Enforce Policy Packages with FortiManager Central Management
Exhibit
FGT # get system fabric-status Fabric Role: Member Fabric Status: Connected Fabric Group: MyGroup Fabric Root: FGT-Root (serial: FG100D3TF16800001) Last contact: 2024-01-15 10:30:00 FGT # diagnose test application fgfms 3 FGFMs status: Registered with FortiManager: Yes FortiManager IP: 192.168.1.100 FortiManager status: Connected Last heartbeat: 2024-01-15 10:29:55
Refer to the exhibit. A FortiGate is connected to the Security Fabric and registered with FortiManager. However, the administrator notices that the FortiGate is not receiving policy updates from FortiManager. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates assume registration and Fabric connectivity guarantee policy updates, but FortiManager requires explicit policy package assignment to the device group or policy target, which is a separate configuration step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy package on FortiManager is not assigned to the correct device group or policy target
FortiManager uses policy packages that must be explicitly assigned to a device group or specific FortiGate. Even if the FortiGate is registered and part of the Security Fabric, if the policy package is not assigned to the correct device group or policy target, the FortiGate will not receive policy updates. This is a common misconfiguration where the policy package exists but is not linked to the device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Fabric Root serial number is incorrect
Why it's wrong here
The Fabric Root serial identifies the root FortiGate for topology and Fabric object sharing; it does not authenticate the FortiManager management tunnel. An incorrect root serial breaks Fabric synchronisation, but policy installation depends on FortiManager registration and the central management configuration.
- ✗
The FortiGate is not registered with FortiManager
Why it's wrong here
The exhibit already shows the FortiGate registered with FortiManager, so registration is not the cause; the failure lies elsewhere, such as policy package assignment or the installation target. Registration is the prerequisite checked when a device has never appeared in FortiManager at all.
- ✓
The policy package on FortiManager is not assigned to the correct device group or policy target
Why this is correct
FortiManager pushes policy only to devices covered by the installed policy package's assignment. If the FortiGate is absent from the target device group or policy target, installation silently skips it, so no updates arrive despite successful registration and Security Fabric membership.
- ✗
The Security Fabric is not fully connected
Why it's wrong here
A broken Security Fabric connection would block Fabric telemetry and dynamic address sharing, not FortiManager policy installation, which runs over the management tunnel independently. Fabric connectivity matters when the FortiGate must resolve Fabric connectors or share objects with other Fabric members.
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.