DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Fortinet FCP_FMG_AD-7.6 Practice Questions & Answers 2026 Part1 | Fortinet NSE 6 - FortiManager Administrator

Are you preparing for the Fortinet NSE 6 - FortiManager Administrator certification exam? SPOTO offers the Fortinet NSE 6 - FortiManager Administrator Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You want to let multiple administrators work in the same ADOM without creating configuration conflicts.What is the best and the most effective solution to apply?
A. Configure RADIUS authentication to assign ADOM roles to each user
B. Enable workflow mode, which is the only way to prevent concurrent configuration conflicts
C. Assign administrators with JSON API access to the FortiManager
D. Activate workspace mode in the ADOM settings
View answer
Correct Answer: D
Question #2
Refer to Exhibits:An administrator has observed the performance status outputs on an HA cluster for 55 seconds.Which FortiGate is the primary?
A. HQ-NGFW-2 with the parameter memory-failover-threshold setting
B. HQ-NGFW-2 with the parameter priority setting
C. HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting
D. HQ-NGFW-1 with the parameter override setting
View answer
Correct Answer: A
Question #3
You want to let multiple administrators work in the same ADOM without creating configuration conflicts.What is the best and the most effective solution to apply?
A. Configure RADIUS authentication to assign ADOM roles to each user
B. Enable workflow mode, which is the only way to prevent concurrent configuration conflicts
C. Assign administrators with JSON API access to the FortiManager
D. Activate workspace mode in the ADOM settings
View answer
Correct Answer: D
Question #4
You want to let multiple administrators work in the same ADOM without creating configuration conflicts.What is the best and the most effective solution to apply?
A. Configure RADIUS authentication to assign ADOM roles to each user
B. Enable workflow mode, which is the only way to prevent concurrent configuration conflicts
C. Assign administrators with JSON API access to the FortiManager
D. Activate workspace mode in the ADOM settings
View answer
Correct Answer: D
Question #5
Refer to the exhibits.FortiGate HQ-NGFW-1 downloads and validates FortiGuard databases from FortiManager which acts as a local FortiGuard Distribution Server (FDS) in a closed network. An administrator pushes a new firewall policy with an intrusion prevention system (IPS) profile from FortiManager to FortiGate HQ- NGFW-1 However, FortiGate does not recognize the new IPS signature from FortiManager.What is the most likely reason why FortiGate HQ-NGFW-1 does not recognize the new IPS signature?
A. FortiGate must enable rating for the FortiManager IP address, 192
B. FortiManager and FortiGate have different IPS database versions
C. The administrator must enable IPv6 connections for FortiGuard services on FortiManager
D. The administrator must enable the fortiguard-anycast option to correctly download all signatures from the local FDS
View answer
Correct Answer: B
Question #6
What is the purpose of ADOM revisions?
A. To save the current state of the whole ADOM
B. To save the current state of all policy packages and objects for an ADOM
C. To revert individual policy packages and device-level settings for a managed FortiGate
D. To save the FortiManager configuration in the System Checkpoints
View answer
Correct Answer: B
Question #7
Refer to the exhibit.An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.After the installation operation is performed, which IP/netmask is shown on FortiManager for this firewall address object for devices without a Per-Device Mapping set?
A. FortiManager generates an error for each FortiGate without a per-device mapping defined for that object
B. 192
C. 192
D. FortiManager replaces the address object to none
View answer
Correct Answer: B
Question #8
Refer to the exhibit.An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.After the installation operation is performed, which IP/netmask will be installed on Remote-Firewall [VDOM1] for the LAN firewall address object?
A. 21
B. 172
C. 172
D. 10
View answer
Correct Answer: A
Question #9
Refer to the exhibit.An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.After the installation operation is performed, which IP/netmask will be installed on Remote-Firewall [VDOM1] for the LAN firewall address object?
A. 21
B. 172
C. 172
D. 10
View answer
Correct Answer: A
Question #10
Refer to the exhibit.Which two statements about the output are true? (Choose two.)
A. The latest revision history for the managed FortiGate does not match the device-level database
B. Configuration changes have been installed on FortiGate, which means the FortiGate configuration has been changed
C. Configuration changes directly made on FortiGate have been automatically updated to the device-level database
D. The latest revision history for the managed FortiGate does match the FortiGate running configuration
View answer
Correct Answer: AB
Question #11
Refer to the exhibit.If the monitored interface for the primary FortiManager device fails, what must you do to maintain high availability (HA)?
