Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCP_FMG_AD-7.6 Exam - Topic 2 Question 14 Discussion

What allows FortiManager to run CLI scripts on FortiGate devices without prompting for SSH authentication each time?
B) The secure management tunnel between FortiManager and FortiGate devices.
A) FortiGate devices using the legacy login method.
C) The script using the Remote FortiGate Directly via CLI option.
D) The script on the FortiManager device database.

Fortinet FCP_FMG_AD-7.6 Exam - Topic 2 Question 14 Discussion

Actual exam question for Fortinet's FCP_FMG_AD-7.6 exam
Question #: 14
Topic #: 2
[All FCP_FMG_AD-7.6 Questions]

What allows FortiManager to run CLI scripts on FortiGate devices without prompting for SSH authentication each time?

Show Suggested Answer Hide Answer
Suggested Answer: B

The correct answer is B. The FortiManager 7.6 Administrator Study Guide explicitly states: ''CLI scripts use the FGFM tunnel and the FGFM tunnel is authenticated using the FortiManager and FortiGate serial numbers.'' It also states: ''Tcl scripts do not run through the FGFM tunnel like CLI scripts do. Tcl scripts use SSH to tunnel through FGFM and they require SSH authentication to do so.''

This is the exact reason CLI scripts can run without prompting for SSH authentication every time: they use the existing secure FGFM management tunnel, not a separate interactive SSH login. The FGFM section of the study guide also confirms that this is a secure communication tunnel established between FortiManager and managed FortiGate devices.

So the enabler is not legacy login, script location, or the ''Remote FortiGate Directly'' option by itself. It is the FGFM secure management tunnel.


Contribute your Thoughts:

0/2000 characters
Leota
1 month ago
I feel like I've seen a similar question before, and it was about the script on the FortiManager device database.
upvoted 0 times
...
Charlesetta
1 month ago
I remember something about the legacy login method, but I can't recall if that relates to this question.
upvoted 0 times
...
Tracey
1 month ago
I think it might be B, the secure management tunnel, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel