Fortinet FCP_FMG_AD-7.6 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full Fortinet FCP_FMG_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 61

A FortiManager administrator wants to allow a junior administrator to modify firewall policies but prevent that administrator from changing system settings. Which approach provides this separation?

  1. Assign a restricted administrative profile
  2. Create a second FortiManager database
  3. Disable the ADOM
  4. Remove the administrator from Device Manager

Correct Answer: 1

Explanation

FortiManager administrative profiles allow organizations to define which management functions an administrator can access. A restricted profile can provide access to policy-related tasks while preventing access to unrelated system or administrative settings. This follows the principle of least privilege and reduces the impact of accidental or unauthorized changes. Administrators should assign only the permissions required for the individual’s responsibilities and review those permissions periodically. Combining administrative profiles with ADOM-level access can provide additional separation when multiple teams or customers are managed through the same FortiManager.

Question 62

A security team manages several customers through one FortiManager appliance. Each customer should have administrators who can manage only their own devices. Which combination is most appropriate?

  1. One global administrator account
  2. Separate ADOMs with appropriate administrator permissions
  3. One shared policy package
  4. One Device Manager view

Correct Answer: 2

Explanation

Separate ADOMs combined with appropriate administrator permissions can provide logical management separation for different customers. Each customer can have devices and configurations maintained within its designated ADOM, while administrators can be restricted to the ADOMs they are authorized to manage. This design helps prevent accidental changes to another customer’s environment and supports delegated administration. Administrators should also use appropriate profiles within each ADOM so users receive only the permissions necessary for their responsibilities. This approach provides stronger administrative isolation than simply organizing devices within one common policy package.

Question 63

An administrator needs to change the FortiManager administrator password policy to require stronger passwords. Which area should be reviewed?

  1. System settings
  2. Policy package
  3. Device group
  4. FortiGate firewall policy

Correct Answer: 1

Explanation

Password and administrator authentication settings are managed through FortiManager’s system and administrative configuration rather than through FortiGate policy packages. Security teams should configure strong password requirements and apply additional authentication controls where supported. Administrative credentials are highly privileged, so protecting them is essential to the security of the centralized management platform. Administrators should also consider limiting management access by trusted networks, using multi-factor authentication where available, and reviewing administrator accounts regularly. Strong authentication controls reduce the likelihood that compromised credentials can be used to modify managed FortiGate configurations.

Question 64

A FortiManager administrator wants to restrict management access to the appliance so that administrators can connect only from approved network addresses. Which security control should be considered?

  1. Trusted hosts
  2. Policy package
  3. Device template
  4. FortiGuard cache

Correct Answer: 1

Explanation

Trusted hosts can restrict administrative access to specified source IP addresses or networks. This provides an additional security layer for FortiManager administrator accounts because even valid credentials may not be usable from unauthorized locations. Trusted-host restrictions should be configured carefully to avoid locking out legitimate administrators, particularly when management networks change. Organizations should combine this control with strong authentication, least-privilege administrative profiles, and secure management protocols. Restricting administrative access to known management networks can significantly reduce the exposure of a highly privileged centralized management platform.

Question 65

A company wants administrators to authenticate to FortiManager using an external identity service instead of maintaining separate local passwords. Which authentication approach can support this design?

  1. Remote authentication
  2. Policy package installation
  3. Device firmware caching
  4. Configuration revision

Correct Answer: 1

Explanation

Remote authentication allows FortiManager administrator authentication to be integrated with supported external authentication services. This can reduce the need to maintain independent local passwords and can centralize authentication management. Depending on the configured service and architecture, administrators may use protocols or identity systems supported by FortiManager. Security teams should ensure that remote authentication servers are highly available and that appropriate administrator mappings and permissions are configured. Local administrative access should also be protected as a recovery mechanism. Centralized authentication can simplify account lifecycle management and improve administrative control.

Question 66

A FortiManager administrator wants to create a new administrator who can view configurations but cannot modify them. Which permission level is most appropriate?

  1. Read-only access
  2. Super administrator
  3. Full configuration access
  4. System administrator

Correct Answer: 1

Explanation

Read-only access allows an administrator to view relevant management information without providing permissions to make configuration changes. This is useful for auditors, monitoring personnel, or junior administrators who need visibility but should not alter production configurations. Using read-only permissions supports least privilege and reduces the risk of accidental changes. The exact access should be scoped further according to ADOM and administrative-profile requirements. Organizations should regularly review accounts with management access and remove permissions that are no longer necessary.

Question 67

A FortiManager administrator wants to maintain a record of administrative actions performed by users on the management platform. Which capability should be reviewed?

  1. Administrative event logs
  2. FortiGuard cache
  3. Policy package objects
  4. Device firmware cache

Correct Answer: 1

Explanation

Administrative event logs provide information about management actions performed within FortiManager. These logs can help security teams investigate configuration changes, identify which administrator performed an action, and support auditing requirements. Monitoring administrative activity is particularly important on centralized management systems because a single compromised account could potentially affect multiple FortiGate devices. Logs should be protected from unauthorized modification and retained according to organizational requirements. Regular review of administrator activity can help identify unexpected changes and support incident investigations involving privileged management accounts.

