[2024年最新] 最高のNSE5_FMG-7.2試験問題集を使って- 実際の試験問題と解答を解こう
テストエンジンを練習してNSE5_FMG-7.2テスト問題
Fortinet NSE5_FMG-7.2試験は、Fortinet Network Security Expert(NSE)認定プログラムの一部であり、Fortinet製品とソリューションを使用するIT専門家のスキルと知識を検証するように設計されています。この試験に合格することにより、候補者はフォルティマナーガーの習熟度を実証し、IT業界でのキャリアの機会を高めることができます。
質問 # 26
When an installation is performed from FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?
- A. FortiGate will reject the CLI commands that will cause the tunnel to go down.
- B. FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.
- C. FortiManager will revert and install a previous configuration revision on the managed FortiGate.
- D. After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.
正解:D
解説:
The configuration change will break the fgfm connection, causing the FortiGate unit to attempt to reconnect for 900 seconds. If the FortiGate cannot reconnect, it will rollback to its previous configuration.
質問 # 27
Which of the following statements are true regarding VPN Manager? (Choose three.)
- A. VPN Manager automatically creates all the necessary firewall policies for traffic to be tunneled by IPsec.
- B. Common IPsec settings need to be configured only once in a VPN Community for all managed gateways.
- C. VPN Manager automatically adds newly-registered devices to a VPN community.
- D. VPN Manager must be enabled on a per ADOM basis.
- E. VPN Manager can install common IPsec VPN settings on multiple FortiGate devices at the same time.
正解:B、D、E
質問 # 28
In addition to the default ADOMs, an administrator has created a new ADOM named Training for FortiGate devices. The administrator sent a device registration to FortiManager from a remote FortiGate. Which one of the following statements is true?
- A. The FortiGate will be automatically added to the Training ADOM.
- B. By default, the unregistered FortiGate will appear in the root ADOM.
- C. The FortiManager administrator must add the unregistered device manually to the unregistered device
- D. The FortiGate will be added automatically to the default ADOM named FortiGate.
正解:B
解説:
manually to the Training ADOM using the Add Device wizard
質問 # 29
Refer to the exhibit.
You ate using the Quick install option to install configuration changes on the managed FortiGate Which two statements correctly describe the result? (Choose two)
- A. It installs device-level changes on the FortiGate device without launching the Install Wizard
- B. It installs all the changes in the device database first and the administrator must reinstall the changes on the FodiGate device
- C. It provides the option to preview only the policy package changes before installing them
- D. It install provisioning template changes on the FortiGate device
正解:A、D
質問 # 30
Refer to the exhibit.
Which two statements about the output are true? (Choose two.)
- A. The latest revision history for the managed FortiGate does match with the FortiGate running configuration
- B. Configuration changes directly made on the FortiGate have been automatically updated to device-level
- C. The latest history for the managed FortiGate does not match with the device-level database
- D. Configuration changes have been installed to FortiGate and represents FortiGate configuration has been changed
正解:A、C
解説:
database
Explanation:
STATUS: dev-db: modified; conf: in sync; cond: pending; dm: retrieved; conn: up
- dev-db: modified - This is the device setting status which indicates that configuration changes were made on FortiManager.
- conf: in sync - This is the sync status which shows that the latest revision history is in sync with Fortigate's configuration.
- cond: pending - This is the configuration status which says that configuration changes need to be installed.
Most probably a retrieve was done in the past (dm: retrieved) updating the revision history DB (conf: in sync) and FortiManager device level DB, now there is a new modification on FortiManager device level DB (dev-db: modified) which wasn't installed to FortiGate (cond: pending), hence; revision history DB is not aware of that modification and doesn't match device DB.
Conclusion:
- Revision DB does match FortiGate.
- No changes were installed to FortiGate yet.
- Device DB doesn't match Revision DB.
