All Obstacles During NSE5_FMG-7.2 Exam Preparation with NSE5_FMG-7.2 Real Test Questions
Fully Updated Free Actual Fortinet NSE5_FMG-7.2 Exam Questions
The Fortinet NSE5_FMG-7.2 exam consists of multiple-choice questions and practical scenarios that test the candidate's ability to configure and manage FortiManager 7.2. NSE5_FMG-7.2 exam covers topics such as device registration, configuration management, policy management, and troubleshooting. Candidates who pass the exam will be recognized as Fortinet NSE 5 certified professionals, which demonstrates their expertise in managing and configuring FortiManager 7.2.
NEW QUESTION # 61
Refer to the exhibit.
An administrator has created a firewall address object, Training which is used in the Local-FortiGate policy package.
When the installation operation is performed, which IP/Netmask will be installed on the Local-FortiGate, for the Training firewall address object?
- A. It will create a firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values.
- B. 192.168.0.1/24
- C. 10.200.1.0/24
- D. Local-FortiGate will automatically choose an IP/Netmask based on its network interface settings.
Answer: B
NEW QUESTION # 62
View the following exhibit, which shows the Download Import Report:
Why it is failing to import firewall policy ID 2?
- A. Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.
- B. Policy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager
- C. Policy ID 2 does not have ADOM Interface mapping configured on FortiManager
- D. The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association locally on the FortiGate
Answer: D
Explanation:
FortiManager_6.4_Study_Guide-Online - page 331 & 332
NEW QUESTION # 63
What will happen if FortiAnalyzer features are enabled on FortiManager?
- A. FortiManager will reboot
- B. FortiManager can be used only as a logging device.
- C. FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices
- D. FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager
Answer: A
Explanation:
Reference:https://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1800_FAZ%20Features/0
NEW QUESTION # 64
Which two settings are required for FortiManager Management Extension Applications (MEA)? (Choose two.)
- A. You must create a MEA special policy on FortiManager using the super user profile
- B. You must open the ports to the Fortinet registry
- C. The administrator must have the super user profile.
- D. When you configure MEA, you must open TCP or UDP port 540.
Answer: A,C
NEW QUESTION # 65
View the following exhibit:
Which two statements are true if the script is executed using the Remote FortiGate Directly (via CLI) option? (Choose two.)
- A. You must install these changes using Install Wizard
- B. FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate.
- C. FortiGate will auto-update the FortiManager's device-level database.
- D. FortiManager will create a new revision history.
Answer: C,D
NEW QUESTION # 66
Which of the following statements are true regarding VPN Gateway configuration in VPN Manager? (Choose two.)
- A. Protected subnets are the subnets behind the device that you don't want to allow access to over the IPsec VPN
- B. Managed devices in other ADOMs must be treated as external gateways
- C. Managed gateways are devices managed by FortiManager in the same ADOM
- D. External gateways are third-party VPN gateway devices only
Answer: B,C
Explanation:
Reference:http://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG-FAZ/1
300_VPN_Manager/0800_IPsec_VPN_Gateway/0400_Create_mngd_gateway.htm
NEW QUESTION # 67
Exhibit.
Which two statements about the output are true'' (Choose two.)
- A. The latest revision history for the managed FortiGate does match the FortiGate running configuration
- B. Configuration changes directly made on FortiGate have been automatically updated to the device-level database
- C. The latest revision history for the managed FortiGate does not match the device-level database
- D. Configuration changes have been installed on FortiGate. which means the FortiGate configuration has been changed
Answer: A,C
Explanation:
"conf: in sync" means FortiGate configuration is in sync with the latest running revision history. "db: modified" and "cond: pending" means that changes have been made to the device-level settings and need to be installed.
The example on this slide shows that the FortiGate configuration is in sync with the latest running revision history. However, changes have been made to the device-level settings. That is why the CLI output is showing db:modified and the cond is showing as pending. After you install the changes on FortiGate, it will show db: not modified and cond:OK. db:modified = Config changes made on FMG cond:in sync = Latest revision history in sync with FGT running-config cond:pending = Config changes needed to be installed Reference [Page 160] - https://ebin.pub/fortinet-fortimanager-study-guide-for-fortimanager-72.html
NEW QUESTION # 68
What is the advantage of using FortiManager to manage PortiAnalyzer?
- A. It allows FortiManager to manage all FortiGate devices
- B. It allows FortiManager to store all managed FortiGate device logs
- C. It allows FortiManager to fun reports based on FortiAnalyzer
- D. It allows FortiManager to act as a collector and FortiAnalyzer device
Answer: C
NEW QUESTION # 69
Refer to the exhibit.