Question 68

A security team wants to make sure a FortiManager administrator cannot create another administrator with greater privileges than the administrator’s own assigned permissions. Which principle should guide the configuration?

  1. Least privilege
  2. Maximum bandwidth
  3. Load balancing
  4. Policy ordering

Correct Answer: 1

Explanation

The principle of least privilege requires administrators to receive only the permissions necessary to perform their assigned responsibilities. Applying this principle to FortiManager administrative accounts helps prevent delegated users from obtaining excessive control over the centralized management environment. Administrator profiles and permission scopes should be designed so that users cannot escalate their management capabilities beyond their authorized responsibilities. This is particularly important because FortiManager can control multiple FortiGate devices. Limiting administrative privileges reduces the potential impact of compromised credentials, mistakes, or intentional misuse.

Question 69

A FortiManager administrator needs to review the current status of managed FortiGate devices, including whether devices are online and reachable. Which area is most useful?

  1. Device Manager
  2. Policy Package editor
  3. FortiGuard cache
  4. Object browser

Correct Answer: 1

Explanation

Device Manager provides centralized visibility into managed FortiGate devices and their management status. Administrators can use it to determine whether devices are reachable, identify device states, and access device-management operations. This information is useful when troubleshooting policy installation or synchronization problems because a device that cannot communicate with FortiManager may not receive configuration changes. Administrators should review device status before starting installations and investigate connectivity problems when necessary. Maintaining accurate device status information helps ensure that centralized configuration deployments are directed toward available and correctly managed FortiGate appliances.

Question 70

A company wants to create a logical hierarchy for organizing FortiGate devices based on geographic regions and branch types. Which FortiManager structure can help organize these devices?

  1. Device Groups
  2. FortiGuard servers
  3. Configuration revisions
  4. Administrative profiles

Correct Answer: 1

Explanation

Device Groups can be used to organize managed FortiGate devices according to criteria such as geographic region, business function, or branch type. Logical grouping makes large FortiManager environments easier to administer and can simplify operations involving similar devices. For example, administrators might create groups for regional offices or specific branch architectures. Device Groups do not themselves replace ADOMs or administrative profiles; rather, they provide an organizational structure for devices within the management environment. Proper grouping can improve operational efficiency and reduce errors when selecting devices for management operations.

Question 71

A FortiManager administrator needs to move a managed FortiGate from one device group to another without removing the device from centralized management. What should be changed?

  1. The device group assignment
  2. The FortiGate serial number
  3. The ADOM firmware version
  4. The FortiManager database format

Correct Answer: 1

Explanation

Changing the device group assignment allows administrators to reorganize a managed FortiGate without removing its management relationship with FortiManager. Device groups are organizational structures that help administrators manage collections of devices according to business or operational requirements. Moving a device between groups does not require changing its serial number or rebuilding the FortiManager database. Before making organizational changes, administrators should confirm that group membership does not affect any associated workflows, policies, or automation. Proper device organization makes large FortiManager deployments easier to manage and maintain.

Question 72

A company wants to apply different configuration settings to FortiGate devices depending on their branch location while still using a common template. Which capability is most useful?

  1. Per-device variables
  2. FortiGuard Web Filtering
  3. Log View
  4. Security Rating

Correct Answer: 1

Explanation

Per-device variables allow a common configuration template to contain values that differ between individual FortiGate devices. This is useful when branch locations require different IP addresses, interface values, hostnames, or other device-specific parameters while retaining the same overall configuration structure. Administrators can maintain one reusable template and provide appropriate values for each target device. This reduces duplication and makes configuration changes easier to maintain. Before deployment, administrators should verify variable values carefully because an incorrect value can cause connectivity problems or incorrect policy behavior on the affected device.

Question 73

A FortiManager administrator wants to prevent accidental installation of a policy package to the wrong FortiGate. Which practice is most effective before deployment?

  1. Verify the installation target and review the installation preview
  2. Disable FortiGuard services
  3. Delete unused objects
  4. Restart the FortiManager appliance

Correct Answer: 1

Explanation

Verifying the installation target and reviewing the installation preview are important safeguards against deploying a configuration to the wrong FortiGate. Centralized management makes it possible to affect multiple devices quickly, so administrators should confirm both the intended device and the exact changes before installation. Reviewing the proposed configuration can reveal incorrect targets, unexpected policy modifications, or object changes. Organizations should also use change-management procedures and appropriate approval workflows for production changes. These controls reduce the likelihood of accidental configuration deployment to an unintended branch or device.

Question 74

A security team wants to maintain multiple versions of a FortiGate configuration so an earlier known-good state can be referenced during troubleshooting. Which FortiManager feature supports this requirement?

  1. Configuration revision history
  2. FortiGuard cache
  3. Device group
  4. Policy installation target

Correct Answer: 1

Explanation

Configuration revision history allows administrators to maintain and review previous configuration states. This is useful when troubleshooting because an administrator can compare a current configuration with an earlier known-good version to identify changes that may have introduced a problem. Revision history can also support auditing and change-management processes. Administrators should understand the distinction between reviewing an earlier configuration and actually restoring it to a production device. Any restoration or rollback should be performed carefully after confirming the appropriate revision and considering changes made since that revision.

Question 75

A FortiManager administrator wants to create a reusable firewall policy package based on an existing package without rebuilding every policy manually. Which operation is most appropriate?

  1. Clone the policy package
  2. Delete the original package
  3. Reset the ADOM
  4. Reinstall FortiManager

Correct Answer: 1

Explanation

Cloning a policy package allows administrators to create a new package based on an existing set of policies and objects rather than rebuilding everything manually. This can be useful when a new group of FortiGate devices requires a similar security policy but needs some modifications. After cloning, administrators should review addresses, interfaces, services, schedules, and other policy elements before installing the package. Cloning saves administrative effort while allowing the new package to be customized. Proper review is important because inherited policies may not be appropriate for every target environment.

Question 76

A company wants to maintain separate policy packages for development and production FortiGate environments. What is the primary benefit of this design?

  1. It provides separate policy management for different environments
  2. It forces both environments to use identical rules
  3. It eliminates the need for ADOMs
  4. It disables configuration revisions

Correct Answer: 1

Explanation

Separate policy packages allow administrators to maintain distinct security policies for different environments. Development and production systems often have different connectivity requirements, access patterns, and security controls, so maintaining separate policy structures can prevent accidental deployment of inappropriate rules. Administrators can still use common objects or templates where appropriate, but the final policies should reflect each environment’s requirements. Separating policy packages also supports controlled testing because changes can be validated in a development environment before similar configurations are introduced into production.

Question 77

A FortiManager administrator needs to determine whether a FortiGate has unsaved local configuration changes that differ from the centralized configuration. Which concept is most relevant?

  1. Configuration revision mismatch
  2. FortiGuard rating
  3. Device firmware cache
  4. Policy schedule

Correct Answer: 1

Explanation

A configuration revision mismatch can indicate that the device configuration differs from the configuration maintained centrally in FortiManager. This can occur when an administrator makes direct changes on the FortiGate or when centralized changes have not yet been installed. Reviewing the configuration difference allows administrators to determine which state should be retained. Configuration drift should be addressed carefully because blindly overwriting the device or FortiManager version can remove legitimate changes. Organizations should establish clear procedures defining where configuration changes are permitted and how discrepancies should be resolved.

Question 78

A security administrator wants to prevent a policy package from being installed until another administrator reviews the proposed changes. Which FortiManager workflow capability should be used?

  1. Approval workflow
  2. FortiGuard cache
  3. Device replacement
  4. Firmware download

Correct Answer: 1

Explanation

An approval workflow can require configuration changes to be reviewed before they are committed or installed. This provides an additional control for production environments where changes should not be deployed by a single administrator without oversight. Approval processes can help organizations implement separation of duties and reduce the risk of unauthorized or accidental policy modifications. Administrators should define who can submit changes, who can approve them, and who can perform installation. Combining workflow controls with administrator profiles and audit logs provides stronger governance over centralized firewall configuration changes.

Question 79

A FortiManager administrator wants to inspect the history of a previous policy installation to determine what was deployed and whether errors occurred. Which information should be reviewed?

  1. Installation history
  2. Device group hierarchy
  3. FortiGuard database
  4. Administrator password policy

Correct Answer: 1

Explanation

Installation history records information about previous deployment operations and can help administrators determine what was installed and whether the operation completed successfully. This is useful when troubleshooting unexpected firewall behavior or investigating when a configuration change was introduced. Administrators can use installation records alongside configuration revisions and device logs to reconstruct the sequence of events. Reviewing deployment history is an important operational practice in centralized management environments because policy changes can affect many devices and may need to be traced during troubleshooting or security investigations.

Question 80

A company wants to reduce configuration errors when deploying a common FortiGate configuration to many branches. Which approach is most appropriate?

  1. Configure each FortiGate manually
  2. Use standardized templates and controlled centralized deployment
  3. Disable configuration validation
  4. Allow all administrators to modify devices directly

Correct Answer: 2

Explanation

Standardized templates combined with controlled centralized deployment can reduce configuration errors across multiple branch FortiGate devices. Templates provide a reusable configuration structure, while FortiManager provides centralized deployment and management. Administrators can use device-specific variables where necessary and validate changes before installation. This approach reduces repetitive manual configuration and improves consistency. Direct administration of every device by multiple users increases the risk of configuration drift and inconsistent security settings. A controlled centralized process also makes changes easier to review, audit, and troubleshoot.