FCP-FMG-AD-7-6 Sample Questions & Answers
Managing policies and objects, including ADOM revisions and workspace mode, takes the biggest share, next to FortiManager's features and administrative domains, device registration and revision history, high availability and FortiGuard services, and troubleshooting.
Launch the full FCP-FMG-AD-7-6 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Policy and Objects · Workspace Mode Operation
An administrator is working in an ADOM where Workspace Mode is enabled. They have locked a policy package to make changes. While the package is locked, another administrator needs to urgently add a new firewall address object that will be used in a different, unlocked policy package.
Show answer & explanation
Correct answer: B
In FortiManager's Workspace Mode, locking is granular and applies to specific objects or policy packages, not the entire ADOM database. The second administrator can create a new address object because it is a separate entity from the locked policy package. They would only be blocked if they tried to modify an object already in use by the locked package or the locked package itself.
- Question 2Advanced
Device Manager · Managing Devices Behind NAT
A company is deploying FortiGates to remote sites where the devices are behind a carrier-grade NAT (CGNAT), meaning they have private, non-routable WAN IP addresses. The administrator needs to manage these FortiGates using FortiManager.
Show answer & explanation
Correct answer: D
When a FortiGate is behind a NAT device, FortiManager cannot initiate a connection to it. The connection must be initiated from the FortiGate to the FortiManager. The FortiGate FGFM protocol is designed for this purpose. The FortiGate uses its WAN interface to connect out to the FortiManager's public IP address, establishing a management tunnel that FortiManager can then use for management.
- Question 3Intermediate
Policy and Objects · Policy Import and Normalization
An administrator has imported a policy package from a newly managed FortiGate. They notice that several address objects that were used in the imported policies on the FortiGate now have a warning icon in FortiManager and are listed as conflicts in the import wizard.
Show answer & explanation
Correct answer: A
During a policy import, FortiManager compares the objects from the FortiGate with the objects already in the ADOM database. If an object from the FortiGate has the same name as an existing ADOM object but with different attributes (e.g., a different IP address), FortiManager flags it as a conflict. This process, called normalization, requires the administrator to choose which version of the object to use.
- Question 4Intermediate
Administration · System Backup and Restore
A system administrator needs to back up the entire FortiManager configuration, including all ADOMs, device configurations, and global settings. They want a single file that can be used to restore the system to a new FortiManager VM in a disaster recovery scenario.
Show answer & explanation
Correct answer: C
The backup option in the System Information widget on the System Settings dashboard is the correct GUI method for creating a full system backup. This single
.datfile contains all configurations for the entire FortiManager appliance, including system settings, all ADOMs, policies, objects, and device databases, making it ideal for a full system restore or migration. - Question 5Advanced
Advanced Configuration · Global Policy Precedence
An organization is using the Global ADOM to manage a set of corporate security policies. They have a global policy package with a "Header Policy" section that denies traffic to known malicious sites. A junior administrator in a regional ADOM is trying to create a policy to allow access to a specific site for a business partner, but the traffic is still being blocked.
Show answer & explanation
Correct answer: B
FortiManager constructs the final policy table on the FortiGate by combining global and local policies in a specific order: Global Header Policies first, then Local ADOM Policies, and finally Global Footer Policies. Since the deny rule is in the Header Policy section, it is evaluated before any of the local ADOM's policies. The first matching rule is applied, so the deny rule in the global header blocks the traffic before the local allow rule is ever reached.
- Question 6IntermediateSelect 2
Device Manager · Model Devices and Variables
An administrator is preparing to deploy a standardized configuration to a new group of FortiGate 100F devices using a model device template in FortiManager. The template needs to configure several settings that are unique to each physical device. The diagram below shows the desired variable substitution.
