Fortinet Enterprise Firewall 7.6 FCSS_EFW_AD-7.6 FortiManager Workflow Scripts Templates Practice Test
This practice test focuses on fortimanager workflow scripts templates and controlled installation through original applied scenarios aligned to the final published Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator 7.6 blueprint. It is intended for study and does not reproduce live exam content. For broader exam preparation, review the Fortinet FCSS_EFW_AD-7.6 Exam Dumps page.
Question 1
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Woodgrove Bank, which option correctly addresses the need to run the same validated CLI change across a defined set of managed FortiGate devices? Choose the smallest targeted change. Only one site is affected; peer sites are healthy.
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager workspace or workflow controls appropriate to the team process
Correct answer: A
Explanation
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This directly addresses the stated requirement.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a FortiManager CLI script scoped to the intended devices and review execution results. Central scripts provide repeatable execution across selected devices while preserving an audit trail.
Question 2
Alpine Ski House has verified basic IP reachability. The remaining requirement is to prevent two administrators from unknowingly editing the same policy package at the same time. Which action should the team take? The answer must address the stated cause rather than a different feature. The change must be validated on a pilot device before broader rollout.
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use a FortiManager CLI script scoped to the intended devices and review execution results
Correct answer: C
Explanation
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This directly addresses the stated requirement.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workspace or workflow controls appropriate to the team process. Workspace and workflow modes coordinate administrative changes and reduce conflicting edits.
Question 3
At Datum Corporation, the security infrastructure engineer must standardize interface and system settings for a large device group without copying changes manually. Which action best addresses the requirement? Preserve the existing design unless the requirement says otherwise. Existing production IP addressing must remain unchanged.
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
Correct answer: D
Explanation
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Templates make repeatable device configuration scalable and reduce manual drift. This directly addresses the stated requirement.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager provisioning templates or metadata-driven templates where supported. Templates make repeatable device configuration scalable and reduce manual drift.
Question 4
During an enterprise firewall change at Contoso Finance, the team needs to deploy a policy change only after a separate reviewer approves it. What should it do? Prefer a change that is reversible and easy to verify. The resulting configuration must remain centrally auditable.
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
Correct answer: A
Explanation
- Workflow controls separate change creation from approval and installation. This directly addresses the stated requirement.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workflow or approval controls so the edit and install stages require the intended authorization. Workflow controls separate change creation from approval and installation.
Question 5
A production review at Litware Logistics identifies this requirement: identify why an install fails because the managed database differs from the device. Which Fortinet action is most appropriate? The team needs an auditable result. A known-good rollback point is available before the change.
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
Correct answer: A
Explanation
- Configuration drift must be reconciled before central management can install a predictable target state. This directly addresses the stated requirement.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install. Configuration drift must be reconciled before central management can install a predictable target state.
Question 6
While troubleshooting at Wide World Importers, the network security architect needs to run the same validated CLI change across a defined set of managed FortiGate devices. What is the best next step? Use normal enterprise Fortinet administration practice. The design must preserve the current segmentation boundaries.
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager workspace or workflow controls appropriate to the team process
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager provisioning templates or metadata-driven templates where supported
Correct answer: A
Explanation
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This directly addresses the stated requirement.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a FortiManager CLI script scoped to the intended devices and review execution results. Central scripts provide repeatable execution across selected devices while preserving an audit trail.
Question 7
Relecloud is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to prevent two administrators from unknowingly editing the same policy package at the same time? Assume the platform versions are compatible with the feature. The team is not allowed to disable the security feature globally.
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workspace or workflow controls appropriate to the team process
Correct answer: E
Explanation
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workspace or workflow controls appropriate to the team process. Workspace and workflow modes coordinate administrative changes and reduce conflicting edits.
Question 8
A change ticket for Adventure Works states that administrators must standardize interface and system settings for a large device group without copying changes manually. Which choice is correct? No unrelated control should be weakened. The symptom appeared immediately after a planned configuration change.
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workspace or workflow controls appropriate to the team process
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
Correct answer: D
Explanation
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Templates make repeatable device configuration scalable and reduce manual drift. This directly addresses the stated requirement.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager provisioning templates or metadata-driven templates where supported. Templates make repeatable device configuration scalable and reduce manual drift.
Question 9
The security team at Fourth Coffee wants to deploy a policy change only after a separate reviewer approves it. Which configuration or operational action most directly satisfies that goal? The team will validate the result immediately after the change. Logs from the affected traffic are available for verification.
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
Correct answer: D
Explanation
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Workflow controls separate change creation from approval and installation. This directly addresses the stated requirement.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workflow or approval controls so the edit and install stages require the intended authorization. Workflow controls separate change creation from approval and installation.
Question 10
An incident at Coho Winery requires the NOC engineer to identify why an install fails because the managed database differs from the device. What should be done first? The change is taking place in a controlled maintenance window. The equivalent configuration works correctly at a separate site.
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workspace or workflow controls appropriate to the team process
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
Correct answer: D
Explanation
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Configuration drift must be reconciled before central management can install a predictable target state. This directly addresses the stated requirement.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install. Configuration drift must be reconciled before central management can install a predictable target state.
Question 11
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Fabrikam Manufacturing, which option correctly addresses the need to run the same validated CLI change across a defined set of managed FortiGate devices? Choose the smallest targeted change. The change must be reversible within the same maintenance window.
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use a FortiManager CLI script scoped to the intended devices and review execution results
Correct answer: E
Explanation
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a FortiManager CLI script scoped to the intended devices and review execution results. Central scripts provide repeatable execution across selected devices while preserving an audit trail.
Question 12
Wingtip Energy has verified basic IP reachability. The remaining requirement is to prevent two administrators from unknowingly editing the same policy package at the same time. Which action should the team take? The answer must address the stated cause rather than a different feature. The device is already synchronized with its central-management database.
- Use FortiManager workspace or workflow controls appropriate to the team process
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
Correct answer: A
Explanation
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This directly addresses the stated requirement.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workspace or workflow controls appropriate to the team process. Workspace and workflow modes coordinate administrative changes and reduce conflicting edits.
Question 13
At Lucerne Publishing, the Fortinet administrator must standardize interface and system settings for a large device group without copying changes manually. Which action best addresses the requirement? Preserve the existing design unless the requirement says otherwise. The current routing table contains the expected connected networks.
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
Correct answer: C
Explanation
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Templates make repeatable device configuration scalable and reduce manual drift. This directly addresses the stated requirement.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager provisioning templates or metadata-driven templates where supported. Templates make repeatable device configuration scalable and reduce manual drift.
Question 14
During an enterprise firewall change at Bellows College, the team needs to deploy a policy change only after a separate reviewer approves it. What should it do? Prefer a change that is reversible and easy to verify. Basic IP reachability to the remote endpoint has already been verified.
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager workspace or workflow controls appropriate to the team process
Correct answer: D
Explanation
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Workflow controls separate change creation from approval and installation. This directly addresses the stated requirement.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workflow or approval controls so the edit and install stages require the intended authorization. Workflow controls separate change creation from approval and installation.
Question 15
A production review at Tailspin Toys identifies this requirement: identify why an install fails because the managed database differs from the device. Which Fortinet action is most appropriate? The team needs an auditable result. Hardware replacement is outside the approved change scope.
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
Correct answer: E
Explanation
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Configuration drift must be reconciled before central management can install a predictable target state. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install. Configuration drift must be reconciled before central management can install a predictable target state.
Question 16
While troubleshooting at Humongous Insurance, the NOC engineer needs to run the same validated CLI change across a defined set of managed FortiGate devices. What is the best next step? Use normal enterprise Fortinet administration practice. The requirement applies only to one policy, peer, or managed device group.
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
Correct answer: A
Explanation
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This directly addresses the stated requirement.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a FortiManager CLI script scoped to the intended devices and review execution results. Central scripts provide repeatable execution across selected devices while preserving an audit trail.
Question 17
Margie Travel is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to prevent two administrators from unknowingly editing the same policy package at the same time? Assume the platform versions are compatible with the feature. The team must avoid broadening administrative trust or permissions.
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workspace or workflow controls appropriate to the team process
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
Correct answer: B
Explanation
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This directly addresses the stated requirement.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workspace or workflow controls appropriate to the team process. Workspace and workflow modes coordinate administrative changes and reduce conflicting edits.
Question 18
A change ticket for Northwind Health states that administrators must standardize interface and system settings for a large device group without copying changes manually. Which choice is correct? No unrelated control should be weakened. The design must preserve existing centralized logging and telemetry.
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workspace or workflow controls appropriate to the team process
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
Correct answer: A
Explanation
- Templates make repeatable device configuration scalable and reduce manual drift. This directly addresses the stated requirement.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager provisioning templates or metadata-driven templates where supported. Templates make repeatable device configuration scalable and reduce manual drift.
