View Full Fortinet FCP_FMG_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 261
What is the purpose of the Global Database ADOM?
- To manage endpoint devices
- To store administrator passwords
- To provide shared policies and objects across ADOMs
- To replace FortiAnalyzer
Correct Answer: 3
Explanation
The Global Database ADOM provides a centralized location for shared policies and objects that can be used across multiple ADOMs. This is useful when an organization needs common configuration elements to be maintained consistently rather than recreated separately in every ADOM. Global policies and objects can simplify administration in larger environments. Administrators should understand the scope of global configurations before making changes because shared elements can affect multiple ADOMs and managed devices.
Question 262
Which type of policy can be used as a shared policy across multiple ADOMs?
- Global policy
- Local device policy only
- Endpoint policy
- Firmware policy
Correct Answer: 1
Explanation
Global policies can be used to provide shared policy elements across multiple ADOMs when the FortiManager global database is configured for that purpose. This can reduce duplication and help maintain common security requirements across different administrative domains. Administrators can define shared policies centrally and assign or incorporate them according to the supported global policy workflow. Because changes can affect multiple environments, administrators should review the intended scope before installing global policy changes.
Question 263
What is a major benefit of shared global objects?
- They reduce duplicate object definitions
- They disable policy installation
- They replace FortiGate HA
- They remove all ADOMs
Correct Answer: 1
Explanation
Shared global objects allow commonly used configuration elements to be maintained centrally instead of recreated separately in multiple ADOMs. This can reduce duplication and make administration more consistent. When an organization uses the same object definitions across multiple environments, central management can simplify updates and reduce configuration inconsistencies. Administrators should still review object dependencies and scope before modifying shared objects because a change to a global object can affect multiple ADOMs or policy packages.
Question 264
What does assigning a global policy package to an ADOM accomplish?
- Makes the global policy available within that ADOM
- Deletes the ADOM
- Changes the FortiGate serial number
- Disables FortiGuard
Correct Answer: 1
Explanation
Assigning a global policy package to an ADOM makes the relevant global policy available for use within that administrative domain. This allows common policy elements to be incorporated into the management workflow for selected ADOMs. The assignment does not replace the ADOM or automatically change unrelated device settings. Administrators should confirm the intended ADOM assignment and review the resulting policy structure before installation to ensure that shared policies are applied to the correct environments.
Question 265
What can Fabric View display in FortiManager?
- Security Fabric relationships and topology
- Administrator passwords
- FortiGuard invoices
- Policy package backups only
Correct Answer: 1
Explanation
Fabric View can provide a visual representation of Security Fabric relationships and topology within a Fortinet environment. This can help administrators understand how Fortinet devices are connected and how they relate to one another within the Security Fabric. The view can be useful when reviewing network structure or troubleshooting device relationships. It does not replace configuration management or policy installation functions, but it can provide valuable visibility into the broader managed environment.
Question 266
What is the purpose of Security Fabric topology information?
- To understand relationships between connected Fortinet devices
- To create administrator accounts
- To replace ADOM permissions
- To modify FortiGuard contracts
Correct Answer: 1
Explanation
Security Fabric topology information helps administrators understand how connected Fortinet devices relate to one another. This visibility can make it easier to identify device relationships and understand the structure of a Security Fabric deployment. When troubleshooting connectivity or configuration issues, topology information can provide useful context about which devices are connected and how they interact. It is a visibility and management aid rather than a replacement for the underlying device configuration or policy management processes.
Question 267
Which FortiManager feature can help display the security posture of a Security Fabric?
- Security Rating
- Device Group
- CLI Script
- Revision History
Correct Answer: 1
Explanation
Security Rating provides information related to the security posture of a Security Fabric environment. It can help administrators identify areas that may require attention and provides a centralized view associated with the security configuration of connected Fortinet devices. Security Rating is different from policy packages and device groups because it focuses on security posture rather than configuration organization. Administrators can use the information as part of broader monitoring and security management activities.
Question 268
What is the main purpose of FortiManager’s policy workflow?
- To control how policy changes are prepared and deployed
- To replace FortiGate hardware
- To create Internet connections
- To manage administrator email
Correct Answer: 1
Explanation
The policy workflow provides a structured process for creating, reviewing, validating, and deploying firewall policy changes. Instead of immediately changing each FortiGate independently, administrators can manage policies centrally and then install approved configurations on selected devices. The workflow can include object management, target selection, validation, installation preview, and deployment. Following a structured workflow reduces accidental changes and makes centralized policy administration easier to control.
Question 269
What should be reviewed before changing a shared global object?
- Its usage across relevant configurations
- The monitor size
- The FortiManager hostname only
- The number of browser windows
Correct Answer: 1
Explanation
Before changing a shared global object, administrators should review where the object is used and understand which configurations may depend on it. Because a global object can be referenced across multiple ADOMs, a modification may affect more than one environment. Reviewing object usage and dependencies helps administrators predict the potential impact of the change. This is especially important for address, service, and other reusable objects that may appear in multiple policy packages.
Question 270
What is an advantage of using a centralized policy package?
- Consistent policy management across selected devices
- Automatic hardware replacement
- Removal of all device configurations
- Elimination of FortiGuard services
Correct Answer: 1
Explanation
A centralized policy package allows administrators to manage related firewall policies from FortiManager and deploy them to selected managed FortiGate devices. This can improve consistency because common policy requirements can be maintained from one management platform. Device-specific differences can be handled through supported mappings or variables where required. Centralized policy management also provides a controlled installation process, allowing administrators to review targets and proposed changes before deployment.
Question 271
Why might an administrator use separate policy packages for different environments?
