Pre-Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet NSE5_FNC_AD_7.6 Fortinet NSE 5 - FortiNAC-F 7.6 Administrator Exam Practice Test

Fortinet NSE 5 - FortiNAC-F 7.6 Administrator Questions and Answers

Question 1

When creating a device profiling rule, what is an advantage of modeling the endpoint as a device in the inventory view?

Options:

A.

The device will have historic connection logs.

B.

The devices can have scheduled connection status polling.

C.

The devices will have connection logs.

D.

The devices can be associated with a logged on user.

Question 2

During an evaluation of state-based enforcement, an administrator discovers that ports that should not be under enforcement have been added to enforcement groups.

In which view would the administrator be able to identify who added the ports to the groups?

(Selected)

Options:

A.

The Admin Auditing view

B.

The Event Management view

C.

The Port Changes view

D.

The Security Events view

Question 3

Refer to the exhibit.

Question # 3

If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?

Options:

A.

The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.

B.

The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.

C.

The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.

D.

The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.

Question 4

Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)

Options:

A.

A FortiNAC-F manager

B.

A FortiNAC-F device designated as a secondary

C.

A dedicated VLAN for primary and secondary synchronization

D.

At least two FortiNAC-F devices designated as primary

Question 5

In which three ways would deploying a FortiNAC-F Manager into a large environment consisting of several FortiNAC-F CAs simplify management? (Choose three.)

Options:

A.

Global infrastructure device inventory

B.

Global version control

C.

Global authentication security policies

D.

Pooled licenses

E.

Global visibility

Question 6

An administrator wants FortiNAC-F to return a group of user-defined RADIUS attributes in RADIUS responses.

Which condition must be true to achieve this?

Options:

A.

The requesting device must support RFC 5176.

B.

Inbound RADIUS requests must contain the Calling-Station-ID attribute.

C.

The device models in the inventory view must be configured for proxy-based authentication.

D.

RADIUS accounting must be enabled on the FortiNAC-F RADIUS server configuration.

Question 7

Refer to the exhibit.

Question # 7

What would FortiNAC-F generate if only one of the security fitters is satisfied?

Options:

A.

A normal alarm

B.

A security event

C.

A security alarm

D.

A normal event

Question 8

As part of a company policy, all end stations must be scanned for compliance each day. The security administrators want to satisfy this requirement without any necessary interaction from the end user. Which two agents can provide that functionality? (Choose two.)

Options:

A.

Dissolvable

B.

Persistent

C.

Passive

D.

Mobile

Question 9

Question # 9

Question # 9

An administrator has configured the DHCP scope for a registration isolation network, but the isolation process isn ' t working.

What is the problem with the configuration?

Options:

A.

The domain name server designation is incorrect.

B.

The label uses a system-reserved value.

C.

The lease pool does not contain a complete subnet.

D.

The gateway defined for the scope is incorrect.

Question 10

Refer to the exhibits.

Question # 10

Question # 10

Based on the given configurations and settings, on which date and time would a guest account created at 8:00 AM on 2025/09/12 expire?

Options:

A.

2025/09/12 at 8:00 PM

B.

2025/09/12 at 7:00 PM

C.

2025/09/12 at 17:00:00

D.

2025/09/13 at 17:00:00

Question 11

An administrator wants FortiNAC-F to pass firewall tags to FortiGate to leverage dynamic address groups used in firewall policies. On FortiNAC-F, what determines the values that are passed?

Options:

A.

Model configuration

B.

Device profiling rule

C.

Security rule

D.

RADIUS group attribute

Question 12

An administrator wants to create a conference manager administrator account but would like to limit the number of conference accounts that can be generated to 30.

Which statement about conference accounts is true?

Options:

A.

In FortiNAC-F, conference accounts can be limited by multiples of 25, so the conference administrator could create 50 accounts.

B.

The administrator can set a maximum of 30 conference accounts in the administrative profile for the conference manager.

C.

The conference account limit is defined in the onboarding conference portal.

D.

Conference account limits are defined in the conference guest and contractor template.

Question 13

When preparing network infrastructure devices for visibility, what are the two main advantages of using MAC notification traps on supported devices instead of link-up and link-down traps? (Choose two.)

Options:

A.

MAC notification traps include IP address information.

B.

Overhead on FortiNAC-F and the infrastructure device is reduced.

C.

Hosts connecting to downstream non-managed hubs are immediately learned.

D.

Faster visibility updates with only a slight increase in processing.

Question 14

When FortiNAC-F is managing VPN clients connecting through FortiGate, why must the clients run a FortiNAC-F agent?

Options:

A.

To transparently update The client IP address upon successful authentication

B.

To collect user authentication details

C.

To collect the client IP address and MAC address

D.

To validate the endpoint policy compliance

Question 15

During the testing of a newly modeled infrastructure switch, the administrator is not seeing hosts as they connect or move from one port to another. What would cause this issue?

Options:

A.

MAC notification traps are misconfigured.

B.

Layer 3 polling is failing.

C.

The default scheduled polling is disabled.

D.

Contact polling is not configured.

Question 16

A healthcare organization is integrating FortiNAC-F with its existing MDM. Communication is failing between the systems.

What could be a probable cause?

Options:

A.

Security Fabric traffic is failing

B.

SSH communication is failing

C.

REST API communication is failing

D.

SOAP API communication is failing

Question 17

While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen to use the shared IP address option.

Which condition must be met for this type of deployment?

Options:

A.

The isolation network type is layer 3.

B.

There is a direct cable link between FortiNAC-F devices.

C.

The primary and secondary administrative interfaces are on the same subnet.

D.

The isolation network type is Layer 2.