Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: w75best

Fortinet NSE6_FNC_AD-7.6 Dumps

Fortinet NSE 6 - FortiNAC-F 7.6 Administrator Questions and Answers

Question 1

Where should you configure MAC notification traps on a supported switch?

Options:

A.

Only on ports that generate linkup and linkdown traps

B.

Only on ports defined as learned uplinks

C.

On all ports on the switch

D.

On all ports except uplink ports

Question 2

How can an administrator configure FortiNAC-F to normalize incoming syslog event levels across vendors?

Options:

A.

Configure severity mappings.

B.

Configure the vendor OUI settings.

C.

Configure the security rule settings.

D.

Configure event to alarm mappings.

Question 3

A network administrator is troubleshooting a network access issue for a specific host. The administrator suspects the host is being assigned a different network access policy than expected.

Where would the administrator look to identify which network access policy, if any, is being applied to a particular host?

Options:

A.

The Policy Logs view

B.

The Connections view

C.

The Policy Details view for the host

D.

The Port Properties view of the hosts port

Question 4

Which two actions must the administrator perform to allow FortiNAC-F to process incoming syslog messages from an unknown vendor? (Choose two answers)

Options:

A.

The device must be added as a server in the Host view

B.

The device sending the messages must be modeled in the Network Inventory view

C.

The device must be added as a log receiver in FortiNAC-F

D.

The device must have an event parser created for it

Question 5

As part of a FortiNAC-F integration with FortiGate for management of VPN users, what must be configured on FortiGate to keep FortiNAC-F up to date with VPN session information?

Options:

A.

SNMP traps

B.

RADIUS accounting

C.

Security Fabric integration

D.

Syslog messages

Question 6

Refer to the exhibits.

as

as

Given the current configuration, what would happen if a contractor triggered two of the defined security filters?

Options:

A.

Two security events would be generated, but no security alarm would be generated

B.

A security alarm and two security events would be generated.

C.

Three security events and one security alarm would be generated.

D.

A security event and a security alarm would be generated.

Question 7

Refer to the output below.

as

Examine the communication between a primary FortiNAC-F (192.168.10.10) and a secondary FortlNAC-F (192.168.10.110) configured as a 1+1 HA pair. What is the current state of the FortiNAC-F HA pair?

Options:

A.

The secondary server is running and in control.

B.

The database replication failed

C.

Failover from the primary server to the secondary server is in progress.

D.

The primary server is running and in control.

Question 8

An administrator wants to use FortiNAC-F to prevent internal engineers from accessing specific websites as defined in web filter categories on FortiGate. In addition to a security trigger and associated action, which configuration must also be defined on FortiNAC-F?

Options:

A.

A compliance policy

B.

A firewall policy

C.

A user/host profile

D.

A profiling method

Question 9

When configuring isolation networks in the configuration wizard, why does a layer 3 network typo allow for mora than ono DHCP scope for each isolation network typo?

Options:

A.

The layer 3 network type allows for one scope for each possible host status.

B.

Configuring more than one DHCP scope allows for DHCP server redundancy

C.

There can be more than one isolation network of each type

D.

Any scopes beyond the first scope are used if the initial scope runs out of IP addresses.

Question 10

Refer to the exhibit.

as

When configuring guest access using a network access policy, where would an administrator configure the Guest-VLAN value?

Options:

A.

In the Model configuration

B.

In the Guest template

C.

In the User/Host profile

D.

in the Guest portal configuration

Question 11

Refer to the exhibits.

as

What would happen if the highlighted port with connected hosts was placed in both the Forced Registration and Forced Remediation port groups?

Options:

A.

Both types of enforcement would be applied

B.

Enforcement would be applied only to rogue hosts

C.

Multiple enforcement groups could not contain the same port.

D.

Only the higher ranked enforcement group would be applied.

Question 12

An administrator wants to control user access to corporate resources by integrating FortiNAC-F with FortiGate using firewall tags defined on FortiNAC-F.

Where would the administrator assign the firewall tag value that will be sent to FortiGate?

Options:

A.

RADIUS group attribute

B.

Logical network

C.

Device profiling rule

D.

Security rule

Question 13

Refer to the exhibits.

as

as

Based on the given configurations and settings, on which date and time would a guest account created at 8:00 AM on 2025/09/12 expire?

Options:

A.

2025/09/12 at 8:00 PM

B.

2025/09/12 at 7:00 PM

C.

2025/09/12 at 17:00:00

D.

2025/09/13 at 17:00:00

Question 14

An administrator is configuring FortiNAC-F to manage FortiGate VPN users. As part of the configuration, the administrator must configure a few FortiGate firewall policies. What is the purpose of the FortiGate firewall policy that applies to clients not yet authorized by FortiNAC-F? (Choose one answer)

Options:

A.

To allow access to only the production DNS server

B.

To allow access to only the production DNS server

C.

To allow access to only the FortiNAC-F VPN interface

D.

To allow access to only the FortiGate VPN interface

Question 15

Refer to the exhibits.

as

as

as

An administrator is troubleshooting visibility issues on a modeled switch The switch is configured to use link traps and to provision hosts based on network access policies. The administrator is seeing hosts on ports with no hosts connected and not seeing hosts on ports where hosts are known to be connected.

What is the most likely cause?

Options:

A.

The logical networks are set to deny.

B.

The host has uninstalled the FortiNAC-F agent.

C.

The switch cannot be contacted by FortiNAC-F

D.

The credentials are incorrect.

Question 16

An administrator manages a corporate environment where all users log into the corporate domain each time they connect to the network. The administrator wants to leverage login scripts to use a FortiNAC-F agent to enhance endpoint visibility. Which agent can be deployed as part of a login script?

Options:

A.

Persistent

B.

Dissolvable

C.

Mobile

D.

Passive

Question 17

A healthcare organization is integrating FortiNAC-F with its existing MDM. Communication is failing between the systems.

What could be a probable cause?

Options:

A.

Security Fabric traffic is failing

B.

SSH communication is failing

C.

REST API communication is failing

D.

SOAP API communication is failing

Question 18

While discovering network infrastructure devices, a switch appears in the inventory topology with a question mark (?) on the icon. What would cause this?

Options:

A.

The wrong SNMP community string was entered during discovery.

B.

The SNMP ObjectlD is not recognized by FortiNAC-F.

C.

A read-only SNMP community siring was used.

D.

SNMP is not enabled on the switch.

Page: 1 / 6
Total 60 questions