Fortinet FCP_FMG_AD-7.6 Practice Test Questions and Exam Dumps Part11 Q201-220

View Full Fortinet FCP_FMG_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 201

What is the purpose of an ADOM operation mode in FortiManager?

  1. To control FortiGuard updates
  2. To determine how an ADOM handles configuration management
  3. To replace device groups
  4. To monitor CPU usage

Correct Answer: 2

Explanation

ADOM operation modes determine how configuration changes are handled within an Administrative Domain. The selected mode can affect how administrators work with device configurations and centralized management workflows. Understanding the operation mode is important before making changes because it influences how FortiManager manages configuration synchronization and installation activities. Administrators should select the mode that matches their organization’s change-control requirements and management approach rather than changing it without considering the effect on existing device configurations.

Question 202

Which mode is commonly used when administrators want changes reviewed before installation?

  1. Workspace mode
  2. FortiGuard mode
  3. Query mode
  4. Discovery mode

Correct Answer: 1

Explanation

Workspace mode provides a controlled workflow in which configuration changes can be reviewed and managed before they are committed or installed. This is useful in environments that require administrative approval or change control. Instead of immediately deploying every modification, administrators can prepare changes, review them, and then proceed with the appropriate installation process. Workspace-based workflows are particularly useful when multiple administrators manage centralized configurations and the organization wants to reduce accidental or unauthorized changes.

Question 203

What is the main function of a device group?

  1. To group managed devices for easier administration
  2. To create FortiGuard licenses
  3. To replace an ADOM
  4. To store API passwords

Correct Answer: 1

Explanation

Device groups organize managed FortiGate devices into logical collections within FortiManager. Grouping devices can make administration easier when several systems share common characteristics, locations, or management requirements. Device groups can simplify navigation and help administrators apply appropriate management actions to selected devices. They do not replace ADOMs, which provide a broader administrative separation. Proper grouping can improve organization, especially in larger deployments containing many managed FortiGate devices.

Question 204

Why might an administrator move a device to another device group?

  1. To change its hardware model
  2. To organize it according to a different management category
  3. To disable FGFM
  4. To change its FortiGuard contract

Correct Answer: 2

Explanation

An administrator may move a managed device to another device group when its organizational or management classification changes. For example, devices can be grouped according to branch, region, environment, or operational responsibility. Moving a device between groups changes its organizational placement within FortiManager without necessarily changing the FortiGate’s underlying configuration. Administrators should understand the purpose of each group before making changes so that device organization remains consistent with the organization’s management structure.

Question 205

What does the FortiManager install wizard help administrators perform?

  1. Install and validate configuration changes
  2. Create physical network cables
  3. Replace FortiGate hardware
  4. Reset all administrator accounts

Correct Answer: 1

Explanation

The install wizard guides administrators through the process of preparing and deploying configuration changes to selected managed devices. It can help identify installation targets, review proposed changes, and perform validation before deployment. Using the wizard provides a structured method for moving approved configurations from FortiManager to FortiGate devices. Administrators should review the installation information carefully before proceeding, especially when multiple devices are associated with the same policy package.

Question 206

A policy package should be installed on only one FortiGate. What should be checked?

  1. FortiGuard cache
  2. Installation target
  3. CPU history
  4. API response code

Correct Answer: 2

Explanation

The installation target determines which managed device or devices will receive the configuration changes. When a policy package is intended for only one FortiGate, the administrator should verify that the correct device is selected as the target before beginning installation. This is especially important when the same policy package is associated with multiple devices. Reviewing the target during the installation workflow helps prevent accidental deployment to unrelated FortiGates and supports controlled configuration management.

Question 207

What is the benefit of using metadata variables in centralized configurations?

  1. They allow values to vary by device while using shared configuration logic
  2. They disable policy installation
  3. They remove object dependencies
  4. They replace ADOMs

Correct Answer: 1

Explanation

Metadata variables allow centralized configurations to use values that can differ between individual managed devices. This is useful when several FortiGates require the same configuration structure but have different addresses, interfaces, or other device-specific values. Instead of creating completely separate configurations, administrators can maintain shared logic while supplying appropriate values for each target. This approach can reduce duplication and simplify centralized management. Variables should be defined and assigned carefully to prevent incorrect values from being deployed.

Question 208

What should be done when a policy package contains an object that is no longer needed?

  1. Delete it immediately
  2. Review its usage and dependencies first
  3. Reboot every FortiGate
  4. Disable all policies

Correct Answer: 2

Explanation

An administrator should review an object’s usage and dependencies before removing it from a policy package. An object that appears unnecessary may still be referenced by a policy or another configuration component. Removing such an object without checking dependencies can cause installation errors or change policy behavior. FortiManager provides object usage information that can help determine whether an object is safe to remove. Careful review is therefore preferable to immediate deletion when performing configuration cleanup.

Question 209

What does policy validation help identify?

  1. Potential configuration problems before deployment
  2. New FortiGuard contracts
  3. Administrator usernames
  4. Device hardware temperatures

Correct Answer: 1

Explanation

Policy validation helps identify potential configuration problems before changes are installed on managed FortiGate devices. Validation can reveal issues involving policy structure, object references, interfaces, or other configuration requirements. Detecting these problems before deployment reduces the risk of failed installations or unexpected policy behavior. Administrators should review validation results and resolve relevant errors before proceeding. Validation is therefore an important part of the centralized policy deployment process.

Question 210

What is a possible reason for reinstalling a policy package?

  1. The administrator wants to reapply the intended configuration to a target
  2. The FortiManager hostname is too short
  3. An ADOM must be deleted
  4. FortiGuard licensing must be disabled

Correct Answer: 1

Explanation

Reinstallation can be useful when an administrator needs to reapply the intended policy package configuration to a managed FortiGate. This may be necessary after configuration changes, recovery activities, or situations where the device configuration no longer matches the centrally managed state. Before reinstalling, administrators should review the target device, configuration differences, and installation preview. Reinstallation should be performed deliberately because it can modify the current configuration on the managed FortiGate.

Question 211

What is configuration drift?

  1. A difference between the intended managed configuration and the device configuration
  2. A FortiGuard update
  3. A type of ADOM
  4. A device group

Correct Answer: 1

Explanation

Configuration drift occurs when the configuration on a managed FortiGate differs from the configuration maintained or expected by FortiManager. Drift can occur because of local administrative changes, incomplete installations, or other configuration activities performed outside the centralized workflow. Identifying drift is important because unexpected differences can affect policy consistency and future deployments. Administrators can use configuration comparison and revision information to investigate the differences and determine which configuration should become the intended state.

Question 212

What should an administrator examine when unexpected local changes appear on a FortiGate?

  1. Configuration comparison and revision information
  2. Monitor brightness
  3. FortiGuard package color
  4. Device group name only

Correct Answer: 1

Explanation

Configuration comparison and revision information can help administrators determine what changed and when the differences appeared. Local changes made directly on a FortiGate may create differences between the device and FortiManager. Reviewing these differences before retrieving or overwriting configuration helps protect legitimate changes and prevents accidental loss of settings. The administrator should identify the source of the change and decide whether the FortiGate or FortiManager configuration represents the intended state before synchronizing the systems.

Question 213

Which FortiManager feature helps track configuration changes over time?

  1. Revision history
  2. Interface mapping
  3. Device Groups
  4. FortiGuard override

Correct Answer: 1

Explanation

Revision history provides a record of configuration changes over time. Administrators can use it to investigate when modifications were made and compare different configuration states. This is especially useful when troubleshooting unexpected behavior because a recent configuration change may be related to the problem. Revision history can also support controlled rollback when an earlier configuration is known to be appropriate. Administrators should verify the correct revision before restoring any previous state.

Question 214

What is the purpose of configuration retrieval?