An administrator would like to create three ADOMs on FortiManager with different access levels based on departments.
What two conclusions can you draw from the design shown in the exhibit? (Choose two.)
- A. Admin A can access VDOM2 and VDOM3 with the super user profile.
- B. The administrator must configure FortiManager in workspace mode.
- C. The FortiManager policies and objects database can be shared between the Financial and HR ADOMs.
- D. The administrator must set the FortiManager ADOM mode to Advanced.
Answer: C,D
NEW QUESTION # 70
An administrator has enabled Service Access on FortiManager.
What is the purpose of Service Access on the FortiManager interface?
- A. Allows FortiManager to automatically configure a default route
- B. Allows FortiManager to download IPS packages
- C. Allows FortiManager to respond to request for FortiGuard services from FortiGate devices
- D. Allows FortiManager to run real-time debugs on the managed devices
Answer: C
NEW QUESTION # 71
An administrator would like to review, approve, or reject all the firewall policy changes made by the junior administrators.
How should the Workspace mode be configured on FortiManager?
- A. Set to disable and use the policy locking feature
- B. Set to workflow and use the ADOM locking feature
- C. Set to normal and use the policy locking feature
- D. Set to read/write and use the policy locking feature
Answer: B
Explanation:
Reference:https://help.fortinet.com/fmgr/50hlp/52/5-2-0/FMG_520_Online_Help/200_What's-New.03.03.html
NEW QUESTION # 72
An administrator has assigned a global policy package to a new ADOM called ADOM1. What will happen if the administrator tries to create a new policy package in ADOM1?
- A. When creating a new policy package, the administrator can select the option to assign the global policy package to the new policy package
- B. When a new policy package is created, the administrator must assign the global policy package from the global ADOM.
- C. When the new policy package is created, FortiManager automatically assigns the global policy package to the new policy package.
- D. When a new policy package is created, the administrator needs to reapply the global policy package to ADOM1.
Answer: A
NEW QUESTION # 73
Refer to the exhibit
An administrator logs in to the FortiManager GUI and sees the panes shown in the exhibit.
Which two reasons can explain why the FortiAnalyzer feature panes do not appear? (Choose two.)
- A. The admin session requires approval before administrator can see the FortiAnalyzer feature panes.
- B. FortiAnalyzer features are not enabled on FortiManager
- C. The administrator profile does not have full access privileges like the Super_User profile
- D. The administrator workflow is enabled on the ADOM.
Answer: B,C
NEW QUESTION # 74
An administrator is replacing a device on FortiManager by running the following command:
execute device replace sn <devname> <serialnum>.
What device name and serial number must the administrator use?
- A. Device name and serial number of the original device.
- B. Device name and serial number of the replacement device.
- C. Device name of the replacement device and serial number of the original device.
- D. Device name of the original device and serial number of the replacement device.
Answer: D
NEW QUESTION # 75
View the following exhibit:
How will FortiManager try to get updates for antivirus and IPS?
- A. From the default server fdsl.fortinet.com
- B. From public FDNI server with highest index number only
- C. From the configured override server list only
- D. From the list of configured override servers with ability to fall back to public FDN servers
Answer: D
NEW QUESTION # 76
Which of the following statements are true regarding schedule backup of FortiManager? (Choose two.)
- A. Backs up all devices and the FortiGuard database.
- B. Does not back up firmware images saved on FortiManager
- C. Supports FTP, SCP, and SFTP
- D. Can be configured from the CLI and GUI
Answer: B,C
NEW QUESTION # 77
Refer to the exhibit.
Given the configuration shown in the exhibit, which two statements are true? (Choose two.)
- A. It allows the same administrator to lock more than one ADOM at the same time.
- B. It allows two or more administrators to make configuration changes at the same time, in the same ADOM.
- C. It disables concurrent read-write access to an ADOM.
- D. It is used to validate administrator login attempts through external servers.
Answer: A,B
NEW QUESTION # 78
......
Validate your NSE5_FMG-7.2 Exam Preparation with NSE5_FMG-7.2 Practice Test: https://www.practicematerial.com/NSE5_FMG-7.2-exam-materials.html
Free NSE5_FMG-7.2 Questions for Fortinet NSE5_FMG-7.2 Exam [Mar-2025]: https://drive.google.com/open?id=18GxZZhas1pmqIIQak7YCMuG_E2i5wC7n

