An administrator is managing a multi-tenant environment using separate ADOMs. They need to create a standardized set of compliance policies (PCI-DSS) that must be applied to all FortiGates across all customer ADOMs, but also allow local administrators to add their own specific policies.
Answer and explanation
Correct answer: B
The Global ADOM is specifically designed for this purpose. Header and footer policies are enforced globally and cannot be modified within individual ADOMs, ensuring compliance. Local ADOM administrators can then add their own policies between the header and footer policies, fulfilling all requirements efficiently.
Question 2
A network engineer is using a TCL script in FortiManager to automate the creation of VLAN interfaces on over 100 FortiGates. The script needs to assign a unique IP address to each new interface based on a value stored in a device-level meta field named 'VLAN_IP'. The script fails on some devices.
Answer and explanation
Correct answer: C
TCL scripts rely on correct syntax to reference variables like meta fields (e.g., using $(meta_field_name)). The script's failure on only some devices strongly suggests that either the script logic for handling the variable is flawed, or the 'VLAN_IP' meta field has not been assigned a value for those specific devices, causing the script to fail when it tries to reference a null or empty value.
Question 3
Multiple answers
A senior administrator is designing a FortiManager architecture for an enterprise with distinct business units (Sales, Engineering, HR) and a central IT security team. The primary design goals are: 1) Isolate the management of devices and policies for each business unit. 2) Allow the central security team to define and enforce a common set of security profiles (AV, IPS, Web Filter) across all business units.
Answer and explanation
Correct answers: A, B
Creating a separate ADOM for each business unit is the standard and most effective way to achieve management isolation for devices, policies, and objects.
The Global ADOM is specifically designed to create and manage objects and policies that can be shared and enforced across multiple regular ADOMs, which perfectly fits the requirement for a central security team to manage common security profiles.
Question 4
True or False: In a FortiManager HA cluster operating in active-passive mode, the secondary unit actively synchronizes its configuration from the primary unit but does not manage any FortiGate devices directly unless a failover occurs.
Answer and explanation
Correct answer: A
This statement is True. In a standard active-passive FortiManager HA cluster, the primary unit handles all management tasks, including communication with FortiGate devices. The secondary (passive) unit maintains a synchronized copy of the configuration and database but remains idle with respect to device management until it is promoted to the primary role during a failover event.
Question 5
A financial services company uses FortiManager 7.6 to manage 50 branch office FortiGates. A junior administrator was tasked with updating the corporate SSL VPN portal banner for all devices. The administrator created a CLI script to upload the new banner text and ran it against the "Branch-Offices" device group. Immediately after, users reported being unable to connect to the SSL VPN.
A senior engineer begins to investigate and observes that the installation log for the script shows "success" for all devices. However, when checking the device settings in FortiManager, the configuration status for all branch FortiGates is "Modified." A diagnose dvm device list command on the FortiManager CLI shows the conf status as out-of-sync. The engineer suspects the script caused an unintended configuration change that is preventing FortiManager from properly managing the devices.
The script used by the junior admin contained the following commands:
config vpn ssl web portal
edit "full-access"
set heading "Welcome to Secure Access v2.0"
end
The engineer needs to rapidly restore SSL VPN connectivity for all users across all 50 branches with minimal disruption and ensure the configuration is consistent with the FortiManager database.
Answer and explanation
Correct answer: C
The core issue is that the devices are out-of-sync with an incorrect local configuration. The most direct and scalable way to fix this is to force FortiManager's version of the configuration onto the devices. Using the "Install Wizard" for "Device Settings" does exactly this. It overwrites the unintended local changes made by the faulty script with the configuration stored in the FortiManager database, restoring service and bringing the devices back into a "synchronized" state.
Question 6
An administrator is working in an ADOM where Workspace Mode is enabled. They have locked a policy package to make changes. While the package is locked, another administrator needs to urgently add a new firewall address object that will be used in a different, unlocked policy package.
Answer and explanation
Correct answer: B
In FortiManager's Workspace Mode, locking is granular and applies to specific objects or policy packages, not the entire ADOM database. The second administrator can create a new address object because it is a separate entity from the locked policy package. They would only be blocked if they tried to modify an object already in use by the locked package or the locked package itself.
Question 7
A company is deploying FortiGates to remote sites where the devices are behind a carrier-grade NAT (CGNAT), meaning they have private, non-routable WAN IP addresses. The administrator needs to manage these FortiGates using FortiManager.
Answer and explanation
Correct answer: D
When a FortiGate is behind a NAT device, FortiManager cannot initiate a connection to it. The connection must be initiated from the FortiGate to the FortiManager. The FortiGate FGFM protocol is designed for this purpose. The FortiGate uses its WAN interface to connect out to the FortiManager's public IP address, establishing a management tunnel that FortiManager can then use for management.
Question 8
An administrator has imported a policy package from a newly managed FortiGate. They notice that several address objects that were used in the imported policies on the FortiGate now have a warning icon in FortiManager and are listed as conflicts in the import wizard.
Answer and explanation
Correct answer: A
During a policy import, FortiManager compares the objects from the FortiGate with the objects already in the ADOM database. If an object from the FortiGate has the same name as an existing ADOM object but with different attributes (e.g., a different IP address), FortiManager flags it as a conflict. This process, called normalization, requires the administrator to choose which version of the object to use.
Question 9
A system administrator needs to back up the entire FortiManager configuration, including all ADOMs, device configurations, and global settings. They want a single file that can be used to restore the system to a new FortiManager VM in a disaster recovery scenario.
Answer and explanation
Correct answer: C
The backup option in the System Information widget on the System Settings dashboard is the correct GUI method for creating a full system backup. This single .dat file contains all configurations for the entire FortiManager appliance, including system settings, all ADOMs, policies, objects, and device databases, making it ideal for a full system restore or migration.
Question 10
An organization is using the Global ADOM to manage a set of corporate security policies. They have a global policy package with a "Header Policy" section that denies traffic to known malicious sites. A junior administrator in a regional ADOM is trying to create a policy to allow access to a specific site for a business partner, but the traffic is still being blocked.
Answer and explanation
Correct answer: B
FortiManager constructs the final policy table on the FortiGate by combining global and local policies in a specific order: Global Header Policies first, then Local ADOM Policies, and finally Global Footer Policies. Since the deny rule is in the Header Policy section, it is evaluated before any of the local ADOM's policies. The first matching rule is applied, so the deny rule in the global header blocks the traffic before the local allow rule is ever reached.