FCP-FMG-AD-7-4 Sample Questions

FCP-FMG-AD-7-4 Sample Questions & Answers

Policy and object management, including ADOM revisions and workspace mode, carries the most weight, alongside administrative domains and initial setup, registering devices and scripting configuration changes, FortiManager HA, and troubleshooting.

Launch the full FCP-FMG-AD-7-4 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Policy and Objects · Perform policy and object management

    A university manages its campus network with multiple FortiGates grouped by building. The central IT team wants to enforce a baseline security policy across all buildings but allow each building's IT staff to add their own specific firewall rules. The central IT team must retain control over the baseline rules, preventing any modifications by building staff. Which FortiManager feature should be used to achieve this hierarchical policy management?

    Show answer & explanation

    Correct answer: B

    The Global ADOM is designed for this purpose. By creating a global policy package and defining rules within the 'Header Policy' section, these rules are enforced at the top of the policy table for all ADOMs that use this global package. Building IT staff can then add their own rules in the ADOM-level policy package, which will be evaluated after the centrally-controlled header policies. This maintains central control while allowing for local flexibility.

  2. Question 2Advanced

    Advanced Configuration · Describe FortiManager HA

    An organization is deploying a new FortiManager HA cluster. The administrator has configured two FortiManager VMs with identical resources and firmware. After configuring the HA settings, the administrator notices that the configuration synchronization is failing between the primary and secondary units. Which of the following is a common cause for this issue?

    Show answer & explanation

    Correct answer: B

    FortiManager HA synchronization relies on a secure channel established between the cluster members. A common cause for synchronization failure is a mismatch in the HA configuration itself. The primary unit must be configured with the correct peer IP address of the secondary unit and a shared HA password. The secondary unit must have the same HA password configured. Any discrepancy in these settings will prevent the secure channel from being established, leading to sync failures.

  3. Question 3Beginner

    Device Manager · Install configuration changes using scripts

    A junior administrator is using a script to update the DNS settings on a group of 20 FortiGates. After running the script, the task monitor shows that the script failed on five of the devices. What is the most effective first step to diagnose the cause of the failures on those specific devices?

    Show answer & explanation

    Correct answer: C

    The Script History page provides detailed logs for each script execution. For failed tasks, it shows the specific device, the time of failure, and often a response from the device indicating the reason for the failure (e.g., command not found, invalid parameter, permission denied). This is the most direct and informative first step for troubleshooting script execution issues.

  4. Question 4Beginner

    Policy and Objects · Manage ADOM revisions

    What is the primary function of ADOM revisions in FortiManager?

    Show answer & explanation

    Correct answer: B

    An ADOM revision is a snapshot of the ADOM's database at a specific moment. This includes all policy packages, objects, and settings within that ADOM. It serves as a backup and a restore point, allowing an administrator to revert the entire ADOM configuration to a previous known-good state if necessary.

  5. Question 5Intermediate

    Administration · Configure administrative domains (ADOMs)

    A new FortiManager administrator profile is being created for a team that only manages Web Application Firewall (WAF) policies. The super administrator wants to limit the team's access to only the relevant sections of the GUI. Which permission setting within the administrator profile achieves this?

    Show answer & explanation

    Correct answer: D

    FortiManager provides granular permissions within administrator profiles. To limit access to a specific function like WAF policy management, a custom profile should be created. The administrator can then navigate to the 'Policy & Objects' section of the permissions and set the access level for 'Security Profiles - WAF Profile' to 'Read-Write' while setting other unrelated permissions to 'None'. This ensures the team can only see and manage the specific components relevant to their job.

  6. Question 6Advanced

    Device Manager · Install configuration changes using scripts

    An administrator is managing a large estate of FortiGates and wants to use Jinja scripting in a CLI template for dynamic configuration. The goal is to set the hostname of each FortiGate based on a meta field called site_code. Which Jinja script snippet correctly retrieves the site_code meta field value from the FortiManager device database?

    Show answer & explanation

    Correct answer: C

    When using Jinja scripts in FortiManager CLI templates, the DVM object is used to access the device database for the target device. Meta fields are accessed through DVM.meta. . Therefore, {{ DVM.meta.site_code }} is the correct syntax to retrieve the value of the 'site_code' meta field during script execution.

  7. Question 7Intermediate

    Administration · Configure workspace mode

    A hospital is using FortiManager to manage its network. Due to compliance requirements, all configuration changes must be reviewed and approved by a senior network architect before being deployed. Additionally, multiple junior administrators need to be able to work on configuration changes in the same ADOM simultaneously without interfering with each other's work. Which FortiManager workspace configuration should be implemented to meet these requirements?

    flowchart TD A[Junior Admin 1] --> B{Create Session 1} C[Junior Admin 2] --> D{Create Session 2} B --> E{Submit for Approval} D --> E E --> F[Senior Architect Review] F -->|Approve| G[Changes Merged] F -->|Reject| H[Return to Admin] G --> I[Install to FortiGate]

    Show answer & explanation

    Correct answer: C

    Workflow mode is specifically designed for this scenario. It allows multiple administrators to work in separate, isolated sessions. When they are finished, they submit their session for approval. A designated approver (the senior architect) can then review, approve, or reject the changes. This meets both requirements: concurrent work and a mandatory approval process.

  8. Question 8Intermediate

    Policy and Objects · Perform policy imports and installations

    An administrator is trying to import a configuration from a FortiGate into a new policy package. During the import process, FortiManager reports a conflict for a firewall address object that already exists in the ADOM database but has a different IP address. What option does the Import wizard provide to resolve this conflict?

    Show answer & explanation

    Correct answer: B

    When importing a configuration, FortiManager's Import wizard detects object conflicts. For each conflict, it provides several resolution options, including: using the existing object from the ADOM database (ignoring the imported one), using the object from the imported FortiGate configuration (overwriting the ADOM object), or renaming the imported object to create a new, distinct object.

  9. Question 9Advanced

    Advanced Configuration · Configure the global database ADOM

    A managed service provider (MSP) uses FortiManager to manage firewalls for multiple customers. Each customer is in a separate ADOM. The MSP wants to apply a standard set of IPS signatures and DNS filters to all customers. What is the most efficient and scalable method to manage these shared security profiles?

    Show answer & explanation

    Correct answer: B

    The Global ADOM is designed for managing shared objects and policies across multiple ADOMs. By creating the standard IPS sensor and DNS filter profile in the Global ADOM, the MSP can manage them from a single location. These global objects can then be used in policy packages within each customer ADOM. Any update to the global profile is automatically inherited by all ADOMs using it, ensuring consistency and simplifying management.

  10. Question 10Advanced

    Troubleshooting · Troubleshoot import and installation issues

    After an administrator installs a policy package to a FortiGate, the device goes into a 'conf sync' status of 'Out of Sync'. The administrator did not make any changes directly on the FortiGate. What is a common reason for this status to occur immediately after a successful installation?

    Show answer & explanation

    Correct answer: B

    When FortiManager installs a policy package for the first time or when significant changes are made, the FortiGate may reorder policy IDs or normalize the configuration as it is committed to its running config. This can cause an immediate 'Out of Sync' status because the configuration read back by FortiManager does not exactly match the one it just sent. A subsequent 'Retrieve Configuration' operation is often needed to re-synchronize FortiManager with the FortiGate's normalized configuration.

Ready for the real thing?

The full FCP-FMG-AD-7-4 simulator has every exam-style question, timed mode, and instant scoring.