Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE4_FGT-7.2 topic 1 question 7 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 7
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibits.
An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).


What must the administrator do to synchronize the address object?

  • A. Change the csf setting on ISFW (downstream) to set configuration-sync local.
  • B. Change the csf setting on ISFW (downstream) to set authorization-request-type certificate.
  • C. Change the csf setting on both devices to set downstream-access enable.
  • D. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Equiano
Highly Voted 1 year, 1 month ago
Selected Answer: D
The correct answer is D. When both devices are configured with set downstream-access-disable (answer in C) then the newly created address objects are still replicated. However, when I configure the root with set fabric-object-unification local the address object is no longer replicated to the downstream FortiGates. I believe that the Exhibit B is wrong!
upvoted 12 times
...
JakubCh
Highly Voted 9 months, 3 weeks ago
Selected Answer: C
D - not correct Fortigate Security guide 7.2 - page 434 The CLI command "set fabric-object-unification" is only available on the root FortiGate.
upvoted 9 times
AxiansPT
3 months, 1 week ago
The named "Local-Fortigate" is the root FortiGate.
upvoted 4 times
...
...
Jere2001
Most Recent 1 week, 4 days ago
Selected Answer: C
The correct answer is C. Because "set fabric-object-unification default" is already defined in the configuration presented in "Exhibit B".
upvoted 1 times
...
Mqbx
3 weeks, 4 days ago
Selected Answer: C
The downstream-access feature must be enable https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/148376/preparing-fortigate-for-supported-security-fabric-devices, if not is enable the security fabric not function
upvoted 1 times
...
MAUROBTA
1 month, 1 week ago
Selected Answer: C
The downstream-access feature must be enable https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/148376/preparing-fortigate-for-supported-security-fabric-devices, if not is enable the security fabric not function
upvoted 1 times
...
Mallu_92
1 month, 2 weeks ago
Selected Answer: C
A and B does not apply here, D answer doesn't change anything in the configuration as it is already configured in the root FG. Correct answer is C.
upvoted 1 times
...
Umbrella2000
3 months ago
When the Security Fabric is enabled, various objects such as addresses, services, and schedules are synced from the upstream FortiGate to all downstream devices by default1. Therefore, if a new address object created on the root FortiGate (Local-FortiGate) is not available on the downstream FortiGate (ISFW) after synchronization, it indicates that there might be a sync issue. However, none of the options A, B, C, and D provided directly address this issue based on the information available
upvoted 1 times
...
paulosrsf
3 months, 2 weeks ago
Selected Answer: D
The Exhibit B is wrong and misleading the answer. The root configuration is "set fabric-object-unification local", then the right answer should be to change it to DEFAULT.
upvoted 2 times
...
AMK2ENG
4 months, 1 week ago
D. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
upvoted 2 times
...
GeniusA
4 months, 2 weeks ago
Option C is the correct answer
upvoted 1 times
...
piipo
5 months, 1 week ago
Selected Answer: C
Answer C is correct.
upvoted 1 times
...
SpikeDad
5 months, 2 weeks ago
Answer C is correct. From the study guide "If object synchronisation is disabled on the root Fortigate, using the command 'set fabric-object disable', firewall addresses and address groups will not be synchronised to downstream Fortigate devices." The question states that the admin created an address object on the root, so it won't be synchronised.
upvoted 2 times
...
wwwwaaaa
5 months, 3 weeks ago
Selected Answer: C
A is wrong, "if set configuration-sync is set to local, the downstream device does not participate in synchronization" B wrong, as the connection has been established and no need to authenticate D is wrong, the command is already there on the root C is the only one left
upvoted 4 times
...
LAFNELL
6 months, 1 week ago
I think neither D nor C is correct. Don't forget the fabric-object-unification command is configured on a downstream device and not on Root Fortigate. It could be correct if we had proposed answer like : "Change the csf settings on ISFW by set fabric-object-unification default"
upvoted 1 times
...
keshzy
6 months, 1 week ago
C - Correct. C stands for correct. jk. This is tricky just because D is already enable by default and is actually given in this scenario that it is already enabled. Clearly C - because look this statement in exhibit B on the root side "set fabric-object disable". this needs to be changed to enable. ^_^
upvoted 1 times
...
Possa
6 months, 3 weeks ago
Selected Answer: C
Fortigate Security guide 7.2 - page 434
upvoted 1 times
...
ake01
7 months, 1 week ago
D - Correct. To synchronize the address object created on the root FortiGate (Local-FortiGate) with the downstream FortiGate (ISFW), the administrator must ensure that the fabric-object-unification setting on the root FortiGate is set to "default" . This setting allows the downstream device to synchronize objects from the root FortiGate. When set to local, the device does not synchronize objects from the root but will still participate in sending the synchronized object downstream .Therefore, the correct answer is:D. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.The Exhibit B is wrong.
upvoted 2 times
skyvahaerie
4 months, 3 weeks ago
I had this question in my exam today (12/12/23) and can tell you the exhibit B is NOT wrong. 100% identical to the exam question. Therefore C must be the correct answer.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...