View Full Fortinet FCP_FMG_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 101
A FortiManager administrator wants to create a reusable configuration that can be applied to multiple FortiGate devices while allowing certain values to differ for each device. Which capability is most appropriate?
- Configuration revision
- Installation history
- Device-specific variables
- FortiGuard cache
Correct Answer: 3
Explanation
Device-specific variables allow a common configuration to be reused while individual FortiGate devices receive different values where required. This is useful for settings such as IP addresses, interface-related values, hostnames, or other parameters that vary between branches. Instead of creating a separate configuration for every device, administrators can maintain a standardized template and assign appropriate values to each target. This improves consistency and reduces repetitive work. Administrators should validate variable values carefully before deployment because an incorrect value can affect connectivity or device behavior after the configuration is installed.
Question 102
A FortiManager administrator is preparing a configuration template for several FortiGate devices. Which consideration is important when the devices require different values for the same configuration field?
- Use metadata or device-specific variables
- Disable ADOM management
- Delete all shared objects
- Disable configuration validation
Correct Answer: 1
Explanation
Metadata or device-specific variables can allow a common configuration template to accommodate values that differ between target FortiGate devices. This approach is useful in environments where devices follow the same configuration structure but require unique addresses, interface values, hostnames, or other parameters. Using variables reduces the need to create separate templates for every device. Administrators should document variable requirements and verify each device’s assigned values before installation. Proper variable management helps maintain standardized configurations while still accommodating legitimate differences between branch or site deployments.
Question 103
Which FortiManager capability allows administrators to execute a predefined set of CLI commands on managed FortiGate devices?
- CLI scripts
- Security Rating
- Device Groups
- Global Database
Correct Answer: 1
Explanation
CLI scripts allow administrators to store and execute predefined command sequences on managed FortiGate devices. They are useful for repetitive configuration tasks, operational changes, and situations where a required command sequence is not conveniently performed through the graphical interface. Scripts can be targeted to appropriate devices and may be scheduled when supported by the workflow. Administrators should test scripts carefully before using them in production because incorrect commands can cause configuration problems. Script content should also be reviewed for compatibility with the FortiOS versions and device models involved.
Question 104
An administrator wants a CLI script to execute automatically at a scheduled time instead of manually starting it. Which feature should be configured?
- Script scheduling
- Device replacement
- Policy cloning
- Revision comparison
Correct Answer: 1
Explanation
Script scheduling allows administrators to configure a CLI script for execution at a specified time or according to an appropriate schedule. This can be useful for recurring administrative tasks or changes that must occur during a maintenance window. Scheduling reduces the need for manual execution but requires careful planning. Administrators should verify the target devices, script commands, timing, and expected impact before enabling a scheduled operation. If a scheduled script fails, connectivity, permissions, command compatibility, and execution logs should be reviewed to determine the cause.
Question 105
A CLI script executes successfully on one FortiGate but fails on another model because the command is unsupported. What should the administrator investigate?
- Command compatibility with the target FortiOS and device
- FortiManager administrator password length
- Security Rating score
- Global policy assignment
Correct Answer: 1
Explanation
CLI commands can vary according to FortiOS version, feature availability, and device model. A command that works on one FortiGate may fail on another if the required feature or syntax is unavailable. Administrators should verify the command against the target FortiOS version and device capabilities before using the script across multiple devices. Scripts intended for heterogeneous environments should be tested on representative devices first. If necessary, administrators can separate devices into appropriate groups or use conditional approaches so that unsupported commands are not executed against incompatible targets.
Question 106
A FortiManager administrator notices that a scheduled script did not run on a target FortiGate. Which issue should be checked first?
- Whether the FortiGate has valid management connectivity
- Whether the policy package contains unused objects
- Whether the Security Rating changed
- Whether the global database is enabled
Correct Answer: 1
Explanation
Management connectivity should be checked when a scheduled script does not execute on a target FortiGate. FortiManager needs an appropriate management communication path to deliver and execute centralized operations. Administrators should verify device status, FGFM communication, network reachability, and any relevant authentication or management settings. Execution history and logs can then provide additional information about the failure. Checking connectivity first helps distinguish communication problems from script syntax or command compatibility problems. Once communication is confirmed, the administrator can investigate the script itself if the operation continues to fail.
Question 107
A company wants FortiManager to retain previous configuration states so administrators can identify when a problematic change was introduced. Which feature should be used?
- Device Groups
- Configuration revision history
- FortiGuard query server
- Interface mapping
Correct Answer: 2
Explanation
Configuration revision history records previous configuration states and provides a reference for investigating changes over time. When a problem appears after a configuration modification, administrators can compare revisions to determine what changed and identify a potentially relevant modification. Revision history can also support change auditing and controlled rollback procedures. Administrators should review the appropriate revision before restoring anything because later changes may contain legitimate updates. Maintaining revision history is particularly valuable in centralized management environments where configuration changes can affect several devices and need to be traced accurately.
