View Full Fortinet FCP_FMG_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 81
Which FortiManager feature allows administrators to apply a policy or object consistently across multiple ADOMs?
- Device Manager
- Revision History
- Global Database ADOM
- FortiGuard Cache
Correct Answer: 3
Explanation
The Global Database ADOM provides a centralized location for shared policies and objects that can be used across multiple ADOMs. This is useful in environments where common security requirements must be maintained consistently across different administrative domains. Instead of recreating identical objects or policies separately, administrators can maintain shared configurations in the global database and assign applicable global policies to ADOMs. This approach can reduce duplication and simplify centralized policy administration. Administrators should carefully determine which configurations should remain global and which should remain specific to individual ADOMs.
Question 82
A company needs to enforce a common security rule before the local policies of several ADOMs are processed. Which global policy type is most relevant?
- Header policy
- Device template
- Local policy
- Dynamic object
Correct Answer: 1
Explanation
A header policy in the global policy structure can be used when a common rule needs to be evaluated before policies specific to individual ADOMs. This is useful for centrally enforcing organization-wide requirements that should apply consistently across multiple environments. Global policies can reduce the need to duplicate common rules in every individual policy package. Administrators should carefully design policy order because firewall policies are evaluated according to their sequence. A centralized policy should be tested and reviewed before deployment to ensure that it does not unintentionally affect traffic that should be handled by local policies.
Question 83
An administrator wants to assign a global policy package to specific ADOMs. Which FortiManager capability supports this requirement?
- Device replacement
- Global policy package assignment
- Firmware cache
- Configuration retrieval
Correct Answer: 2
Explanation
Global policy package assignment allows administrators to determine which ADOMs receive policies maintained through the global database. This provides centralized control while still allowing individual ADOMs to maintain their own local configurations. The assignment should be planned carefully because changes to a global policy can affect multiple environments. Administrators should verify policy order, target ADOMs, and expected traffic behavior before installation. Global policy assignment is particularly useful for organizations that need common security controls across multiple customers, regions, or administrative domains while retaining separate local policies.
Question 84
Which statement best describes the purpose of a Global Database ADOM in FortiManager?
- It stores only device firmware images
- It replaces all individual ADOMs
- It provides a shared location for common policies and objects
- It stores only FortiManager administrator accounts
Correct Answer: 3
Explanation
The Global Database ADOM provides a shared management area for common policies and objects that can be referenced by multiple ADOMs. It does not replace individual ADOMs because local policy and device management still occur within their respective administrative domains. The global database is intended to reduce duplication and provide centralized control over configurations that should be consistent across environments. Administrators can use global policies for organization-wide requirements while maintaining local policies where necessary. Careful planning is important because changes to shared configurations can have a broad operational impact.
Question 85
A network administrator wants to see the topology and security relationships of devices participating in a Fortinet Security Fabric. Which FortiManager capability should be reviewed?
- Script Scheduler
- Revision History
- Fabric View
- Policy Package Clone
Correct Answer: 3
Explanation
Fabric View provides visibility into the Fortinet Security Fabric topology and relationships between participating devices. This can help administrators understand how FortiGate and other supported Fortinet components are connected within the security architecture. Visualizing the fabric can make it easier to identify device relationships and investigate certain deployment or connectivity issues. The view complements other FortiManager management functions rather than replacing device or policy management. Administrators should use topology information together with device status, logs, and configuration details when investigating problems across a Security Fabric environment.
Question 86
A security team wants to review the overall security posture of a Fortinet Security Fabric from FortiManager. Which capability can provide this type of information?
- Security Rating
- Device Group
- CLI Script
- Installation Preview
Correct Answer: 1
Explanation
Security Rating provides an assessment of security-related configuration and posture within supported Fortinet environments. It can help administrators identify areas that may require attention and provide visibility into security recommendations. Security Rating should be treated as an assessment and improvement aid rather than a replacement for detailed configuration review. Administrators should investigate the underlying findings and determine whether recommended changes fit their organization’s requirements. When used with Fabric View and device-management information, security assessment capabilities can help teams obtain a broader understanding of their Security Fabric environment.
Question 87
A FortiManager administrator needs to make a common address object available to multiple policy packages through centralized management. Which approach is appropriate?
- Create the object independently on every FortiGate
- Use a shared object within the appropriate ADOM scope
- Disable object validation
- Store the object in installation history
Correct Answer: 2
Explanation
Shared objects can be used when the same address or other policy object is required by multiple policies within the applicable management scope. Centralizing commonly used objects reduces duplication and helps maintain consistency. When an object is changed, administrators should consider every policy and device that depends on it because the change may have a wider effect than a device-specific modification. Proper object naming and organization are also important in large environments. Administrators should review object usage before modifying shared objects to avoid unintended changes to production firewall policies.
