Fortinet NSE 5 NSE5_FMG-7.0 Exam Study Guides
NSE5_FMG-
7.0
Exam Dumps
Questions
NSE5_FMG-7.0 Exam Dumps
Questions
1.Which of the following statements are true regarding
reverting to previous revision version from the revision
history? (Choose two.)
A. To push these changes to a managed device, it required
an install operation to the managed FortiGate.
B. Reverting to a previous revision history will generate a
new version ID and remove all other history
versions.
C. Reverting to a previous revision history will tag the
device settings status as Auto-Update.
D. It will modify device-level database
NSE5_FMG-7.0 Exam Dumps
Questions
2.Which of the following statements are true regarding
VPN Gateway configuration in VPN Manager? (Choose
two.)
A. Managed gateways are devices managed by
FortiManager in the same ADOM
B. External gateways are third-party VPN gateway devices
only
C. Protected subnets are the subnets behind the device
that you don’t want to allow access to over the IPsec VPN
D. Managed devices in other ADOMs must be treated as
external gateways
NSE5_FMG-7.0 Exam Dumps
Questions
3.Which of the following statements are true regarding
VPN Manager? (Choose three.)
A. VPN Manager must be enabled on a per ADOM basis.
B. VPN Manager automatically adds newly-registered
devices to a VPN community.
C. VPN Manager can install common IPsec VPN settings on
multiple FortiGate devices at the same time.
D. Common IPsec settings need to be configured only once
in a VPN Community for all managed gateways.
E. VPN Manager automatically creates all the necessary
firewall policies for traffic to be tunneled by IPsec.
NSE5_FMG-7.0 Exam Dumps
4.An administrator wQoulud elikse ttoi oaunthsorize a newly-
installed AP using AP Manager. What steps does the
administrator need to perform to authorize an AP?
A. Authorize the new AP using AP Manager and wait until
the change is updated on the FortiAP. Changes to the AP's
state do not require installation.
B. Changes to the AP's state must be performed directly
on the managed FortiGate.
C. Authorize the new AP using AP Manager and install the
policy package changes on the managed FortiGate.
D. Authorize the new AP using AP Manager and install the
device level settings on the managed FortiGate.
NSE5_FMG-7.0 Exam Dumps
Questions
5.Which of the following statements are true
regarding schedule backup of FortiManager?
(Choose two.)
A. Backs up all devices and the FortiGuard
database.
B. Does not back up firmware images saved on
FortiManager
C. Supports FTP, SCP, and SFTP
D. Can be configured from the CLI and GUI
NSE5_FMG-7.0 Exam Dumps
Questions
6.An administrator has added all the devices in a
Security Fabric group to FortiManager. How does
the administrator identify the root FortiGate?
A. By a dollar symbol ($) at the end of the device
name
B. By an at symbol (@) at the end of the device
name
C. By a QUESTION NO: mark(?) at the end of the
device name
D. By an Asterisk (*) at the end of the device
name
NSE5_FMG-7.0 Exam Dumps
Questions
7.What does a policy package status of Modified indicate?
A. FortiManager is unable to determine the policy package
status
B. The policy package was never imported after a device
was registered on FortiManager
C. The Policy configuration has been changed on a
managed device and changes have not yet been imported
into FortiManager
D. The Policy package configuration has been changed on
FortiManager and changes have not yet been installed on
the managed device.
NSE5_FMG-7.0 Exam Dumps
8.An administratoQr wuoeusldt liioken tso create an SD-
WAN default static route for a newly created SD-
WAN using the FortiManager GUI. Both port1 and
port2 are part of the SD-WAN member
interfaces. Which interface must the
administrator select in the static route device
drop-down list?
A. port2
B. virtual-wan-link
C. port1
D. auto-discovery
NSE5_FMG-7.0 Exam Dumps
Questions
9.An administrator would like to create an SD-WAN using
central management. What steps does the administrator
need to perform to create an SD-WAN using central
management?
A. First create an SD-WAN firewall policy, add member
interfaces to the SD-WAN template and create a static
route
B. You must specify a gateway address when you create a
default static route
C. Remove all the interface references such as routes or
policies
D. Enable SD-WAN central management in the ADOM, add
member interfaces, create a static route and SDWAN
firewall policies.
NSE5_FMG-7.0 Exam Dumps
Questions
10.What does the diagnose dvm check-integrity
command do? (Choose two.)
A. Internally upgrades existing ADOMs to the
same ADON version in order to clean up and
correct the ADOM syntax
B. Verifies and corrects unregistered, registered,
and deleted device states
C. Verifies and corrects database schemas in all
object tables
D. Verifies and corrects duplicate VDOM entries
NSE5_FMG-7.0 Exam Dumps
1.Answer: AD Answers
2.Answer: AD
3.Answer: A,C,D
4.Answer: D
5.Answer: BC
6.Answer: D
7.Answer: D
8.Answer: B
9.Answer: D
10.Answer: BD
Comments