Question 108
A FortiManager administrator identifies a previous configuration revision that represents a known-good state. What can revision management help the administrator accomplish?
- Compare or revert configuration changes
- Increase FortiGate interface speed
- Replace the FortiManager hardware automatically
- Disable all firewall policies
Correct Answer: 1
Explanation
Revision management allows administrators to review historical configurations and, when appropriate, revert configuration changes to an earlier state. This can be useful when a recent modification causes unexpected behavior and a known-good configuration is available. Administrators should first compare the relevant revisions and understand which changes would be removed by a rollback. A rollback should follow the organization’s change-management process, particularly for production systems. Revision management provides a controlled method for tracking configuration evolution and recovering from problematic changes without manually reconstructing the previous configuration.
Question 109
A FortiManager administrator needs to determine whether a configuration changed automatically because of synchronization or an update process. Which information can provide useful evidence?
- Revision history and configuration change records
- Device group names only
- FortiGuard cache size only
- Policy object colors
Correct Answer: 1
Explanation
Revision history and configuration change records can help administrators determine when configuration changes occurred and identify differences between configuration states. This information is useful when investigating changes that were not manually expected. By comparing revisions and reviewing associated records, administrators can establish whether a configuration was modified and determine what changed. Additional logs may be required to identify the exact source of a change. Keeping historical configuration information provides valuable evidence during troubleshooting and makes it easier to distinguish intentional modifications from unexpected synchronization or update activity.
Question 110
Which FortiManager capability is designed to help administrators identify differences between the configuration stored in FortiManager and the configuration on a managed FortiGate?
- Configuration comparison
- FortiGuard Web Filtering
- Security Rating
- Firmware cache
Correct Answer: 1
Explanation
Configuration comparison helps administrators identify differences between the configuration maintained in FortiManager and the configuration currently present on a managed FortiGate. Such differences can occur after local changes, incomplete installations, or other configuration events. Identifying the differences allows administrators to determine which configuration should be retained and what corrective action is required. This process is important for preventing accidental overwrites. Administrators should review the changes carefully before synchronizing configurations because either side may contain legitimate modifications that need to be preserved.
Question 111
A FortiManager administrator needs to check whether a managed FortiGate has made local changes that have not been incorporated into the centralized configuration. Which task is most relevant?
- Compare the device configuration with the FortiManager database
- Clear the firmware cache
- Create a new administrator profile
- Modify the Security Rating
Correct Answer: 1
Explanation
Comparing the device configuration with the FortiManager database can reveal local changes that have not been incorporated into centralized management. Direct changes made on a FortiGate can create configuration drift, resulting in differences between the device and FortiManager. Administrators should review those differences before deciding whether to retrieve the device configuration, keep the centrally managed version, or reconcile the two states. This process helps prevent legitimate local changes from being accidentally overwritten. Regular comparison is especially useful in environments where direct FortiGate administration is restricted but still possible.
Question 112
A company wants to maintain high availability for its FortiManager management platform. Which feature should be considered?
- FortiManager HA
- Policy object cleanup
- Interface mapping
- CLI script scheduling
Correct Answer: 1
Explanation
FortiManager HA provides a mechanism for maintaining management availability by using multiple FortiManager units in an HA configuration. The design can help reduce the impact of a failure affecting one FortiManager unit. HA planning should consider synchronization, network connectivity, configuration consistency, and the organization’s recovery requirements. Administrators should understand how the selected HA design handles primary and secondary roles and what occurs during a failure. High availability does not eliminate the need for backups and operational procedures; it should be part of a broader management-platform resilience strategy.
Question 113
In a FortiManager HA deployment, why is configuration synchronization between HA members important?
- It keeps relevant management information consistent between members
- It automatically upgrades every FortiGate
- It removes all ADOMs from the primary unit
- It prevents administrators from using policies
Correct Answer: 1
Explanation
Configuration synchronization helps keep the relevant FortiManager management information consistent between HA members. If the active member becomes unavailable, the other member needs an appropriate synchronized state to continue management operations according to the HA design. Administrators should monitor synchronization status and investigate discrepancies promptly. Network connectivity, configuration changes, and HA health can affect synchronization. Maintaining consistent HA members reduces the risk that a failover will expose outdated or incomplete management information. HA synchronization should therefore be monitored as part of routine FortiManager administration.
Question 114
A FortiManager administrator is investigating an HA event and needs to determine which unit is currently serving the active management role. Which information should be reviewed?
