Free FCP-FMG-AD-7-4 Fortinet FCP-FMG-AD-7-4 Practice Test Question

Loading demo links...

Showing 4–6 of 7 questions

Question 4 (Topic 1)

Refer to the exhibit which shows the Download Import Report. Why is FortiManager failing to import firewall policy ID 1?

Select an option, then click Submit answer.

  • Policy ID 1 is configured from the interface any to port6. FortiManager rejects the request to import this policy because the any interface does not exist on FortiManager.
  • Policy ID 1 for this managed FortiGate already exists on FortiManager in the policy package named Remote-FortiGate.
  • Policy ID 1 has an address object that already exists in the ADOM database with any as the interface association, and conflicts with the address object interface association locally on FortiGate.
  • Policy ID 1 does not have the ADOM interface mapping configured on FortiManager.
Question 5 (Topic 1)

You are moving managed FortiGate devices from one ADOM to a new ADOM. Which statement correctly describes the expected result?

Select an option, then click Submit answer.

  • The shared device settings will be installed automatically.
  • The shared policy package will not be moved to the new ADOM automatically.
  • Any unused objects from a previous ADOM are moved to the new ADOM automatically.
  • Policy packages will be imported into the new ADOM automatically.
Question 6 (Topic 1)

Refer to the exhibit. In the event that the monitored interface for the primary FortiManager device fails, which action must you perform to return FortiManager high availability (HA) to a working state?

Select an option, then click Submit answer.

  • Manually promote one of the working secondary devices to the primary role, and reboot the old primary device to remove the peer IP address of the failed device.
  • Reboot the current primary device to force a secondary device to become the new primary.
  • The FortiManager HA failover is transparent to administrators and does not require any additional action.
  • Reconfigure the primary device to remove the peer IP address of the failed device from its configuration.