A. The FortiManager HA failover is transparent to administrators and does not require any additional action
B. Manually promote one of the working secondary devices to the primary role: and reboot the original primary device to remove the peer IP address of the failed device
C. Reconfigure the primary device to remove the peer IP address of the failed device from its configuration
D. Check the integrity database of the primary device to force a secondary device to become the new primary with all active interfaces
View answer
Correct Answer: A
Question #12
Refer to the exhibit.Given the configuration shown in the exhibit, which two conclusions can you draw from the installation targets in the Install On column? (Choose two.)
A. Policy seq
B. Policy seq
C. Policy seq
D. Policy seq
View answer
Correct Answer: AD
Question #13
An administrator wants to configure and manage multiple objects in the FortiManager database and give access to other users who work in the same database.To stay in control of the changes made to firewall policies by other team members, the administrator needs a setup where all modifications go through a central check before they can be installed.How can the administrator create this setup?
A. Enable the prompt asking the administrator to accept firewall policies changes before saving
B. Enable the workspace (for all ADOMs) to control all changes made by any administrator
C. Enable device lock and the advanced mode feature in the ADOM
D. Enable workflow mode and the ADOM lock feature
View answer
Correct Answer: D
Question #14
An administrator is in the process of copying a system template profile between ADOMs by running the following command: execute fmprofile import-profile ADOM2 3547 /tmp/myfile Where does this command import the system template profile from?
A. ortiManager file system
B. ource ADOM policy database
C. DOM2 object database
D. DOM2 device database
View answer
Correct Answer: A
Question #15
An administrator sees that the policy package status of HQ-NGFW-1 is Never Installed. What can you conclude from this status? Choose one answer
A. The policies have not yet been retrieved from the HQ-NGFW-1 device-level database of FortiManager
B. The policy package was never imported to the revision history after HQ-NGFW-1 was registered on FortiManager
C. The firewall policies were created or changed in the ADOM, and they need to be installed on the managed HQ-NGFW-1 for the first time
D. The firewall policies exist only in the HQ-NGFW-1 device-level database, and no policy package has been assigned to the firewall
View answer
Correct Answer: D
Question #16
An administrator wants to configure and manage multiple objects in the FortiManager database and give access to other users who work in the same database.To stay in control of the changes made to firewall policies by other team members, the administrator needs a setup where all modifications go through a central check before they can be installed.How can the administrator create this setup?
A. Enable the prompt asking the administrator to accept firewall policies changes before saving
B. Enable the workspace (for all ADOMs) to control all changes made by any administrator
C. Enable device lock and the advanced mode feature in the ADOM
D. Enable workflow mode and the ADOM lock feature
View answer
Correct Answer: D
Question #17
Refer to the exhibit.What are two results from the configuration shown in the exhibit? Choose two answers.
A. The same administrator can lock more than one ADOM at the same time
B. Multiple administrators can lock and work on separate ADOMs at the same time
C. All changes must be approved before they can be installed on a device
D. Concurrent read-write access to an ADOM is disabled
View answer
Correct Answer: AD
Question #18
Which statement about the policy lock feature on FortiManager is true?
A. Policy locking is available in workspace normal mode
B. Locking a policy takes precedence over a locked ADOM
C. When a policy is locked, the ADOM that contains it is also locked
D. Administrators in the approval group can work concurrently on a locked policy
View answer
Correct Answer: C
Question #19
An administrator enabled workspace mode and now wants to delete an address object that is currently referenced in a firewall policy.Which two results can the administrator expect? (Choose two.)
A. FortiManager will temporarily change the status of the referenced firewall policy to disabled
B. FortiManager will disable the status of the address object until the changes are installed
C. FortiManager will not allow the administrator to delete a referenced address object until they lock the ADOM
D. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy
View answer
Correct Answer: CD
Question #20
Refer to the exhibits.An administrator needed to recover all the configurations related to the user, Support. The configurations were saved in configuration revision ID 9.The administrator reverted the configuration using the Configuration Revision History window and received the CLI output shown in the exhibit.What can you conclude from the CLI output?
A. The administrator set the flag to 0 to prevent configuration overrides
B. The administrator reinstalled the policy package
C. The administrator needs to retrieve the device to correctly detect the FortiGate firmware version
D. The administrator installed only the device-level configuration
View answer
Correct Answer: C
Question #21
Refer to the exhibit.A service provider administrator has assigned a global policy package to a managed customer ADOM namedMy_ADOM, which has four policy packages. The customer administrator has access only toMy_ADOM.How can the customer or service provider administrators remove the global header policy from the policy package namedShared_Package?
A. he service provider administrator can unassign the global policy from My_ADOM
B. he customer administrator can unassign the global policy from My_ADOM
C. he customer administrator can unassign the policy by locking My_ADOM
D. he service provider administrator can unassign the policy from the global ADOM
View answer
Correct Answer: D
Question #22
Refer to the exhibits.An administrator needed to recover all the configurations related to the user, Support. The configurations were saved in configuration revision ID 9.The administrator reverted the configuration using the Configuration Revision History window and received the CLI output shown in the exhibit.What can you conclude from the CLI output?
A. The administrator set the flag to 0 to prevent configuration overrides
B. The administrator reinstalled the policy package
C. The administrator needs to retrieve the device to correctly detect the FortiGate firmware version
D. The administrator installed only the device-level configuration
View answer
Correct Answer: C
Question #23
Refer to the exhibits.An administrator needed to recover all the configurations related to the user, Support. The configurations were saved in configuration revision ID 9.The administrator reverted the configuration using the Configuration Revision History window and received the CLI output shown in the exhibit.What can you conclude from the CLI output?
A. The administrator set the flag to 0 to prevent configuration overrides
B. The administrator reinstalled the policy package
C. The administrator needs to retrieve the device to correctly detect the FortiGate firmware version
D. The administrator installed only the device-level configuration
View answer
Correct Answer: D
Question #24
Refer to the exhibit.If the monitored interface for the primary FortiManager device fails, what must you do to maintain high availability (HA)?
A. The FortiManager HA failover is transparent to administrators and does not require any additional action
B. Manually promote one of the working secondary devices to the primary role: and reboot the original primary device to remove the peer IP address of the failed device
C. Reconfigure the primary device to remove the peer IP address of the failed device from its configuration
D. Check the integrity database of the primary device to force a secondary device to become the new primary with all active interfaces
View answer
Correct Answer: A
Question #25
What is the purpose of ADOM revisions?
A. To save the current state of the whole ADOM
B. To save the current state of all policy packages and objects for an ADOM
C. To revert individual policy packages and device-level settings for a managed FortiGate
D. To save the FortiManager configuration in the System Checkpoints
View answer
Correct Answer: B
Question #26
Refer to the exhibit.If the monitored interface for the primary FortiManager device fails, what must you do to maintain high availability (HA)?
A. The FortiManager HA failover is transparent to administrators and does not require any additional action
B. Manually promote one of the working secondary devices to the primary role: and reboot the original primary device to remove the peer IP address of the failed device
C. Reconfigure the primary device to remove the peer IP address of the failed device from its configuration
D. Check the integrity database of the primary device to force a secondary device to become the new primary with all active interfaces
View answer
Correct Answer: A
Question #27
An administrator enabled workspace mode and now wants to delete an address object that is currently referenced in a firewall policy.Which two results can the administrator expect? (Choose two.)
A. FortiManager will temporarily change the status of the referenced firewall policy to disabled
B. FortiManager will disable the status of the address object until the changes are installed
C. FortiManager will not allow the administrator to delete a referenced address object until they lock the ADOM
D. FortiManager will replace the deleted address object with the none address object in the referenced firewall policy
View answer
Correct Answer: CD
Question #28
Refer to the exhibit.Which two statements about the output are true? (Choose two.)
A. The latest revision history for the managed FortiGate does not match the device-level database
B. Configuration changes have been installed on FortiGate, which means the FortiGate configuration has been changed
C. Configuration changes directly made on FortiGate have been automatically updated to the device-level database
D. The latest revision history for the managed FortiGate does match the FortiGate running configuration
View answer
Correct Answer: AD
Question #29
Which two conditions trigger FortiManager to create a new revision history? (Choose two.)
A. When FortiManager installs device-level changes on a managed device
B. When changes to the device-level database are made on FortiManager
C. When FortiManager is auto-updated with configuration changes made directly on a managed device
D. When a provisioning template is assigned to a managed device on the device-level database
View answer
Correct Answer: BC
Question #30
Refer to the exhibit.An administrator has created a firewall address object that is used in multiple policy packages for multiple FortiGate devices in an ADOM.After the installation operation is performed, which IP/netmask is shown on FortiManager for this firewall address object for devices without a Per-Device Mapping set?
A. FortiManager generates an error for each FortiGate without a per-device mapping defined for that object
B. 192
C. 192
D. FortiManager replaces the address object to none
View answer
Correct Answer: B

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us