Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: big75certs

Free and Premium Fortinet NSE6_FNC_AD-7.6 Dumps Questions Answers

Fortinet NSE 6 - FortiNAC-F 7.6 Administrator Questions and Answers

Question 1

Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)

Options:

A.

A FortiNAC-F manager

B.

A FortiNAC-F device designated as a secondary

C.

A dedicated VLAN for primary and secondary synchronization

D.

At least two FortiNAC-F devices designated as primary

Buy Now
Question 2

Refer to the exhibits.

What would happen if the highlighted port with connected hosts was placed in both the Forced Registration and Forced Remediation port groups?

Options:

A.

Both types of enforcement would be applied

B.

Enforcement would be applied only to rogue hosts

C.

Multiple enforcement groups could not contain the same port.

D.

Only the higher ranked enforcement group would be applied.

Question 3

Refer to the exhibit.

Which devices are automatically evaluated by these device profiling rules?

Options:

A.

Rogue devices, only when they are initially added to the database

B.

Known trusted devices, each time they connect

C.

All hosts, each time they connect

D.

Rogue devices, each time they change location

Question 4

Refer to the exhibit.

When a contractor account is created using this template, which value is set in the accounts Role field?

Options:

A.

Engineer-Contractor

B.

Eng-Contractor

C.

Contractor

D.

Accounting Contractor

Question 5

When creating a user or host profile, which three criteria can you apply? (Choose three.)

Options:

A.

Host or user group memberships

B.

Host or user attributes

C.

Adapter current VLAN

D.

An applied access policy

E.

Location

Question 6

As part of a company policy, all end stations must be scanned for compliance each day. The security administrators want to satisfy this requirement without any necessary interaction from the end user. Which two agents can provide that functionality? (Choose two.)

Options:

A.

Dissolvable

B.

Persistent

C.

Passive

D.

Mobile

Question 7

A network administrator is troubleshooting a network access issue for a specific host. The administrator suspects the host is being assigned a different network access policy than expected.

Where would the administrator look to identify which network access policy, if any, is being applied to a particular host?

Options:

A.

The Policy Logs view

B.

The Connections view

C.

The Policy Details view for the host

D.

The Port Properties view of the hosts port

Question 8

When creating a device profiling rule, what are two advantages of registering the device in the host view? (Choose two.)

Options:

A.

The devices can be managed as a generic SNMP device.

B.

The devices will have connection logs.

C.

The devices can be associated with a user.

D.

The devices can be polled for connection status.

Question 9

Refer to the exhibit.

If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?

Options:

A.

The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.

B.

The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.

C.

The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.

D.

The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.

Question 10

What must an administrator configure to allow FortiNAC-F to process incoming syslog messages that are not supported by default?

Options:

A.

A Syslog Service Connector

B.

A Security Action

C.

A Security Event Parser

D.

A Log Receiver

Question 11

An administrator wants to create a conference manager administrator account but would like to limit the number of conference accounts that can be generated to 30. Which statement about conference accounts is true?

Options:

A.

In FortiNAC-F, conference accounts can be limited by multiples of 25, so the conference administrator could create 50 accounts.

B.

The administrator can set a maximum of 30 conference accounts in the administrative profile for the conference manager.

C.

The conference account limit is defined in the onboarding conference portal.

D.

Conference account limits are defined in the conference guest and contractor template.

Question 12

Two FortiNAC-F devices have been configured as a 1 + 1 HA pair. The primary server went offline and a successful failover to the secondary has occurred. What happens if the primary server comes back online?

Options:

A.

The primary and secondary servers will resume communication and the secondary will maintain control.

B.

The secondary server will update the primary and the servers will load balance until an administrator forces the primary to resume full control.

C.

The primary server will determine that the secondary has control and power down for maintenance.

D.

After five successful heartbeats between the servers, the primary server will resume control.

Question 13

An administrator wants FortiNAC-F to return a group of user-defined RADIUS attributes in RADIUS responses.

Which condition must be true to achieve this?

Options:

A.

The requesting device must support RFC 5176.

B.

Inbound RADIUS requests must contain the Calling-Station-ID attribute.

C.

The device models in the inventory view must be configured for proxy-based authentication.

D.

RADIUS accounting must be enabled on the FortiNAC-F RADIUS server configuration.

Question 14

Refer to the exhibit.

What would FortiNAC-F generate if only one of the security fitters is satisfied?

Options:

A.

A normal alarm

B.

A security event

C.

A security alarm

D.

A normal event

Question 15

Refer to the exhibit.

A FortiNAC-F N+1 HA configuration is shown.

What will occur if CA-2 fails?

Options:

A.

CA-1 and CA-3 will operate as a 1+1 HA cluster with CA-3 acting as a hot standby.

B.

CA-3 will continue to operate as a secondary in an N+1 HA configuration.

C.

CA-3 will be promoted to a primary and share management responsibilities with CA-1.

D.

CA-3 will be promoted to a primary and FortiNAC-F manager will load balance between CA-1 and CA-3.

Question 16

Refer to the exhibit.

Given this topology, and a layer 3 registration network configuration, which IP address would be designated in the DHCP relay configuration for the registration network?

Options:

A.

192.168.10.254

B.

192.168.100 75

C.

192.168.100.20

D.

192.168.200.10

Question 17

An organization wants to add a FortiNAC-F Manager to simplify their large FortiNAC-F deployment.

Which two policy types can be managed globally? (Choose two.)

Options:

A.

Authentication

B.

Endpoint Compliance

C.

Supplicant EasyConnect

D.

Network Access

Question 18

An administrator wants to build device profiling rules based on network traffic, but the network session view is not populated with any records.

Which two settings can be enabled to gather network session information? (Choose two.)

Options:

A.

Network traffic polling on any modeled infrastructure device

B.

Firewall session polling on modeled FortiGate devices

C.

Netflow setting on the FortiNAC-F interfaces

D.

Layer 3 polling on the infrastructure devices