Certification Provider: FortinetExam: FCP: Forti Manager 7.2 AdministratorExam Code: NSE5 FMG v7.2Total Question: 72Question per Quiz: 35Updated On: 10 April 2025Note: In order to practice all the Q/A's, you have to practice multiple time. Question's and Answer's will be presented randomly and will help you get hands-on for real exam. 1. Refer to the exhibit. Given the configuration shown in the exhibit, what are two results from this configuration? (Choose two.) Unlocking an ADOM will submit configuration changes automatically to the approval administrator. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out. Unlocking an ADOM will install configuration changes automatically on managed devices. The same administrator can lock more than one ADOM at the same time. 2. Refer to the exhibit. A junior administrator is troubleshooting a FortiManager connectivity issue that is occurring with managed FortiGate devices. Given the FortiManager device manager settings shown in the exhibit, what can you conclude from the exhibit? The administrator must refresh both devices to restore connectivity. The administrator can reclaim the FGFM tunnel to get both devices online. The administrator had restored the Forti Manager configuration file. Forti Manager lost internet connectivity, therefore, both devices appear to be down. None 3. What will be the result of reverting to a previous revision version in the revision history? It will tag the device settings status as Auto-Update. It will install configuration changes to managed device automatically. It will modify the device-level database. It will generate a new version ID and remove all other revision history versions. None 4. Which configuration setting for FortiGate is part of an ADOM-level database on FortiManager? Routing Security profiles SNMP NSX-T Service Template None 5. Push updates are failing on a FortiGate device that is located behind a NAT device. Which two settings should the administrator check? (Choose two.) That the NAT device IP address and correct ports are configured on FortiManager That the override server IP address is set on FortiManager and the NAT device That the external IP address on the NAT device is set to DHCP and configured with the virtual IP That the virtual IP address and correct ports are set on the NAT device 6. Refer to the exhibit. An administrator is about to add the FortiGate device to FortiManager using the discovery process. FortiManager is operating behind a NAT device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings. What is the expected result? During discovery, FortiManager sets the FortiManager NATed IP address on FortiGate. During discovery, FortiManager sets the NATed device IP address on FortiGate. During discovery, FortiManager uses only the FortiGate serial number to establish the connection. During discovery, FortiManager sets both the FortiManager NATed IP address and NAT device IP address on FortiGate. None 7. Refer to the exhibit. What will happen if the script is run using the Remote FortiGate Directly (via CLI) option? (Choose two.) FortiGate will auto-update the FortiManager device-level database. You must install these changes using the Install Wizard. FortiManager will create a new revision history. FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate. 8. An administrator enabled workspace mode and now wants to delete an address object that is currently referenced in a firewall policy. Which two results can the administrator expect to happen? (Choose two.) FortiManager will disable the status of the address object. FortiManager will not allow the administrator to delete a referenced address object until the ADOM is locked. FortiManager will temporarily change the status of the referenced firewall policy. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy. 9. Refer to the exhibit. Which statement is true about the Forti Manager ADOM policy tab based on the API request? The API command has enabled both central NAT and interface policy on the policy tab. The API command has failed when requesting policy tab permissions information. The API command has requested the policy tab permissions information only. The API command has applied to customer with ID: 200. None 10. Refer to the exhibit. An administrator is importing a new device to FortiManager and has selected the options shown in the exhibit. What will happen if the administrator makes the changes and installs the modified policy package on this managed FortiGate? The unused objects that are not tied to the firewall policies locally on FortiGate will be deleted. The unused objects that are not tied to the firewall policies will be installed on FortiGate. The unused objects that are not tied to the firewall policies will remain as read-only locally on FortiGate. The unused objects that are not tied to the firewall policies in the policy package will be deleted from the FortiManager database. None 11. An administrator runs the Policy Check feature on Forti Manager ADOM. What will be the result? It will find and provide recommendations to combine multiple separate policy packages into one common policy package. It will find and delete disabled firewall policies in the policy package. It will find and merge duplicate policies in the policy package. It will find and provide recommendations for optimizing policies in a policy package. None 12. An administrator has assigned a global policy package to a new ADOM called ADOM1. What will happen if the administrator tries to create a new policy package in ADOM1? When a new policy package is created, the administrator must assign the global policy package from the global ADOM. When creating a new policy package, the administrator can select the option to assign the global policy package to the new policy package. When a new policy package is created, the administrator must import the global policy package to ADOM1. When the new policy package is created, FortiManager automatically assigns the global policy package to the new policy package. None 13. An administrator created a header and footer global policy package and assigned it to an ADOM. What are two outcomes from this action? (Choose two.) You must manually move the header and footer policies after the policy assignment. After you assign the global policy package to an ADOM, the policy package is hidden from the ADOM and cannot be viewed. You can edit or delete all the global objects in the global ADOM. f you assign an additional global policy package to the same ADOM, FortiManager removes previously assigned policies. 14. In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices only. The administrator authorized the FortiGate device on FortiManager using the Fortinet Security Fabric. Given the administrator’s actions, which statement correctly describes the expected result? The authorized FortiGate will appear in the root ADOM. The FortiManager administrator must add the authorized device to the Training ADOM using the Add Device wizard only. The authorized FortiGate will be automatically added to the Training ADOM. The authorized FortiGate can be added to the Training ADOM using FortiGate Fabric Connectors. None 15. Which two items are included in the FortiManager backup? (Choose two.) FortiGuard database Firmware images All devices Flash configuration 16. An administrator has enabled Service Access on FortiManager. What is the purpose of Service Access on the FortiManager interface? It allows third-party applications to gain read/write access to FortiManager. It allows FortiManager to respond to requests for FortiGuard services from FortiGate devices. It allows administrative access to FortiManager. It allows FortiManager to determine the connection status of managed devices. None 17. Refer to the exhibit showing a Download Import Report. Why is it failing to import firewall policy ID 1? Policy ID 1 for this managed FortiGate already exists on FortiManager in the policy package named Remote-FortiGate. The address object used in policy ID 1 already exists in the ADOM database with any as the interface association, and conflicts with the address object interface association locally on FortiGate. Policy ID 1 is configured from the interface any to port6. FortiManager rejects the request to import this policy because the any interface does not exist on FortiManager. Policy ID 1 does not have the ADOM Interface mapping configured on FortiManager. None 18. Refer to the exhibit. A service provider administrator has assigned a global policy package to a managed customer ADOM named My_ADOM, which has four policy packages. The customer administrator has access only to My_ADOM. How can customer or service provider administrators remove both global header and footer policies from the policy package named Shared_Package? The service provider administrator can unassign both global policies from My_ADOM The customer administrator can unassign both global polices from My_ADOM The service provider administrator can unassign both policies from the global ADOM The customer administrator can unassign both polices by locking My_ADOM None 19. Refer to the exhibit. According to the error message, why is FortiManager failing to add the FortiAnalyzer device? The administrator must turn off the Use Legacy Device login and add the FortiAnalyzer device to the same network as Forti Manager. The administrator must use the correct user name and password of the FortiAnalyzer device. The administrator must select the Forti Manager administrative access checkbox on the Forti Analyzer management interface. The administrator must use the Add Model Device section and discover the Forti Analyzer device. None 20. View the following exhibit. Which statement is true regarding this failed installation log? Policy ID 2 is installed without a source address Policy ID 2 is installed without a source device Policy ID 2 will not be installed Policy ID 2 is installed in disabled state None 21. Refer to the exhibit. What can you conclude from the failed installation log shown in the exhibit? Policy ID 2 is installed in the disabled state. Policy ID 2 will not be installed. Policy ID 2 is installed without a source address. Policy ID 2 is installed without the remote user student. None 22. Given the configuration shown in the exhibit, which two statements are true? An administrator can also lock the Local-FortiGate-1 policy package. The FortiManager ADOM is locked by the administrator. The Forti Manager ADOM workspace mode is set to Normal. Forti Manager is in workflow mode. 23. An administrator would like to review, approve or reject all the firewall policy changes made by the junior administrators. How should the workspace mode settings be configured on FortiManager? Set to normal and using the approval group feature Set to workflow and using the ADOM locking feature Set to workspace and using the policy locking feature Set to read/write and using the policy locking feature None 24. Refer to the exhibit. An administrator logs in to the FortiManager GUI and sees the panes shown in the exhibit. Which two reasons can explain why the FortiAnalyzer feature panes do not appear? (Choose two.) The administrator profile does not have full access privileges like the Super_User profile. FortiAnalyzer features are not enabled on FortiManager. The administrator workflow is enabled on the ADOM. The admin session requires approval before administrator can see the FortiAnalyzer feature panes. 25. Which two settings must be configured for SD-WAN Central Management? (Choose two.) SD-WAN must be enabled on per-ADOM basis The first step in creating an SD-WAN using FortiManager is to create two SD-WAN firewall policies. You can create multiple SD-WAN interfaces per VDOM When you configure an SD-WAN, you must specify at least two member interfaces. 26. What is the purpose of the Policy Check feature on FortiManager? To find and provide recommendation to combine multiple separate policy packages into one common To find and delete disabled firewall policies in the policy package To find and provide recommendation for optimizing policies in a policy package To find and merge duplicate policies in the policy package None 27. You are moving managed FortiGate devices from one ADOM to a new ADOM. Which statement correctly describes the expected result? Policy packages will be imported into the new ADOM automatically. Any unused objects from a previous ADOM are moved to the new ADOM automatically. The shared policy package will not be moved to the new ADOM. The shared device settings will be installed automatically. None 28. An administrator enabled workspace mode and now wants to delete an address object that is currently referenced in a firewall policy. Which two results can the administrator expect to happen? (Choose two.) FortiManager will temporarily change the status of the referenced firewall policy. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy. FortiManager will disable the status of the address object. FortiManager will not allow the administrator to delete a referenced address object until the ADOM is locked. 29. An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session. What can prevent an admin account that has Super_User rights over the device from approving a workflow session? Trainer is not a part of workflow approval group. Trainer must first create their own workflow session to approve student session. Trainer must close Student’s workflow session before approving the request. Trainer does not have full rights over this ADOM. None 30. An administrator with the Super_User profile is unable to log in to FortiManager because of an authentication failure message. Which troubleshooting step should you take to resolve the issue? Make sure ADOMs are enabled and the administrator has access to the Global ADOM Make sure Offline Mode is disabled Make sure FortiManager Access is enabled in the administrator profile Make sure the administrator IP address is part of the trusted hosts. None Time's up