Fortinet FCP_FMG_AD-7.6 Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Fortinet FCP_FMG_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 121

A FortiManager administrator needs to retrieve the latest configuration from a managed FortiGate after changes were made directly on the device. Which operation is most appropriate?

  1. Configuration retrieval
  2. Firmware caching
  3. Policy cloning
  4. ADOM deletion

Correct Answer: 1

Explanation

Configuration retrieval allows FortiManager to obtain the current configuration from a managed FortiGate. This can be useful when local changes have been made directly on the device and the administrator needs to bring the current device configuration into the centralized management process. Before retrieving a configuration, administrators should understand the impact on the existing FortiManager database and follow organizational change procedures. The retrieved configuration should be reviewed for unexpected modifications, especially when direct device administration is normally restricted. Careful retrieval helps prevent legitimate local changes from being lost.

Question 122

A FortiManager administrator discovers that a FortiGate was changed locally and now differs from the configuration stored in FortiManager. What should be done before overwriting the FortiGate configuration?

  1. Disable FGFM
  2. Compare the configurations
  3. Delete the policy package
  4. Restart FortiManager

Correct Answer: 2

Explanation

The configurations should be compared before overwriting the FortiGate. Local changes may contain legitimate modifications that have not yet been incorporated into the centralized configuration. Comparing the FortiGate configuration with the FortiManager database allows administrators to identify differences and decide which changes should be retained. Overwriting the device without reviewing those differences could remove required settings or introduce unexpected behavior. Administrators should document the decision and use the appropriate retrieval, reconciliation, or installation process to restore a consistent configuration state.

Question 123

Which condition can cause a FortiManager administrator to encounter configuration drift between FortiManager and a managed FortiGate?

  1. Direct configuration changes on the FortiGate
  2. Viewing the Device Manager
  3. Reviewing installation history
  4. Creating a read-only administrator

Correct Answer: 1

Explanation

Direct configuration changes on a managed FortiGate can create configuration drift because those changes may not be reflected in the configuration database maintained by FortiManager. When this happens, the device state and centralized state can become different. Administrators should identify the source of the differences and determine which configuration should be authoritative before installing or retrieving changes. Organizations can reduce configuration drift by controlling direct device access and encouraging administrators to make changes through FortiManager. Regular configuration comparisons can also help identify discrepancies early.

Question 124

A FortiManager administrator wants to identify whether a managed device has a different configuration from the revision currently stored in the ADOM. Which action is most useful?

  1. Configuration comparison
  2. FortiGuard firmware caching
  3. Policy package cloning
  4. Security Rating calculation

Correct Answer: 1

Explanation

Configuration comparison allows administrators to examine differences between configuration states and determine whether the managed device matches the configuration represented within the ADOM. This is useful when investigating configuration drift, failed installations, or unexpected local changes. The comparison can help identify which settings differ before an administrator decides whether to retrieve, modify, or install a configuration. Reviewing differences first reduces the chance of overwriting valid changes. Administrators should use comparison information together with revision history and installation records when investigating complex configuration synchronization problems.

Question 125

A FortiManager administrator is investigating a failed configuration installation. Which information can help identify the exact stage or operation where the installation failed?

  1. Installation logs
  2. Device group names
  3. Administrator password policy
  4. FortiGuard cache contents

Correct Answer: 1

Explanation

Installation logs provide detailed information about deployment operations and can help identify where an installation failed. Administrators can use the reported errors to determine whether the problem involves connectivity, object configuration, policy validation, command execution, or another stage of deployment. Reviewing logs is more useful than repeatedly attempting the same installation without identifying the underlying cause. After finding the error, the administrator should correct the relevant configuration or connectivity problem and then perform an appropriate validation before trying the installation again.

Question 126

A FortiGate configuration import fails during the process of bringing the device under centralized FortiManager management. Which area should be investigated first?

  1. Device connectivity and management communication
  2. Unused policy objects
  3. Security Rating
  4. Firmware cache

Correct Answer: 1

Explanation

Device connectivity and management communication should be investigated when a FortiGate configuration import fails. FortiManager must be able to communicate with the device through the appropriate management process before configuration information can be exchanged reliably. Administrators should verify network reachability, FGFM status, addressing, authentication, and relevant management settings. If connectivity is functioning correctly, the administrator can then investigate configuration compatibility or import-specific errors. Starting with communication helps separate basic connectivity problems from database or configuration issues that may occur later in the import process.

Question 127

A FortiManager administrator receives an error indicating that a device configuration could not be copied during an import or installation operation. What should be reviewed?

  1. Connectivity and relevant process or transfer errors
  2. Policy package naming convention only
  3. Security Rating score
  4. Administrator profile description

Correct Answer: 1

Explanation

A configuration copy failure can be associated with communication problems or errors during the configuration transfer process. Administrators should review connectivity between FortiManager and the affected FortiGate and examine relevant logs or process information for more specific error details. The administrator should avoid repeatedly retrying the operation without identifying the cause because repeated failures can complicate troubleshooting. Once the communication or transfer issue is corrected, the operation can be attempted again. Reviewing the complete error information is important because a copy failure may have different causes depending on the stage of the management process.

Question 128

A FortiManager administrator suspects that an import operation has left the device database and ADOM database in different states. Which approach is appropriate?

  1. Compare the relevant database and configuration information
  2. Delete the entire ADOM immediately
  3. Disable all FortiManager administrators
  4. Clear the FortiGuard cache

Correct Answer: 1

Explanation

When an import operation may have produced inconsistent database information, administrators should compare the relevant device and ADOM configuration states before taking destructive action. FortiManager maintains management information associated with devices and ADOMs, and an import failure can leave unexpected differences that require investigation. Comparing the states can help identify which information is current and where the inconsistency exists. Administrators should use documented recovery procedures and avoid deleting an ADOM as an initial troubleshooting step. Preserving existing information makes it easier to diagnose and correct the underlying problem.

Question 129

A FortiManager administrator needs to troubleshoot an ADOM-level configuration problem without changing the configuration on the physical FortiGate. Which information is especially relevant?

  1. ADOM database information
  2. FortiGate hardware temperature only
  3. FortiGuard firmware cache
  4. Browser history

Correct Answer: 1

Explanation

ADOM database information is relevant when troubleshooting problems associated with the centralized configuration maintained for devices within an ADOM. The ADOM database contains management information and configuration relationships that FortiManager uses to organize and control devices and policies. Comparing ADOM information with device-level configuration can help identify whether a problem originates in centralized management or on the physical FortiGate. Administrators should avoid making unnecessary changes during troubleshooting. Reviewing database status, configuration differences, and relevant logs can provide a clearer picture of the source of the problem.

Question 130

Which situation is most likely to require comparing the device database with the ADOM database?

  1. The device configuration and centralized configuration appear inconsistent
  2. A user wants to rename a browser bookmark
  3. A firmware image is being downloaded
  4. An administrator changes a trusted-host address

Correct Answer: 1

Explanation

Comparing the device database with the ADOM database is useful when the configuration represented at the device level appears inconsistent with the configuration maintained within the ADOM. Such differences may result from failed imports, local device changes, incomplete installations, or database-related problems. Comparing the relevant states helps administrators identify where the discrepancy exists before selecting a recovery action. This is particularly important in centralized management because blindly replacing one state with another could remove legitimate configuration changes. Troubleshooting should preserve existing information until the correct source of configuration is established.

Question 131

A FortiManager administrator notices that a managed FortiGate repeatedly changes from connected to disconnected. Which communication information should be examined?

  1. FGFM keepalive status
  2. Policy object names
  3. Security Rating only
  4. Global policy order

Correct Answer: 1

Explanation

FGFM keepalive status can provide useful information when a managed FortiGate repeatedly changes between connected and disconnected states. Keepalive communication helps FortiManager determine whether the management relationship with the FortiGate remains active. Intermittent connectivity can be caused by network instability, routing problems, NAT behavior, resource issues, or management-process problems. Administrators should review communication status together with network reachability and relevant logs. Repeated connection changes should be investigated rather than treated as a normal condition because they can interfere with policy installation and centralized management operations.

Question 132

A FortiManager administrator wants to determine whether a FortiGate management session is being maintained through regular management messages. Which concept should be reviewed?

  1. FGFM keepalive
  2. Object duplication
  3. Policy cloning
  4. Firmware cache

Correct Answer: 1

Explanation

FGFM keepalive messages help maintain and monitor the management relationship between FortiManager and managed FortiGate devices. They provide information that can be used to determine whether the communication path remains active. If keepalive communication is interrupted, FortiManager may detect that the device is no longer reachable through the expected management channel. Troubleshooting should include checking network connectivity, NAT behavior, relevant processes, and device status. Understanding keepalive behavior is useful when diagnosing intermittent management connections or unexpected changes in a device’s centralized management state.

Question 133

A managed FortiGate stops responding to FortiManager, and the administrator suspects a network problem. Which troubleshooting action should be performed?

  1. Verify network reachability between the devices
  2. Delete the device from the ADOM
  3. Remove all policy objects
  4. Rebuild every policy package

Correct Answer: 1

Explanation

Network reachability should be verified when FortiManager cannot communicate with a managed FortiGate. The administrator should confirm that routing, interfaces, required communication paths, and any relevant NAT or firewall controls allow management traffic to pass. Once basic connectivity is confirmed, FGFM status and management processes can be investigated. Removing the device or rebuilding policies does not address a basic communication failure and could create additional administrative problems. Starting with network verification provides a structured troubleshooting path and helps determine whether the issue is connectivity-related or caused by the management application.

Question 134

A FortiManager appliance shows unusually high CPU utilization. Which approach is appropriate for troubleshooting the issue?

  1. Review system resource usage and running processes
  2. Delete all ADOMs
  3. Disable every managed FortiGate
  4. Remove all policy packages

Correct Answer: 1

Explanation

High CPU utilization should be investigated by reviewing system resource usage and identifying processes that may be consuming excessive resources. Administrators can use available monitoring and diagnostic information to determine whether the load is temporary or associated with a particular process or management operation. The investigation should consider recent activities, device operations, scheduled tasks, and other resource-intensive functions. Destructive actions such as deleting ADOMs or policy packages are not appropriate initial troubleshooting steps. Identifying the source of the resource usage allows administrators to apply a targeted corrective action.

Question 135

A FortiManager appliance is experiencing high memory utilization. What should an administrator examine before taking corrective action?

  1. Memory usage and active processes
  2. Only the policy package names
  3. Only the device serial numbers
  4. Only the Security Fabric topology

Correct Answer: 1

Explanation

Memory usage and active processes should be examined when FortiManager experiences unusually high memory utilization. Administrators need to determine whether a specific process, management operation, or sustained workload is consuming excessive memory. Monitoring resource usage over time can also help identify whether the condition is temporary or persistent. Relevant diagnostic information and process status can provide additional context. Administrators should avoid making unrelated configuration changes simply because memory usage is high. Identifying the source of the resource consumption first makes it easier to select an appropriate corrective action.

Question 136

A FortiManager administrator receives an alert that disk utilization is unusually high. Which area should be reviewed first?

  1. File-system and disk usage
  2. Policy ordering
  3. Device group membership
  4. Interface mapping

Correct Answer: 1

Explanation

File-system and disk usage should be reviewed when FortiManager reports unusually high disk utilization. Administrators should identify which directories, logs, databases, cached files, or other stored data are consuming available space. High disk usage can eventually affect system operations, so it should be addressed before available storage becomes critically low. Administrators should follow supported cleanup and maintenance procedures rather than manually deleting unknown system files. Reviewing disk usage regularly can also help identify abnormal growth and establish appropriate retention or storage-management practices.

Question 137

A FortiManager administrator needs to determine whether a particular system process is running normally. Which information is most useful?

  1. Process status
  2. Policy package order
  3. Object usage
  4. Device group membership

Correct Answer: 1

Explanation

Process status provides information about the operational state of FortiManager system processes. When troubleshooting management problems, administrators can use process information to determine whether an expected process is running or whether a process may have stopped or behaved abnormally. Process status should be considered alongside system resource usage, logs, and relevant diagnostic commands. Administrators should avoid restarting processes without understanding the potential impact. A structured review of process state can help narrow the source of issues involving management communication, resource utilization, or other system functions.

Question 138

A FortiManager administrator wants to collect more detailed information about a management process that appears to be malfunctioning. Which capability should be considered?

  1. Debug commands
  2. Policy cloning
  3. Device grouping
  4. Firmware caching

Correct Answer: 1

Explanation

Debug commands can provide detailed diagnostic information about FortiManager processes and system operations. They are useful when standard status information and logs do not provide enough detail to identify the source of a problem. Administrators should use debugging carefully because detailed debug output can generate significant information and may affect system resources depending on the command and duration. Debugging should generally be enabled only for the necessary period and disabled after sufficient information has been collected. The resulting output should then be reviewed to identify communication or process-related errors.

Question 139

A FortiManager administrator is troubleshooting repeated management failures after a system restart. Which information can help determine whether a required process has recovered correctly?

  1. Process status and system logs
  2. Object naming conventions
  3. Policy package descriptions
  4. Device group labels

Correct Answer: 1

Explanation

Process status and system logs can help administrators determine whether required FortiManager processes recovered correctly after a restart. A system restart can temporarily interrupt management services, and a process may fail to initialize properly even though the appliance itself appears available. Reviewing process states and associated logs can reveal startup errors or service failures. Administrators should also verify device connectivity after recovery. This approach provides evidence about whether the problem is related to a system process rather than immediately changing policies or removing managed devices.

Question 140

A FortiManager administrator needs to troubleshoot a system issue while minimizing unnecessary changes to the production configuration. Which approach is most appropriate?

  1. Collect status, logs, resource, and diagnostic information before making changes
  2. Delete the affected ADOM immediately
  3. Reinstall every policy package
  4. Remove all managed FortiGate devices

Correct Answer: 1

Explanation

Collecting status, logs, resource information, and relevant diagnostic output before making changes provides a structured way to troubleshoot FortiManager problems. This approach helps administrators identify the actual cause without introducing additional configuration changes that could complicate the investigation. Information such as process status, CPU and memory usage, disk utilization, management communication, and system logs can help narrow the problem. Once the cause is understood, administrators can apply a targeted corrective action. Preserving the existing configuration during investigation is especially important in production management environments.