Question 88
A FortiManager administrator discovers that a shared object is referenced by several policies. Before deleting it, what should the administrator check?
- The appliance serial number only
- The FortiManager hostname
- Object usage and policy references
- The firmware cache
Correct Answer: 3
Explanation
Before deleting an object, administrators should check where the object is being used. An address, service, schedule, or other object may be referenced by multiple policies, and removing it can cause validation or installation problems. FortiManager provides object-usage information that can help administrators determine whether an object is safe to remove. Reviewing dependencies before making changes is especially important in shared policy environments. Administrators should also consider whether the object is used by templates or other configurations. Dependency checking helps prevent unexpected policy failures and unnecessary troubleshooting after deployment.
Question 89
A FortiManager administrator wants to identify objects that are not referenced by any policy. Which feature is most useful?
- Used Objects view
- Unused Objects review
- Installation History
- Security Rating
Correct Answer: 2
Explanation
Unused Objects review helps administrators identify objects that are not currently referenced by applicable policies or configurations. Removing unnecessary objects can make policy databases easier to maintain and reduce administrative clutter. However, administrators should confirm that an apparently unused object is not required by another configuration, template, or future deployment before deleting it. Object cleanup should be performed carefully in production environments. Maintaining a well-organized object database makes it easier to locate the correct objects during policy creation and reduces confusion caused by large numbers of obsolete or duplicate entries.
Question 90
Why should duplicate policy objects be reviewed in a large FortiManager environment?
- They can create unnecessary administrative complexity
- They automatically increase FortiManager memory
- They disable ADOM functionality
- They prevent all FortiGate devices from connecting
Correct Answer: 1
Explanation
Duplicate objects can make centralized policy administration more difficult because administrators may have multiple objects representing the same or similar resource. This can cause confusion when selecting objects for policies and may make future changes harder to manage. Reviewing duplicates allows teams to consolidate objects where appropriate and establish consistent naming conventions. Administrators should verify object references before removing duplicates because different objects may have subtle differences. Careful object management improves policy clarity and reduces the chance that administrators will select an incorrect object when creating or modifying firewall policies.
Question 91
A FortiManager administrator needs to map an interface name used in a policy package to the corresponding interface on different FortiGate models. Which feature is designed for this purpose?
- Revision History
- Interface Mapping
- Global Database
- Security Rating
Correct Answer: 2
Explanation
Interface Mapping allows FortiManager policy configurations to account for differences in interface names across managed FortiGate devices. This is useful when multiple models or deployments use different physical or logical interface names while following a common policy structure. Instead of creating completely separate policies for every device variation, administrators can map the policy interface to the appropriate device interface. Correct mappings should be verified before installation because an incorrect interface association can affect traffic handling. Interface mapping is particularly useful in standardized multi-device policy deployments.
Question 92
A company uses the same policy package for multiple FortiGate devices but each device has different interface names. What should the administrator configure?
- Interface mapping
- Firmware cache
- Device replacement
- Administrative profiles
Correct Answer: 1
Explanation
Interface mapping allows a common policy package to accommodate differences in interface names between FortiGate devices. This makes centralized policy management more practical when devices have different hardware models or interface naming conventions. The administrator can associate the logical interface used by the policy with the correct physical or logical interface on each target device. This reduces the need to maintain separate policy packages solely because of interface-name differences. Administrators should validate mappings carefully because incorrect mappings can result in policies being applied to unintended interfaces or failing during installation.
Question 93
During policy installation, FortiManager reports that an object referenced by a policy is unavailable on the target configuration. What should the administrator review first?
- Object dependencies and policy references
- The administrator’s browser cache
- FortiManager’s hostname
- The Security Fabric topology only
Correct Answer: 1
Explanation
Object dependencies and policy references should be reviewed when an installation fails because a required object is unavailable. A policy may reference an address, service, interface, schedule, or another object that is missing, incorrectly scoped, or incompatible with the target device. FortiManager administrators should inspect the affected policy and verify that all referenced objects exist and are correctly associated with the target. Installation validation can help identify these issues before changes are committed. Resolving the underlying dependency is preferable to repeatedly attempting the same failed installation.
Question 94
A FortiManager administrator wants to determine whether a policy package contains objects that are not required by any policy. What is the main advantage of performing this review?
- It automatically upgrades FortiOS
- It helps identify unnecessary configuration objects
- It disables unused firewall policies
- It changes the ADOM operation mode
Correct Answer: 2
Explanation
Reviewing unused objects helps administrators identify configuration elements that are no longer required by active policies. Large environments can accumulate obsolete addresses, services, schedules, and other objects over time. Removing unnecessary objects can make the policy database easier to understand and maintain. However, administrators should verify references carefully before deletion because an object may be required by a configuration outside the immediately reviewed policy set. Object cleanup should follow change-management procedures, particularly in production environments. A clean object database makes future policy administration and troubleshooting more efficient.
Question 95
Which FortiManager capability helps an administrator determine the changes that would be made before installing a policy package?
- Installation preview
- Device replacement
- FortiGuard query server
- Security Fabric rating
Correct Answer: 1
Explanation
Installation preview allows administrators to review proposed configuration changes before they are installed on target FortiGate devices. This provides an opportunity to identify unexpected policy modifications, object changes, or other differences before affecting production systems. Reviewing the preview is an important part of controlled deployment because centralized management can distribute changes to multiple devices. Administrators should compare the proposed changes with the approved change request and verify the intended targets. If unexpected changes appear, the installation should be investigated before proceeding.
Question 96
A company wants to reinstall the same approved policy package on a managed FortiGate without creating an entirely new policy package. Which operation is appropriate?
- Reinstallation
- ADOM deletion
- Device discovery
- Object duplication
Correct Answer: 1
Explanation
Reinstallation allows an existing policy package to be deployed again to its intended target without requiring administrators to create a new package. This can be useful when configuration synchronization needs to be restored or when an approved configuration needs to be reapplied. Administrators should still verify the target device and review the expected changes before proceeding. Reinstallation should not be used as a substitute for troubleshooting an underlying configuration problem. If the package contains incorrect policies or objects, reinstalling it may reproduce the same problem on the target FortiGate.
Question 97
A FortiManager administrator notices that a policy package has configuration changes that have not yet been deployed to a target FortiGate. Which state best describes this situation?
- Fully synchronized
- Pending installation
- Device replacement
- Factory default
Correct Answer: 2
Explanation
A policy package with approved or saved changes that have not yet been deployed to the target FortiGate can be considered pending installation. The centralized configuration and the actual device state may therefore differ until the installation process completes successfully. Administrators should review pending changes and confirm the intended target before installation. After deployment, the administrator can verify the installation result and device synchronization status. Tracking pending changes is important in centralized management because administrators need to know which configurations exist in FortiManager but have not yet reached production devices.
Question 98
Which FortiManager function is most directly associated with determining whether managed devices are synchronized with their centralized configurations?
- Device and configuration status
- FortiGuard firmware cache
- Global policy header
- Security Rating
Correct Answer: 1
Explanation
Device and configuration status information helps administrators determine whether managed FortiGate devices are synchronized with the configurations maintained by FortiManager. A mismatch can indicate that changes were made locally, that an installation is pending, or that a previous deployment did not complete successfully. Administrators should investigate the reason for a mismatch before overwriting either configuration state. Reviewing configuration differences and installation history can provide additional context. Maintaining synchronization is important because centralized management is most effective when the FortiManager database accurately represents the intended device configuration.
Question 99
A FortiManager administrator needs to verify that a policy installation completed successfully on the intended FortiGate. Which information should be checked after deployment?
- Installation result and device synchronization status
- Only the FortiManager serial number
- Only the administrator profile
- Only the ADOM name
Correct Answer: 1
Explanation
After deployment, administrators should review the installation result and device synchronization status to confirm that the intended FortiGate received the configuration successfully. A successful initiation of an installation process does not by itself guarantee that every configuration change was applied correctly. Installation logs and status information can reveal errors or incomplete operations. Administrators should also verify critical policy behavior when appropriate. Post-installation validation is an important step in controlled configuration management because it confirms that the centralized configuration has reached the target device as intended.
Question 100
An administrator is preparing to make a major policy change affecting several production FortiGate devices. Which sequence provides the most controlled approach?
- Install immediately and investigate errors later
- Modify each FortiGate independently without review
- Review the configuration, validate the target devices, preview changes, and then install
- Delete the existing policy package before creating the new one
Correct Answer: 3
Explanation
A controlled deployment should include configuration review, target verification, validation, and installation preview before changes are committed to production devices. This sequence gives administrators opportunities to identify incorrect targets, missing objects, unexpected policy changes, and other issues before deployment. After the installation, administrators should review the result and synchronization status. This process reduces the likelihood of accidental configuration changes across multiple production FortiGates. FortiManager’s centralized capabilities are most effective when combined with structured change management, appropriate approvals, and post-installation verification.