FCP-FMG-AD-7-4 FCP - FortiManager 7.4 Administrator Practice Questions
Prepare for FCP-FMG-AD-7-4 with more than an answer.
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 5
- Administration20%
- Device Manager25%
- Policy and Objects30%
- Advanced Configuration15%
- Troubleshooting10%
- 1
Which two of the following are valid device registration methods for adding a new FortiGate to FortiManager? (Select TWO).
Show answer details
Correct answer: A, B
FortiManager supports adding devices that are already online using the 'Discover' wizard. It also supports pre-provisioning offline devices by adding them as a 'Model Device'. This involves providing the device's serial number, which allows FortiManager to prepare configurations that can be pushed once the device comes online and connects.
- 2
An administrator uses the 'Find and Merge Duplicate Objects' tool and discovers two address objects, 'Server_A' (10.1.1.1/32) and 'Host_A' (10.1.1.1/32), that are identical. 'Server_A' is used in Policy ID 5, and 'Host_A' is used in Policy ID 10. If the administrator chooses to merge these objects and keep 'Server_A', what is the result?
Show answer details
Correct answer: A
The 'Find and Merge Duplicate Objects' tool is designed to consolidate redundant objects. When merging, the administrator selects which object to keep. FortiManager then automatically updates all references (like firewall policies) that used the deleted object to point to the kept object. In this case, Policy ID 10 will be updated to use 'Server_A', and the 'Host_A' object will be removed from the database.
- 3
A FortiManager is configured to manage a Security Fabric with a FortiGate as the root and several downstream FortiSwitches and FortiAPs. The administrator wants to upgrade the firmware for the entire Fabric. What is the recommended upgrade sequence?
Show answer details
Correct answer: C
In a Security Fabric topology, the recommended best practice is to upgrade the downstream devices (endpoints) first and work your way up to the root. Therefore, the FortiAPs and FortiSwitches should be upgraded before the root FortiGate. This ensures that the managing device (FortiGate) maintains compatibility with the devices it controls throughout the upgrade process.
- 4
An administrator has enabled ADOMs on FortiManager and is creating a new ADOM to manage a group of FortiGates running FortiOS 7.2. During ADOM creation, what is the significance of setting the 'FortiOS Version' to 7.2?
Show answer details
Correct answer: A
Setting the FortiOS version for an ADOM is crucial because it tailors the FortiManager GUI and its available configuration options to match that specific firmware version. This prevents an administrator from attempting to configure a feature that does not exist on the target devices, ensuring compatibility and preventing installation errors.
- 5
True or False: In a FortiManager HA cluster, both the primary and secondary units can be used to manage devices and push configuration changes simultaneously.
Show answer details
Correct answer: B
False. FortiManager HA operates in an active-passive mode. Only the primary (master) unit is active and can be used for administrative tasks like managing devices and pushing configurations. The secondary (slave) unit receives configuration updates from the primary but remains in a read-only, standby state, ready to take over if the primary unit fails.
- 6
A financial services company is using FortiManager in workflow mode to ensure a strict change control process. An administrator submits a session containing changes to a critical firewall policy. The designated approver reviews the session but finds a minor error in one of the service objects used. What is the approver's most appropriate action within the FortiManager workflow process?
Show answer details
Correct answer: B
In FortiManager's workflow mode, the approver's role is to validate the submitted changes. If an error is found, the correct procedure is to reject the session and provide comments. This sends the session back to the original administrator who can then repair the session by correcting the error and resubmitting it for approval. Approving a session with a known error violates the principle of change control. Approvers cannot directly edit or repair sessions submitted by others.
- 7
A network administrator is tasked with adding 100 new retail branch FortiGates to FortiManager using the Zero Touch Provisioning (ZTP) feature. The administrator has created a device blueprint that includes a system template and assigns a policy package. However, they notice that after a new FortiGate is registered via ZTP, the assigned policy package is not being installed automatically. What is a likely cause for this issue?
Show answer details
Correct answer: B
For Zero Touch Provisioning (ZTP) to automatically install configurations, including policy packages, the 'auto-link' setting must be enabled within the device blueprint. This setting instructs FortiManager to automatically run the installation process for assigned templates and policy packages after the device successfully registers. If it is disabled, the device will be added to FortiManager but will require a manual installation task to be initiated.
- 8
An administrator needs to create a firewall policy that allows traffic only from authenticated Active Directory users in the 'Engineering' group. The FSSO connector is configured correctly in the ADOM. When creating the firewall policy, which two objects must be selected to correctly define the source of the traffic? (Select TWO).
Show answer details
Correct answer: A, B
When creating a user identity-based firewall policy, you must specify both the source user/group and the source address. The FSSO user group object identifies the authenticated user, while the firewall address object (often 'all' or a specific subnet) defines the network location from which the user's traffic originates. Both are required for the policy to function correctly.
- 9
True or False: When FortiManager is operating in a closed network without internet access, it is impossible to manage FortiGuard subscriptions for managed devices.
Show answer details
Correct answer: B
False. FortiManager can operate as a local FortiGuard Distribution Server (FDS) in a closed or air-gapped network. An administrator can use a separate FortiManager with internet access to download FortiGuard packages, export them to a removable media, and then import them into the closed-network FortiManager. This allows the air-gapped FortiManager to provide FortiGuard updates to its managed devices.
- 10
A system administrator is reviewing the revision history for a managed FortiGate and observes several configuration changes that were made directly on the FortiGate, causing a 'Modified' state in FortiManager. The administrator wants to overwrite the local changes on the FortiGate with the configuration stored in FortiManager's device database. Which action should be performed?
Show answer details
Correct answer: B
When a device's configuration state is 'Modified', it means the running configuration on the FortiGate differs from what FortiManager has in its database for that device. To enforce FortiManager's configuration and overwrite the local changes, the administrator must perform an installation. Using the Install Wizard and selecting 'Install Device Settings' will push the configuration from the FortiManager device database to the FortiGate, resolving the 'Modified' state and ensuring consistency.
