01. Intro And Initial Config Flashcards

1
Q

Purpose of ADOMs

A
  1. to divide administration of devices by ADOM
  2. to control (restrict) administrator access.
  3. If VDOMs are used, ADOMs can further restrict access to only data from a specific device VDOM.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the main benefit of using FMG as local FDN

A. The reduction of network delays and internet bandwidth use
B. the maintenance local ad servers and users

A

A. The reduction of network delays and internet bandwidth use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Difference between FMG and FAZ in regards to logging

A

FortiManager and FortiAnalyzer run on the same hardware and software platform.
Like FortiAnalyzer, FortiManager can also act as a logging and reporting device, but there are logging rate restrictions. Logging volumes are limited to fix amount each day
Also, FortiManager requires additional resources (CPU, memory, disk) to process logs and reports.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When would you use FMG for logging and when prefer FAZ?

A

FortiManager can be used as a fully functional logging and reporting device for low volumes of logs

If you have high log volumes, you should use a dedicated FortiAnalyzer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Management layers

A

Global ADOM level
ADOM level
Device management layer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Global ADOM layer contain

A

Global objects shared across ADOMs
Header policies
Footer policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ADOM layer contains

A

Common object db. The databases contains information such as addresses, services, and security profiles.
Devices
Device groups
Policy packages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Device manager layer contain

A

Centrally managed Device info:
name and type of device
model
IP address
current firmware installed
revision history
real-time status.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What happens if device config changes

A

whether the change is made locally or on the FortiManager—then, FortiManager compares the current configuration revision to the changed configuration, and creates a new configuration revision on FortiManager.
Whether the configuration change is big or small, FortiManager records it and saves the new configuration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which statement about global ADOM layers is true

A. Same policy can be assigned to multiple ADOMS
B. global ADOM rules are auto installed on managed FGT

A

A. Same policy can be assigned to multiple ADOMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What info is recorded in device manager layer for managed device

A. Common ADOM layer db
B. Real-time status of managed device

A

B. Real-time status of managed device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

FMG deployment best practice

A
  1. Deploy behind fw
  2. Open only required ports
  3. For remote access outside of the network define Virtual IP
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What statement about managed FAZ on FMG is true

A. FMG supports FAZ reports
B. FMG has logging rate restriction on managed FAZ

A

A. FMG supports FAZ reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which port used between FMG and FGT for remote config management (IPv4)

A. TCP/541
B. TCP/514

A

A. TCP/541

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which statement about large mssp using FMG is true

A. Each customer must have dedicated FMG
B. ADOMS can be used by separate customers

A

B. ADOMS can be used by separate customers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which API is available on FMG

A. JSON API
B. UML API

A

A. JSON API

17
Q

FMG ha heartbeat or sync port

A

TCP/5199