Courseiva

CCNA Nse7 Enterprise Firewall Central Management Questions

32 questions · Nse7 Enterprise Firewall Central Management · All types, answers revealed

1
MCQhard

You are managing FortiGates across multiple ADOMs. How can you share common firewall objects (e.g., mail servers, common IP ranges) across these ADOMs?

A.Create objects in the Global Database
B.Manually copy objects to each ADOM
C.Use the API to script the creation in every ADOM
D.Enable 'Object Sharing' in system settings
AnswerA

Global database objects are available to all ADOMs.

Why this answer

Using the 'Global Database' or 'Global Policy' objects allows administrators to define objects once and share them across multiple ADOMs.

2
Multi-Selectmedium

Which TWO options are available when configuring an SD-WAN rule in FortiManager?

Select 2 answers
A.Interface physical speed
B.Source/Destination criteria
C.Traffic steering strategy
D.MAC address spoofing
E.Hardware acceleration toggle
AnswersB, C

Traffic matching is standard.

Why this answer

SD-WAN rules allow setting traffic steering based on criteria like source/destination and strategy (load balancing/manual).

3
MCQhard

An administrator is migrating a standalone FortiGate into an existing FortiManager. What happens to the existing firewall policies on the FortiGate during the import process?

A.They are moved to a 'Disabled' state
B.They are deleted to ensure a clean slate
C.They are merged into the Global Policy
D.They are imported and converted into a Policy Package
AnswerD

The import process captures existing policies into the database.

Why this answer

When importing, the FortiManager imports the configuration and creates a Policy Package; the existing policies are added to the 'Policy & Objects' database.

4
MCQhard

An administrator notices that logs are not appearing in FortiManager for a specific FortiGate. What is the first thing to check to ensure log forwarding is active?

A.The FortiManager license
B.The device's physical connection
C.Log forwarding configuration on the FortiGate
D.The firmware version of the FortiGate
AnswerC

FGT must be configured to send logs.

Why this answer

Checking the 'Log Settings' on the FortiGate to ensure the 'Remote Logging' feature is enabled and pointing to the correct FortiManager/FortiAnalyzer IP.

5
MCQmedium

What is the benefit of using 'CLI Templates' in FortiManager?

A.They replace the GUI completely
B.They convert the policy to a CLI script
C.They allow applying configuration commands to multiple devices
D.They improve the FortiGate hardware performance
AnswerC

Templates provide bulk configuration.

Why this answer

CLI templates allow you to push specific configuration lines to multiple devices, which is useful for settings not covered by the GUI policy editor.

6
MCQeasy

Which component of FortiManager allows for the centralized management of firmware across multiple devices?

A.Policy Database
B.Device Templates
C.Log View
D.Firmware Management
AnswerD

This is the correct module for firmware.

Why this answer

The 'Firmware Management' tool is dedicated to tracking, uploading, and deploying firmware to managed FortiGates.

7
MCQmedium

An administrator wants to use FortiManager to push a configuration change to 50 FortiGates simultaneously. Which method minimizes downtime and ensures consistency?

A.Create 50 separate ADOMs
B.Assign devices to a Device Group and push a common Policy Package
C.Connect to each FortiGate via SSH and run scripts
D.Enable 'Auto-Push' for every change
AnswerB

Device groups enable bulk management.

Why this answer

Using 'Provisioning Templates' or 'Device Groups' allows the administrator to push changes to multiple devices in a controlled, unified manner.

8
MCQhard

An administrator needs to perform a firmware upgrade on 100 FortiGates. Which feature in FortiManager allows this to be done securely with a rollback option?

A.Automated patch management
B.Manual script pushing
C.Firmware Management in Device Manager
D.Global Policy upgrade task
AnswerC

This manages upgrades across devices.

Why this answer

The 'Firmware Management' feature in Device Manager allows for scheduled upgrades and provides options for managing firmware versions across groups.

9
MCQeasy

What is the result of 'Pushing' a policy package from FortiManager to a FortiGate?

A.The FortiGate policy is sent to the FortiManager
B.The policy is saved in a draft state on the FortiGate
C.The FortiManager policy is appended to the existing FortiGate policy
D.The FortiGate policy configuration is overwritten with the FortiManager version
AnswerD

Pushing overwrites the device config.

Why this answer

Pushing a policy package replaces the current policy configuration on the FortiGate with the version stored in the FortiManager database.

10
Multi-Selectmedium

Which TWO methods can be used to authenticate a FortiGate when it registers to a FortiManager?

Select 2 answers
A.External RADIUS server
B.SNMP community string
C.Password/Pre-shared Key
D.Serial Number registration
E.IP-based automatic discovery
AnswersC, D

Passwords are used for secure registration.

Why this answer

Registration can be secured using a serial number/password combination or by adding the device's IP and certificate/serial in the FMG.

