View all questions & answers for the NSE 5 - FortiManager 7.6 Administrator Exam Materials exam


Question 13 Discussion

Refer to the exhibit. An administrator assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview, they noticed some settings they did not modify and are unsure about the changes. Based on the exhibit, which two things will happen if they continue with the installation? (Choose two answers)

  • A. FortiGate HQ-NGFW-1 can use FortiManager firmware templates to upgrade firmware and ratings.
  • B. FortiGate HQ-NGFW-1 can contact the FortiManager acting as FortiGuard Distribution Server (FDS) to download FortiGuard updates.
  • C. FortiGate HQ-NGFW-1 will use the root_CA3 certificate in firewall address objects or policies.
  • D. FortiManager will install the CA certificate named root_CA3 to authenticate FortiGate-to-FortiManager communication protocol (FGFM) tunnel connections with FortiGate HQ-NGFW-1.
Correct Answer: B,D

Brave-Dump Clients Votes

BD 66.67%
BC 33.33%

Comments



Saeed Abd El Halim Hamada 2025-07-16 21:33:54

Selected Answers: B, C


Correct Answer: B &C ,
From this output
config vpn certificate ca
edit "root_CA3"
set ca "-----BEGIN CERTIFICATE-----"
This means the certificate "root_CA3" is being added to the FortiGate and can be used for SSL inspection, IPsec tunnels, or certificate-based authentication in policies or objects.

D. Incorrect — The config doesn’t show root_CA3 being used for FGFM authentication.


Mahboab Ali Ghaleb 2025-08-07 03:16:31

Selected Answers: B, D


CA certificates are not used directly in address objects or policy rules.
They are used for SSL inspection, certificate validation, or FortiManager-to-FortiGate trust.


Alejandro Rivarola 2026-01-27 15:40:51

Selected Answers: B, D


usa la the CA certificate named root_CA3 para autenticar el fortigate con el manager.
y usa al manager como servidor de actualizacion del fortiguard