exam questions

Exam NSE7_EFW-7.2 All Questions

View all questions & answers for the NSE7_EFW-7.2 exam

Exam NSE7_EFW-7.2 topic 1 question 46 discussion

Actual exam question from Fortinet's NSE7_EFW-7.2
Question #: 46
Topic #: 1
[All NSE7_EFW-7.2 Questions]

You configured an address object on the root FortiGate in a Security Fabric. This object is not synchronized with a downstream device.

Which two reasons could be the cause? (Choose two.)

  • A. The downstream FortiGate has fabric-object-unification set to local.
  • B. The root FortiGate has configuration-sync set to enable.
  • C. The address object on the root FortiGate has fabric-object set to disable.
  • D. The downstream FortiGate has configuration-sync set to local.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Alexander101
3 days, 13 hours ago
Selected Answer: AC
The root FortiGate must have the address object set to fabric object enable and the downstream FortiGate must have the fabric object unification setting set to default. Configuration sync has to do with FortiAnalyzer and FortiManager Configuration settings being synced to downstream appliances which would not have an effect in the event of an address object.
upvoted 1 times
...
myrmidon3
1 month, 1 week ago
Selected Answer: AD
A. The downstream FortiGate has fabric-object-unification set to local. True. If the downstream FortiGate has fabric-object-unification set to local, it will not synchronize global objects from the root FortiGate. This setting allows the downstream FortiGate to maintain its own local objects independently of the root. B. The root FortiGate has configuration-sync set to enable. False. The configuration-sync on the root FortiGate is typically enabled to push objects downstream. This setting would not prevent synchronization but rather facilitate it. C. The address object on the root FortiGate has fabric-object set to disable. False. If the fabric-object is disabled for an address object, it won't be marked for synchronization within the Security Fabric. However, this option is not specified in the scenario, so it is unlikely to be the cause. D. The downstream FortiGate has configuration-sync set to local. True. If the downstream FortiGate has configuration-sync set to local, it will not import global CMDB objects from the root FortiGate. This setting restricts the synchronization of global objects to that specific device.
upvoted 2 times
...
infinitum
2 months, 2 weeks ago
Selected Answer: AC
Object synchronization can be configured with the following commands: config system csf set fabric-object-unification [default | local] set configuration-sync [default | local] ... next end https://docs.fortinet.com/document/fortigate/6.4.0/new-features/893434/synchronizing-objects-across-the-security-fabric
upvoted 1 times
...
charruco
8 months, 2 weeks ago
Selected Answer: CD
C and D are correct
upvoted 2 times
...
millerry
8 months, 3 weeks ago
Selected Answer: CD
A is incorrect because fabric-object-unification is not a setting applicable to downstream FortiGates. B is incorrect because configuration-sync being enabled on the root FortiGate should facilitate, not prevent, synchronization. C is correct because if the address object on the root FortiGate has fabric-object set to disable, it will not be synchronized. D is correct because if the downstream FortiGate has configuration-sync set to local, it will not accept the synchronized configuration from the root FortiGate.
upvoted 4 times
...
evdw
9 months ago
Selected Answer: CD
Correct answer C, D
upvoted 2 times
...
morsas23
9 months ago
Selected Answer: CD
C & D are correct SG page 67
upvoted 4 times
...
GCISystemIntegrator
9 months ago
Selected Answer: AC
we discuss about an address object and a downstream without specify how many downstream there are .... , and for this reason "C" is correct. A -- OK C -- OK
upvoted 1 times
evdw
8 months, 4 weeks ago
fabric-object-unification is configured on the root fotigate, is not for the downstream fortigates therefore C, and D
upvoted 3 times
...
...
Disposable_Me_2018
9 months ago
Selected Answer: AC
A & C are correct. B and D are wrong, as "configuration-sync" is "Synchronize configuration for IPAM, FortiAnalyzer, FortiSandbox, and Central Management with root node.", not object synchronisation. https://docs.fortinet.com/document/fortigate/7.4.4/cli-reference/
upvoted 3 times
...
dsticht
9 months ago
Selected Answer: CD
A fabric-object-unification is a root configuration. So, C & D
upvoted 4 times
...
dsticht
9 months ago
Selected Answer: AD
We agree on A being correct. I think the reason C is not correct is that they aren't saying ALL downstream FortiGates aren't synchronizing. They are referencing a single downstream device.
upvoted 3 times
dsticht
9 months ago
I change my answer to C & D. A. fabric-object-unification is a root configuration.
upvoted 1 times
...
...
K4KarOt0
9 months ago
Selected Answer: AC
Sorry, The CORRECT is AC: If set fabric-object (Fabric synchronization option in the GUI) is disabled for firewall addresses and address groups on the root FortiGate, they will not be synchronized to downstream FortiGates https://docs.fortinet.com/document/fortigate/6.4.0/new-features/520820/improvements-to-synchronizing-objects-across-the-security-fabric-6-4-4
upvoted 2 times
...
K4KarOt0
9 months ago
Selected Answer: AD
AD is the Correct. *fabric-object-unification* default: Global CMDB objects will be synchronized in Security Fabric. local: Global CMDB objects will not be synchronized to and from this device. *configuration-sync* default: Synchronize configuration for FortiAnalyzer, FortiSandbox, and Central Management to root node. local: Do not synchronize configuration with root node. https://docs.fortinet.com/document/fortigate/6.4.0/new-features/893434/synchronizing-objects-across-the-security-fabric
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago