Fortinet FortiManager 7.6 Administrator (FCP_FMG_AD-7.6)
Get full access to the updated question bank and confidently prepare for your exam.
Vendor
Fortinet
Certification
Secure Networking
Content
62 Qs
Status
Verified
Updated
3 hours ago
Test the Practice Engine
Experience our interactive testing environment with free demo questions
Premium Bundle
Complete Success Suite
Save $39 Instantly
-
✓Full PDF + Interactive Engine Everything you need to pass
-
✓All Advanced Question Types Drag & Drop, Hotspots, Case Studies
-
✓Priority 24/7 Expert Support Direct line to certification leads
-
✓90 Days Free Priority Updates Stay current as exams change
Success Metric
98.4% Pass Rate
Standard Simulation
Practice Engine
One-Time Payment
-
Web-Based (Zero Install)
-
Real Testing Environment Virtual & Practice Modes
-
Interactive Engine Drag & Drop, Hotspots
-
60 Days Free Updates
Compatible with All Devices
Basic Tier
PDF Study Guide
Digital Access
- ✓ Exam Questions (PDF)
- ✓ Mobile Friendly
- ✓ 60 Days Updates
Verified 13-Question Preview (FCP_FMG_AD-7.6)
Verified Community
The CertoMetrics Standard.
Recommend the #1 platform for verified Fortinet certification resources.
Success Network
Help a Colleague Succeed.
Invite a peer to get their own updated FCP_FMG_AD-7.6 prep kit.
Exam Overview
The Fortinet FortiManager 7.6 Administrator (FCP_FMG_AD-7.6) certification is a pivotal credential for cybersecurity professionals aiming to master centralized management of Fortinet security infrastructure. This certification validates your expertise in leveraging FortiManager to streamline operations, enhance security posture, and ensure consistent compliance across diverse FortiGate deployments. Achieving this demonstrates proficiency in critical areas such as centralized configuration, robust policy management, efficient firmware upgrades, and comprehensive monitoring capabilities. This translates directly into improved operational efficiency, reduced human error, and a more resilient security fabric. Employers highly value certified professionals who can expertly utilize FortiManager to maintain a scalable and consistent security architecture, making this certification a significant career accelerator in the dynamic cybersecurity domain.
Questions
35
Passing Score
700/1000
Duration
60 Minutes
Difficulty
Intermediate
Level
Professional
Skills Measured
Career Path
Target Roles
Common Questions
Is the material up to date?
Yes. We update our question bank weekly to match the latest Fortinet standards. You get free updates for 90 days.
What format do I get?
You get instant access to both the **PDF** (for reading) and our **Premium Test Engine** (for exam simulation).
Is there a guarantee?
Absolutely. If you fail the FCP_FMG_AD-7.6 exam using our materials, we offer a full money-back guarantee.
When do I get the download?
Instantly. The download link is available in your dashboard immediately after payment is confirmed.
Free Study Guide Samples
Previewing updated FCP_FMG_AD-7.6 bank (13 Questions).
Which two conditions trigger FortiManager to create a new revision history? (Choose two.)
Correct Option: A,C
The correct two conditions that trigger FortiManager to create a new revision history are A and C.
A. When FortiManager installs device-level changes on a managed device
C. When FortiManager is auto-updated with configuration changes made directly on a managed device
An administrator has assigned a global policy package to a new ADOM named ADOM1.
What will happen if the administrator tries to create a new policy package in ADOM1?
Correct Option: A
When a global policy package is assigned to an ADOM (ADOM1 in this case), it appears in that ADOM's policy package list. If an administrator then creates a new policy package within ADOM1, this new package will be a local policy package. During the creation or subsequent configuration of this new local policy package, the administrator will be presented with options to define its relationship and interaction with other existing policy packages, including the global one. This typically involves setting the installation order, determining if the new package's policies apply before or after the global policies. Therefore, the administrator actively selects how the global policy package's context is integrated with the new local policy package, rather than it being automatic or requiring re-assignment.
Reference: https://docs.fortinet.com/document/fortimanager/7.4.0/administration-guide/464817/managing-global-and-local-adoms
Refer to the exhibits.


FortiGate HQ-NGFW-1 downloads and validates FortiGuard databases from FortiManager which acts as a local FortiGuard Distribution Server (FDS) in a closed network. An administrator pushes a new firewall policy with an intrusion prevention system (IPS) profile from FortiManager to FortiGate HQ- NGFW-1 However, FortiGate does not recognize the new IPS signature from FortiManager.
What is the most likely reason why FortiGate HQ-NGFW-1 does not recognize the new IPS signature?
Correct Option: B
The FortiGate GUI (Exhibit 1) displays the current IPS Definitions version as 6.00741. In contrast, the FortiManager GUI (Exhibit 2) shows much newer versions available for IPS signatures, such as 'Signature Meta Data (IPS Regular)' and 'Signature Meta Data (IPS Extended)' with versions like 29.0906. This significant discrepancy indicates that the FortiGate's IPS database is outdated compared to what is available on the FortiManager, which acts as the local FortiGuard Distribution Server (FDS). Consequently, the FortiGate cannot recognize newer IPS signatures that exist in the FortiManager's updated database but are absent from its own.
Why the other choices are incorrect:
- A: FortiGate must enable rating for the FortiManager IP address, 192.168.1.120, in server list 1. Rating services (e.g., web filtering or application control) are distinct from IPS signature updates. The issue is with IPS signature recognition, not rating.
- C: The administrator must enable IPv6 connections for FortiGuard services on FortiManager. The FortiGate's update server is configured with an IPv4 address (192.168.1.120) in the server list. There is no indication that IPv6 connectivity is required or that the lack of it is causing the signature recognition problem.
- D: The administrator must enable the fortiguard-anycast option to correctly download all signatures from the local FDS. The
fortiguard-anycastoption is used for connecting to the nearest FortiGuard cloud server in a distributed environment. In a closed network with a specific local FDS configured via a server list, anycast is not relevant or necessary for downloading signatures. The problem is a version mismatch, not a connection issue to the FDS.
Reference: https://docs.fortinet.com/document/fortimanager/7.4.0/administration-guide/526715/fortimanager-as-a-local-fortiguard-distribution-server
Which is recommended when you are managing a high volume of logs in your network?
Correct Option: B
When managing a high volume of logs in a network, the recommended approach is to leverage FortiAnalyzer. FortiManager is primarily a centralized management platform for Fortinet devices, while FortiAnalyzer is purpose-built for high-performance log collection, storage, analysis, and reporting. Integrating FortiAnalyzer with FortiManager allows FortiManager to offload the intensive task of log management to a dedicated system, thereby maintaining optimal performance for configuration management and orchestration, while FortiAnalyzer handles the large volume of log data efficiently and provides advanced analytics and reporting capabilities. FortiManager can then retrieve necessary log information or reports from FortiAnalyzer.
- Option A is incorrect: Storing high volumes of logs directly on FortiManager can strain its resources, negatively impacting its primary management functions and leading to performance degradation. FortiManager's storage is not optimized for high-volume, long-term log retention and analysis compared to FortiAnalyzer.
- Option C is incorrect: Enabling advanced ADOM mode on FortiManager is a feature for logical segmentation of devices and administrators within FortiManager. It does not address the underlying challenge of managing high volumes of log data; it's a management organizational feature, not a log processing solution.
- Option D is incorrect: Forwarding logs from FortiAnalyzer to FortiManager daily is counterproductive. FortiAnalyzer is designed to process and store logs efficiently. Sending high volumes of logs from FortiAnalyzer back to FortiManager would impose an unnecessary burden on the FortiManager, defeating the purpose of using a dedicated log management solution.
Reference: https://docs.fortinet.com/document/fortimanager/7.4.0/administration-guide/466601/integrating-with-fortianalyzer
While attempting to push a NetFlow configuration script through the FortiManager policy package: an administrator encounters an error stating that an object is unrecognized in line 4.

What must the administrator do to successfully apply the NetFlow configuration script and avoid the object unrecognized error?
Correct Option: B
Why this fixes the error:
When you run a CLI script in FortiManager, you have two primary options for where it executes: the Device Database or the Remote Device (directly via CLI).
The Problem: When you try to push a configuration script via a Policy Package or run it directly on the remote device, FortiManager attempts to apply the syntax immediately. If the script contains references to objects or configurations that only exist in the local FortiManager database but haven't been compiled/synchronized yet, the FortiGate or the policy compiler will reject it as an "unrecognized object."
What is the best explanation of how FortiManager helps with mass provisioning?
Correct Option: C
FortiManager excels in mass provisioning by centralizing device management and configuration deployment. Its primary method for achieving this is through the use of templates. Administrators can create standardized configurations or common settings within templates (e.g., Device Templates, CLI Templates, Policy Packages) and then apply these templates to multiple FortiGate or FortiAP devices simultaneously. This significantly streamlines the deployment process, ensures consistency across the network, and reduces manual configuration errors when managing a large number of devices.
Reference: https://docs.fortinet.com/document/fortimanager/7.4.0/administration-guide/464817/device-provisioning
What is the purpose of ADOM revisions?
Correct Option: D
The correct answer is D. ADOM revisions in FortiManager serve as snapshots, saving the complete state of all policy packages, objects, and configuration data within a specific ADOM at a given point in time. This functionality is crucial for version control, allowing administrators to create restore points before major changes or to revert to a previous, known-good configuration. It acts as a safety mechanism, enabling efficient recovery from misconfigurations or unwanted alterations.
Why the other choices are incorrect:
- A is incorrect: ADOM revisions are not primarily for finding unused, duplicate, or unnecessary firewall policies and objects; that's typically done by auditing tools or policy analysis features.
- B is incorrect: While revisions indirectly help track changes, their main purpose isn't to show specific changes during installation. They save the state of the ADOM's configuration.
- C is incorrect: Comparing previous snapshots with device-level databases is a function that can be performed using revisions, but it is not the primary purpose of creating a revision itself. A revision's fundamental purpose is to save the state.
Reference: https://docs.fortinet.com/document/fortimanager/7.0.0/administration-guide/464879/adom-revisions
Refer to the exhibit.
An administrator assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview, they noticed some settings they did not modify and are unsure about the changes.
Based on the exhibit, which two things will happen if they continue with the installation? (Choose two.)
Correct Option: B,D
The installation preview shows two key configurations:
config system central-managementandset server-type update rating: This command configures the FortiGate to use the FortiManager as its source for FortiGuard updates and ratings. This means the FortiGate will contact the FortiManager (acting as a FortiGuard Distribution Server or proxy) to download security updates like antivirus, IPS definitions, web filtering, and application control ratings. This aligns with Option B.config vpn certificate caandedit "root_CA3": This command installs a Certificate Authority (CA) certificate named 'root_CA3' onto the FortiGate. In a FortiManager-FortiGate deployment, installing a trusted CA on the FortiGate often serves to enable the FortiGate to authenticate the FortiManager's own certificate during the establishment of the secure FortiGate-to-FortiManager (FGFM) communication tunnel. This ensures that the FortiGate trusts the FortiManager it is communicating with, aligning with Option D.
set server-type update rating refers to FortiGuard updates/ratings, not firmware templates. While FortiManager manages firmware, this specific CLI snippet doesn't show a configuration related to firmware upgrades.Option C is incorrect because CA certificates are trust anchors used for validating other certificates (e.g., for SSL inspection, VPN, or management authentication), not directly as elements within firewall address objects or policies.
Reference: https://docs.fortinet.com/document/fortimanager/7.4.0/administration-guide/209995/device-manager-basics
Refer to the exhibit.

An administrator created two new meta fields in FortiManager.
Which operation can you perform with these parameters?
Correct Option: A
✅ Option A (Correct)
Meta fields in FortiManager are specifically designed to extend standard configuration objects, such as firewall addresses, services, or policies, with custom attributes. This functionality allows administrators to add unique descriptive or functional properties to objects, enhancing organization, search capabilities, and enabling more dynamic configuration based on these custom data points.
❌ Why the other choices are incorrect:
- Option B is incorrect: Meta fields are typically ADOM-specific. There is no direct, native export/import mechanism to transfer meta field definitions between different ADOMs in FortiManager.
- Option C is incorrect: While meta field values associated with objects can be leveraged in policy package templates or scripts that process those objects, they are not directly used as general-purpose variables within scripts in the same manner as global or device variables.
- Option D is incorrect: The '$' character is primarily used to invoke system-defined or global variables (e.g., $adom_name, $__device_name). Meta fields are custom attributes of objects and are referenced contextually through object properties, not by direct '$' invocation as standalone variables.
Reference: https://docs.fortinet.com/document/fortimanager/7.0.0/administration-guide/526732/meta-fields
Push updates are failing on a FortiGate device located behind a network address translation (NAT) device?
Which two settings should the administrator check to correct this problem? (Choose two.)
Correct Option: A,C
When a FortiGate device is located behind a Network Address Translation (NAT) device and FortiManager needs to push updates, two key configurations are essential:
- Option C: Configure Virtual IP (VIP) on the NAT device: The NAT device must have a Virtual IP (VIP) configured. This VIP maps an external public IP address and port (e.g., TCP 8890) to the FortiGate's internal private IP address and the corresponding management port. This allows the FortiManager, located on the external network, to initiate a connection to the FortiGate.
- Option A: Configure FortiManager with the NAT device's external IP: FortiManager needs to know the reachable IP address of the FortiGate. In a NAT scenario, this will be the external public IP address of the NAT device (the VIP) that is configured to forward traffic to the FortiGate. The FortiManager's device settings for the FortiGate must specify this public IP address and the correct management port (typically 8890).
Without both these settings, FortiManager will not be able to establish a connection to the FortiGate to push updates.
Reference: https://docs.fortinet.com/document/fortimanager/7.4.0/administration-guide/202685/adding-devices-to-fortimanager
The administrator uses FortiManager to push a CLI script using the Remote FortiGate Directly (via CLI) option to configure an IPsec VPN. However, when running the script, the administrator receives the following error: config vpn ipsec phase2-interface [parameter(s) invalid. detail: object mismatch]
What must the administrator do to resolve the script error and successfully apply the IPsec configuration?
Premium Solution Locked
Unlock all 62 answers & explanations
An administrator has a FortiGate-HQ device with VDOMs—root, HR and Facilities, currently managed under the FortiManager ADOM—Site1. They try to move VDOM HR to the FortiManager ADOM—Site2, but it does not work.
Why is the administrator not able to move FortiGate-HQ VDOM HR to FortiManager ADOM—Site2?
Premium Solution Locked
Unlock all 62 answers & explanations
Refer to the exhibit.
FortiManager is operating behind a network address translation (NAT) device, and the administrator configured the FortiManager NATed IP address under the FortiManager system administration settings.
What is the expected result during discovery?
Premium Solution Locked
Unlock all 62 answers & explanations
Full Question Bank Locked
You have reached the end of the free study guide preview. Upgrade now to unlock all 62 questions and the full simulation engine.
Certification Path
Related Certifications
Customer Reviews
Global Community Feedback
David M.
"The practice engine is incredible. It feels exactly like the real testing environment and helped me build so much confidence."
Sarah J.
"The PDF is very well organized and the explanations for the answers are actually helpful, not just random text."
Michael C.
"I was skeptical, but the content is high quality and definitely worth the price. I passed on my first try!"