View Full Fortinet FCP_FMG_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 21
Which FortiManager feature allows an administrator to execute a predefined set of CLI commands on managed FortiGate devices?
- Policy Package
- ADOM
- CLI Script
- Device Group
Correct Answer: 3
Explanation
A CLI Script in FortiManager allows administrators to create and execute CLI commands on managed FortiGate devices. This is useful when a configuration task is not conveniently performed through the standard FortiManager graphical interface or when the same command sequence must be applied to multiple devices. Scripts can help automate repetitive administrative operations and maintain consistency across managed systems. Administrators should test scripts carefully because incorrect commands can alter device behavior or cause configuration problems. Appropriate permissions and change-control procedures should also be applied.
Question 22
An administrator needs to create a reusable set of FortiGate configuration settings that can be assigned to multiple devices. Which FortiManager capability is most suitable?
- Device Template
- Event Monitor
- FortiView
- Log Forwarding
Correct Answer: 1
Explanation
A Device Template can provide reusable configuration settings that administrators can apply to multiple managed FortiGate devices. This is useful when several devices require common system or feature configurations. Templates reduce repetitive configuration work and can help maintain consistency across an environment. Administrators should verify that the target devices support the settings contained in the template and account for device-specific values where necessary. Templates are particularly useful in larger deployments because they allow common configurations to be maintained centrally rather than manually recreated on every FortiGate.
Question 23
A FortiManager administrator wants to automate configuration deployment based on a standardized set of device-specific variables. Which capability is useful for this requirement?
- Log View
- Metadata variables
- FortiGuard Web Filtering
- Security Rating
Correct Answer: 2
Explanation
Metadata variables allow FortiManager configurations and templates to use values that can differ between individual managed devices. This is useful when a common configuration must be deployed across several FortiGate devices while certain values, such as IP addresses or interface-specific information, vary by device. Instead of creating completely separate configurations, administrators can maintain a reusable configuration structure and provide appropriate values for each device. This approach improves scalability and consistency while reducing duplicated configuration work in environments containing many FortiGate systems.
Question 24
An administrator wants to review the exact configuration differences between a FortiManager configuration and the configuration currently installed on a FortiGate before deployment. Which action is most appropriate?
- Run a Security Rating
- Open FortiView
- View the installation preview
- Restart FortiManager
Correct Answer: 3
Explanation
The installation preview allows an administrator to review proposed configuration changes before they are installed on a managed FortiGate. This is valuable because it provides an opportunity to identify unintended changes, incorrect objects, or configuration differences before deployment. Reviewing the proposed installation is an important change-management practice, especially when policies or shared objects affect multiple devices. Administrators should verify the target device, inspect the changes, and confirm that the resulting configuration matches the intended design before proceeding with the installation.
Question 25
A company wants to manage FortiGate devices running different FortiOS versions within FortiManager. What should the administrator consider when configuring ADOMs?
- The ADOM must support the relevant FortiOS version
- All FortiGates must use identical hostnames
- Every FortiGate must use the same serial number
- Each device must have a separate FortiManager
Correct Answer: 1
Explanation
ADOM configuration must take supported FortiOS versions into account when managing FortiGate devices through FortiManager. The appropriate ADOM version determines which device configurations and features FortiManager can manage. When devices use different FortiOS versions, administrators should verify compatibility and select an appropriate ADOM configuration rather than assuming every device can be managed identically. Version compatibility is particularly important when deploying policies, objects, and configuration settings. Administrators should also follow supported upgrade and migration procedures when changing FortiOS versions or ADOM configurations.
Question 26
Which FortiManager function is useful when an administrator needs to identify why a policy installation failed on a managed FortiGate?
- FortiGuard Distribution
- Installation history and logs
- Web Filter
- Device firmware cache
Correct Answer: 2
Explanation
Installation history and related logs provide information that can help administrators troubleshoot failed policy installations. They can reveal errors encountered during validation, communication, or configuration deployment. When an installation fails, administrators should review the target device, installation task details, error messages, and configuration dependencies rather than repeatedly attempting the same deployment. Troubleshooting should also include checking device connectivity and synchronization status. Reviewing installation information helps identify whether the problem originates from the policy, device configuration, unsupported settings, or communication between FortiManager and the managed FortiGate.
Question 27
A security team wants FortiManager to automatically install a specific configuration template when a new managed FortiGate is provisioned. Which feature is designed for this type of automation?
- FortiView
- Zero-touch provisioning
- Log View
- Security Rating
Correct Answer: 2
Explanation
Zero-touch provisioning can simplify deployment by allowing newly provisioned Fortinet devices to receive predefined management and configuration settings without extensive manual configuration at the remote location. In centralized environments, this approach can reduce deployment effort and improve consistency. The administrator must establish the required provisioning workflow and ensure that the device can securely connect to the appropriate management infrastructure. Zero-touch deployment is especially useful for organizations with many branch offices where physically configuring every FortiGate before deployment would increase operational effort.
Question 28
An administrator needs to retrieve configuration information from a managed FortiGate into FortiManager after changes were made directly on the device. Which operation helps update the FortiManager database with the device configuration?
- Import Configuration
- Delete ADOM
- Create Policy Package
- Reset Dashboard
Correct Answer: 1
Explanation
Importing configuration can synchronize relevant configuration information from a managed FortiGate into FortiManager after direct device-side changes. This is important when administrators need to reconcile configuration differences between the FortiManager database and the actual FortiGate configuration. Direct changes can create configuration drift if FortiManager is intended to remain the central management platform. Before importing or synchronizing configurations, administrators should understand which version represents the desired state. Proper change control helps prevent accidentally replacing an approved centralized configuration with unintended device-side modifications.
Question 29
A FortiManager administrator wants to maintain a reusable collection of CLI commands for recurring administrative tasks. Which approach is appropriate?
- Create and store CLI scripts
- Create a FortiView dashboard
- Configure a log filter
- Create an ADOM
Correct Answer: 1
Explanation
Stored CLI scripts provide a reusable way to maintain command sequences for recurring administrative operations. Instead of manually entering the same commands repeatedly, an administrator can create a script and execute it against appropriate managed devices. This can improve efficiency and consistency when performing supported configuration or troubleshooting tasks. Scripts should be carefully reviewed before execution because CLI commands can make significant changes to a FortiGate. Administrators should also restrict script-management permissions and maintain appropriate documentation so that automated configuration changes remain controlled and auditable.
Question 30
Which FortiManager capability helps administrators create a standardized configuration for multiple FortiGate devices while allowing certain values to vary per device?
- FortiView
- Device Manager
- Configuration templates with variables
- Log View
Correct Answer: 3
Explanation
Configuration templates combined with variables allow administrators to maintain a common configuration structure while supplying different values for individual FortiGate devices. For example, branch-specific IP addresses or interface values may differ even though the overall configuration is standardized. This approach reduces duplication and improves consistency across deployments. Administrators should define variables carefully and verify the resulting configuration before installation. Template-based management is especially valuable in environments where many devices share similar architecture but require certain device-specific parameters.
Question 31
An organization has multiple FortiManager administrators and wants changes made by one administrator to require approval before being committed. Which feature supports this controlled workflow?
- Workspace workflow
- FortiGuard updates
- Device firmware cache
- FortiView
Correct Answer: 1
Explanation
Workspace workflow capabilities can support controlled administrative processes where configuration changes are prepared and reviewed before being committed or deployed. This is useful in environments where multiple administrators share responsibility for FortiManager and security changes require oversight. A controlled workflow can help reduce accidental modifications and provide a formal review process before changes become active. Organizations should define appropriate administrator roles, approval responsibilities, and change procedures. This approach is particularly valuable for production environments where unauthorized or unreviewed policy changes could affect network security.
Question 32
A FortiManager administrator needs to assign a FortiGate to a different administrative domain. What should the administrator consider first?
- Whether the target ADOM supports the device and its configuration
- Whether FortiAnalyzer has enough disk space
- Whether the FortiGate has an SSL VPN license
- Whether FortiGuard Web Filtering is enabled
Correct Answer: 1
Explanation
Before moving or assigning a FortiGate to another ADOM, the administrator should verify that the target ADOM is appropriate for the device and its FortiOS version and configuration requirements. ADOMs provide management boundaries, and their supported settings can affect how devices and policies are represented in FortiManager. Moving a device can also affect policy packages, objects, and management relationships. Administrators should review the implications before performing the change and ensure that the target ADOM has the appropriate configuration structure for the FortiGate.
Question 33
A company wants to standardize the configuration of interfaces, system settings, and other common FortiGate features across many devices. Which FortiManager capability should be considered?
- Device configuration templates
- Log View
- FortiGuard rating
- Event Monitor
Correct Answer: 1
Explanation
Device configuration templates can help standardize common FortiGate settings across multiple managed devices. Instead of manually configuring similar settings on every FortiGate, administrators can create a reusable configuration structure and apply it to appropriate devices. Templates can improve consistency and reduce configuration errors, particularly in environments with many branches or similar appliances. Administrators should account for device-specific requirements and verify that template settings are supported on each target device. A controlled deployment process should be used to validate the resulting configuration before applying it to production systems.
Question 34
A managed FortiGate was changed locally, and FortiManager now reports a configuration mismatch. What is the most likely reason?
- FortiManager has automatically deleted the FortiGate
- The local change created configuration drift
- FortiGuard disabled the device
- The ADOM was converted into a VDOM
Correct Answer: 2
Explanation
A configuration mismatch commonly occurs when a managed FortiGate is modified directly instead of through the centralized FortiManager workflow. The local modification can cause the device configuration to differ from the configuration stored in FortiManager, creating configuration drift. Administrators should review the differences and determine which configuration represents the intended state before synchronizing or installing changes. Organizations that use centralized management should limit unnecessary direct changes on managed devices. Clear administrative procedures help prevent repeated synchronization conflicts and maintain consistent configurations.
Question 35
A security administrator wants to execute a CLI script only on a selected group of FortiGate devices. What should the administrator do?
- Execute the script against the appropriate target devices
- Convert the devices into a single VDOM
- Disable the ADOM
- Delete the existing policy package
Correct Answer: 4
Explanation
When executing a CLI script, administrators must carefully select the intended target devices. FortiManager supports centralized script execution, but the impact depends on which managed FortiGate devices are selected. Before execution, the administrator should verify that the commands are appropriate for every selected target and that required variables or device-specific settings are available. Testing a script on a limited set of devices can reduce risk. Administrative permissions and change-control procedures should also be applied to prevent unintended execution against production devices.
Question 36
Which FortiManager feature can help an administrator identify whether a policy package contains configuration changes that differ from the installed policy on a FortiGate?
- Configuration status and policy installation comparison
- FortiGuard antivirus
- Security Fabric topology
- FortiView applications
Correct Answer: 1
Explanation
FortiManager provides configuration and installation information that can help administrators identify differences between centrally managed policies and the configuration installed on a FortiGate. Reviewing this information before deployment can reveal pending changes and help administrators determine whether the device is synchronized with the intended policy package. This is especially important after administrators modify policies or objects in FortiManager. Comparing the expected and installed states helps reduce configuration drift and gives administrators an opportunity to correct mistakes before changes are deployed to production traffic.
Question 37
A FortiManager administrator wants to use an external system to automate management operations through a programmatic interface. Which capability should be used?
- FortiManager API
- FortiView
- FortiGuard Web Filter
- Device firmware cache
Correct Answer: 1
Explanation
The FortiManager API provides a programmatic interface that external systems can use to automate supported management operations. APIs can be useful for integrating FortiManager with orchestration platforms, custom automation systems, and operational workflows. Administrators should authenticate API requests appropriately and restrict access to the permissions required by the integration. API responses and errors should also be handled correctly by automation scripts. When implementing API-based management, security teams should protect credentials, use secure communication, and follow least-privilege principles for API users.
Question 38
An automation application sends a request to FortiManager and receives an HTTP 401 response. What does this response generally indicate?
- The policy package is empty
- Authentication is required or failed
- The ADOM does not exist
- The FortiGate is offline
Correct Answer: 2
Explanation
An HTTP 401 response generally indicates that authentication is required or that the supplied authentication information was not accepted. When using the FortiManager API, administrators should verify that the authentication method, credentials, session information, and request structure are correct. The response does not specifically indicate that a policy package is empty or that a FortiGate is offline. API troubleshooting should begin by confirming authentication and authorization requirements before investigating application-specific parameters or FortiManager configuration objects.
Question 39
A company wants to use FortiManager to manage FortiAnalyzer functionality in an integrated environment. Which statement best describes the purpose of this integration?
- It turns FortiManager into a FortiGate firewall
- It allows centralized management and integration of supported FortiAnalyzer functions
- It disables FortiAnalyzer logging
- It replaces all FortiAnalyzer storage
Correct Answer: 2
Explanation
FortiManager can integrate with FortiAnalyzer to support centralized administration and related management functions in environments using both products. This integration can help administrators manage Fortinet infrastructure more efficiently while maintaining the distinct roles of the two platforms. FortiAnalyzer remains focused on logging, analysis, and reporting capabilities, while FortiManager primarily provides centralized device and configuration management. Administrators should understand the supported integration features and permissions when designing the environment so that management responsibilities remain clear and security controls are properly configured.
Question 40
A FortiManager administrator wants to determine which devices are currently registered and managed within an ADOM. Which area should be checked first?
- FortiGuard Center
- Policy package history
- Device Manager
- FortiView
Correct Answer: 3
Explanation
Device Manager provides the primary interface for viewing and administering devices managed by FortiManager. Within the appropriate ADOM, administrators can use Device Manager to review registered FortiGate devices and their management information. This makes it the logical starting point when verifying whether a device is present, checking its status, or reviewing management relationships. Other areas such as policy packages focus on configuration rather than providing the primary device inventory. Accurate device organization is important for reliable centralized policy deployment and administration.