Questions for the FCP FMG AD 7 6 were updated on : Nov 23 ,2025
Refer to the exhibits.

An administrator runs the reload failure command diagnose test deploymanager reloadconf 262 on
FortiManager.
Why does the administrator receive an error message?
B
Explanation:
The error occurs because the FortiGate HQ-NGFW device with ID 262 is a newly added model device
and has not yet been fully synchronized or installed with a configuration package, which causes the
reload configuration command to fail.
Refer to the exhibit.
Which two results occur if you run the script using the Device Database option? (Choose two.)
A, D
Explanation:
Running a script on the Device Database marks the configuration as modified but does not
immediately apply changes to the device.
The administrator must use the Install Wizard to push and install these changes from the Device
Database onto the managed device.
Refer to the exhibit.
What are two results from the configuration shown in the exhibit? (Choose two.)
A, B
Explanation:
In normal workspace mode, ungraceful session closures will keep the ADOM locked until the session
times out, preventing other administrators from editing.
Normal workspace mode allows administrators to lock policy blocks and the global ADOM, providing
granular locking control.
An administrator is copying a system template profile between ADOMs by running the following
command:
execute fmprofile export-profile ADOM 3547 /tmp/Backup_File
output dump to file: [/tmp/Backup_File]
Where does this command export the system template profile from?
B
Explanation:
The command exports the system template profile from the FortiManager ADOM policy database,
which stores the configuration templates for devices within that ADOM.
Refer to the exhibit.
What can you conclude from the downloaded import report?
B
Explanation:
The import report shows that a new policy package named Remote-FortiGate_root will be created in
the FortiManager ADOM database, but some firewall addresses and policies failed to import due to
interface binding conflicts.
A service provider administrator has assigned a global policy package to a managed customer ADOM
named My_ADOM. The customer administrator has access only to My_ADOM.
How can the customer administrator edit the global header policy of the global policy package?
D
Explanation:
The global policy package is managed only from the global ADOM by the service provider
administrator. Customer administrators with access solely to their ADOM (My_ADOM) cannot edit
the global header policy; such changes must be made by the service provider administrator in the
global ADOM.
Which output is displayed right after moving the ISFW device from one ADOM to another?
A)
B)
C)
D)
C
Explanation:
Right after moving the ISFW device to a new ADOM, the status typically shows the policy package as
never-installed, indicating that the device has been assigned to the new ADOM but no policy package
has yet been installed in that ADOM.
After correcting a policy package configuration issue, you want to prevent administrators from
repeating the mistake that caused the issue.
Which FortiManager approach best meets this need?
D
Explanation:
Enabling a workflow with approval ensures that any policy package changes must be reviewed and
approved before installation, preventing administrators from repeating configuration mistakes and
enforcing change control.
Refer to the exhibits.

An administrator has been asked to install the same policies from a central policy package onto the
BR1-FGT-1 firewall.
The administrator added BR1-FGT-1 as a target in the central policy package installation.
What should the administrator do when reinstalling the central policy package on the BR1-FGT-1
firewall?
C
Explanation:
Using the Install Wizard is the recommended method to reinstall the central policy package on the
BR1-FGT-1 firewall, ensuring all settings, installation targets, and dependencies are correctly
processed during installation.
Refer to the exhibit.
Which two statements about the output are true? (Choose two.)
A, D
Explanation:
The status "pending" indicates the latest revision history does not match the device-level database,
meaning there are unapplied changes.
The template is marked as [modified], so the system template default will override device-level
database configurations when installed.
Refer to the exhibits.


An administrator needs to push a FortiToken Mobile to assign it to HR_user in the HQ-NGFW-1.
However, when installing the policy package, they receive the following error message:
Why is the administrator not able to install the FortiToken on the HQ-NGFW-1 firewall?
B
Explanation:
The error occurs because the FortiToken used (FTKM0B4A9AC5C56D) must already exist and be
registered on the FortiGate device HQ-NGFW-1. FortiManager cannot push or create new FortiTokens
on the device; the token must be valid and present on the FortiGate before it can be assigned to a
user.
An administrator must create a policy and install it on a FortiGate device within an ADOM in backup
mode.
How can the administrator perform this task?
D
Explanation:
In backup mode, FortiManager does not directly manage policy installation via the usual ADOM
policy packages; instead, administrators use FortiManager scripts to push configuration changes,
including policies, to FortiGate devices.
Refer to the exhibit.
An administrator added a FortiGate device to FortiManager with the default object settings at the
ADOM layer.
What can you conclude from the import policy package process of the HQ-NGFW- 1 device?
C
Explanation:
The import process shows that FortiManager will create normalized interfaces named LAN, port4,
and port6 at the ADOM layer, mapping them to the corresponding device interfaces based on the
import settings.
Company policy dictates that any time a change is made to a policy package on FortiManager an
ADOM revision is created before the change installed, and that revision is held for a minimum of
90 days.
Over the past three months, each installed change has resulted in several unused policies and
duplicate objects.
The FortiManager administrator plans to upgrade the FortiGate devices and then upgrade the
FortiManager ADOM from version 7.4 to 7.6.
Which action can the administrator take to avoid slow ADOM upgrades?
D
Explanation:
Limiting ADOM revisions reduces the number of stored historical configurations, which helps avoid
performance degradation and slow ADOM upgrades caused by a large volume of revisions.
An administrator configures a new BGP peer in the FortiManager device-level database of FortiGate.
They reinstall the policy package to the managed FortiGate device without any errors. However,
when the administrator logs in to FortiGate, they do not see the BGP configuration changes.
What is the most likely reason why FortiManager did not push the BGP peer changes to FortiGate?
B
Explanation:
If a BGP template is assigned to the FortiGate device on FortiManager, device-level BGP
configurations made directly in the device-level database are overridden by the template settings, so
the changes do not get pushed to the device.