Fortinet NSE5_FMG-5.4 Exam Practice Questions (P. 1)
- Full Access (56 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
When installation is performed from the FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?
- AAfter 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.Most Voted
- BFortiGate will reject the CLI commands that will cause the tunnel to go down.
- CFortiManager will revert and install a previous configuration revision on the managed FortiGate.
- DFortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.
Correct Answer:
C
C
send
light_mode
delete
Question #2
Which of the following statements are true regarding VPN Manager? (Choose three.)
- AVPN Manager must be enabled on a per ADOM basis.
- BVPN Manager automatically adds newly-registered devices to a VPN community.
- CVPN Manager can install common IPsec VPN settings on multiple FortiGate devices at the same time.
- DCommon IPsec settings need to be configured only once in a VPN Community for all managed gateways.
- EVPN Manager automatically creates all the necessary firewall policies for traffic to be tunneled by IPsec.
Correct Answer:
ACD
ACD
send
light_mode
delete
Question #3
View the following exhibit:

When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)

When using Install Config option to install configuration changes to managed FortiGate, which of the following statements are true? (Choose two.)
- AWill not create new revision in the revision history.
- BProvides the option to preview configuration changes prior to installing them.
- CInstalls device-level changes to FortiGate without launching the Install Wizard.
- DOnce installed, the install process cannot be canceled and changes will be installed on the managed device.
Correct Answer:
BC
BC
send
light_mode
delete
Question #4
View the following exhibit:

Which of the following statements are true if both FortiManager and FortiGate are behind the NAT devices? (Choose two.)

Which of the following statements are true if both FortiManager and FortiGate are behind the NAT devices? (Choose two.)
- AFortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management.
- BIf the FGFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
- CFortiGate is discovered by FortiManager through the FortiGate NATed IP address.
- DDuring discovery, the FortiManager NATed IP address is not set by default on FortiGate.
Correct Answer:
BC
BC
send
light_mode
delete
Question #5
What is the purpose of the Policy Check feature on FortiManager?
- ATo find and merge duplicate policies in the policy package.
- BTo find and provide recommendation to combine multiple separate policy packages into one common policy package.
- CTo find and delete disabled firewall policies in the policy package.
- DTo find and provide recommendation for optimizing policies in a policy package.Most Voted
Correct Answer:
A
The policy check tool allows you to check all policy packages within an ADOM to ensure consistency and eliminate conflicts that may prevent your devices from passing traffic. This allows you to optimize your policy sets and potentially reduce the size of your databases. The check will verify:
1. Object duplication: two objects that have identical definitions
2. Object shadowing: a higher priority object completely encompasses another object of the same type
3. Object overlap: one object partially overlaps another object of the same type
4. Object orphaning: an object has been defined but has not been used anywhere.
Reference:
https://docs.fortinet.com/uploaded/files/2905/FortiManager-5.4.0-Administration-Guide.pdf
A
The policy check tool allows you to check all policy packages within an ADOM to ensure consistency and eliminate conflicts that may prevent your devices from passing traffic. This allows you to optimize your policy sets and potentially reduce the size of your databases. The check will verify:
1. Object duplication: two objects that have identical definitions
2. Object shadowing: a higher priority object completely encompasses another object of the same type
3. Object overlap: one object partially overlaps another object of the same type
4. Object orphaning: an object has been defined but has not been used anywhere.
Reference:
https://docs.fortinet.com/uploaded/files/2905/FortiManager-5.4.0-Administration-Guide.pdf
send
light_mode
delete
All Pages