exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 20 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 20
Topic #: 1
[All NSE4_FGT-7.0 Questions]

Refer to the exhibits.
Exhibit A.

Exhibit B.

An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).
What must the administrator do to synchronize the address object?

  • A. Change the csf setting on Local-FortiGate (root) to set configuration-sync local.
  • B. Change the csf setting on ISFW (downstream) to set configuration-sync local.
  • C. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
  • D. Change the csf setting on ISFW (downstream) to set fabric-object-unification default.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PonPom3
Highly Voted 1 year, 3 months ago
Selected Answer: C
Its C. On the config output set fabric-object-unification is se to local, which means the device does not synchronize objects from the root but will send the synchronized objects downstream. So it must be changed back to default ( which is the default setting) and Global CMDB objects will be synchronized in the Security Fabric. https://docs.fortinet.com/document/fortigate/6.4.5/administration-guide/880913/synchronizing-objects-across-the-security-fabric
upvoted 7 times
...
Kimkeezai
Highly Voted 1 year, 4 months ago
Should be A. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Disable-re-enable-automatic-synchronization-of-the/ta-p/191082?externalID=FD43820
upvoted 7 times
...
raydel92
Most Recent 4 months, 1 week ago
Selected Answer: C
Correct: C. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default. FortiGate Security 7.2 Study Guide (p.434): "The CLI command set fabric-object-unification is only available on the root FortiGate. When set to local, global objects will not be synchronized to downstream devices in the Security Fabric. The default value is default" Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 1 times
...
Azr0d
9 months ago
The CLI command set fabric-object-unification is only available on the root fortigate. When set to local, global objects will not be syncronized to downstream devices in the security fabric. The default value is default. The CLI command set configuration-sync local is used when a downstream fortigate doesn't need to participate in object synchronization. When set to local on dowsntream fortigate, the device does not synchronize objects from the root, but will still participate in sending the synchronized objects downstream.
upvoted 2 times
mahareth
8 months, 2 weeks ago
C is correct.
upvoted 1 times
...
...
hamidreza0010
10 months, 2 weeks ago
Selected Answer: C
C is correct
upvoted 2 times
...
Ernestokoro
1 year, 4 months ago
@Kimkeezai, No bro, the answer is correct with C. Option A will not synchronise global fabric objects downstream . Answer remains C
upvoted 6 times
Kimkeezai
1 year, 4 months ago
U r right bro, it's C. Referring to FG Infra pg 75, change fabric-object-unification back to default.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago