Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Fortinet NSE5_FNC_AD_7.6 Dumps Questions Answers

Fortinet NSE 5 - FortiNAC-F 7.6 Administrator Questions and Answers

Question 1

During the testing of a newly modeled infrastructure switch, the administrator is not seeing hosts as they connect or move from one port to another. What would cause this issue?

Options:

A.

MAC notification traps are misconfigured.

B.

Layer 3 polling is failing.

C.

The default scheduled polling is disabled.

D.

Contact polling is not configured.

Buy Now
Question 2

While discovering network infrastructure devices, a switch appears in the inventory topology with a question mark (?) on the icon. What would cause this?

Options:

A.

The wrong SNMP community string was entered during discovery.

B.

The SNMP ObjectlD is not recognized by FortiNAC-F.

C.

A read-only SNMP community siring was used.

D.

SNMP is not enabled on the switch.

Question 3

Refer to the output below.

Examine the communication between a primary FortiNAC-F (192.168.10.10) and a secondary FortlNAC-F (192.168.10.110) configured as a 1+1 HA pair. What is the current state of the FortiNAC-F HA pair?

Options:

A.

The secondary server is running and in control.

B.

The database replication failed

C.

Failover from the primary server to the secondary server is in progress.

D.

The primary server is running and in control.

Question 4

An organization has FortiNAC-F deployed and is using Layer 3 isolation networks across multiple sites with firewalls. At a minimum, which three protocols must be allowed between the isolation networks and FortiNAC-F? (Choose three.)

Options:

A.

DDNS

B.

NTP

C.

HTTP/HTTPS

D.

DNS

E.

DHCP

Question 5

An administrator manages a corporate environment where all users log into the corporate domain each time they connect to the network. The administrator wants to leverage login scripts to use a FortiNAC-F agent to enhance endpoint visibility

Which agent can be deployed as part of a login script?

Options:

A.

Persistent

B.

Dissolvable

C.

Mobile

D.

Passive

Question 6

When configuring isolation networks in the configuration wizard, why does a layer 3 network typo allow for mora than ono DHCP scope for each isolation network typo?

Options:

A.

The layer 3 network type allows for one scope for each possible host status.

B.

Configuring more than one DHCP scope allows for DHCP server redundancy

C.

There can be more than one isolation network of each type

D.

Any scopes beyond the first scope are used if the initial scope runs out of IP addresses.

Question 7

Which two statements are true about integrating a third-party device using SNMP traps from that device as input to generate an event? (Choose two.)

Options:

A.

The sending device must be modeled in the inventory topology.

B.

The sending device must support SNMPv3.

C.

set allowaccess snmp must be configured using the CLI on the FortiNAC-F receiving interface.

D.

The IP address OID and MAC address OID must be configured in the trap MIB file.

Question 8

Two FortiNAC-F devices have been configured as a 1 + 1 HA pair. The primary server went offline and a successful failover to the secondary has occurred. What happens if the primary server comes back online?

Options:

A.

The primary and secondary servers will resume communication and the secondary will maintain control.

B.

The secondary server will update the primary and the servers will load balance until an administrator forces the primary to resume full control.

C.

The primary server will determine that the secondary has control and power down for maintenance.

D.

After five successful heartbeats between the servers, the primary server will resume control.

Question 9

While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen to use the shared IP address option.

Which condition must be met for this type of deployment?

Options:

A.

The isolation network type is layer 3.

B.

There is a direct cable link between FortiNAC-F devices.

C.

The primary and secondary administrative interfaces are on the same subnet.

D.

The isolation network type is Layer 2.

Question 10

An administrator has configured the DHCP scope for a registration isolation network, but the isolation process isn ' t working.

What is the problem with the configuration?

Options:

A.

The domain name server designation is incorrect.

B.

The label uses a system-reserved value.

C.

The lease pool does not contain a complete subnet.

D.

The gateway defined for the scope is incorrect.

Question 11

When working with a FortiNAC-F Manager and cluster management, what will occur when a cluster manager recovers from a non-responsive state?

Options:

A.

It will be removed from the cluster and placed in a standalone group.

B.

It automatically returns to the manager state.

C.

It rejoins the cluster as a worker node.

D.

It will perform a health check and be demoted to standby.

Question 12

Refer to the exhibit.

After a successful layer 2 poll, two hosts were learned on the same port The port is a member of the Role-Based Access and Forced Registration groups. The switch has been configured to leverage a single isolation VLAN.

How will FortiNAC-F manage this port?

Options:

A.

The port will be provisioned to the isolation network

B.

The port will be provisioned for the normal state host, but the second host will have access to only the isolation portal page.

C.

The port will be provisioned as an uplink to a hub or unmanaged switch.

D.

The port will be added to the Access Point Management group

Question 13

Refer to the exhibit.

What would FortiNAC-F generate if only one of the security fitters is satisfied?

Options:

A.

A normal alarm

B.

A security event

C.

A security alarm

D.

A normal event

Question 14

An administrator wants to control user access to corporate resources by integrating FortiNAC-F with FortiGate using firewall tags defined on FortiNAC-F.

Where would the administrator assign the firewall tag value that will be sent to FortiGate?

Options:

A.

RADIUS group attribute

B.

Logical network

C.

Device profiling rule

D.

Security rule

Question 15

Refer to the exhibit.

An administrator wants to use FortiNAC-F to automatically provision printers throughout their organization. Each building uses its own local VLAN for printers.

Which FortiNAC-F feature would allow this to be accomplished with a single network access policy?

Options:

A.

Dynamic host groups

B.

Logical networks

C.

Device profiling rules

D.

Preferred VLAN designations

Question 16

An administrator is configuring FortiNAC-F to manage FortiGate VPN users. As part of this configuration, what is the purpose of the FortiGate firewall policy that applies to clients not yet authorized?

Options:

A.

To allow access to only the production DNS server

B.

To allow access to only the production DNS server

C.

To allow access to only the FortiNAC-F VPN interface

D.

To allow access to only the FortiGate VPN interface

Question 17

When FortiNAC-F is managing VPN clients connecting through FortiGate, why must the clients run a FortiNAC-F agent?

Options:

A.

To transparently update The client IP address upon successful authentication

B.

To collect user authentication details

C.

To collect the client IP address and MAC address

D.

To validate the endpoint policy compliance