Fortinet Certified Professional - FortiManager 7.4 Administrator Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 204 questions. Use the simulator for timed and flashcard mode.

Try Simulator

FCP-FMG-AD-7-4 Sample Questions

  1. Question 1

    Q1

    A financial services company is using FortiManager in workflow mode to ensure a strict change control process. An administrator submits a session containing changes to a critical firewall policy. The designated approver reviews the session but finds a minor error in one of the service objects used. What is the approver's most appropriate action within the FortiManager workflow process?

    Show answer & explanation

    Correct answer: B

    In FortiManager's workflow mode, the approver's role is to validate the submitted changes. If an error is found, the correct procedure is to reject the session and provide comments. This sends the session back to the original administrator who can then repair the session by correcting the error and resubmitting it for approval. Approving a session with a known error violates the principle of change control. Approvers cannot directly edit or repair sessions submitted by others.

  2. Question 2

    Q2

    A network administrator is tasked with adding 100 new retail branch FortiGates to FortiManager using the Zero Touch Provisioning (ZTP) feature. The administrator has created a device blueprint that includes a system template and assigns a policy package. However, they notice that after a new FortiGate is registered via ZTP, the assigned policy package is not being installed automatically. What is a likely cause for this issue?

    Show answer & explanation

    Correct answer: B

    For Zero Touch Provisioning (ZTP) to automatically install configurations, including policy packages, the 'auto-link' setting must be enabled within the device blueprint. This setting instructs FortiManager to automatically run the installation process for assigned templates and policy packages after the device successfully registers. If it is disabled, the device will be added to FortiManager but will require a manual installation task to be initiated.

  3. Question 3

    Q3Multiple answers

    An administrator needs to create a firewall policy that allows traffic only from authenticated Active Directory users in the 'Engineering' group. The FSSO connector is configured correctly in the ADOM. When creating the firewall policy, which two objects must be selected to correctly define the source of the traffic? (Select TWO).

    Show answer & explanation

    Correct answers: A, B

    When creating a user identity-based firewall policy, you must specify both the source user/group and the source address. The FSSO user group object identifies the authenticated user, while the firewall address object (often 'all' or a specific subnet) defines the network location from which the user's traffic originates. Both are required for the policy to function correctly.

  4. Question 4

    Q4

    True or False: When FortiManager is operating in a closed network without internet access, it is impossible to manage FortiGuard subscriptions for managed devices.

    Show answer & explanation

    Correct answer: B

    False. FortiManager can operate as a local FortiGuard Distribution Server (FDS) in a closed or air-gapped network. An administrator can use a separate FortiManager with internet access to download FortiGuard packages, export them to a removable media, and then import them into the closed-network FortiManager. This allows the air-gapped FortiManager to provide FortiGuard updates to its managed devices.

  5. Question 5

    Q5

    A system administrator is reviewing the revision history for a managed FortiGate and observes several configuration changes that were made directly on the FortiGate, causing a 'Modified' state in FortiManager. The administrator wants to overwrite the local changes on the FortiGate with the configuration stored in FortiManager's device database. Which action should be performed?

    Show answer & explanation

    Correct answer: B

    When a device's configuration state is 'Modified', it means the running configuration on the FortiGate differs from what FortiManager has in its database for that device. To enforce FortiManager's configuration and overwrite the local changes, the administrator must perform an installation. Using the Install Wizard and selecting 'Install Device Settings' will push the configuration from the FortiManager device database to the FortiGate, resolving the 'Modified' state and ensuring consistency.

  6. Question 6

    Q6

    A university manages its campus network with multiple FortiGates grouped by building. The central IT team wants to enforce a baseline security policy across all buildings but allow each building's IT staff to add their own specific firewall rules. The central IT team must retain control over the baseline rules, preventing any modifications by building staff. Which FortiManager feature should be used to achieve this hierarchical policy management?

    Show answer & explanation

    Correct answer: B

    The Global ADOM is designed for this purpose. By creating a global policy package and defining rules within the 'Header Policy' section, these rules are enforced at the top of the policy table for all ADOMs that use this global package. Building IT staff can then add their own rules in the ADOM-level policy package, which will be evaluated after the centrally-controlled header policies. This maintains central control while allowing for local flexibility.

  7. Question 7

    Q7

    An organization is deploying a new FortiManager HA cluster. The administrator has configured two FortiManager VMs with identical resources and firmware. After configuring the HA settings, the administrator notices that the configuration synchronization is failing between the primary and secondary units. Which of the following is a common cause for this issue?

    Show answer & explanation

    Correct answer: B

    FortiManager HA synchronization relies on a secure channel established between the cluster members. A common cause for synchronization failure is a mismatch in the HA configuration itself. The primary unit must be configured with the correct peer IP address of the secondary unit and a shared HA password. The secondary unit must have the same HA password configured. Any discrepancy in these settings will prevent the secure channel from being established, leading to sync failures.

  8. Question 8

    Q8

    A junior administrator is using a script to update the DNS settings on a group of 20 FortiGates. After running the script, the task monitor shows that the script failed on five of the devices. What is the most effective first step to diagnose the cause of the failures on those specific devices?

    Show answer & explanation

    Correct answer: C

    The Script History page provides detailed logs for each script execution. For failed tasks, it shows the specific device, the time of failure, and often a response from the device indicating the reason for the failure (e.g., command not found, invalid parameter, permission denied). This is the most direct and informative first step for troubleshooting script execution issues.

  9. Question 9

    Q9

    What is the primary function of ADOM revisions in FortiManager?

    Show answer & explanation

    Correct answer: B

    An ADOM revision is a snapshot of the ADOM's database at a specific moment. This includes all policy packages, objects, and settings within that ADOM. It serves as a backup and a restore point, allowing an administrator to revert the entire ADOM configuration to a previous known-good state if necessary.

  10. Question 10

    Q10

    A new FortiManager administrator profile is being created for a team that only manages Web Application Firewall (WAF) policies. The super administrator wants to limit the team's access to only the relevant sections of the GUI. Which permission setting within the administrator profile achieves this?

    Show answer & explanation

    Correct answer: D

    FortiManager provides granular permissions within administrator profiles. To limit access to a specific function like WAF policy management, a custom profile should be created. The administrator can then navigate to the 'Policy & Objects' section of the permissions and set the access level for 'Security Profiles - WAF Profile' to 'Read-Write' while setting other unrelated permissions to 'None'. This ensures the team can only see and manage the specific components relevant to their job.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the FCP-FMG-AD-7-4 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 204 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon