Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A managed service provider runs a single FortiManager 7.6 instance to manage FortiGate devices belonging to multiple independent customers. Each customer requires strict separation of policies, objects, and administrative access, and administrators from one customer must never be able to view or modify another customer's configuration. Which FortiManager feature should the MSSP use to meet this requirement?
ADOMs are the core FortiManager feature designed to logically separate devices, policies, objects, and administrative access into isolated domains, which is exactly what an MSSP needs to keep customer configurations and administrative visibility separate on a shared FortiManager. Device groups only organize devices within an ADOM and do not provide administrative separation. Policy packages and meta fields do not isolate administrative access or object visibility between tenants.
An administrator is performing the initial setup of a brand-new FortiManager 7.6 appliance using the setup wizard. During this process, the wizard prompts the administrator to configure basic network settings and optionally integrate the appliance with FortiAnalyzer functionality. Which statement about this initial configuration process is correct?
FortiManager 7.6 supports integrating FortiAnalyzer features onto the same physical or virtual appliance, allowing it to perform both device management and log analysis functions; the setup wizard includes an option to enable this. FortiAnalyzer functionality does not require a separate physical appliance. Network settings can be configured independently of any FortiGate connection, and ADOM creation is not a prerequisite for completing the initial setup wizard.
An administrator adds a new FortiGate to FortiManager using the Add Device wizard. During the device discovery phase, the wizard reports that it cannot establish a connection to the FortiGate even though the device's IP address and admin credentials appear correct. Which of the following is a valid item on the basic discovery failure checklist that the administrator should verify?
Discovery failures are commonly caused by administrative access restrictions on the FortiGate or intermediate firewalls blocking the required protocols (HTTPS/SSH for discovery, FGFM for ongoing management). Workspace mode, Global ADOM database mode, device blueprints, and FDS override configuration are unrelated to basic connectivity/discovery failures and are not part of the standard discovery troubleshooting checklist.
An administrator working in a FortiManager ADOM that has Workspace Mode enabled needs to modify a firewall policy package. Another administrator is currently editing the same policy package. When the first administrator tries to open the policy package for editing, FortiManager denies the request and indicates the object is locked. What is the correct behavior to expect in this scenario?
Workspace Mode enforces locking at the ADOM, policy package, or per-policy level to prevent conflicting simultaneous edits. A locked object remains locked until the owning administrator commits and releases the lock, or until a super_user administrator manually force-unlocks the session. FortiManager does not auto-merge conflicting edits, per-policy locking is a supported feature, and sessions are not automatically terminated to grant access to another administrator.
A managed FortiGate behind a strict corporate firewall periodically drops out of "Up" status in FortiManager's Device Manager, even though the FortiGate itself remains fully operational and reachable via SSH. The administrator suspects the FGFM tunnel between FortiManager and the FortiGate is being silently dropped by an intermediate firewall due to session idle timeout. Which FortiManager/FortiGate mechanism is specifically designed to prevent this kind of silent tunnel drop?
FGFM keepalive messages are periodically exchanged between the managed FortiGate and FortiManager specifically to keep the management tunnel active and to detect and recover from connectivity issues such as those caused by intermediate firewalls dropping idle sessions. ADOM revision snapshots, FortiGuard push updates, and backup scripts serve entirely different purposes unrelated to maintaining the FGFM tunnel's connectivity state.
65 questions covering all exam domains, starting from $20
Exam domains verified against: Official Fortinet NSE6_FMG_AD-7.6 exam guide, last checked September 2026.
Master FortiManager features including administrative domains, API functionality, and initial configuration. This section covers ADOM operation modes, administrator profiles, workspace mode, and backup/restoration procedures for managing multiple administrative environments across your infrastructure.
Learn to register and organize devices within ADOMs using template provisioning and discovery methods. Covers FortiGate HA cluster management, device groups, FGFM communication protocol, and strategies for handling device lifecycle operations from registration through configuration management.
Work with policy packages, object configurations, and dynamic objects across ADOMs. Includes policy workflow, installation targets, meta fields, policy locking mechanisms, and workspace mode permissions to ensure secure policy deployment and change management across managed devices.
Sample question from this domain above: Q4
Configure FortiManager high availability, FortiGuard services, and global database ADOMs for distributed management. Covers HA synchronization, firmware caching, antivirus and IPS service management, and shared global policies to support large-scale security deployments.
Diagnose and resolve import, installation, and device-level issues using logs and configuration analysis. Includes database integrity checks, device and ADOM database comparison, system resource troubleshooting, and recovery from common deployment scenarios like NAT traversal problems.
Common questions about the exam itself