Question 19
The security team at Blue Yonder Airlines wants to deploy a policy change only after a separate reviewer approves it. Which configuration or operational action most directly satisfies that goal? The team will validate the result immediately after the change. Production subnets cannot be renumbered as part of this change.
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use a FortiManager CLI script scoped to the intended devices and review execution results
Correct answer: D
Explanation
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Workflow controls separate change creation from approval and installation. This directly addresses the stated requirement.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workflow or approval controls so the edit and install stages require the intended authorization. Workflow controls separate change creation from approval and installation.
Question 20
An incident at Trey Research requires the network operations engineer to identify why an install fails because the managed database differs from the device. What should be done first? The change is taking place in a controlled maintenance window. A maintenance window is open, but service interruption must be minimized.
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager provisioning templates or metadata-driven templates where supported
Correct answer: A
Explanation
- Configuration drift must be reconciled before central management can install a predictable target state. This directly addresses the stated requirement.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install. Configuration drift must be reconciled before central management can install a predictable target state.
Question 21
For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Apex Retail, which option correctly addresses the need to run the same validated CLI change across a defined set of managed FortiGate devices? Choose the smallest targeted change. The team must preserve existing certificate-trust relationships unless the requirement explicitly changes them.
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use a FortiManager CLI script scoped to the intended devices and review execution results
Correct answer: E
Explanation
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to run the same validated CLI change across a defined set of managed FortiGate devices.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use a FortiManager CLI script scoped to the intended devices and review execution results. Central scripts provide repeatable execution across selected devices while preserving an audit trail.
Question 22
Proseware Media has verified basic IP reachability. The remaining requirement is to prevent two administrators from unknowingly editing the same policy package at the same time. Which action should the team take? The answer must address the stated cause rather than a different feature. The change will be reviewed later using the configuration and event audit trail.
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use a FortiManager CLI script scoped to the intended devices and review execution results
Correct answer: D
Explanation
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This directly addresses the stated requirement.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to prevent two administrators from unknowingly editing the same policy package at the same time.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workspace or workflow controls appropriate to the team process. Workspace and workflow modes coordinate administrative changes and reduce conflicting edits.
Question 23
At City Power & Light, the enterprise firewall engineer must standardize interface and system settings for a large device group without copying changes manually. Which action best addresses the requirement? Preserve the existing design unless the requirement says otherwise. The chosen approach must continue to work as additional branch sites are added.
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use FortiManager provisioning templates or metadata-driven templates where supported
Correct answer: E
Explanation
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to standardize interface and system settings for a large device group without copying changes manually.
- Templates make repeatable device configuration scalable and reduce manual drift. This directly addresses the stated requirement.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager provisioning templates or metadata-driven templates where supported. Templates make repeatable device configuration scalable and reduce manual drift.
Question 24
During an enterprise firewall change at VanArsdel, the team needs to deploy a policy change only after a separate reviewer approves it. What should it do? Prefer a change that is reversible and easy to verify. A second engineer will verify the result using independent operational evidence.
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use a FortiManager CLI script scoped to the intended devices and review execution results
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workspace or workflow controls appropriate to the team process
Correct answer: A
Explanation
- Workflow controls separate change creation from approval and installation. This directly addresses the stated requirement.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Configuration drift must be reconciled before central management can install a predictable target state. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to deploy a policy change only after a separate reviewer approves it.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use FortiManager workflow or approval controls so the edit and install stages require the intended authorization. Workflow controls separate change creation from approval and installation.
Question 25
A production review at Woodgrove Bank identifies this requirement: identify why an install fails because the managed database differs from the device. Which Fortinet action is most appropriate? The team needs an auditable result. The team requires a deterministic rollback path if validation fails.
- Compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install
- Use FortiManager workflow or approval controls so the edit and install stages require the intended authorization
- Use FortiManager provisioning templates or metadata-driven templates where supported
- Use FortiManager workspace or workflow controls appropriate to the team process
- Use a FortiManager CLI script scoped to the intended devices and review execution results
Correct answer: A
Explanation
- Configuration drift must be reconciled before central management can install a predictable target state. This directly addresses the stated requirement.
- Workflow controls separate change creation from approval and installation. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Templates make repeatable device configuration scalable and reduce manual drift. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Workspace and workflow modes coordinate administrative changes and reduce conflicting edits. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
- Central scripts provide repeatable execution across selected devices while preserving an audit trail. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to identify why an install fails because the managed database differs from the device.
Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, compare device and FortiManager revisions, retrieve or reconcile the device configuration as appropriate, then repeat the controlled install. Configuration drift must be reconciled before central management can install a predictable target state.