- HA status and member role
- Unused object list
- Policy package name only
- FortiGuard firmware cache
Correct Answer: 1
Explanation
HA status and member-role information identify the operational state of FortiManager HA members and indicate which unit is currently serving the active role according to the configured HA design. This information is useful during troubleshooting because administrators need to know which unit is handling management operations and whether the standby member is healthy. Reviewing HA status can also reveal synchronization or communication problems between members. Administrators should check HA health before making changes during an incident so that troubleshooting actions do not unintentionally interfere with failover or synchronization.
Question 115
A FortiManager administrator needs to troubleshoot a managed FortiGate that suddenly stops communicating with FortiManager. Which management protocol should be reviewed first?
- HTTP
- FGFM
- SMTP
- DNS
Correct Answer: 2
Explanation
FGFM is the FortiGate-to-FortiManager management protocol used for communication between managed FortiGate devices and FortiManager. When a managed device unexpectedly stops communicating, administrators should verify the FGFM communication path and related connectivity. Network reachability, management settings, authentication, NAT behavior, and device status may all need to be checked. Reviewing the relevant communication state can help determine whether the problem is network-related or associated with FortiManager or FortiGate configuration. Understanding FGFM is therefore important when diagnosing device registration, synchronization, and management communication problems.
Question 116
A FortiGate is located behind a NAT device and must communicate with a FortiManager located on another network. What should the administrator consider?
- NAT and the required management communication path
- Only the FortiGate policy package name
- Only the FortiManager administrator profile
- Only the number of unused objects
Correct Answer: 1
Explanation
When a FortiGate is behind NAT, administrators must consider how NAT affects the management communication path between the FortiGate and FortiManager. The required ports, routing, address translation, and management communication behavior must be compatible with the deployment. Troubleshooting should include checking reachability and the relevant management communication status. NAT can change how endpoints appear to each other, so administrators should verify that the architecture supports the intended FGFM connection. Correctly planning NAT-related connectivity is essential for reliable centralized management of FortiGate devices.
Question 117
A FortiManager administrator wants to use the appliance to provide cached FortiGuard updates to managed FortiGate devices. Which capability should be configured?
- FortiManager as a local FortiGuard server or cache
- Device Group hierarchy
- Policy package cloning
- Configuration revision rollback
Correct Answer: 1
Explanation
FortiManager can provide FortiGuard services through local caching and related distribution capabilities. This can allow managed FortiGate devices to obtain supported FortiGuard updates through FortiManager rather than each device independently retrieving every required update from external FortiGuard infrastructure. Such an architecture can reduce repeated external downloads and may be useful in controlled or bandwidth-sensitive environments. Administrators should verify licensing, service configuration, connectivity, and update status when deploying this capability. Troubleshooting should include checking whether FortiManager can reach the appropriate FortiGuard services and whether managed devices are correctly configured to use it.
Question 118
Which FortiGuard-related capability can reduce repeated downloads by storing update packages locally on FortiManager?
- Firmware cache
- Administrative profile
- Interface mapping
- Revision history
Correct Answer: 1
Explanation
The firmware cache allows FortiManager to retain supported firmware images locally so that administrators can use cached files when managing firmware deployments. Local caching can reduce repeated downloads from external sources and make firmware distribution to managed devices more efficient. Administrators should manage cached firmware carefully because storage capacity is limited and obsolete images may no longer be required. Before performing firmware upgrades, administrators should also verify device compatibility, licensing, and the intended target version. Firmware caching is primarily an efficiency and distribution capability rather than a replacement for upgrade planning.
Question 119
A FortiManager administrator needs to confirm whether the organization’s FortiGuard services are properly licensed before troubleshooting update problems. What should be checked?
- FortiGuard contract and license information
- Device group names
- Policy package order only
- Administrator browser settings
Correct Answer: 1
Explanation
FortiGuard contract and license information should be checked when troubleshooting FortiGuard service or update problems. An expired or unavailable entitlement can prevent expected services from operating correctly, so verifying contract status is an important troubleshooting step. Administrators should also review connectivity, service configuration, and relevant FortiGuard status information. Checking licensing first helps distinguish entitlement problems from network or configuration problems. A complete troubleshooting process should combine contract verification with connection-status checks and appropriate diagnostic information rather than assuming that every update failure is caused by network connectivity.
Question 120
A company wants to apply a common security policy across several ADOMs while allowing each ADOM to maintain its own local policies. Which FortiManager design best supports this requirement?
- Use only separate local policies
- Use the Global Database ADOM for shared policies and local policies within individual ADOMs
- Disable all ADOMs
- Place every device into one policy package
Correct Answer: 2
Explanation
The Global Database ADOM allows organizations to maintain shared policies and objects that can be assigned to appropriate ADOMs while still preserving local policy management within each individual ADOM. This design supports centralized enforcement of common security requirements without requiring every ADOM to contain duplicated versions of the same global rules. Administrators can use global policies for organization-wide controls and local policies for environment-specific requirements. Policy order and target assignments should be reviewed carefully before installation because a global rule can affect traffic across multiple administrative domains.