Fortinet NSE5_FMG-7.2 Online Practice
Questions and Exam Preparation
NSE5_FMG-7.2 Exam Details
Exam Code
:NSE5_FMG-7.2
Exam Name
:Fortinet NSE 5 - FortiManager 7.2
Certification
:Fortinet Certifications
Vendor
:Fortinet
Total Questions
:101 Q&As
Last Updated
:May 25, 2026
Fortinet NSE5_FMG-7.2 Online Questions &
Answers
Question 71:
An administrator has assigned a global policy package to custom ADOM1. Then the administrator creates a new policy package, Fortinet, in the custom ADOM1. Which statement about the global policy package assignment to the newly-created policy package Fortinet is true?
A. When a new policy package is created, it automatically assigns the global policies to the new package. B. When a new policy package is created, you need to assign the global policy package from the global ADOM. C. When a new policy package is created, you need to reapply the global policy package to the ADOM. D. When a new policy package is created, you can select the option to assign the global policies to the new package.
A. When a new policy package is created, it automatically assigns the global policies to the new package.
Question 72:
An administrator run the reload failure command: diagnose test deploymanager reload config on FortiManager. What does this command do?
A. It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database. B. It installs the latest configuration on the specified FortiGate and update the revision history database. C. It compares and provides differences in configuration on FortiManager with the current running configuration of the specified FortiGate. D. It installs the provisioning template configuration on the specified FortiGate.
A. It downloads the latest configuration from the specified FortiGate and performs a reload operation on the device database.
Question 73:
View the following exhibit.
If both FortiManager and FortiGate are behind the NAT devices, what are the two expected results? (Choose two.)
A. FortiGate is discovered by FortiManager through the FortiGate NATed IP address. B. FortiGate can announce itself to FortiManager only if the FortiManager IP address is configured on FortiGate under central management. C. During discovery, the FortiManager NATed IP address is not set by default on FortiGate. D. If the FCFM tunnel is torn down, FortiManager will try to re-establish the FGFM tunnel.
A. FortiGate is discovered by FortiManager through the FortiGate NATed IP address. C. During discovery, the FortiManager NATed IP address is not set by default on FortiGate.
Question 74:
View the following exhibit.
An administrator has created a firewall address object, Training, which is used in the Local- FortiGate policy package. When the install operation is performed, which IP Netmask will be installed on the Local-FortiGate, for the Training firewall address object?
A. 10.0.1.0/24 B. It will create firewall address group on Local-FortiGate with 192. 168.0.1/24 and 10.0.1.0/24 object values C. 192. 168.0.1/24 D. Local-FortiGate will automatically choose an IP Network based on its network interface settings.
C. 192. 168.0.1/24
Question 75:
Refer to the exhibit.
A service provider administrator has assigned a global policy package to a managed customer ADOM named My_ADOM, which has four policy packages. The customer administrator has access onlytoMy_ADOM. How can customer or service provider administrators remove both global header and footer policies from the policy package named Shared_Package?
A. The service provider administrator can unassign both policies from the global ADOM. B. The service provider administrator can unassign both global policies from My_ADOM. C. The customer administrator can unassign both polices by locking My_ADOM. D. The customer administrator can unassign both global polices from My_ADOM.
A. The service provider administrator can unassign both policies from the global ADOM.
Question 76:
Refer to the exhibit.
What can you conclude from the failed installation log shown in the exhibit?
A. Policy ID 2 will not be installed. B. Policy ID 2 is installed in the disabled state. C. Policy ID 2 is installed without a source address. D. Policy ID 2 is installed without the remote user student.
D. Policy ID 2 is installed without the remote user student.
Question 77:
Push updates are failing on a FortiGate device that is located behind a NAT device Which two settings should the administrator check? (Choose two.)
A. That the virtual IP address and correct ports are set on the NAT device B. That the NAT device IP address and correct ports are configured on FortiManager C. That the external IP address on the NAT device is set to DHCP and configured with the virtual IP D. That the override server IP address is set on FortiManager and the NAT device
B. That the NAT device IP address and correct ports are configured on FortiManager C. That the external IP address on the NAT device is set to DHCP and configured with the virtual IP
Question 78:
Refer to the exhibit.
An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.
After the installation operation is performed, which IP/netmask will be shown on FortiManager for this firewall address object without specify Per-Device Mapping?
A. The FortiManager replaces the address object to none. B. 0.0.0.0/0. C. 192. 168.1.0/24. D. 10.0.5. 0/24.
C. 192. 168.1.0/24.
Question 79:
Refer to the exhibit.
Given the configuration shown in the exhibit, which two statements are true? (Choose two.)
A. The FortiManager ADOM workspace mode is set to Normal. B. An administrator can also lock the Local-FortiGate-1 policy package. C. The FortiManager ADOM is locked by the administrator. D. FortiManager is in workflow mode.
A. The FortiManager ADOM workspace mode is set to Normal. B. An administrator can also lock the Local-FortiGate-1 policy package.
Question 80:
Which of the following statements are true regarding VPN Manager? (Choose three.)
A. VPN Manager must be enabled on a per ADOM basis. B. VPN Manager automatically adds newly-registered devices to a VPN community. C. VPN Manager can install common IPsec VPN settings on multiple FortiGate devices at the same time. D. Common IPsec settings need to be configured only once in a VPN Community for all managed gateways. E. VPN Manager automatically creates all the necessary firewall policies for traffic to be tunneled by IPsec.
A. VPN Manager must be enabled on a per ADOM basis. C. VPN Manager can install common IPsec VPN settings on multiple FortiGate devices at the same time. D. Common IPsec settings need to be configured only once in a VPN Community for all managed gateways.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Fortinet exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your NSE5_FMG-7.2 exam preparations
and Fortinet certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.