Fortinet NSE 5 - FortiManager 6.4 NSE5_FMG-6.4 Dumps in PDF

Free Fortinet NSE5_FMG-6.4 Real Questions (page: 3)

Which configuration setting for FortiGate is part of a device-level database on FortiManager?

  1. VIP and IP Pools
  2. Firewall policies
  3. Security profiles
  4. Routing

Answer(s): D

Explanation:

The FortiManager stores the FortiGate configuration details in two distinct databases. The device-level database includes configuration details related to device-level settings, such as interfaces, DNS, routing, and more. The ADOM-level database includes configuration details related to firewall policies, objects, and security profiles.



Refer to the exhibit.



Which two statements about the output are true? (Choose two.)

  1. The latest revision history for the managed FortiGate does match with the FortiGate running configuration
  2. Configuration changes have been installed to FortiGate and represents FortiGate configuration has been changed
  3. The latest history for the managed FortiGate does not match with the device-level database
  4. Configuration changes directly made on the FortiGate have been automatically updated to device-level
    database

Answer(s): A,C

Explanation:

STATUS: dev-db: modified; conf: in sync; cond: pending; dm: retrieved; conn: up­ dev-db: modified ­ This is the device setting status which indicates that configuration changes were made on FortiManager.­ conf: in sync ­ This is the sync status which shows that the latest revision history is in sync with Fortigate's configuration.­ cond: pending ­ This is the configuration status which says that configuration changes need to be installed.
Most probably a retrieve was done in the past (dm: retrieved) updating the revision history DB (conf: in sync) and FortiManager device level DB, now there is a new modification on FortiManager device level DB (dev-db: modified) which wasn't installed to FortiGate (cond: pending), hence; revision history DB is not aware of that modification and doesn't match device DB.
Conclusion:­ Revision DB does match FortiGate.­ No changes were installed to FortiGate yet.­ Device DB doesn't match Revision DB.­ No changes were done on FortiGate (auto-update) but configuration was retrieved instead After an Auto-Update or Retrieve:device database = latest revision = FGT Then after a manual change on FMG end (but no install yet):latest revision = FGT (still) but now device database has been modified (is different). After reverting to a previous revision in revision history:device database = reverted revision != FGT



An administrator would like to review, approve, or reject all the firewall policy changes made by the junior administrators.

How should the Workspace mode be configured on FortiManager?

  1. Set to workflow and use the ADOM locking feature
  2. Set to read/write and use the policy locking feature
  3. Set to normal and use the policy locking feature
  4. Set to disable and use the policy locking feature

Answer(s): A


Reference:

https://help.fortinet.com/fmgr/50hlp/52/5-2- 0/FMG_520_Online_Help/200_What's-New.03.03.html



Which two settings must be configured for SD-WAN Central Management? (Choose two.)

  1. SD-WAN must be enabled on per-ADOM basis
  2. You can create multiple SD-WAN interfaces per VDOM
  3. When you configure an SD-WAN, you must specify at least two member interfaces.
  4. The first step in creating an SD-WAN using FortiManager is to create two SD-WAN firewall policies.

Answer(s): A,C



When an installation is performed from FortiManager, what is the recovery logic used between FortiManager and FortiGate for an FGFM tunnel?

  1. After 15 minutes, FortiGate will unset all CLI commands that were part of the installation that caused the tunnel to go down.
  2. FortiManager will revert and install a previous configuration revision on the managed FortiGate.
  3. FortiGate will reject the CLI commands that will cause the tunnel to go down.
  4. FortiManager will not push the CLI commands as a part of the installation that will cause the tunnel to go down.

Answer(s): A


Reference:

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/067f5236-ca6d- 11e9-8977-00505692583a/FGFM-6.2-Communications_Protocol_Guide.pdf page 17



Share your comments for Fortinet NSE5_FMG-6.4 exam with other users:

T
Timi
8/19/2023 5:30:00 PM

my first attempt

B
Blessious Phiri
8/13/2023 10:32:00 AM

very explainable

M
m7md ibrahim
5/26/2023 6:21:00 PM

i think answer of q 462 is variance analysis

T
Tehu
5/25/2023 12:25:00 PM

hi i need see questions

A
Ashfaq Nasir
1/17/2024 1:19:00 AM

best study material for exam

R
Roberto
11/27/2023 12:33:00 AM

very interesting repository

N
Nale
9/18/2023 1:51:00 PM

american history 1

T
Tanvi
9/27/2023 4:02:00 AM

good level of questions

B
Boopathy
8/17/2023 1:03:00 AM

i need this dump kindly upload it

S
s_123
8/12/2023 4:28:00 PM

do we need c# coding to be az204 certified

B
Blessious Phiri
8/15/2023 3:38:00 PM

excellent topics covered

M
Manasa
12/5/2023 3:15:00 AM

are these really financial cloud questions and answers, seems these are basic admin question and answers

N
Not Robot
5/14/2023 5:33:00 PM

are these comments real

K
kriah
9/4/2023 10:44:00 PM

please upload the latest dumps

E
ed
12/17/2023 1:41:00 PM

a company runs its workloads on premises. the company wants to forecast the cost of running a large application on aws. which aws service or tool can the company use to obtain this information? pricing calculator ... the aws pricing calculator is primarily used for estimating future costs

M
Muru
12/29/2023 10:23:00 AM

looks interesting

T
Tech Lady
10/17/2023 12:36:00 PM

thanks! that’s amazing

M
Mike
8/20/2023 5:12:00 PM

the exam dumps are helping me get a solid foundation on the practical techniques and practices needed to be successful in the auditing world.

N
Nobody
9/18/2023 6:35:00 PM

q 14 should be dmz sever1 and notepad.exe why does note pad have a 443 connection

M
Muhammad Rawish Siddiqui
12/4/2023 12:17:00 PM

question # 108, correct answers are business growth and risk reduction.

E
Emmah
7/29/2023 9:59:00 AM

are these valid chfi questions

M
Mort
10/19/2023 7:09:00 PM

question: 162 should be dlp (b)

E
Eknath
10/4/2023 1:21:00 AM

good exam questions

N
Nizam
6/16/2023 7:29:00 AM

I have to say this is really close to real exam. Passed my exam with this.

P
poran
11/20/2023 4:43:00 AM

good analytics question

A
Antony
11/23/2023 11:36:00 AM

this looks accurate

E
Ethan
8/23/2023 12:52:00 AM

question 46, the answer should be data "virtualization" (not visualization).

N
nSiva
9/22/2023 5:58:00 AM

its useful.

R
Ranveer
7/26/2023 7:26:00 PM

Pass this exam 3 days ago. The PDF version and the Xengine App is quite useful.

S
Sanjay
8/15/2023 10:22:00 AM

informative for me.

T
Tom
12/12/2023 8:53:00 PM

question 134s answer shoule be "dlp"

A
Alex
11/7/2023 11:02:00 AM

in 72 the answer must be [sys_user_has_role] table.

F
Finn
5/4/2023 10:21:00 PM

i appreciated the mix of multiple-choice and short answer questions. i passed my exam this morning.

A
AJ
7/13/2023 8:33:00 AM

great to find this website, thanks

AI Tutor 👋 I’m here to help!