exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 7 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 7
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibits.
An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).


What must the administrator do to synchronize the address object?

  • A. Change the csf setting on ISFW (downstream) to set configuration-sync local.
  • B. Change the csf setting on ISFW (downstream) to set authorization-request-type certificate.
  • C. Change the csf setting on both devices to set downstream-access enable.
  • D. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Equiano
Highly Voted 1 year, 9 months ago
Selected Answer: D
The correct answer is D. When both devices are configured with set downstream-access-disable (answer in C) then the newly created address objects are still replicated. However, when I configure the root with set fabric-object-unification local the address object is no longer replicated to the downstream FortiGates. I believe that the Exhibit B is wrong!
upvoted 15 times
...
JakubCh
Highly Voted 1 year, 5 months ago
Selected Answer: C
D - not correct Fortigate Security guide 7.2 - page 434 The CLI command "set fabric-object-unification" is only available on the root FortiGate.
upvoted 11 times
[Removed]
11 months, 2 weeks ago
The named "Local-Fortigate" is the root FortiGate.
upvoted 7 times
...
...
davidmdlp85
Most Recent 2 months ago
Selected Answer: C
set downstream-access enable On the root FortiGate of the Security Fabric, enable downstream access.
upvoted 1 times
...
0d6e481
2 months, 3 weeks ago
Selected Answer: D
It's D. On the actual test it's set to local.
upvoted 1 times
...
Milopezg2004
2 months, 4 weeks ago
FGTA-1 # config system csf set status enable set group-name "csf_script" set fabric-object-unification default ... end FGTB-1 # config system csf set status enable set upstream-ip 10.2.200.1 set configuration-sync local ... end
upvoted 1 times
...
Jere2001
8 months, 3 weeks ago
Selected Answer: C
The correct answer is C. Because "set fabric-object-unification default" is already defined in the configuration presented in "Exhibit B".
upvoted 3 times
...
Mqbx
9 months, 1 week ago
Selected Answer: C
The downstream-access feature must be enable https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/148376/preparing-fortigate-for-supported-security-fabric-devices, if not is enable the security fabric not function
upvoted 3 times
...
MAUROBTA
9 months, 3 weeks ago
Selected Answer: C
The downstream-access feature must be enable https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/148376/preparing-fortigate-for-supported-security-fabric-devices, if not is enable the security fabric not function
upvoted 2 times
...
Mallu_92
9 months, 4 weeks ago
Selected Answer: C
A and B does not apply here, D answer doesn't change anything in the configuration as it is already configured in the root FG. Correct answer is C.
upvoted 4 times
...
Umbrella2000
11 months, 2 weeks ago
When the Security Fabric is enabled, various objects such as addresses, services, and schedules are synced from the upstream FortiGate to all downstream devices by default1. Therefore, if a new address object created on the root FortiGate (Local-FortiGate) is not available on the downstream FortiGate (ISFW) after synchronization, it indicates that there might be a sync issue. However, none of the options A, B, C, and D provided directly address this issue based on the information available
upvoted 1 times
...
paulosrsf
11 months, 4 weeks ago
Selected Answer: D
The Exhibit B is wrong and misleading the answer. The root configuration is "set fabric-object-unification local", then the right answer should be to change it to DEFAULT.
upvoted 3 times
learner2024
8 months ago
That is my idea, the exhibit be is wrong, as it is there is nothing wrong that prevents the object from syncing. if 'fabric-object-unification' is set to local on root Fg, yes it prevents syncing; now it is 'default' so no problem seen, so there is no right choice from A-D in this case.
upvoted 2 times
...
...
AMK2ENG
1 year ago
D. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
upvoted 2 times
...
GeniusA
1 year ago
Option C is the correct answer
upvoted 1 times
...
piipo
1 year, 1 month ago
Selected Answer: C
Answer C is correct.
upvoted 1 times
...
SpikeDad
1 year, 1 month ago
Answer C is correct. From the study guide "If object synchronisation is disabled on the root Fortigate, using the command 'set fabric-object disable', firewall addresses and address groups will not be synchronised to downstream Fortigate devices." The question states that the admin created an address object on the root, so it won't be synchronised.
upvoted 3 times
...
wwwwaaaa
1 year, 2 months ago
Selected Answer: C
A is wrong, "if set configuration-sync is set to local, the downstream device does not participate in synchronization" B wrong, as the connection has been established and no need to authenticate D is wrong, the command is already there on the root C is the only one left
upvoted 5 times
...
LAFNELL
1 year, 2 months ago
I think neither D nor C is correct. Don't forget the fabric-object-unification command is configured on a downstream device and not on Root Fortigate. It could be correct if we had proposed answer like : "Change the csf settings on ISFW by set fabric-object-unification default"
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago