Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Fortinet NSE 6 Network Security Specialist NSE6_FMG_AD-7.6 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam NSE6_FMG_AD-7.6 Premium Access

View all detail and faqs for the NSE6_FMG_AD-7.6 exam


0 Students Passed

0% Average Score

0% Same Questions
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

A service provider administrator has assigned a global policy package to a managed customer ADOM named My_ADOM. The customer administrator has access only to My_ADOM.

How can the customer administrator edit the global header policy of the global policy package?

Options:

A.

The customer administrator can edit the header policy by using workspace mode on the global ADOM.

B.

The customer administrator can edit the header policy by using workflow mode on the global ADOM and My_ADOM.

C.

The service provider administrator can unlock the global policy from the global ADOM to authorize changes to the customer administrator.

D.

The customer administrator cannot edit the global header policy; only the service provider administrator can make changes from the global ADOM.

Questions # 12:

Refer to the exhibit.

Question # 12

Which two statements about the configuration shown in the exhibit are true? Choose two answers.

Options:

A.

An administrator can lock the Local-FortiGate_root policy package.

B.

The administrator created a snapshot of the Remote-FortiGate policy package.

C.

The FortiManager ADOM workspace mode is set to normal.

D.

The FortiManager is in workflow mode.

Questions # 13:

Refer to the exhibits.

Question # 13

Question # 13

Question # 13

FortiGate HQ-NGFW-1 downloads and validates FortiGuard databases from FortiManager which acts as a local FortiGuard Distribution Server (FDS) in a closed network. An administrator pushes a new firewall policy with an intrusion prevention system (IPS) profile from FortiManager to FortiGate HQ- NGFW-1 However, FortiGate does not recognize the new IPS signature from FortiManager.

What is the most likely reason why FortiGate HQ-NGFW-1 does not recognize the new IPS signature?

Options:

A.

FortiGate must enable rating for the FortiManager IP address, 192.168.1.120, in server list 1.

B.

FortiManager and FortiGate have different IPS database versions.

C.

The administrator must enable IPv6 connections for FortiGuard services on FortiManager.

D.

The administrator must enable the fortiguard-anycast option to correctly download all signatures from the local FDS.

Questions # 14:

Refer to the exhibit.

Question # 14

What are two results from the configuration shown in the exhibit? (Choose two.)

Options:

A.

Ungraceful closed sessions will keep the ADOM in a locked state until the administrator session times out.

B.

The administrator can lock policy blocks and FortiManager global ADOM.

C.

The same administrator can lock more than one ADOM at the same time.

D.

The administrator must have access to the ADOM to approve changes.

Questions # 15:

Refer to the exhibit.

Question # 15

What can you conclude from the downloaded import report?

Options:

A.

FortiManager does not support per-device mapping for firewall addresses.

B.

The administrator will see a new policy package named Remote-FortiGate_root in the FortiManager ADOM database.

C.

FortiManager will change the configuration of REMOTE_SUBNET to match the interface mapping coming in from Remote-FortiGate.

D.

As a result of this policy import process, FortiManager will create a new firewall address called REMOTE_SUBNET in the ADOM database.

Questions # 16:

If one of the secondary FortiManager devices fails, which action must be performed to return the FortiManager HA manual mode to a working state?

Options:

A.

The FortiManager high availability HA state transition is transparent to administrators and does not require any reconfiguration.

B.

Run a sanity check on the failed device to make sure HA heartbeat packets are using TCP port 5199.

C.

Manually promote one of the working secondary devices to the primary role.

D.

Remove the peer IP of the failed device on the primary device.

Questions # 17:

An administrator has a FortiGate-HQ device with VDOMs—root, HR and Facilities, currently managed under the FortiManager ADOM—Site1. They try to move VDOM HR to the FortiManager ADOM—Site2, but it does not work.

Why is the administrator not able to move FortiGate-HQ VDOM HR to FortiManager ADOM—Site2?

Options:

A.

The FortiGate-HQ must be managed under the FortiManager ADOM—root to allow moving its VDOMs to different ADOMs.

B.

The administrator must have full access in the device layer of FortiGate-HQ VDOM-root before they can VDOMs to different ADOMs.

C.

FortiManager must be in ADOM normal mode, which does not allow VDOMs to be managed separately.

D.

The administrator must delete the FortiGate-HQ device from FortiManager and add it again using the Add Device wizard before moving the VDOM.

Questions # 18:

Refer to the exhibit.

Question # 18

What percentage of the available RAM is being used by the process in charge of downloading the web and email filter databases from the public FortiGuard servers?

Options:

A.

1.5

B.

3.1

C.

4.1

D.

2.9

Questions # 19:

You want to let multiple administrators work in the same ADOM without creating configuration conflicts.

What is the best and the most effective solution to apply?

Options:

A.

Configure RADIUS authentication to assign ADOM roles to each user.

B.

Enable workflow mode, which is the only way to prevent concurrent configuration conflicts.

C.

Assign administrators with JSON API access to the FortiManager.

D.

Activate workspace mode in the ADOM settings.

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.