Fortinet · FCP_FMG_AD-7.6
Validates the ability to centrally manage multiple FortiGate devices using FortiManager, covering administration, device registration, policy and object management, advanced configuration, and troubleshooting. Designed for network and security analysts responsible for day-to-day management of FortiGate security policies via FortiManager.
Practice Questions
600
≈ 10 practice exams
Duration
70 minutes
Passing Score
Pass/Fail
Difficulty
ProfessionalLast Updated
May 2026
Use this FCP_FMG_AD-7.6 practice exam to prepare for FCP - FortiManager 7.6 Administrator (FCP_FMG_AD-7.6) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for Fortinet FCP_FMG_AD-7.6, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Administration and Initial Configuration, Device Manager and ADOM Management, Policy and Object Management, FortiGuard Services Configuration, and High Availability. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The FCP – FortiManager 7.6 Administrator (FCP_FMG_AD-7.6) certification validates a professional's ability to centrally manage multiple FortiGate devices using Fortinet's FortiManager platform. The exam tests applied knowledge across the full FortiManager administrative lifecycle, including initial system configuration, administrative domain (ADOM) management, device registration and synchronization, centralized policy and object management, FortiGuard services integration, high availability configuration, logging, reporting, and troubleshooting at both device and system levels. The exam is based on FortiManager 7.6.1 and FortiOS 7.6, ensuring relevance to current production deployments.
This certification is a recognized elective within the Fortinet Certified Professional (FCP) – Network Security track. To earn the FCP – Network Security designation, candidates must pass a core exam (FCP – FortiGate Administrator) plus one elective; FCP_FMG_AD-7.6 fulfills that elective requirement. Effective July 15, 2026, the associated course and exam will transition from the NSE 5 – Secure Networking track to the NSE 6 – Secure Networking track, reflecting its increasing depth and specialization.
This certification is designed for network and security analysts, firewall administrators, and security engineers who are responsible for the day-to-day centralized management of FortiGate security policies and device configurations through FortiManager. It is particularly well-suited to professionals working in environments with multiple FortiGate devices, such as large enterprises, managed service providers (MSPs) managing multiple customer tenants, and organizations with distributed branch deployments.
Candidates typically hold roles such as Network Security Administrator, Security Operations Center (SOC) Analyst, Firewall Engineer, or IT Security Specialist. Those pursuing advancement into senior roles—such as Network Security Architect or Fortinet Consultant—also benefit from this credential as a step toward higher-level Fortinet certification tracks.
There are no formal prerequisites to register for or sit the FCP_FMG_AD-7.6 exam. However, Fortinet strongly recommends that candidates possess prerequisite knowledge of all topics covered in the FortiGate Administrator course, as FortiManager operations are deeply integrated with FortiGate configuration concepts. Hands-on familiarity with FortiGate device administration, security policy management, and basic networking fundamentals (routing, VLANs, firewall rules) is essential for success.
Fortinet's official training recommendation is completion of the FortiManager Administrator instructor-led course (7 lecture hours, 6 lab hours across approximately two days), which covers the exact domains tested in the exam. Candidates with 6–12 months of practical experience managing FortiGate devices in a production environment—particularly those who have worked with centralized management tools—are well-positioned to attempt this exam.
The FCP_FMG_AD-7.6 exam consists of 35 multiple-choice questions to be completed within 70 minutes. Questions are either single-selection or multiple-selection format. Fortinet's scoring policy requires that all selected answers in a multiple-selection question must be correct to receive credit for that question—no partial credit is awarded. Incorrect answers do not incur a score penalty.
The exam is delivered in English and Japanese through Pearson VUE, available at Pearson VUE test centers worldwide as well as via online proctoring (OnVUE) for remote candidates. The exam result is reported as Pass or Fail; no numerical score is disclosed. The exam fee is $200 USD.
Earning the FCP – FortiManager 7.6 Administrator credential positions professionals for roles directly responsible for enterprise-scale network security operations, including Network Security Administrator, Firewall Engineer, SOC Analyst, and MSP Security Engineer. Fortinet holds a leading market share in the network security space, and organizations running Fortinet Security Fabric deployments increasingly require administrators who can operate FortiManager at scale. Certified professionals with Fortinet FCP credentials typically command salaries in the range of $80,000 to $135,000 annually in the United States, depending on experience level and geography, with senior architects and consultants often exceeding those figures.
The FCP_FMG_AD-7.6 is particularly valuable for MSP engineers managing multiple customer environments through FortiManager's multi-ADOM architecture, and for enterprise administrators tasked with consolidating security policy management across distributed branch networks. Compared to vendor-neutral certifications, this credential provides immediate, role-specific validation that hiring managers at Fortinet-centric organizations directly recognize. The certification aligns with the NICE Cybersecurity Workforce Framework, supporting applicability in federal and government-sector hiring contexts.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 10 full-length practice exams.
Preview — answers shown1. A Tailspin Toys network automation team wants to manage FortiManager configurations using infrastructure-as-code principles with support for idempotent deployments and configuration drift detection via an officially supported Fortinet integration. Which Ansible component and connection method provides this capability for FortiManager? (Select one!)
Explanation
The fortinet.fortimanager Ansible collection is the official Fortinet-supported integration for FortiManager automation. It uses the httpapi connection plugin, which communicates over the FortiManager JSON-RPC API via HTTPS, providing access to all FortiManager management functions including device management, policy package deployment, object management, and script execution. The collection supports idempotent operations by leveraging the API set method behavior and enables drift detection through get operations that compare current state with desired state. The fortinet.fortios collection is designed for direct FortiGate device management and cannot manage FortiManager centralized configurations. There is no official community.network Ansible collection with a fortimanager_facts module. While SSH-based CLI automation using paramiko is technically possible, it is not officially supported by Fortinet and lacks the idempotency, structured data handling, and drift detection capabilities provided by the dedicated API-based collection.
2. A Contoso network team has two policy packages in FortiManager: one containing strict security policies for production FortiGate VDOMs and another with relaxed policies for a lab environment. An administrator attempts to assign the lab policy package to a VDOM that is already targeted by the production policy package. What will FortiManager do? (Select one!)
Explanation
In FortiManager, each FortiGate VDOM can only be an installation target for one policy package at a time. When an administrator assigns a second policy package to a VDOM that is already targeted by an existing package, FortiManager automatically removes the VDOM from the current package assignment and associates it exclusively with the newly specified package. The original production package is not deleted — it simply no longer lists that VDOM as an installation target. This one-package-per-VDOM constraint ensures a single unambiguous source of policy truth for each VDOM and prevents conflicting policy sets from being applied simultaneously. Administrators should review existing package assignments carefully before reassigning VDOMs, since this behavior can silently remove a production device from its intended policy package without a confirmation prompt.
3. A Contoso network architect is configuring centralized SD-WAN management through FortiManager for branch offices running VoIP and video conferencing applications that are highly sensitive to latency and jitter. Each branch has two WAN links: a low-latency fiber connection and a higher-latency cable connection. The architect wants FortiManager to dynamically route latency-sensitive traffic to the best-performing link based on real-time measurements. Which SD-WAN steering strategy should be configured? (Select one!)
Explanation
Best Quality steering strategy dynamically evaluates all available WAN links based on real-time performance measurements including latency, jitter, and packet loss, and routes traffic to the link with the best current characteristics. This is ideal for latency-sensitive applications such as VoIP and video conferencing because it responds automatically to changes in link quality and can switch away from a degraded link even if it is the statically preferred choice. Manual strategy uses static priority and cannot adapt to changing link conditions. Lowest Cost strategy selects the cheapest link meeting minimum SLA thresholds, which may route sensitive traffic to the higher-latency cable connection if it meets the defined minimums. Maximize Bandwidth distributes traffic across multiple links to aggregate throughput, which is better suited for bulk data transfer rather than latency-sensitive real-time communications.
4. An administrator is comparing FortiManager database operations. Which synchronization operation updates BOTH the Remote Device Database AND the Device Database in FortiManager simultaneously? (Select one!)
Explanation
The Import operation is unique among FortiManager database operations because it updates both the Remote Device Database and the Device Database simultaneously. This makes Import the correct choice when the administrator wants to accept the FortiGate's current running configuration as the new authoritative baseline — effectively telling FortiManager to treat the device's current state as the desired state going forward. The Install operation updates only the Remote Device Database on success after pushing changes to the device; it never modifies the Device Database. The Retrieve operation updates only the Remote Device Database — it pulls the device's current configuration for comparison purposes but intentionally does not modify the Device Database, preserving the administrator's candidate configuration. The Revert operation modifies only the Device Database by restoring it to a historical revision's content; the Remote Device Database is not updated until a subsequent successful install.
5. Fabrikam's SD-WAN administrator is configuring traffic steering rules for VoIP calls that are extremely sensitive to latency and jitter. The administrator wants the FortiGate to continuously measure link quality and always route VoIP traffic over the link with the best real-time performance metrics. Which SD-WAN traffic steering strategy should the administrator select? (Select one!)
Explanation
The Best Quality SD-WAN steering strategy continuously evaluates real-time link quality metrics including latency, jitter, and packet loss, and steers traffic to the link that currently has the best measured quality. This makes it ideal for latency-sensitive applications like VoIP. The Lowest Cost (SLA) strategy selects the cheapest link that merely meets a minimum SLA threshold rather than optimizing for the best quality. Maximize Bandwidth is designed for high-throughput bulk transfers, not latency-sensitive traffic. Manual priority does not adapt based on link conditions and keeps traffic on the configured primary link regardless of degradation.
Fortinet NSE 7 Network Security Architect—Public Cloud Security
NSE 7 · 600 questions
Fortinet NSE 7 – Network Security Architect (SASE)
NSE7_SAR · 600 questions
Fortinet NSE 7 - Security Operations 7.6 Architect (NSE7_SOC_AR-7.6)
NSE7_SOC_AR-7.6 · 600 questions
FCP – Secure Wireless LAN 7.4 Administrator (FCP_FWF_AD-7.4)
FCP_FWF_AD-7.4 · 600 questions
Fortinet NSE 4 – FortiOS 7.6 Administrator (FOS-ADM-7.6)
FOS-ADM-7.6 · 600 questions
Fortinet NSE 5 - FortiAnalyzer 7.4 Analyst (NSE5_FAZ-7.4)
NSE5_FAZ-7.4 · 597 questions
$17.99
One-time access to this exam