- To apply environment-specific policies
- To disable ADOMs
- To remove object references
- To stop FortiManager logging
Correct Answer: 1
Explanation
Separate policy packages can be useful when different environments have different security requirements. For example, production, testing, and branch environments may require different firewall policies even though they are managed from the same FortiManager. Using separate packages allows administrators to maintain those differences while still benefiting from centralized management. The package structure should reflect the organization’s operational requirements and should be reviewed regularly to avoid unnecessary duplication or inconsistent policy definitions.
Question 272
What does policy cloning help administrators do?
- Create a copy of an existing policy package or policy configuration
- Repair a damaged hard drive
- Replace FortiGate firmware
- Create a FortiGuard server
Correct Answer: 1
Explanation
Policy cloning allows administrators to create a copy of an existing policy or policy package as a starting point for another configuration. This can save time when a new environment requires a configuration similar to an existing one. After cloning, administrators should review objects, interfaces, targets, and other environment-specific settings before installation. Simply cloning a configuration does not guarantee that it is appropriate for the new target, so validation and review remain important parts of the deployment process.
Question 273
Which setting controls which FortiManager features are visible to administrators?
- Feature visibility
- FGFM keepalive
- FortiGuard override
- Device discovery
Correct Answer: 1
Explanation
Feature visibility controls which configuration features are displayed within the FortiManager interface. Administrators can use it to simplify the management interface by showing features that are relevant to their environment. If a required configuration option is not visible, checking feature visibility can help determine whether the feature has been hidden. Feature visibility does not remove the underlying configuration from the system; it primarily controls the available interface elements presented to administrators.
Question 274
What is the purpose of installation preview?
- To review proposed changes before installation
- To renew device licenses
- To create new ADOMs
- To monitor physical temperature
Correct Answer: 1
Explanation
Installation preview provides administrators with an opportunity to examine proposed configuration changes before they are deployed to managed devices. Reviewing the preview can reveal unexpected modifications, target issues, or configuration differences that require attention. This is particularly valuable in production environments where an incorrect deployment can affect network traffic or security controls. Administrators should use the preview together with validation and target verification to maintain a controlled installation process.
Question 275
What can a duplicate-object review prevent?
- Unnecessary object duplication and configuration confusion
- FortiGate hardware failure
- FortiManager license expiration
- FGFM communication
Correct Answer: 1
Explanation
Reviewing duplicate objects can help reduce unnecessary configuration duplication and make object management clearer. Multiple objects with identical or nearly identical definitions can make policies harder to maintain and may lead to confusion when administrators modify configurations. Before consolidating duplicates, administrators should review references and dependencies to ensure that removing one object will not break existing policies. A controlled cleanup process can improve configuration organization without introducing unexpected policy changes.
Question 276
What should be checked when an interface mapping causes an installation error?
- The mapped interfaces and target device
- The administrator’s browser
- The FortiManager display language
- The number of revisions only
Correct Answer: 1
Explanation
When interface mapping causes an installation error, administrators should verify that the mapped interfaces actually exist on the target FortiGate and correspond to the intended network roles. Interface names can vary between devices, so a mapping that works for one device may not be valid for another. Reviewing the policy, target device, and interface configuration can reveal incorrect or missing mappings. Correcting the mapping before retrying the installation can resolve the deployment problem.
Question 277
What is the purpose of device-specific variables?
- To supply different values to shared configurations
- To disable policy packages
- To create global administrators
- To replace FortiManager databases
Correct Answer: 1
Explanation
Device-specific variables allow a common configuration structure to use different values for individual managed devices. This is useful when several FortiGates require similar policies but have different addresses, interfaces, hostnames, or other device-dependent information. Instead of creating an entirely separate configuration for every device, administrators can maintain reusable logic and assign appropriate values. Proper variable assignment should be verified before installation because an incorrect value can result in an invalid or unintended configuration.
Question 278
What should be verified when a shared configuration is deployed to several FortiGates?
- Device-specific values and installation targets
- Only the FortiManager hostname
- Browser cache
- FortiGuard invoice number
Correct Answer: 1
Explanation
When deploying shared configurations to multiple FortiGates, administrators should verify both the intended installation targets and any device-specific values used by the configuration. Shared policies may depend on variables, interface mappings, or other device-specific information. An incorrect value could cause an installation failure or result in an unintended configuration on one device. Reviewing the installation preview and validation results before deployment provides an additional safeguard against these problems.
Question 279
Which action is appropriate after correcting a failed policy configuration?
- Validate the corrected configuration before reinstalling
- Delete the ADOM
- Disable all FortiGuard services
- Remove the target device
Correct Answer: 1
Explanation
After correcting a policy configuration that previously failed, administrators should validate the revised configuration before attempting another installation. Validation can identify remaining problems with policies, objects, interfaces, or other dependencies. The installation target should also be confirmed before deployment. Reinstalling without validating the correction may simply reproduce the same failure. A controlled sequence of correction, validation, preview, and installation helps reduce repeated deployment problems.
Question 280
Why is controlled policy deployment important?
- It reduces the risk of unintended configuration changes
- It eliminates the need for backups
- It disables FortiManager logging
- It removes all configuration dependencies
Correct Answer: 1
Explanation
Controlled policy deployment reduces the risk of accidentally changing the wrong device or deploying an incorrect configuration. Administrators can review policy changes, validate configurations, confirm installation targets, and examine the installation preview before committing changes. This structured approach is especially valuable in environments where multiple FortiGates are managed from one FortiManager. Controlled deployment does not eliminate the need for backups or change management, but it provides important safeguards against configuration errors.