Free 2021 Fortinet NSE 5 NSE5_FMG-6.2 dumps are available by Lead2Passed [Q19-Q39]

Share

Free 2021 Fortinet NSE 5 NSE5_FMG-6.2 dumps are available on Google Drive shared by Lead2Passed

Welcome to download the newest Lead2Passed NSE5_FMG-6.2 PDF dumps: https://www.lead2passed.com/Fortinet/NSE5_FMG-6.2-practice-exam-dumps.html ( 85  Q&As)

NEW QUESTION 19
Which of the following items does an FGFM keepalive message include? (Choose two.)

  • A. FortiGate IPS version
  • B. FortiGate license information
  • C. FortiGate uptime
  • D. FortiGate configuration checksum

Answer: B,D

Explanation:
FGFM Keepalive Messages configured on FortiManager. Only FortiGate sends a keepalive message to FortiManager, regardless of which device established the FGFM tunnel. FortiGate also sends a configuration checksum to confirm synchronization as a part of keepalive.

 

NEW QUESTION 20
An administrator, Trainer, who is assigned the Super_User profile, is trying to approve a workflow session that was submitted by another administrator, Student. However, Trainer is unable to approve the approving a workflow session?

  • A. Trainer must close Student's workflow session before approving the request
  • B. Trainer is not a part of workflow approval group
  • C. Student, who submitted the workflow session, must first self-approve the request
  • D. Trainer does not have full rights over this ADOM

Answer: B

 

NEW QUESTION 21
Refer to the exhibit. An administrator has created a firewall address object which is used in multiple policy packages for multiple FortiGate devices in an ADOM.

When the installation operation is performed, which IP/Netmask will be installed on managed devices for this firewall address object?

  • A. 10.200.1.0/24 on Remote-FortiGate
  • B. If no dynamic mapping is defined for other FortiGate devices, the object will not be installed
  • C. The FortiManager administrator can choose the value for the firewall address object in the Install Wizard for Remote-FortiGate
  • D. 192.168.0.1/24 on Remote-FortiGate

Answer: A

 

NEW QUESTION 22
What is the purpose of ADOM revisions?

  • A. To create System Checkpoints for the FortiManager configuration.
  • B. To save the current state of all policy packages and objects for an ADOM.
  • C. To revert individual policy packages and device-level settings for a managed FortiGate by reverting to a specific ADOM revision
  • D. To save the current state of the whole ADOM.

Answer: B

 

NEW QUESTION 23
Which two items are included in the FortiManager backup? (Choose two.)

  • A. All devices
  • B. FortiGuard database
  • C. Global database
  • D. Logs

Answer: A,C

Explanation:
Reference:
https://kb.fortinet.com/kb/viewContent.do?externalId=FD34549

 

NEW QUESTION 24
As a result of enabling FortiAnalyzer features on FortiManager, which of the following statements is true?

  • A. FortiManager will enable ADOMs automatically to collect logs from non-FortiGate devices
  • B. FortiManager will send the logging configuration to the managed devices so the managed devices will start sending logs to FortiManager
  • C. FortiManager can be used only as a logging device.
  • D. FortiManager will reboot

Answer: D

 

NEW QUESTION 25
An administrator is replacing a device on FortiManager by running the following command:
execute device replace sn <devname> <serialnum>.
What device name and serial number must the administrator use?

  • A. Device name of the original device and serial number of the replacement device.
  • B. Device name and serial number of the replacement device.
  • C. Device name and serial number of the original device.
  • D. Device name of the replacement device and serial number of the original device.

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 26
What does a policy package status of Modified indicate?

  • A. Policy configuration has been changed on a managed device and changes have not yet been imported into FortiManager
  • B. The policy package was never imported after a device was registered on FortiManager
  • C. Policy package configuration has been changed on FortiManager and changes have not yet been installed on the managed device.
  • D. FortiManager is unable to determine the policy package status

Answer: C

Explanation:
http://help.fortinet.com/fmgr/50hlp/56/5-6-1/FortiManager_Admin_Guide/1200_Policy%20and%20Objects/0800_Managing%20policy%20packages/2200_Policy%
20Package%20Installation%20targets.htm

 

NEW QUESTION 27
View the following exhibit.

Which one of the following statements is true regarding the object named ALL?

  • A. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate.
  • B. FortiManager updated the object ALL using FortiGate's value in its database
  • C. FortiManager installed the object ALL with the updated value.
  • D. FortiManager updated the object ALL using FortiManager's value in its database

Answer: B

Explanation:
If a conflict is detected, FortiManager updates the object associated with the selected device. When you choose the FortiGate device value and import the address object ALL, an entry named update previous object is added to the import report.

 

NEW QUESTION 28
Refer to the following exhibit:

Which of the following statements are true based on this configuration? (Choose two.)

  • A. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out
  • B. The same administrator can lock more than one ADOM at the same time
  • C. Unlocking an ADOM will install configuration automatically on managed devices
  • D. Unlocking an ADOM will submit configuration changes automatically to the approval administrator

Answer: A,B

Explanation:
To enable ADOM locking and disable concurrent ADOM access:
config system global
set workspace-mode normal
end
Reference: http://help.fortinet.com/fmgr/cli/5-6-2/Document/0800_ADOMs/200_Configuring+.htm

 

NEW QUESTION 29
When installation is performed from the FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?

  • A. FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.
  • B. FortiManager will revert and install a previous configuration revision on the managed FortiGate.
  • C. FortiGate will reject the CLI commands that will cause the tunnel to go down.
  • D. After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.

Answer: D

Explanation:
The point of this question is "recovery logic". The only real issue of concern is whether the FGFM tunnel goes down because of the config pushed from FM to FG.
If the tunnel goes down because of this pushed change, FM cannot do anything about it....because the tunnel is now down.
The only way to have recovery logic when change was pushed from FM to FG, is to provide FG with a mechanism to determine if the changes it received caused the tunnel to go down. Therefore, the answer has to involve what the FG will do. FM's role is simply to provide FG with both SET operations for the change and UNSET options to roll back. Roll back occurs after 15min. FG will test tunnel condition and if it is down it will issue the UNSET cmd on those changes that it received. If this still does not resolve the tunnel down issue, the FG will reboot. Changes at this point are held in running (volitle) memory and will be lost (and therefore reverted) when FG reboots.

 

NEW QUESTION 30
Refer to the exhibit.

Which statement about the object named ALL is true?

  • A. FortiManager created the object ALL as a unique entity in its database, which can be only used by this managed FortiGate.
  • B. FortiManager updated the object ALL using the FortiManager value in its database.
  • C. FortiManager installed the object ALL with the updated value.
  • D. FortiManager updated the object ALL using the FortiGate value in its database.

Answer: D

 

NEW QUESTION 31
What does a policy package status of Conflict indicate?

  • A. The policy package reports inconsistencies and conflicts during a Policy Consistency Check.
  • B. The policy configuration has never been imported after a device was registered on FortiManager.
  • C. The policy package does not have a FortiGate as the installation target.
  • D. The policy package configuration has been changed on both FortiManager and the managed device independently.

Answer: A

 

NEW QUESTION 32
What configuration setting for FortiGate is part of a device-level database on FortiManager?

  • A. Security profiles
  • B. VIP and IP Pools
  • C. Firewall policies
  • D. Routing

Answer: D

Explanation:
The device-level database includes configuration details related to device-level settings, such as interfaces, DNS, routing, and more.
The ADOM-level database includes configuration details related to firewall policies, objects, and security profiles.

 

NEW QUESTION 33
Refer to the following exhibit:

Which of the following statements are true based on this configuration? (Choose two.)

  • A. Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out
  • B. The same administrator can lock more than one ADOM at the same time
  • C. Unlocking an ADOM will install configuration automatically on managed devices
  • D. Unlocking an ADOM will submit configuration changes automatically to the approval administrator

Answer: A,B

 

NEW QUESTION 34
An administrator has added all the devices in a Security Fabric group to FortiManager. How does the administrator identify the root FortiGate?

  • A. By an Asterisk (*) at the end of the device name
  • B. By a Question: mark(?) at the end of the device name
  • C. By a dollar symbol ($) at the end of the device name
  • D. By an at symbol (@) at the end of the device name

Answer: A

 

NEW QUESTION 35
Which two statements are correct regarding synchronization between primary and secondary devices in a FortiManager HA duster? (Choose two)

  • A. Local logs and log configuration settings are synchronized in the HA cluster.
  • B. FortiGuard databases are downloaded separately by each cluster device.
  • C. FortiGuard databases are downloaded by the primary FortManager device and then synchronized with all secondary devices.
  • D. All device configurations including global databases are synchrorized in the HA cluster,

Answer: B,D

 

NEW QUESTION 36
The service access settings for a FortiManager network interface relate to which product feature?

  • A. FortiView
  • B. Policy & Objects
  • C. FortiGuard
  • D. Device Manger

Answer: C

 

NEW QUESTION 37
View the following exhibit.

An administrator is importing a new device to FortiManager and has selected the shown options. What will happen if the administrator makes the changes and installs the modified policy package on this managed FortiGate?

  • A. The unused objects that are not tied to the firewall policies in policy package will be deleted from the FortiManager database
  • B. The unused objects that are not tied to the firewall policies will be installed on FortiGate
  • C. The unused objects that are not tied to the firewall policies will remain as read-only locally on FortiGate
  • D. The unused objects that are not tied to the firewall policies locally on FortiGate will be deleted

Answer: D

 

NEW QUESTION 38
Refer to the exhibit. Review the Download Import Report.

Why is it failing to import firewall policy ID 2?

  • A. Policy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.
  • B. The address object used in policy ID 2 already exists in the ADOM database with any as the interface association, and conflicts with the address object interface association locally on FortiGate.
  • C. Policy ID 2 does not have ADOM Interface mapping configured on FortiManager.
  • D. Policy ID 2 is configured from the interface any to port6. FortiManager rejects to import this policy because the any interface does not exist on FortiManager.

Answer: B

 

NEW QUESTION 39
......

Tested Material Used To NSE5_FMG-6.2: https://www.lead2passed.com/Fortinet/NSE5_FMG-6.2-practice-exam-dumps.html