nse5_fmg-72 Exam QuestionsBrowse all questions from this exam

nse5_fmg-72 Exam - Question 2


An administrator enabled workspace mode and now wants to delete an address object that is currently referenced in a firewall policy.

Which two results can the administrator expect to happen? (Choose two.)

Show Answer
Correct Answer: CD

When an administrator attempts to delete an address object that is currently referenced in a firewall policy on FortiManager with workspace mode enabled, two outcomes are expected. First, FortiManager will replace the deleted address object with the 'none' address object in the referenced firewall policy, effectively making the policy invalid or null. Second, FortiManager will not allow the deletion of a referenced address object unless the ADOM (Administrative Domain) is locked, as objects cannot be modified or deleted without locking the ADOM to ensure consistency and prevent conflicting changes.

Discussion

1 comment
Sign in to comment
DatBroNZOptions: CD
Jan 16, 2024

FortiManager 7.2 Study Guide, page 214: If you delete a used object, FortiManager will replace it with a none object. The none object is equal to null, which means any traffic that meets that firewall policy will be blocked. FortiManager 7.2 Study Guide, page 73: When workspace is enabled, the ADOM is initially read-only. To enable read/write permission, and make changes to the ADOM, you must lock the ADOM, device, or policy package.