Which TWO of the following methods can be used in FortiManager to correctly populate device-specific values like hostname and management IP during the template deployment? (Select TWO)
graph TD subgraph FortiManager T[Model Device Template] M1[Meta Field: Hostname] M2[Meta Field: Mgmt_IP] end subgraph Deployment T -- Deploys to --> FGT1[New FGT-100F #1] T -- Deploys to --> FGT2[New FGT-100F #2] end subgraph Result FGT1 -- Configured with --> C1["hostname: Branch1-FW mgmt_ip: 10.10.1.1"] FGT2 -- Configured with --> C2["hostname: Branch2-FW mgmt_ip: 10.10.2.1"] end M1 & M2 -- Used by --> TShow answer & explanation
Correct answers: A, E
Using meta fields is a primary and highly scalable method. You define custom fields and then assign the specific values to each managed device object. The model device template can then reference these meta fields to pull in the device-specific data upon deployment.
The Install Wizard provides an option to define variables that must be populated for each device during the installation process. This is another valid method, often used for values that might change per-deployment rather than being a static property of the device.
- Question 7Advanced
Policy and Objects · Workspace Mode and Workflow
Global Corp is migrating its firewall management to FortiManager 7.6. They have 200 FortiGates globally, managed by regional teams in AMER, EMEA, and APAC. The CISO has mandated a strict change control process. All policy changes must be reviewed and approved by a senior security architect before being deployed. The regional teams are responsible for creating the change requests, but they must not be able to push changes directly to the FortiGates.
The current FortiManager setup uses three ADOMs: AMER, EMEA, and APAC. The Lead Architect needs to configure the system to enforce the CISO's mandate. The desired workflow is as follows: A regional administrator drafts a policy change, the change is then submitted for approval, the senior architect receives a notification, reviews the diff, and either approves or rejects the change. Only upon approval can the change be installed by a separate deployment team.
The Lead Architect is evaluating the configuration options within the ADOM settings to implement this process. The solution must prevent accidental or unauthorized deployments while providing a clear audit trail of all changes and approvals.
Show answer & explanation
Correct answer: B
"Workspace Mode" with "Workflow" is the feature specifically designed to meet these requirements. It creates a structured environment where administrators can make changes in a private workspace, then submit them for approval. The workflow engine handles notifications to designated approvers, allows them to review the changes (diff), and approve or reject them. Only approved changes can be moved into the deployment phase. This provides the required change control, separation of duties, and audit trail.
- Question 8Intermediate
Troubleshooting · Installation Error Analysis
An administrator attempts to install a policy package to a FortiGate, but the installation fails. When reviewing the installation log, they see the error message: "copy running config to flash failed".
Show answer & explanation
Correct answer: B
The error "copy running config to flash failed" is a specific message from the FortiGate itself, indicating that while it could receive and load the configuration into its running memory, it failed when trying to save that configuration permanently to its flash storage. This is almost always due to a lack of available space on the flash disk.
- Question 9Beginner
Administration · Initial Configuration and ADOMs
True or False: By default, a new FortiManager installation has the Administrative Domains (ADOMs) feature disabled.
Show answer & explanation
Correct answer: A
This is True. On a fresh installation of FortiManager, the ADOM feature is disabled by default. The administrator must manually enable it under
System Settings > All ADOMsif they need to manage multiple independent domains. When disabled, all devices are managed within a single default domain. - Question 10Intermediate
Device Manager · Firmware Management for HA Clusters
An administrator is managing a FortiGate HA cluster (active-passive) through FortiManager. They need to push a firmware upgrade to the cluster.
Show answer & explanation
Correct answer: B
FortiManager is designed to simplify HA management. The "Upgrade Firmware" wizard is HA-aware and follows the correct, minimally disruptive procedure. It upgrades the passive unit first, verifies its status, initiates a graceful failover so the upgraded unit becomes active, and then proceeds to upgrade the original primary (now passive) unit. This ensures continuous operation with minimal downtime.
Ready for the real thing?
The full FCP-FMG-AD-7-6 simulator has every exam-style question, timed mode, and instant scoring.