Pre-Winter Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet NSE6_FNC_AD-7.6 Fortinet NSE 6 - FortiNAC-F 7.6 Administrator Exam Practice Test

Demo: 18 questions
Total 60 questions

Fortinet NSE 6 - FortiNAC-F 7.6 Administrator Questions and Answers

Question 1

While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen to use the shared IP address option.

Which condition must be met for this type of deployment?

Options:

A.

The isolation network type is layer 3.

B.

There is a direct cable link between FortiNAC-F devices.

C.

The primary and secondary administrative interfaces are on the same subnet.

D.

The isolation network type is Layer 2.

Question 2

Refer to the exhibit.

If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?

Options:

A.

The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.

B.

The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.

C.

The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.

D.

The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.

Question 3

As part of a company policy, all end stations must be scanned for compliance each day. The security administrators want to satisfy this requirement without any necessary interaction from the end user. Which two agents can provide that functionality? (Choose two.)

Options:

A.

Dissolvable

B.

Persistent

C.

Passive

D.

Mobile

Question 4

Refer to the exhibit.

When a contractor account is created using this template, which value is set in the accounts Role field?

Options:

A.

Engineer-Contractor

B.

Eng-Contractor

C.

Contractor

D.

Accounting Contractor

Question 5

When managing multiple FortiNAC-F CAs with a FortiNAC-F Manager, how is endpoint information updated in the FortiNAC-F Manager database?

Options:

A.

Endpoint information is pulled from the managed CAs by the FortiNAC-F Manager at a set interval.

B.

Endpoint information is updated in real time when a host status changes.

C.

Endpoint information is updated when an administrator synchronizes with each CA.

D.

Endpoint information is pushed to the FortiNAC-F Manager based on an administratively configured scheduled task.

Question 6

Which two actions must the administrator perform to allow FortiNAC-F to process incoming syslog messages from an unknown vendor? (Choose two answers)

Options:

A.

The device must be added as a server in the Host view

B.

The device sending the messages must be modeled in the Network Inventory view

C.

The device must be added as a log receiver in FortiNAC-F

D.

The device must have an event parser created for it

Question 7

When creating a device profiling rule, what are two advantages of registering the device in the host view? (Choose two.)

Options:

A.

The devices can be managed as a generic SNMP device.

B.

The devices will have connection logs.

C.

The devices can be associated with a user.

D.

The devices can be polled for connection status.

Question 8

Refer to the exhibit.

Which devices are automatically evaluated by these device profiling rules?

Options:

A.

Rogue devices, only when they are initially added to the database

B.

Known trusted devices, each time they connect

C.

All hosts, each time they connect

D.

Rogue devices, each time they change location

Question 9

Refer to the exhibit.

An administrator wants to ensure that guest accounts created from this template are not allowed network access outside of the designated times.

To achieve this, all necessary configurations must be made to force isolation of hosts in which state?

Options:

A.

At-risk

B.

Disabled

C.

Non-authenticated

D.

Rogue

Question 10

When working with a FortiNAC-F Manager and cluster management, what will occur when a cluster manager recovers from a non-responsive state?

Options:

A.

It will be removed from the cluster and placed in a standalone group.

B.

It automatically returns to the manager state.

C.

It rejoins the cluster as a worker node.

D.

It will perform a health check and be demoted to standby.

Question 11

When creating a device profiling rule, what is an advantage of modeling the endpoint as a device in the inventory view?

Options:

A.

The device will have historic connection logs.

B.

The devices can have scheduled connection status polling.

C.

The devices will have connection logs.

D.

The devices can be associated with a logged on user.

Question 12

Where should you configure MAC notification traps on a supported switch?

Options:

A.

Only on ports that generate linkup and linkdown traps

B.

Only on ports defined as learned uplinks

C.

On all ports on the switch

D.

On all ports except uplink ports

Question 13

An administrator has created several device profiling rules and evaluated all existing devices in the database. Some of the devices appear in the profiled devices view because they matched a rule, but they remain unknown and the registration column in the profiled devices view shows " No " . What is the most likely cause?

Options:

A.

The confirm device profiling rule option is not enabled.

B.

The devices match more than one device profiling rule.

C.

The device profiling rule has registration set to manual.

D.

The devices have persistent agents installed, and the point of connection has PA optimization enabled.

Question 14

A network administrator is troubleshooting a network access issue for a specific host. The administrator suspects the host is being assigned a different network access policy than expected.

Where would the administrator look to identify which network access policy, if any, is being applied to a particular host?

Options:

A.

The Policy Logs view

B.

The Connections view

C.

The Policy Details view for the host

D.

The Port Properties view of the hosts port

Question 15

Refer to the exhibit.

An administrator wants to use FortiNAC-F to automatically provision printers throughout their organization. Each building uses its own local VLAN for printers.

Which FortiNAC-F feature would allow this to be accomplished with a single network access policy?

Options:

A.

Dynamic host groups

B.

Logical networks

C.

Device profiling rules

D.

Preferred VLAN designations

Question 16

In which three ways would deploying a FortiNAC-F Manager into a large environment consisting of several FortiNAC-F CAs simplify management? (Choose three.)

Options:

A.

Global infrastructure device inventory

B.

Global version control

C.

Global authentication security policies

D.

Pooled licenses

E.

Global visibility

Question 17

An administrator wants to build a security rule that will quarantine contractors who attempt to access specific websites.

In addition to a user host profile, which Iwo components must the administrator configure to create the security rule? (Choose two.)

Options:

A.

Methods

B.

Action

C.

Endpoint compliance policy

D.

Trigger

E.

Security String

Question 18

When FortiNAC-F is managing VPN clients connecting through FortiGate, why must the clients run a FortiNAC-F agent?

Options:

A.

To transparently update The client IP address upon successful authentication

B.

To collect user authentication details

C.

To collect the client IP address and MAC address

D.

To validate the endpoint policy compliance

Demo: 18 questions
Total 60 questions