD-WAN using the FortiManager GUI. Both port1 and port2 are part of the SD-WAN member interfaces.
Which interface must the administrator select in the static route device drop-down list?
- A. auto-discovery
- B. virtual-wan-link
- C. port1
- D. port2
Answer: B
NEW QUESTION # 55
An administrator has added all the devices in a Security Fabric group to FortiManager.
How does the administrator identify the root FortiGate?
- A. By a dollar symbol ($) at the end of the device name
- B. By an at symbol (@) at the end of the device name
- C. Question mark(?) at the end of the device name
- D. By an Asterisk (*) at the end of the device name
Answer: D
NEW QUESTION # 56
......
NSE5_FMG-7.2 Exam Dumps, NSE5_FMG-7.2 Practice Test Questions: https://www.vcedumps.com/NSE5_FMG-7.2-examcollection.html
Free NSE5_FMG-7.2 Exam Dumps to Pass Exam Easily: https://drive.google.com/open?id=1dxdnBUX3CS4oMe8b3a_wfyokKq1hADda
