Skip to content

FCP-FMG-AD-7-6 Fortinet FCP - FortiManager 7.6 Administrator Practice Questions

Prepare for FCP-FMG-AD-7-6 with more than an answer.

242 questions in the full set20 sample questionsUpdated Jan 25, 2026
Level
Professional
Valid for
2 years
Domains covered on the exam 5
  1. Administration20%
  2. Device Manager25%
  3. Policy and Objects30%
  4. Advanced Configuration15%
  5. Troubleshooting10%
  1. 1

    A security architect is reviewing a complex policy package in FortiManager and identifies several redundant firewall policies. They want to use the built-in tools to identify and merge these policies to simplify the rulebase.

    Which TWO of the following are valid criteria that FortiManager's "Policy Merge" feature requires for two policies to be considered mergeable? (Select TWO)

    Show answer details

    Correct answer: A, C

    To be merged, policies must control traffic flowing through the same network path, which means their source and destination interfaces must match.

    The security inspection applied to the traffic must be identical. If one policy has AV and the other has AV and IPS, they cannot be merged.

  2. 2

    A FortiManager HA cluster is configured and running correctly. An administrator needs to perform planned maintenance on the primary FortiManager unit. They want to ensure the secondary unit takes over all management tasks gracefully before they shut down the primary.

    Show answer details

    Correct answer: D

    The command execute ha failover is the standard procedure to gracefully force a failover in a FortiManager HA cluster. When run on the primary unit, it signals the secondary unit to take over the primary role, ensuring a smooth transition of services for planned maintenance.

  3. 3

    A FortiGate's configuration status in FortiManager is "Unknown". The administrator has verified that there is network connectivity between the FortiManager and the FortiGate, and the FGFM tunnel is up.

    Show answer details

    Correct answer: D

    The "Unknown" status specifically indicates that FortiManager cannot determine the synchronization state. FortiManager relies on retrieving a checksum of the FortiGate's configuration to compare it with its own database. If it cannot get this checksum—due to an incompatible firmware version, a problem with the FGFM management tunnel, or a device-side issue—it will report the status as "Unknown". An out-of-band change would typically result in a "Modified" status.

  4. 4

    An administrator needs to create a new restricted admin profile in FortiManager. The profile should only allow the user to view policies and objects within a specific ADOM but not make any changes.

    Show answer details

    Correct answer: B

    The "Read-Only" permission level is designed for this exact purpose. It grants the administrator the ability to view configurations, such as policy packages and object databases, but prevents them from creating, editing, or deleting any items. "None" would hide the module entirely, and "Read-Write" would grant full modification permissions.

  5. 5

    An administrator is using dynamic objects in a FortiManager policy package. They have a dynamic address object that is populated by a FortiGate connector that pulls a list of malicious IPs from a threat feed.

    Show answer details

    Correct answer: A

    When using dynamic objects (like those populated from a connector, SDN, or threat feed), FortiManager does not resolve the IP addresses at the time of installation. Instead, it pushes the policy to the FortiGate with a reference to the dynamic object name. The FortiGate itself is then responsible for locally resolving and updating the list of addresses associated with that dynamic object, ensuring the policy is always enforced against the most current data.

  6. 6

    An administrator is managing a multi-tenant environment using separate ADOMs. They need to create a standardized set of compliance policies (PCI-DSS) that must be applied to all FortiGates across all customer ADOMs, but also allow local administrators to add their own specific policies.

    Show answer details

    Correct answer: B

    The Global ADOM is specifically designed for this purpose. Header and footer policies are enforced globally and cannot be modified within individual ADOMs, ensuring compliance. Local ADOM administrators can then add their own policies between the header and footer policies, fulfilling all requirements efficiently.

  7. 7

    A network engineer is using a TCL script in FortiManager to automate the creation of VLAN interfaces on over 100 FortiGates. The script needs to assign a unique IP address to each new interface based on a value stored in a device-level meta field named 'VLAN_IP'. The script fails on some devices.

    Show answer details

    Correct answer: C

    TCL scripts rely on correct syntax to reference variables like meta fields (e.g., using $(meta_field_name)). The script's failure on only some devices strongly suggests that either the script logic for handling the variable is flawed, or the 'VLAN_IP' meta field has not been assigned a value for those specific devices, causing the script to fail when it tries to reference a null or empty value.

  8. 8

    A senior administrator is designing a FortiManager architecture for an enterprise with distinct business units (Sales, Engineering, HR) and a central IT security team. The primary design goals are: 1) Isolate the management of devices and policies for each business unit. 2) Allow the central security team to define and enforce a common set of security profiles (AV, IPS, Web Filter) across all business units.

    Show answer details

    Correct answer: A, B

    Creating a separate ADOM for each business unit is the standard and most effective way to achieve management isolation for devices, policies, and objects.

    The Global ADOM is specifically designed to create and manage objects and policies that can be shared and enforced across multiple regular ADOMs, which perfectly fits the requirement for a central security team to manage common security profiles.

  9. 9

    True or False: In a FortiManager HA cluster operating in active-passive mode, the secondary unit actively synchronizes its configuration from the primary unit but does not manage any FortiGate devices directly unless a failover occurs.

    Show answer details

    Correct answer: A

    This statement is True. In a standard active-passive FortiManager HA cluster, the primary unit handles all management tasks, including communication with FortiGate devices. The secondary (passive) unit maintains a synchronized copy of the configuration and database but remains idle with respect to device management until it is promoted to the primary role during a failover event.

  10. 10

    A financial services company uses FortiManager 7.6 to manage 50 branch office FortiGates. A junior administrator was tasked with updating the corporate SSL VPN portal banner for all devices. The administrator created a CLI script to upload the new banner text and ran it against the "Branch-Offices" device group. Immediately after, users reported being unable to connect to the SSL VPN.

    A senior engineer begins to investigate and observes that the installation log for the script shows "success" for all devices. However, when checking the device settings in FortiManager, the configuration status for all branch FortiGates is "Modified." A diagnose dvm device list command on the FortiManager CLI shows the conf status as out-of-sync. The engineer suspects the script caused an unintended configuration change that is preventing FortiManager from properly managing the devices.

    The script used by the junior admin contained the following commands:

    config vpn ssl web portal
    edit "full-access"
    set heading "Welcome to Secure Access v2.0"
    end
    

    The engineer needs to rapidly restore SSL VPN connectivity for all users across all 50 branches with minimal disruption and ensure the configuration is consistent with the FortiManager database.

    Show answer details

    Correct answer: C

    The core issue is that the devices are out-of-sync with an incorrect local configuration. The most direct and scalable way to fix this is to force FortiManager's version of the configuration onto the devices. Using the "Install Wizard" for "Device Settings" does exactly this. It overwrites the unintended local changes made by the faulty script with the configuration stored in the FortiManager database, restoring service and bringing the devices back into a "synchronized" state.

Create an account to continue.