- No changes were done on FortiGate (auto-update) but configuration was retrieved instead After an Auto-Update or Retrieve:
device database = latest revision = FGT
Then after a manual change on FMG end (but no install yet):
latest revision = FGT (still) but now device database has been modified (is different).
After reverting to a previous revision in revision history:
device database = reverted revision != FGT
質問 # 31
Refer to the exhibit.
A service provider administrator has assigned a global policy package to a managed customer ADOM named My_ADOM, which has four policy packages. The customer administrator has access onlytoMy_ADOM.
How can customer or service provider administrators remove both global header and footer policies from the policy package named Shared_Package?
- A. The service provider administrator can unassign both policies from the global ADOM.
- B. The service provider administrator can unassign both global policies from My_ADOM.
- C. The customer administrator can unassign both global polices from My_ADOM.
- D. The customer administrator can unassign both polices by locking My_ADOM.
正解:B
質問 # 32
Which two settings must be configured for SD-WAN Central Management? (Choose two.)
- A. You can create multiple SD-WAN interfaces per VDOM
- B. The first step in creating an SD-WAN using FortiManager is to create two SD-WAN firewall policies.
- C. When you configure an SD-WAN, you must specify at least two member interfaces.
- D. SD-WAN must be enabled on per-ADOM basis
正解:C、D
質問 # 33
Which of the following statements are true regarding VPN Gateway configuration in VPN Manager? (Choose two.)
- A. Protected subnets are the subnets behind the device that you don't want to allow access to over the IPsec VPN
- B. Managed gateways are devices managed by FortiManager in the same ADOM
- C. Managed devices in other ADOMs must be treated as external gateways
- D. External gateways are third-party VPN gateway devices only
正解:B、C
解説:
Reference:http://help.fortinet.com/fmgr/50hlp/56/5-6-1/FMG-FAZ/1
300_VPN_Manager/0800_IPsec_VPN_Gateway/0400_Create_mngd_gateway.htm
質問 # 34
Refer to the exhibit.
An administrator has configured the command shown in the exhibit on FortiManager. A configuration change has been installed from FortiManager to the managed FortiGate that causes the FGFM tunnel to go down for more than 15 minutes.
What is the purpose of this command?
- A. It allows the FortiManager to revert and install a previous configuration revision on the managed FortiGate.
- B. It allows FortiGate to reboot and restore a previously working firmware image.
- C. It allows FortiGate to unset central management settings.
- D. It allows FortiGate to reboot and recover the previous configuration from its configuration file.
正解:D
質問 # 35
View the following exhibit.
An administrator is importing a new device to FortiManager and has selected the shown options. What will happen if the administrator makes the changes and installs the modified policy package on this managed FortiGate?
- A. The unused objects that are not tied to the firewall policies will be installed on FortiGate
- B. The unused objects that are not tied to the firewall policies will remain as read-only locally on FortiGate
- C. The unused objects that are not tied to the firewall policies in policy package will be deleted from the FortiManager database
- D. The unused objects that are not tied to the firewall policies locally on FortiGate will be deleted
正解:D
解説:
Reference:https://community.fortinet.com/t5/FortiManager/Import-all-objects-Versus-Import-only-policy-depend
質問 # 36
View the following exhibit.
Given the configurations shown in the exhibit, what can you conclude from the installation targets in the Install On column?
- A. Policy seq#3 will be not installed on any managed device
- B. Policy seq#3 will be installed on the Trainer[NAT] VDOM only
- C. Policy seq#3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
- D. The Install On column value represents successful installation on the managed devices
正解:C
質問 # 37
View the following exhibit.
An administrator has created a firewall address object, Training, which is used in the Local-FortiGate policy package. When the install operation is performed, which IP Netmask will be installed on the Local-FortiGate, for the Training firewall address object?
- A. 10.0.1.0/24
- B. It will create firewall address group on Local-FortiGate with 192.168.0.1/24 and 10.0.1.0/24 object values
- C. 192.168.0.1/24
- D. Local-FortiGate will automatically choose an IP Network based on its network interface settings.
正解:A
質問 # 38
Refer to the exhibit.
An administrator would like to create three ADOMs on FortiManager with different access levels based on departments.
What two conclusions can you draw from the design shown in the exhibit? (Choose two.)
- A. The administrator must set the FortiManager ADOM mode to Advanced.
- B. The administrator must configure FortiManager in workspace mode.
- C. Admin A can access VDOM2 and VDOM3 with the super user profile.
- D. The FortiManager policies and objects database can be shared between the Financial and HR ADOMs.
正解:A、D
質問 # 39
Which three settings are the factory default settings on FortiManager? (Choose three.)
- A. Reports and Event Monitor panes are enabled
- B. port1 interface IP address is 192.168.1.99/24
- C. Username is admin
- D. Password is fortinet
- E. FortiAnalyzer features are disabled
正解:B、C、E
質問 # 40
What are two outcomes of ADOM revisions? (Choose two.)
- A. ADOM revisions can create System Checkpoints for the FortiManager configuration
- B. ADOM revisions can significantly increase the size of the configuration backups.
- C. ADOM revisions can save the current size of the whole ADOM
- D. ADOM revisions can save the current state of all policy packages and objects for an ADOM
正解:B、D
解説:
Reference:https://docs2.fortinet.com/document/fortimanager/6.0.0/best-practices/101837/adom-revisions
質問 # 41
An administrator configures a new firewall policy on FortiManager and has not yet pushed the changes to the managed FortiGate.
In which database will the configuration be saved?
- A. Device-level database
- B. Revision history database
- C. ADOM-level database
- D. Configuration-level database
正解:C
解説:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47942
質問 # 42
Refer to the exhibit showing a Download Import Report.
Why is it failing to import firewall policy ID 1?
- A. Policy ID 1 is configured from the interface any to port6. FortiManager rejects the request to import this policy because the any interface does not exist on FortiManager.
- B. The address object used in policy ID 1 already exists in the ADOM database with any as the interface association, and conflicts with the address object interface association locally on FortiGate.
- C. Policy ID 1 does not have the ADOM Interface mapping configured on FortiManager.
- D. Policy ID 1 for this managed FortiGate already exists on FortiManager in the policy package named Remote-FortiGate.
正解:B
質問 # 43
View the following exhibit.
Given the configurations shown in the exhibit, what can you conclude from the installation targets in the Install Oncolumn?
- A. Policy seq#3 will be not installed on any managed device
- B. Policy seq#3 will be installed on the Trainer[NAT] VDOM only
- C. Policy seq#3 will be installed on all managed devices and VDOMs that are listed under Installation Targets
- D. The Install On column value represents successful installation on the managed devices
正解:C
質問 # 44
Refer to the exhibit.
An administrator has created a firewall address object,Trainingwhich is used in the Local-FortiGate policy package.
When the installation operation is performed, which IP/Netmask will be installed on the Local-FortiGate, for theTrainingfirewall address object?
- A. It will create a firewall address group on Local-FortiGate with192.168.0.1/24and10.0.1.0/24object values.
- B. Local-FortiGate will automatically choose an IP/Netmask based on its network interface settings.
- C. 192.168.0.1/24
- D. 10.200.1.0/24
正解:C
質問 # 45
......
Fortinet NSE5_FMG-7.2 認定試験は、Fortinet セキュリティソリューションに関連する幅広いトピックをカバーしています。FortiManager の構成と管理、FortiAnalyzer のインストールと構成、FortiManager と FortiAnalyzer の統合、および FortiManager と FortiAnalyzer のトラブルシューティングを含みます。認定試験は、複雑なネットワーク環境で Fortinet セキュリティソリューションを展開および管理する候補者の能力をテストするように設計されています。
NSE5_FMG-7.2実際の問題アンサーPDFには100%カバー率リアルな試験問題:https://jp.fast2test.com/NSE5_FMG-7.2-premium-file.html