Certification Provider: FortinetExam: FCP: Forti Manager 7.2 AdministratorExam Code: NSE5 FMG v7.2Total Question: 72Question per Quiz: 35Updated On: 10 April 2025Note: In order to practice all the Q/A's, you have to practice multiple time. Question's and Answer's will be presented randomly and will help you get hands-on for real exam. 1. Which configuration setting for FortiGate is part of an ADOM-level database on FortiManager? SNMP Security profiles Routing NSX-T Service Template None 2. In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator sent a device registration to FortiManager from a remote FortiGate. Which one of the following statements is true? The FortiManager administrator must add the unregistered device manually to the unregistered device manually to the Training ADOM using the Add Device wizard The FortiGate will be automatically added to the Training ADOM. The FortiGate will be added automatically to the default ADOM named FortiGate. By default, the unregistered FortiGate will appear in the root ADOM. None 3. View the following exhibit. What is the purpose of setting ADOM Mode to Advanced? The setting enables the ADOMs feature on FortiManager The setting disables concurrent ADOM access and adds ADOM locking The setting allows automatic updates to the policy package configuration for a managed device This setting allows you to assign different VDOMs from the same FortiGate to different ADOMs. None 4. How are bulk configuration changes made using FortiManager CLI scripts? (Choose two.) When run on the Device Database, changes are applied directly to the managed FortiGate device. When run on the Remote FortiGate directly, administrators do not have the option to review the changes prior to installation. When run on the All FortiGate in ADOM, changes are automatically installed without the creation of a new revision history. 5. An administrator has configured the command shown in the exhibit on FortiManager. A configuration change has been installed from FortiManager to the managed FortiGate that causes the FGFM tunnel to go down for more than 15 minutes. What is the purpose of this command? It allows FortiGate to reboot and restore a previously working firmware image. It allows FortiGate to reboot and recover the previous configuration from its configuration file. It allows FortiManager to revert and install a previous configuration revision on the managed FortiGate. It allows FortiManager to unset the new configuration through CLI and reboot FortiGate. None 6. Refer to the exhibit. An administrator wants to create a policy on the Staging ADOM in backup mode, and install it on the FortiGate device in the same ADOM. How can the administrator perform this task? The administrator must use the Policy & Objects section to create a policy first. The administrator must disable the FortiManager offline mode first. The administrator must use the FortiManager script. The administrator must change the ADOM mode to Advanced to bring the FortiManager online. None 7. An administrator is replacing a failed device on FortiManager by running the following command: execute device replace sn . Which device name and serial number must the administrator use? The device name and serial number of the new device. The device name and serial number of the failed device. The device name of the failed device and serial number of the new device. The device name of the new device and serial number of the failed device. None 8. An administrator would like to create an SD-WAN using central management in the Training ADOM. To create an SD-WAN using central management, which two steps must be completed? (Choose two) Remove all the interface references such as routes or policies that will be a part of SD-WAN member interfaces Configure and install the SD-WAN firewall policy and SD-WAN static route before installing the SDWAN template settings Enable SD-WAN central management in the Training ADOM Specify a gateway address when you create a default SD-WAN static route 9. Refer to the exhibit. Given the configuration shown in the exhibit, what are two results from this configuration? (Choose two.) The same administrator can lock more than one ADOM at the same time. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out. Unlocking an ADOM will install configuration changes automatically on managed devices. Unlocking an ADOM will submit configuration changes automatically to the approval administrator. 10. Which two settings must be configured for SD-WAN Central Management? (Choose two.) When you configure an SD-WAN, you must specify at least two member interfaces. SD-WAN must be enabled on per-ADOM basis You can create multiple SD-WAN interfaces per VDOM The first step in creating an SD-WAN using FortiManager is to create two SD-WAN firewall policies. 11. What will happen if FortiAnalyzer features are enabled on FortiManager? FortiManager will enable ADOMs to collect logs automatically from non-FortiGate devices. FortiManager will keep all the logs and reports on the FortiManager. FortiManager can be used only as a logging device. FortiManager will install the logging configuration to the managed devices. None 12. Refer to the exhibit. A service provider administrator has assigned a global policy package to a managed customer ADOM named My_ADOM, which has four policy packages. The customer administrator has access only to My_ADOM. How can customer or service provider administrators remove both global header and footer policies from the policy package named Shared_Package? The service provider administrator can unassign both global policies from My_ADOM The service provider administrator can unassign both policies from the global ADOM The customer administrator can unassign both global polices from My_ADOM The customer administrator can unassign both polices by locking My_ADOM None 13. Refer to the exhibit. Which two statements about the output are true? (Choose two.) Configuration changes directly made on FortiGate have been automatically updated to the device-level database. Configuration changes have been installed on FortiGate, which means the FortiGate configuration has been changed. The latest revision history for the managed FortiGate does match the FortiGate running configuration. The latest revision history for the managed FortiGate does not match the device-level database. 14. An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the workflow session. What can prevent an admin account that has Super_User rights over the device from approving a workflow session? Trainer does not have full rights over this ADOM. Trainer must close Student’s workflow session before approving the request. Trainer must first create their own workflow session to approve student session. Trainer is not a part of workflow approval group. None 15. An administrator has enabled Service Access on FortiManager. What is the purpose of Service Access on the FortiManager interface? It allows third-party applications to gain read/write access to FortiManager. It allows FortiManager to determine the connection status of managed devices. It allows FortiManager to respond to requests for FortiGuard services from FortiGate devices. It allows administrative access to FortiManager. None 16. Refer to the exhibit. What can you conclude from the failed installation log shown in the exhibit? Policy ID 2 is installed without a source address. Policy ID 2 is installed without the remote user student. Policy ID 2 is installed in the disabled state. Policy ID 2 will not be installed. None 17. Which two items does an FGFM keepalive message include? (Choose two.) FortiGate IPS version FortiGate configuration checksum FortiGate license information FortiGate uptime 18. Which two statements about the scheduled backup of FortiManager are true? It supports FTP, SCP, and SFTP. It backs up all devices and the FortiGuard database. t can be configured using the CLI and GUI. It does not back up firmware images saved on FortiManager. 19. If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.) FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management. During discovery, the FortiManager NATed IP address is not set by default on FortiGate. FortiGate is discovered by FortiManager through the FortiGate NATed IP address. If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel. 20. What does a policy package status of Never Installed indicate? The policy package was never imported after a device was registered on Forti Manager. The policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager. The policy configuration has been changed on FortiManager and changes have not yet been installed on the managed device. FortiManager is unable to determine the policy package status. None 21. What is the advantage of using FortiManager to manage FortiAnalyzer? It allows FortiManager to store all managed FortiGate device logs. It allows FortiManager to act as a collector and FortiAnalyzer device. It allows FortiManager to manage all FortiGate devices. It allows FortiManager to run reports based on FortiAnalyzer. None 22. Refer to the exhibit. Which statement about the object named ALL is true? FortiManager updated the object ALL using the FortiManager value in its database. FortiManager installed the object ALL with the updated value. FortiManager updated the object ALL using the FortiGate value in its database. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate. None 23. Which two statements about Security Fabric integration with FortiManager are true? (Choose two.) The Fabric View module enables you to view the Security Fabric ratings for Security Fabric devices. The Security Fabric settings are part of the device-level settings. The Security Fabric license, group name, and password are required for the FortiManager Security Fabric integration. The Fabric View module enables you to generate the Security Fabric ratings for Security Fabric devices. 24. An administrator with the Super_User profile is unable to log in to FortiManager because of an authentication failure message. Which troubleshooting step should you take to resolve the issue? Make sure ADOMs are enabled and the administrator has access to the Global ADOM Make sure the administrator IP address is part of the trusted hosts. Make sure FortiManager Access is enabled in the administrator profile Make sure Offline Mode is disabled None 25. An administrator run the reload failure command: diagnose test deploymanager reload config on FortiManager. What does this command do? It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate. It installs the provisioning template configuration on the specified FortiGate. It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database. It installs the latest configuration on the specified FortiGate and update the revision history database. None 26. What are two outcomes of ADOM revisions? (Choose two.) ADOM revisions can save the current size of the whole ADOM ADOM revisions can save the current state of all policy packages and objects for an ADOM ADOM revisions can significantly increase the size of the configuration backups. ADOM revisions can create System Checkpoints for the FortiManager configuration 27. Refer to the exhibit. What will happen if the script is run using the Remote FortiGate Directly (via CLI) option? (Choose two.) FortiGate will auto-update the FortiManager device-level database. You must install these changes using the Install Wizard. FortiManager provides a preview of CLI commands before executing this script on a managed FortiGate. FortiManager will create a new revision history. 28. Which two items are included in the FortiManager backup? (Choose two.) FortiGuard database Firmware images Flash configuration All devices 29. Refer to the exhibit. According to the error message, why is FortiManager failing to add the FortiAnalyzer device? The administrator must use the Add Model Device section and discover the Forti Analyzer device. The administrator must turn off the Use Legacy Device login and add the FortiAnalyzer device to the same network as Forti Manager. The administrator must use the correct user name and password of the FortiAnalyzer device. The administrator must select the Forti Manager administrative access checkbox on the Forti Analyzer management interface. None 30. What is the purpose of the Policy Check feature on FortiManager? To find and delete disabled firewall policies in the policy package To find and merge duplicate policies in the policy package To find and provide recommendation for optimizing policies in a policy package To find and provide recommendation to combine multiple separate policy packages into one common None Time's up