  1. To obtain configuration information from a managed device
  2. To create a new FortiManager license
  3. To delete an ADOM
  4. To configure endpoint antivirus

Correct Answer: 1

Explanation

Configuration retrieval allows FortiManager to obtain configuration information from a managed FortiGate. This can be useful when the device contains changes that need to be reviewed or incorporated into centralized management. Before retrieval, administrators should consider whether local changes are expected and whether they should become part of the managed configuration. Comparing the existing FortiManager configuration with the device configuration can help administrators make an informed decision and avoid unintentionally replacing or losing important settings.

Question 215

What should be verified after a policy installation completes?

  1. Installation result and device synchronization status
  2. Desktop resolution
  3. Number of administrator profiles only
  4. FortiGuard server color

Correct Answer: 1

Explanation

After a policy installation completes, administrators should verify the installation result and synchronization status of the target device. A completed installation process does not necessarily mean that every expected configuration change was successfully applied. Installation logs can provide additional details when errors occur. Checking the device status and comparing the resulting configuration with the intended state helps confirm successful deployment. This verification step is especially important after changes involving multiple policies, objects, or managed devices.

Question 216

Which log can help investigate a failed configuration installation?

  1. Installation log
  2. Browser history
  3. Desktop event log
  4. FortiGuard license invoice

Correct Answer: 1

Explanation

The installation log provides information about the process of deploying configuration changes from FortiManager to a managed device. When an installation fails, the log can help identify the stage or configuration component responsible for the failure. Administrators can use this information to determine whether the problem involves connectivity, configuration syntax, object dependencies, or another issue. Reviewing the log before retrying the installation helps avoid repeatedly deploying the same problematic configuration.

Question 217

What can cause a FortiManager installation to fail because of an unreachable device?

  1. Management connectivity problems
  2. An unused address object
  3. A long policy name
  4. Multiple ADOMs

Correct Answer: 1

Explanation

Management connectivity problems can prevent FortiManager from successfully installing configuration changes on a FortiGate. The managed device must be reachable through the required management communication path. Administrators should check network connectivity, routing, firewall rules, NAT conditions, device status, and FGFM communication when an installation cannot reach the target. Reviewing the installation log can help confirm whether the failure occurred because FortiManager could not communicate with the device or because another configuration problem occurred after communication was established.

Question 218

What is a key consideration when replacing a managed FortiGate?

  1. Maintaining the correct management relationship and configuration
  2. Deleting every policy package
  3. Disabling all ADOMs
  4. Removing FortiGuard services

Correct Answer: 1

Explanation

When a managed FortiGate is replaced, the administrator must ensure that the replacement device is correctly identified, authorized, and associated with the intended centralized configuration. The management relationship and device information should be reviewed so that the replacement receives the correct policies and settings. Administrators should also verify connectivity and installation targets before deploying configuration. Careful replacement procedures help prevent the new device from receiving an incorrect configuration or the old device from remaining incorrectly represented in FortiManager.

Question 219

Which symptom can indicate a high CPU resource problem on FortiManager?

  1. Slow or delayed management operations
  2. A changed ADOM name
  3. A new device group
  4. A duplicate policy object

Correct Answer: 1

Explanation

High CPU utilization can cause FortiManager management operations to become slow or delayed. Administrators experiencing performance problems should review system resource usage and identify processes consuming excessive CPU. A temporary workload may explain the increase, while persistent high utilization may require deeper investigation. Process status, system monitoring, and relevant diagnostic commands can help identify the source. Administrators should correlate resource usage with recent tasks or scheduled operations before making configuration changes.

Question 220

What should be investigated when FortiManager disk usage becomes unusually high?

  1. Large files, logs, databases, and stored data
  2. Only the administrator password
  3. Device group names
  4. Policy interface colors

Correct Answer: 1

Explanation

Unusually high disk usage should prompt an administrator to investigate stored data such as logs, databases, files, reports, backups, or other accumulated content. Excessive disk utilization can affect system operation and may eventually create additional problems if available space becomes critically low. Administrators should use appropriate system status and diagnostic information to identify the source of the consumption. Cleanup should be performed carefully so that required configuration data, logs, or system files are not removed unnecessarily.