View Full Fortinet FCP_FMG_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 181
What is the main purpose of dynamic objects in FortiManager?
- To dynamically identify objects based on defined criteria
- To replace ADOMs
- To disable policy installation
- To manage administrator passwords
Correct Answer: 1
Explanation
Dynamic objects allow FortiManager to reference objects based on information or criteria that can vary between managed devices. This can reduce the need to create separate static configurations for every device when the underlying values differ. Dynamic objects are particularly useful in centralized policy management because they can help maintain reusable configurations across multiple FortiGate devices. Administrators should define the required values carefully so that policies reference the correct resources when they are installed on individual managed devices.
Question 182
What does interface mapping help accomplish?
- Remove unused ADOMs
- Map policy interfaces to device-specific interfaces
- Change administrator permissions
- Create FortiGuard contracts
Correct Answer: 2
Explanation
Interface mapping allows a centralized policy configuration to use appropriate interfaces on different managed FortiGate devices. Interface names may differ between devices even when the same policy logic is required. Mapping provides a way to associate the policy’s interface references with the corresponding interfaces on each target device. This is useful when a shared policy package is deployed across devices with different interface naming or topology. Correct mapping should be verified before installation to prevent policy deployment errors.
Question 183
Why is feature visibility important in FortiManager?
- It controls which configuration features are displayed
- It changes the FortiGate serial number
- It disables FGFM
- It replaces the installation wizard
Correct Answer: 1
Explanation
Feature visibility controls which configuration options and features are available within the FortiManager management interface. This can simplify administration by displaying only the features required for a particular environment or administrative workflow. If a required feature is hidden, an administrator may incorrectly assume that the functionality is unavailable. Checking feature visibility can therefore be useful when a configuration option cannot be found. Administrators should enable the necessary features while avoiding unnecessary interface complexity.
Question 184
What is a policy package used for?
- Managing FortiManager administrators
- Storing FortiGuard contracts
- Organizing firewall policies for managed devices
- Monitoring CPU temperature
Correct Answer: 3
Explanation
A policy package contains firewall policy configurations that FortiManager can manage and install on targeted FortiGate devices. It provides a centralized way to organize and maintain related policies instead of configuring each FortiGate independently. Policy packages can contain references to objects and other configuration elements required by the policies. Before installation, administrators can review the target devices and validate the proposed changes. This centralized workflow helps maintain consistency while still allowing device-specific requirements where supported.
Question 185
What should be checked before installing a policy package?
- The administrator’s desktop wallpaper
- Installation targets and configuration changes
- The FortiManager serial number only
- The number of logged-in users
Correct Answer: 2
Explanation
Before installing a policy package, administrators should verify the intended installation targets and review the configuration changes that will be deployed. The installation preview or validation process can help identify potential issues before changes reach production FortiGate devices. Reviewing targets is especially important when a policy package is associated with multiple devices because an unintended target could receive configuration changes. Careful validation helps reduce deployment errors and provides a controlled approach to centralized policy installation.
Question 186
Which FortiManager feature can help determine where an object is being used?
- Object usage information
- FortiGuard licensing
- FGFM keepalive
- System reboot
Correct Answer: 1
Explanation
Object usage information helps administrators identify where a configuration object is referenced. This is useful when reviewing or cleaning up address objects, services, or other reusable configuration elements. Before deleting an object, administrators should determine whether it is referenced by policies or other configurations. Removing an object that is still required can cause configuration problems or installation failures. Usage information therefore supports safer object management and helps identify unused configuration items that may be candidates for cleanup.
Question 187
What is the purpose of an unused-object review?
- To identify objects that may no longer be required
- To force all FortiGates into HA
- To reset administrator accounts
- To disable policy packages
Correct Answer: 1
Explanation
An unused-object review helps administrators identify configuration objects that are not currently referenced by relevant policies or configurations. Over time, centralized environments can accumulate obsolete addresses, services, and other objects. Reviewing unused objects can improve configuration organization and reduce unnecessary clutter. However, administrators should verify an object’s actual usage before removing it because an object that appears unused in one context may be required elsewhere. Cleanup should therefore be performed carefully and preferably after reviewing dependencies.
Question 188
Which action is appropriate when an object is reported as a duplicate?
- Delete every object immediately
- Ignore all object references
- Compare the duplicate objects and their usage
- Reboot FortiManager
Correct Answer: 3
Explanation
When duplicate objects are identified, administrators should first compare their names, definitions, references, and usage before making changes. Two objects may appear similar but serve different purposes or be referenced by different policies. Reviewing object dependencies helps determine whether consolidation is safe. If redundant objects are confirmed, the administrator can plan a controlled cleanup while preserving required references. Immediate deletion without checking dependencies can introduce policy errors and may result in failed installations or unexpected behavior on managed devices.
Question 189
What does the installation preview provide?
- A view of proposed configuration changes before deployment
- A replacement FortiGate license
- A new administrator account
- A FortiGuard contract
Correct Answer: 1
Explanation
Installation preview allows administrators to review proposed changes before they are installed on target FortiGate devices. It can help identify configuration differences, unexpected modifications, or deployment targets that require attention. Reviewing the preview is an important part of a controlled change process because administrators can detect problems before affecting production devices. The preview should be considered alongside validation results, installation targets, and the expected policy or configuration changes before proceeding with deployment.
Question 190
A script runs successfully on one FortiGate but fails on another. What is a likely consideration?
- The administrator’s username
- Device-specific command compatibility
- The number of ADOMs
- FortiAnalyzer report formatting
Correct Answer: 2
Explanation
CLI commands supported by one FortiGate may not be supported or may behave differently on another device because of differences in FortiOS versions, models, or configuration context. When a script succeeds on one device but fails on another, administrators should review command compatibility and device-specific requirements. Variables and configuration differences should also be checked. Testing scripts against representative devices before broad deployment can reduce failures. Scripts should be written with supported syntax and appropriate targeting in mind.
Question 191
What is a common cause of a CLI script execution failure?
- Invalid or unsupported commands
- Excessive monitor brightness
- Too many ADOM names
- FortiManager hostname length
Correct Answer: 1
Explanation
Invalid or unsupported CLI commands are common causes of script execution failures. A command may contain incorrect syntax, reference a feature that is unavailable on the target FortiGate, or depend on configuration conditions that are not present. Administrators should review the script output and error messages to identify the failing command. Testing commands individually can also help isolate the problem. Scripts should be validated against the relevant FortiOS version and device configuration before they are deployed broadly.
Question 192
Why can script scheduling fail even when the script itself is correct?
- The policy package is too large
- The scheduled target may be unreachable
- The ADOM name contains letters
- The FortiManager interface is enabled
Correct Answer: 2
Explanation
A correctly written script can still fail during scheduled execution if the target device cannot be reached or does not have the required management connectivity. Scheduled operations depend on the communication path between FortiManager and the target FortiGate. Administrators should therefore verify device status, network reachability, FGFM communication, and scheduling settings when troubleshooting these failures. Reviewing execution logs can also show whether the problem occurred before the script reached the device or while the commands were being processed.
Question 193
Which feature records different saved versions of a FortiManager configuration?
- Configuration revision history
- Device Groups
- Interface mapping
- FortiGuard cache
Correct Answer: 1
Explanation
Configuration revision history records previous versions of configuration changes so administrators can review how the configuration changed over time. This information is valuable for troubleshooting, auditing, and identifying changes that may have introduced a problem. Depending on the situation, an administrator may compare revisions to determine what changed or revert to an appropriate earlier configuration. Revision history should be used carefully because restoring a previous state can affect current configurations and should follow the organization’s change-management process.
Question 194
An administrator needs to restore an earlier configuration state. Which feature should be reviewed?
- Security Rating
- Revision history
- Device discovery
- FortiGuard query server
Correct Answer: 2
Explanation
Revision history should be reviewed when an administrator needs to investigate or restore an earlier configuration state. It provides access to previously recorded configuration revisions and allows administrators to examine changes over time. Before reverting, the administrator should identify the correct revision and understand what configuration differences will be introduced. Reviewing the current state and relevant change history helps prevent accidental loss of legitimate newer changes. Reversion should be performed carefully and followed by appropriate validation.
Question 195
What is a useful first step when a FortiGate cannot be discovered by FortiManager?
- Delete the ADOM
- Check network and management connectivity
- Remove all policies
- Disable FortiGuard
Correct Answer: 2
Explanation
When FortiManager cannot discover a FortiGate, checking network and management connectivity is an appropriate first step. The devices must be able to communicate through the required management path for discovery and authorization to succeed. Administrators should verify addressing, routing, firewall rules, NAT conditions, and relevant FGFM settings. Device status and connection information can provide additional clues. Starting with connectivity helps eliminate basic communication problems before investigating more advanced configuration or database issues.
Question 196
What is the purpose of device blueprints in FortiManager?
- To define device-related configuration information before deployment
- To replace FortiAnalyzer
- To store administrator passwords
- To disable device discovery
Correct Answer: 1
Explanation
Device blueprints can be used to define information and configuration requirements for devices before the actual deployment or onboarding process is completed. They help administrators prepare device-related settings in a structured manner. This can support standardized onboarding and reduce repetitive configuration work when adding managed devices. Blueprints should be designed according to the organization’s device requirements and deployment workflow. They are part of the broader device management process rather than a replacement for active FortiGate management.
Question 197
What does the device discovery process help FortiManager accomplish?
- Identify and add FortiGate devices for management
- Create FortiGuard contracts
- Replace firewall policies
- Change FortiManager hardware
Correct Answer: 1
Explanation
Device discovery helps FortiManager identify FortiGate devices that can be added to centralized management. Once a device is discovered and properly authorized, administrators can manage its configuration, policies, and other supported settings through FortiManager. Discovery depends on appropriate connectivity and management communication. If discovery fails, administrators should verify the network path, device configuration, credentials or authorization requirements, and FGFM communication. Successful discovery is an important step before centralized policy deployment can begin.
Question 198
Which command-line approach is useful when troubleshooting FortiManager problems?
- Using relevant diagnostic and status commands
- Changing every policy manually
- Removing all device groups
- Disabling administrator access
Correct Answer: 1
Explanation
Relevant diagnostic and status commands can provide detailed information when troubleshooting FortiManager issues. Depending on the problem, administrators may use commands that show system status, processes, connectivity, management communication, or other operational information. CLI diagnostics can provide details that are not always visible in the graphical interface. The specific command should match the issue being investigated. Administrators should avoid making unrelated configuration changes during troubleshooting because they can complicate the investigation and make the original problem harder to isolate.
Question 199
What can a FortiManager administrator use to compare a device configuration with a stored configuration?
- Configuration comparison
- Security Rating
- FortiGuard cache
- Device blueprint only
Correct Answer: 1
Explanation
Configuration comparison helps administrators identify differences between configurations maintained by FortiManager and those associated with a managed FortiGate. This is useful when investigating configuration drift or determining whether local changes have occurred on a device. Comparing the configurations can show which settings differ and help administrators decide whether changes should be retrieved, overwritten, or reviewed. This process is especially valuable before deployment because it helps prevent unexpected configuration changes from being introduced into a managed environment.
Question 200
Why should administrators review configuration differences before overwriting a managed device configuration?
- To avoid unintentionally replacing legitimate local changes
- To increase the number of ADOMs
- To disable FGFM
- To remove FortiGuard services
Correct Answer: 1
Explanation
Reviewing configuration differences before overwriting a managed device helps administrators identify legitimate local changes that may not yet exist in the FortiManager database. Overwriting without reviewing these differences could remove settings that are still required on the FortiGate. Configuration comparison and revision information can help determine what changed and why. Administrators can then choose an appropriate synchronization or deployment action based on the intended configuration state. This approach reduces the risk of accidental configuration loss.