Fortinet FCP_FMG_AD-7.6 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Fortinet FCP_FMG_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 341

What is the primary purpose of a policy package in FortiManager?

  1. To store firmware images
  2. To organize firewall policies for managed FortiGate devices
  3. To monitor CPU usage
  4. To manage administrator passwords

Correct Answer: 2

Explanation

A policy package is a collection of firewall policies and related configuration used to manage security policy deployment to FortiGate devices. FortiManager allows administrators to create and maintain policy packages centrally and then install them on appropriate managed devices. A policy package can contain multiple policy types and associated objects. Before deployment, administrators should review the package, installation targets, and relevant objects to ensure that the intended configuration is sent to the correct FortiGate devices.

Question 342

Which feature can automatically provide different values for the same configuration setting on different devices?

  1. Configuration revisions
  2. Installation logs
  3. Metadata variables
  4. FortiGuard queries

Correct Answer: 3

Explanation

Metadata variables allow FortiManager to use device-specific values while maintaining a common configuration structure. This is useful when multiple FortiGate devices require different values for settings such as IP addresses, interface-related parameters, or other device-specific information. Instead of creating entirely separate configurations, administrators can use variables to adapt shared templates or scripts. Proper variable assignment is important because an incorrect value can cause configuration errors or produce unexpected results during installation.

Question 343

Why is feature visibility useful in FortiManager policy configuration?

  1. It controls which supported configuration features are displayed
  2. It changes the FortiManager serial number
  3. It deletes unused ADOMs
  4. It manages physical cabling

Correct Answer: 1

Explanation

Feature visibility controls which supported configuration options are displayed in the FortiManager interface. Administrators can use it to expose relevant features while keeping unnecessary options hidden, making policy administration more focused. The available features can depend on the selected FortiOS version, ADOM configuration, and FortiManager capabilities. Feature visibility does not itself deploy configuration. Instead, it affects the administrative interface and helps administrators work with the configuration features required for their environment.

Question 344

What should an administrator verify before installing a policy package on a FortiGate?

  1. The administrator’s browser bookmarks
  2. The FortiManager hostname length
  3. The target device and installation scope
  4. The color of the policy icon

Correct Answer: 3

Explanation

Before installing a policy package, administrators should verify the target device or devices and confirm that the installation scope is correct. This is especially important when one FortiManager manages multiple environments because an incorrect target can result in configuration being deployed to an unintended FortiGate. Administrators should also review the installation preview and relevant configuration changes. Confirming the target before deployment is a basic safeguard against accidental changes to production or unrelated devices.

Question 345

Which action can help identify objects that are no longer referenced by a policy configuration?

  1. Reviewing unused objects
  2. Restarting FortiManager
  3. Checking API logout status
  4. Changing the ADOM mode

Correct Answer: 1

Explanation

Reviewing unused objects can help administrators identify configuration objects that are no longer referenced by active policies or related configuration elements. Over time, policy changes can leave obsolete objects in an ADOM, making administration more difficult. Administrators can review unused objects before deciding whether they should be removed. However, an object should not be deleted solely because it appears unused without confirming that it is not required by another supported configuration component or future management workflow.

Question 346

What does the Install Wizard help administrators perform?

  1. Firmware manufacturing
  2. Controlled deployment of configuration changes
  3. Administrator account recovery
  4. Hardware replacement

Correct Answer: 2

Explanation

The Install Wizard guides administrators through the process of deploying configuration changes from FortiManager to selected managed FortiGate devices. It helps organize the installation workflow and provides opportunities to review relevant changes before deployment. The process can include validation, target selection, and installation status information. Using the installation workflow carefully helps administrators avoid unintended deployments and provides a more controlled method for moving centrally managed policy changes into production.

Question 347

What is the purpose of an installation preview?

  1. To show proposed changes before they are deployed
  2. To create a new FortiManager appliance
  3. To renew FortiGuard contracts
  4. To remove all unused objects

Correct Answer: 1

Explanation

An installation preview allows administrators to inspect proposed configuration changes before they are actually installed on a managed device. This can reveal policy modifications, object changes, or other differences that may not have been expected. Reviewing the preview is particularly useful before significant deployments or when multiple administrators have modified the same policy package. It provides an additional validation step and gives administrators an opportunity to stop and investigate unexpected changes before they affect the target FortiGate.

Question 348

If a policy package contains an object that is not supported by the target FortiOS version, what should the administrator consider?

  1. Browser cache settings
  2. Object compatibility with the target device
  3. Administrator display preferences
  4. FortiManager screen resolution

Correct Answer: 2

Explanation

Object compatibility with the target FortiOS version should be reviewed when an installation involves configuration features that may not be supported by the destination device. FortiManager manages devices that can run different FortiOS versions, so configuration support may vary. An unsupported object or feature can cause validation or installation problems. Administrators should check the target device version, relevant ADOM compatibility, and installation messages before modifying the configuration or attempting the deployment again.

Question 349

What is the purpose of reinstallation in FortiManager?

  1. To apply the intended managed configuration again to a device
  2. To create a new ADOM
  3. To remove FortiGuard services
  4. To change the FortiManager operating system

Correct Answer: 1

Explanation

Reinstallation can be used when an administrator needs to deploy the intended managed configuration to a FortiGate again. This may be useful after configuration differences, device replacement, or other circumstances where the managed state needs to be reapplied. Before reinstalling, administrators should review the current configuration and installation targets to ensure that the expected configuration is being deployed. Reinstallation should be performed carefully because it can overwrite local differences that were not incorporated into FortiManager.

Question 350

Which information is particularly useful when investigating a failed policy installation?

  1. Installation logs
  2. Administrator profile color
  3. Browser bookmarks
  4. Device group description

Correct Answer: 1

Explanation

Installation logs provide detailed information about what occurred during a policy or configuration deployment. They can show errors, failed operations, rejected commands, communication issues, or other conditions that prevented successful installation. Reviewing the log helps administrators determine where the process stopped instead of relying only on a general failure message. When troubleshooting, the log should be considered together with device connectivity, configuration differences, and the current status of the affected FortiGate.

Question 351

What can cause a FortiManager configuration installation to fail because of connectivity?

  1. An unreachable target FortiGate
  2. A correctly named policy
  3. A valid object reference
  4. A successful installation preview

Correct Answer: 1

Explanation

An unreachable target FortiGate can prevent FortiManager from completing a configuration installation. Management communication is required for the deployment process, so routing problems, firewall restrictions, NAT issues, or an unavailable device can interrupt the operation. Administrators should verify device connectivity and management status before repeatedly attempting installation. If connectivity is restored, the installation can be retried after reviewing any remaining errors. Network troubleshooting is therefore an important part of resolving failed deployments.

Question 352

What is a configuration revision useful for when troubleshooting an unexpected policy change?

  1. It identifies previous configuration states
  2. It increases available disk space
  3. It changes FortiGuard servers
  4. It creates device groups

Correct Answer: 1

Explanation

Configuration revisions provide historical states that administrators can review when investigating unexpected policy or configuration changes. By comparing revisions, an administrator can determine what changed and potentially identify when an unwanted modification was introduced. Revision information is especially valuable in environments where several administrators manage the same ADOM or policy package. Before reverting any configuration, administrators should verify the intended revision and understand the potential impact of restoring it.

Question 353

What should an administrator do before reverting to an earlier configuration revision?

  1. Confirm that the selected revision contains the desired configuration
  2. Delete the current ADOM
  3. Disable all FortiGuard services
  4. Remove every policy package

Correct Answer: 1

Explanation

Before reverting a configuration, the administrator should confirm that the selected revision contains the desired state and that restoring it will address the problem. Reviewing the revision history and comparing configuration differences can help identify the appropriate version. Administrators should also consider changes made after that revision because reverting may remove legitimate updates. A controlled review before restoration reduces the chance of replacing a current configuration with an unsuitable or incomplete historical state.

Question 354

Which database stores configuration information associated with devices managed within an ADOM?

  1. FortiGuard database
  2. Device database
  3. ADOM database
  4. Firmware cache

Correct Answer: 3

Explanation

The ADOM database contains configuration information associated with the devices and management objects within that Administrative Domain. It represents the configuration state maintained by FortiManager for the ADOM. The device database is another important concept used when comparing or troubleshooting managed configurations, but the ADOM database specifically represents the centralized configuration information maintained within the ADOM. Understanding these database layers helps administrators diagnose synchronization and configuration discrepancies.

Question 355

Why might an administrator compare the device database with the ADOM database?

  1. To identify configuration differences
  2. To renew an administrator license
  3. To create a firmware image
  4. To change the FortiManager hostname

Correct Answer: 1

Explanation

Comparing the device database with the ADOM database can help identify differences between configuration information associated with the managed device and the centralized ADOM configuration. Such differences may indicate configuration drift, incomplete synchronization, local changes, or another management issue. Administrators can use the comparison as part of troubleshooting before deciding whether to retrieve, install, or revert configuration. Understanding which database contains the unexpected state helps determine the appropriate corrective action.

Question 356

What is an important consideration after a FortiGate is replaced in a FortiManager-managed environment?

  1. Verify the replacement device is correctly associated and synchronized
  2. Delete all policy packages
  3. Disable FGFM permanently
  4. Remove the ADOM

Correct Answer: 1

Explanation

After replacing a managed FortiGate, the administrator should verify that the replacement device is correctly associated with FortiManager and that the expected management and configuration state is synchronized. Device identity, registration, connectivity, and configuration should be checked before production deployment. The replacement process should not be treated as simply connecting a new appliance and assuming that all previous relationships are automatically correct. Verification helps ensure that the replacement receives the intended configuration without introducing management conflicts.

Question 357

Which condition should be investigated if FortiManager reports that a managed device is out of synchronization?

  1. Configuration differences between FortiManager and the device
  2. Browser font selection
  3. Administrator screen resolution
  4. Policy icon size

Correct Answer: 1

Explanation

A synchronization warning indicates that the configuration state known to FortiManager and the state on the managed device may differ. Administrators should investigate configuration differences to determine whether changes were made locally, an installation failed, or synchronization did not complete. Comparing the relevant configurations and reviewing revision or installation information can help identify the cause. Administrators should avoid blindly overwriting the device until they understand which configuration represents the intended operational state.

Question 358

What is one reason to use separate policy packages for different environments?

  1. To isolate configurations for different operational requirements
  2. To increase FortiManager hardware speed
  3. To disable configuration revisions
  4. To replace FortiGuard updates

Correct Answer: 1

Explanation

Separate policy packages can help isolate configurations when different environments have different security or operational requirements. For example, development, testing, and production environments may require distinct firewall policies even when they are managed from the same FortiManager. Separate packages reduce the risk of unintentionally applying environment-specific rules to another group of devices. Administrators should still maintain clear naming, target assignments, and review procedures so that each package is deployed only to its intended devices.

Question 359

What should be reviewed before deleting a duplicate configuration object?

  1. Its references and dependencies
  2. The FortiManager serial number only
  3. The browser version
  4. The administrator’s username length

Correct Answer: 1

Explanation

Before deleting a duplicate object, administrators should review its references and dependencies to determine whether policies or other configuration elements still use it. Two objects may appear identical but have different references or purposes. Removing one without checking dependencies can cause policy validation or installation problems. A careful review allows administrators to identify which object should remain and whether dependent policies need to be updated before cleanup is performed.

Question 360

Why should administrators verify device status after a major configuration deployment?

  1. To confirm the intended configuration reached the target devices
  2. To change the ADOM operating mode
  3. To create additional firmware cache
  4. To disable policy validation

Correct Answer: 1

Explanation

Verifying device status after a major deployment helps confirm that the configuration reached the intended FortiGate devices and that the managed state is consistent. Administrators can review installation results, synchronization information, and device status to identify incomplete or failed deployments. This post-installation verification is particularly important when changes affect multiple devices because one target may succeed while another encounters a connectivity or configuration problem. Confirming the final state provides stronger assurance than relying only on the installation completion message.