New Year Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet FCP_FCT_AD-7.4 Fortinet NSE 6 - FortiClient EMS 7.4 Administrator Exam Practice Test

Fortinet NSE 6 - FortiClient EMS 7.4 Administrator Questions and Answers

Question 1

An administrator has lost web access to the FortiClient EMS console, and the web page to access to the console is timing out.

How can the administrator gather information to investigate the issue? (Choose one answer)

Options:

A.

Use the CLI diagnostic tool on the EMS server.

B.

Download the webserver logs from the PostgreSQL server.

C.

Use the diagnostic logs option from the FortiClient EMS GUI.

D.

Download the log generator from the support site and run it on the EMS server.

Question 2

Refer to the exhibit.

Question # 2

Based on the settings shown in the exhibit, which two actions must the administrator take to make the endpoint compliant? (Choose two.)

Options:

A.

Enable the web filter profile.

B.

Run Calculator application on the endpoint.

C.

Integrate FortiSandbox tor infected file analysis

D.

Patch applications that have vulnerability rated as high or above.

Question 3

In a ForliSandbox integration, what does the remediation option do?

Options:

A.

Deny access to a tile when it sees no results

B.

Alert and notify only

C.

Exclude specified files

D.

Wait for FortiSandbox results before allowing files

Question 4

Exhibit.

Question # 4

Refer to the exhibits, which show the Zero Trust Tag Monitor and the FortiClient GUI status.

Remote-Client is tagged as Remote-User* on the FortiClient EMS Zero Trust Tag Monitor.

What must an administrator do to show the tag on the FortiClient GUI?

Options:

A.

Change the FortiClient EMS shared settings to enable tag visibility.

B.

Change the endpoint alerts configuration to enable tag visibility.

C.

Update tagging rule logic to enable tag visibility.

D.

Change the FortiClient system settings to enable lag visibility.

Question 5

An administrator installs FortiClient on Windows Server.

What is the default behavior of real-time protection control?

Options:

A.

Real-time protection must update AV signature database

B.

Real-time protection sends malicious files to FortiSandbox when the file is not detected locally

C.

Real-time protection is disabled

D.

Real-time protection must update the signature database from FortiSandbox

Question 6

Refer to the exhibits.

Question # 6

Question # 6

Based on the FortiGate Security Fabric settings shown in the exhibits, what must an administrator do on the EMS server to successfully quarantine an endpoint. when it is detected as a compromised host (loC)?

Options:

A.

The administrator must enable remote HTTPS access to EMS.

B.

The administrator must enable FQDN on EMS.

C.

The administrator must authorize FortiGate on FortiAnalyzer.

D.

The administrator must enable SSH access to EMS.

Question 7

Refer to the exhibit.

Question # 7

Based on the FortiClient logs shown in the exhibit which application is blocked by the application firewall?

Options:

A.

Twitter

B.

Facebook

C.

Internet Explorer

D.

Firefox

Question 8

An administrator installs FortiClient EMS in the enterprise.

Which component is responsible for enforcing protection and checking security posture?

Options:

A.

FortiClient EMS tags

B.

FortiClient vulnerability scan

C.

FortiClient

D.

FortiClient EMS

Question 9

Refer to the exhibit.

Question # 9

Based on the CLI output from FortiGate. which statement is true?

Options:

A.

FortiGate is configured to pull user groups from FortiClient EMS

B.

FortiGate is configured with local user group

C.

FortiGate is configured to pull user groups from FortiAuthenticator

D.

FortiGate is configured to pull user groups from AD Server.

Question 10

Refer to the exhibits.

Question # 10

Question # 10

Which show the Zero Trust Tag Monitor and the FortiClient GUI status.

Remote-Client is tagged as Remote-Users on the FortiClient EMS Zero Trust Tag Monitor.

What must an administrator do to show the tag on the FortiClient GUI?

Options:

A.

Update tagging rule logic to enable tag visibility

B.

B. Change the FortiClient system settings to enable tag visibility

C.

Change the endpoint control setting to enable tag visibility

D.

Change the user identity settings to enable tag visibility

Question 11

Refer to the exhibit, which shows FortiClient EMS deployment, profiles.

Question # 11

When an administrator creates a deployment profile on FortiClient EMS. which statement about the deployment profile is true?

Options:

A.

Deployment-2 will upgrade FortiClient on both the AD group and workgroup.

B.

Deployment-1 will install FortiClient on new AO group endpoints.

C.

Deployment-2 will install FortiClient on both the AD group and workgroup.

D.

Deployment-1 will upgrade FortiClient only on the workgroup.

Question 12

Refer to the exhibit.

Question # 12

Which behavior should you expect when FortiClient with an invalid certificate is connecting to FortiClient EMS? (Choose one answer)

Options:

A.

FortiClient is blocked from connecting to FortiClient EMS.

B.

FortiClient requires an additional password to connect to FortiClient EMS.

C.

FortiClient displays a warning message to the end user.

D.

FortiClient EMS pushes a valid certificate to FortiClient.

Question 13

Which two VPNtypes can a FortiClientendpoint user inmate from the Windows command prompt? (Choose two)

Options:

A.

L2TP

B.

PPTP

C.

IPSec

D.

SSL VPN

Question 14

Which component or device shares ZTNA tag information through Security Fabric integration?

Options:

A.

FortiGate

B.

FortiGate Access Proxy

C.

FortiClient

Question 15

Why does FortiGate need the root CA certificate of FortiCient EMS?

Options:

A.

To revoke FortiClient client certificates

B.

To sign FortiClient CSR requests

C.

To update FortiClient client certificates

D.

To trust certificates issued by FortiClient EMS

Question 16

An administrator needs to connect FortiClient EMS as a fabric connector to FortiGate What is the prerequisite to get FortiClient EMS lo connect to FortiGate successfully?

Options:

A.

Import and verify the FortiClient EMS tool CA certificate on FortiGate.

B.

Revoke and update the FortiClient client certificate on EMS.

C.

Import and verify the FortiClient client certificate on FortiGate.

D.

Revoke and update the FortiClient EMS root CA.

Question 17

Refer to the exhibit, which shows the Zero Trust Tagging Rule Set configuration.

Question # 17

Which two statements about the rule set are true? (Choose two.)

Options:

A.

The endpoint must satisfy that only Windows 10 is running.

B.

The endpoint must satisfy that only AV software is installed and running.

C.

The endpoint must satisfy that antivirus is installed and running and Windows 10 is running.

D.

The endpoint must satisfy that only Windows Server 2012 R2 is running.

Question 18

Refer to the exhibit.

Question # 18

Based on the FortiClient tog details shown in the exhibit, which two statements ace true? (Choose two.)

Options:

A.

The filename Is Unconfirmed 899290.crdovnload.

B.

The file status is Quarantined

C.

The filename is sent to FortiSandbox for further inspection.

D.

The file location is \??\D:\Users\.

Question 19

Which two are benefits of using multi-tenancy mode on FortiClient EMS? (Choose two.)

Options:

A.

Separate host servers manage each site.

B.

Licenses are shared among sites

C.

The fabric connector must use an IP address to connect to FortiClient EMS.

D.

It provides granular access and segmentation.

Question 20

A company must integrate the FortiClient EMS with their existing identity management infrastructure for user authentication, and implement and enforce administrative access with multi-factor authentication (MFA). Which two authentication methods can they use in this scenario? (Choose two answers)

Options:

A.

LDAPS

B.

RADIUS

C.

TACACS

D.

SAML