Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: discactive

Fortinet NSE6_FNC_AD-7.6 Fortinet NSE 6 - FortiNAC-F 7.6 Administrator Exam Practice Test

Fortinet NSE 6 - FortiNAC-F 7.6 Administrator Questions and Answers

Question 1

Refer to the exhibit.

Question # 1

What would FortiNAC-F generate if only one of the security fitters is satisfied?

Options:

A.

A normal alarm

B.

A security event

C.

A security alarm

D.

A normal event

Question 2

When configuring isolation networks in the configuration wizard, why does a layer 3 network typo allow for mora than ono DHCP scope for each isolation network typo?

Options:

A.

The layer 3 network type allows for one scope for each possible host status.

B.

Configuring more than one DHCP scope allows for DHCP server redundancy

C.

There can be more than one isolation network of each type

D.

Any scopes beyond the first scope are used if the initial scope runs out of IP addresses.

Question 3

Question # 3

Question # 3

An administrator has configured the DHCP scope for a registration isolation network, but the isolation process isn ' t working.

What is the problem with the configuration?

Options:

A.

The domain name server designation is incorrect.

B.

The label uses a system-reserved value.

C.

The lease pool does not contain a complete subnet.

D.

The gateway defined for the scope is incorrect.

Question 4

An organization wants to add a FortiNAC-F Manager to simplify their large FortiNAC-F deployment.

Which two policy types can be managed globally? (Choose two.)

Options:

A.

Authentication

B.

Endpoint Compliance

C.

Supplicant EasyConnect

D.

Network Access

Question 5

Where should you configure MAC notification traps on a supported switch?

Options:

A.

Only on ports that generate linkup and linkdown traps

B.

Only on ports defined as learned uplinks

C.

On all ports on the switch

D.

On all ports except uplink ports

Question 6

Refer to the exhibit.

Question # 6

An administrator wants to ensure that guest accounts created from this template are not allowed network access outside of the designated times.

To achieve this, all necessary configurations must be made to force isolation of hosts in which state?

Options:

A.

At-risk

B.

Disabled

C.

Non-authenticated

D.

Rogue

Question 7

An administrator wants each department to create and manage its own contractor accounts but not be able to manage contractor accounts for other departments. What must the administrator configure to limit the sponsor ' s capabilities?

Options:

A.

The contractor ' s template

B.

The portal settings on the kiosk portal page

C.

The user/host profile applied to the contractor

D.

The sponsor ' s administrative profile

Question 8

When managing multiple FortiNAC-F CAs with a FortiNAC-F Manager, how is endpoint information updated in the FortiNAC-F Manager database?

Options:

A.

Endpoint information is pulled from the managed CAs by the FortiNAC-F Manager at a set interval.

B.

Endpoint information is updated in real time when a host status changes.

C.

Endpoint information is updated when an administrator synchronizes with each CA.

D.

Endpoint information is pushed to the FortiNAC-F Manager based on an administratively configured scheduled task.

Question 9

An organization has FortiNAC-F deployed and is using Layer 3 isolation networks across multiple sites with firewalls. At a minimum, which three protocols must be allowed between the isolation networks and FortiNAC-F? (Choose three.)

Options:

A.

DDNS

B.

NTP

C.

HTTP/HTTPS

D.

DNS

E.

DHCP

Question 10

Refer to the exhibit.

Question # 10

Which devices are automatically evaluated by these device profiling rules?

Options:

A.

Rogue devices, only when they are initially added to the database

B.

Known trusted devices, each time they connect

C.

All hosts, each time they connect

D.

Rogue devices, each time they change location

Question 11

An administrator wants to build device profiling rules based on network traffic, but the network session view is not populated with any records.

Which two settings can be enabled to gather network session information? (Choose two.)

Options:

A.

Network traffic polling on any modeled infrastructure device

B.

Firewall session polling on modeled FortiGate devices

C.

Netflow setting on the FortiNAC-F interfaces

D.

Layer 3 polling on the infrastructure devices

Question 12

Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)

Options:

A.

A FortiNAC-F manager

B.

A FortiNAC-F device designated as a secondary

C.

A dedicated VLAN for primary and secondary synchronization

D.

At least two FortiNAC-F devices designated as primary

Question 13

In which three ways would deploying a FortiNAC-F Manager into a large environment consisting of several FortiNAC-F CAs simplify management? (Choose three.)

Options:

A.

Global infrastructure device inventory

B.

Global version control

C.

Global authentication security policies

D.

Pooled licenses

E.

Global visibility

Question 14

An administrator is configuring FortiNAC-F to manage FortiGate VPN users. As part of this configuration, what is the purpose of the FortiGate firewall policy that applies to clients not yet authorized?

Options:

A.

To allow access to only the production DNS server

B.

To allow access to only the production DNS server

C.

To allow access to only the FortiNAC-F VPN interface

D.

To allow access to only the FortiGate VPN interface

Question 15

Refer to the exhibit.

Question # 15

After a successful layer 2 poll, two hosts were learned on the same port The port is a member of the Role-Based Access and Forced Registration groups. The switch has been configured to leverage a single isolation VLAN.

How will FortiNAC-F manage this port?

Options:

A.

The port will be provisioned to the isolation network

B.

The port will be provisioned for the normal state host, but the second host will have access to only the isolation portal page.

C.

The port will be provisioned as an uplink to a hub or unmanaged switch.

D.

The port will be added to the Access Point Management group

Question 16

When preparing network infrastructure devices for visibility, what are the two main advantages of using MAC notification traps on supported devices instead of link-up and link-down traps? (Choose two.)

Options:

A.

MAC notification traps include IP address information.

B.

Overhead on FortiNAC-F and the infrastructure device is reduced.

C.

Hosts connecting to downstream non-managed hubs are immediately learned.

D.

Faster visibility updates with only a slight increase in processing.

Question 17

Refer to the exhibit.

Question # 17

Given this topology, and a layer 3 registration network configuration, which IP address would be designated in the DHCP relay configuration for the registration network?

Options:

A.

192.168.10.254

B.

192.168.100 75

C.

192.168.100.20

D.

192.168.200.10

Question 18

Which two statements are true about integrating a third-party device using SNMP traps from that device as input to generate an event? (Choose two.)

Options:

A.

The sending device must be modeled in the inventory topology.

B.

The sending device must support SNMPv3.

C.

set allowaccess snmp must be configured using the CLI on the FortiNAC-F receiving interface.

D.

The IP address OID and MAC address OID must be configured in the trap MIB file.