Courseiva

Enforce Policy Packages with FortiManager Central Management

Exhibit

FGT # get system fabric-status
Fabric Role: Member
Fabric Status: Connected
Fabric Group: MyGroup
Fabric Root: FGT-Root (serial: FG100D3TF16800001)
Last contact: 2024-01-15 10:30:00
FGT # diagnose test application fgfms 3
FGFMs status:
  Registered with FortiManager: Yes
  FortiManager IP: 192.168.1.100
  FortiManager status: Connected
  Last heartbeat: 2024-01-15 10:29:55

Refer to the exhibit. A FortiGate is connected to the Security Fabric and registered with FortiManager. However, the administrator notices that the FortiGate is not receiving policy updates from FortiManager. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates assume registration and Fabric connectivity guarantee policy updates, but FortiManager requires explicit policy package assignment to the device group or policy target, which is a separate configuration step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy package on FortiManager is not assigned to the correct device group or policy target

FortiManager uses policy packages that must be explicitly assigned to a device group or specific FortiGate. Even if the FortiGate is registered and part of the Security Fabric, if the policy package is not assigned to the correct device group or policy target, the FortiGate will not receive policy updates. This is a common misconfiguration where the policy package exists but is not linked to the device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Fabric Root serial number is incorrect

    Why it's wrong here

    The Fabric Root serial identifies the root FortiGate for topology and Fabric object sharing; it does not authenticate the FortiManager management tunnel. An incorrect root serial breaks Fabric synchronisation, but policy installation depends on FortiManager registration and the central management configuration.

  • ✗

    The FortiGate is not registered with FortiManager

    Why it's wrong here

    The exhibit already shows the FortiGate registered with FortiManager, so registration is not the cause; the failure lies elsewhere, such as policy package assignment or the installation target. Registration is the prerequisite checked when a device has never appeared in FortiManager at all.

  • ✓

    The policy package on FortiManager is not assigned to the correct device group or policy target

    Why this is correct

    FortiManager pushes policy only to devices covered by the installed policy package's assignment. If the FortiGate is absent from the target device group or policy target, installation silently skips it, so no updates arrive despite successful registration and Security Fabric membership.

  • ✗

    The Security Fabric is not fully connected

    Why it's wrong here

    A broken Security Fabric connection would block Fabric telemetry and dynamic address sharing, not FortiManager policy installation, which runs over the management tunnel independently. Fabric connectivity matters when the FortiGate must resolve Fabric connectors or share objects with other Fabric members.

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.