11
MCQmedium

When using FortiAnalyzer integration with FortiManager, where do you view the aggregated log reports?

A.System Settings
B.Reports & Analytics tab
C.Device Manager
D.Policy & Objects
AnswerB

This is where reports are generated.

Why this answer

Reports are generated and viewed within the FortiAnalyzer module, which is embedded in the FortiManager.

12
MCQhard

A FortiManager administrator needs to ensure that logs from all enterprise FortiGates are aggregated and purged based on storage thresholds. Where is this configured?

A.FortiAnalyzer/Log Settings under Device Manager
B.System settings under 'Network' tab
C.Global Policy settings
D.ADOM management settings
AnswerA

Log settings define disk management for logs.

Why this answer

The log retention and storage settings are managed in the FortiManager's 'FortiView' or 'Device Settings' regarding log management, specifically under 'Log Settings' where disk quota and retention policies are defined.

13
Multi-Selectmedium

Which TWO administrative actions require a 'Workspace Mode' enabled in FortiManager?

Select 2 answers
A.Automatic log rotation
B.Creating new ADOMs
C.Forcing a reboot
D.Locking policies for editing
E.Reviewing changes before publishing
AnswersD, E

Workspace mode enables locking.

Why this answer

Workspace mode is required for concurrent editing and locking of policies by multiple administrators.

14
Multi-Selectmedium

Which TWO actions can be performed on a Revision History item in FortiManager?

Select 2 answers
A.Compare with current version
B.Restore to a previous state
C.Delete the entire ADOM
D.Export the revision to an external cloud
E.Modify the version permanently
AnswersA, B

Diff/Compare identifies changes.

Why this answer

Revision history allows you to compare versions (diff) and restore to a previous state.

15
MCQhard

You are troubleshooting a policy installation failure where the FortiManager reports a 'Configuration conflict'. Which action should you perform to identify the root cause of the mismatch?

A.Force an 'Import Policy' operation
B.Reboot the FortiManager
C.Disable the policy package entirely
D.Use the 'Diff' feature in the Policy & Objects tab to compare the database and device config
AnswerD

The Diff tool is the standard method for resolving conflicts.

Why this answer

The 'Check Configuration' or 'Diff' tool in the Policy & Objects tab allows administrators to compare the database version against the running device configuration to pinpoint the exact setting causing the conflict.

16
Multi-Selectmedium

Which TWO types of reports can be generated in the FortiAnalyzer module of FortiManager?

Select 2 answers
A.Custom reports
B.Pre-defined reports
C.Policy change impact reports
D.Hardware diagnostic reports
E.Firmware compatibility reports
AnswersA, B

Admins can build custom reports.

Why this answer

FortiAnalyzer provides both pre-defined reports and custom reports for tailored analysis.

17
MCQeasy

When adding a FortiGate to FortiManager, which mode must the FortiGate be in to allow the FortiManager to manage its configuration and policies?

A.Registration-only mode
B.Backup mode
C.Normal mode
D.Read-only mode
AnswerC

Normal mode is required for full management.

Why this answer

The FortiGate must be in 'Normal' mode; if it is in 'Backup' or 'Read-only' mode, full management is not possible.

18
Multi-Selecthard

Which THREE items are included in a Policy Package when it is pushed from FortiManager?

Select 3 answers
A.Service Objects
B.Firewall Policies
C.System interface settings
D.Routing tables
E.Address Objects
AnswersA, B, E

Services define ports/protocols for policies.

Why this answer

Policy packages include firewall policies, address objects, and services used within those policies.

19
Multi-Selecthard

Which THREE features are specific to the FortiManager 'Enterprise Firewall' management workflow?

Select 3 answers
A.Object database management
B.Revision control
C.Traffic shaping on routers
D.Web filter database updates
E.Centralized policy management
AnswersA, B, E

Objects are managed globally.

Why this answer

Centralized policy management, object database management, and revision control are key parts of the enterprise workflow.

20
MCQeasy

What is the primary purpose of an ADOM in FortiManager?

A.To logically group devices for delegated administration and policy management
B.To provide high availability for the FortiGate
C.To allow external API access to the FortiGate
D.To increase the storage capacity of the FortiManager
AnswerA

ADOMs provide administrative segmentation.

Why this answer

Administrative Domains (ADOMs) allow the segregation of managed devices based on geography, customer, or business unit for delegated administration.

21
MCQmedium

An administrator is configuring the FortiManager to manage multiple FortiGate devices across different regions. Which method ensures that the device configuration remains synchronized with the FortiManager policy database during an automatic configuration update?

A.Set the FortiGate to 'Read-Only' mode
B.Enable Auto-update in the Device Manager configuration settings
C.Enable ADOM-level scheduling
D.Configure a manual CLI script to push updates
AnswerB

Auto-update ensures configuration synchronization.

Why this answer

The 'Auto-update' feature in the FortiManager Device Manager ensures that the configuration on the managed device is automatically synchronized with the policy package defined in the FortiManager database.

22
MCQmedium

Which type of script in FortiManager is designed to run on the FortiManager itself rather than the managed devices?

A.CLI scripts
B.TCL scripts
C.Configuration scripts
D.Policy scripts
AnswerB

TCL scripts run on the FMG.

Why this answer

TCL scripts can be used to automate FortiManager functions, whereas CLI scripts typically target the managed devices.

23
MCQmedium

Which FortiManager feature allows an administrator to test policy changes in a sandbox environment before applying them to production FortiGates?

A.Policy Testing Mode
B.Policy Package Cloning/Revision History
C.Global Policy Lockdown
D.Device Manager Simulation
AnswerB

Cloning allows for safe testing of changes.

Why this answer

The 'Revision History' or 'Policy Package cloning' allows admins to modify and verify changes before pushing them to the production devices.

24
Multi-Selecthard

Which THREE factors influence log storage efficiency on a FortiAnalyzer/FortiManager?

Select 3 answers
A.Log compression settings
B.Log retention days
C.The firewall firmware version
D.Disk quota for specific devices
E.The number of active users
AnswersA, B, D

Compression reduces storage footprint.

Why this answer

Log compression, log retention settings, and disk quota management determine how long logs persist and how much space they consume.

25
MCQmedium

You are setting up an SD-WAN configuration via FortiManager. Which object type is used to group multiple WAN interfaces for SD-WAN member assignment?

A.IP Pool
B.Virtual Wire Pair
C.SD-WAN Zone
D.Interface Group
AnswerC

Zones allow grouping of SD-WAN members.

Why this answer

The 'SD-WAN Zone' object is used in FortiManager to group multiple interfaces together for use in SD-WAN policies.

26
MCQeasy

Where can an administrator check the status of the connection between a FortiGate and FortiManager?

A.Log View
B.Device Manager
C.Policy & Objects
D.System Settings
AnswerB

Device Manager shows connectivity status.

Why this answer

The 'Device Manager' page lists all managed devices and displays their status (e.g., 'Up', 'Down', 'Synchronized').

27
MCQmedium

You want to automate the onboarding of new FortiGate units. Which FortiManager feature allows you to pre-configure devices before they connect to the network?

A.Provisioning Templates
B.Scripting
C.Device Registration Key
D.Policy cloning
AnswerA

Templates enable automated configuration.

Why this answer

Provisioning Templates allow you to define configuration settings that are applied automatically when the device registers with the FortiManager.

28
MCQmedium

An enterprise firewall administrator needs to deploy different security profiles to branch offices while sharing the same firewall policy structure. Which feature should be used?

A.Creating multiple ADOMs for every branch
B.Manual copy-paste of rules
C.Using CLI templates exclusively
D.Policy Package inheritance and mapping
AnswerD

Inheritance allows sharing of policy structures.

Why this answer

Policy Packages allow for the grouping of policies, while the use of 'Global Policy' or 'Package Inheritance' allows for common policies to be shared across various ADOMs or device groups.

29
Multi-Selecthard

Which THREE steps are involved in the 'Policy Package Installation' workflow?

Select 3 answers
A.Select the target device
B.Perform a factory reset
C.Review the install preview
D.Select the policy package
E.Reboot the target device
AnswersA, C, D

Target selection is required.

Why this answer

The workflow involves selecting the package, choosing the target device, and executing the installation (with a preview).

30
MCQmedium

When a policy change is made in FortiManager, it must be 'Installed' to take effect. What is the first stage of the install process?

A.Install Preview
B.Database validation
C.Config push
D.Reboot
AnswerA

Previewing is the first phase of verification.

Why this answer

The install process begins with an 'Install Preview' to verify the configuration changes before they are actually pushed to the device.

31
MCQhard

An administrator needs to provide access to FortiManager for a junior team member who should only be able to view logs and reports. Which feature is used to define this access?

A.Administrator Profiles
B.Access Control Lists (ACLs)
C.ADOM Assignment
D.User Groups
AnswerA

Profiles control feature-level access.

Why this answer

Administrators create 'Administrator Profiles' to restrict access to specific modules and permissions.

32
Multi-Selecthard

Which THREE items can be managed via Device Templates in FortiManager?

Select 3 answers
A.Firewall policies
B.NTP configuration
C.Application control databases
D.DNS settings
E.Local interface IP settings
AnswersB, D, E

NTP is a standard template item.

Why this answer

Device templates are used for system-level settings like DNS, NTP, and local interface configurations.

Ready to test yourself?

Try a timed practice session using only Nse7 Enterprise Firewall Central Management questions.