Fortinet NSE6_FNC-7.2 Study Guide Archives Updated on Jun 12, 2024 [Q13-Q33]

Share

Fortinet NSE6_FNC-7.2 Study Guide Archives Updated on Jun 12, 2024

Download NSE6_FNC-7.2 Mock Test Study Material


Fortinet NSE6_FNC-7.2 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Model and organize infrastructure devices
  • Monitor network devices and device status
Topic 2
  • Use logging options available on FortiNAC
  • Configure FortiGate VPN integration with FortiNAC
Topic 3
  • Explain and configure logical networks
  • Explain isolation networks and the configuration wizard
Topic 4
  • Explain and configure device profiling
  • Integrate with third-party devices using Syslog and SNMP trap input
Topic 5
  • Configure security automation
  • Options for rogue classification
  • Configure and use FortiNAC Control Manager

 

NEW QUESTION # 13
When FortiNAC is managing FortiGate VPN users, why is an endpoint compliance policy necessary?

  • A. To confirm installed security software
  • B. To designate the required agent type
  • C. To validate the VPN client being used
  • D. To validate the VPN user credentials

Answer: A


NEW QUESTION # 14
Where are logical network values defined?

  • A. In the model configuration view of each infrastructure device
  • B. In the port properties view of each port
  • C. In the security and access field of each host record
  • D. On the profiled devices view

Answer: A


NEW QUESTION # 15
Refer to the exhibit, and then answer the question below.

Which host is rogue?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 16
What agent is required in order to detect an added USB drive?

  • A. Dissolvable
  • B. Persistent
  • C. Mobile
  • D. Passive

Answer: B


NEW QUESTION # 17
Which command line shell and scripting language does FortiNAC use for WinRM?

  • A. Powershell
  • B. Linux
  • C. Bash
  • D. DOS

Answer: A


NEW QUESTION # 18
During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)

  • A. The wrong agent is installed.
  • B. Bridging is enabled on the host
  • C. The ports default VLAN is the same as the Registration VLAN.
  • D. There is another unregistered host on the same port.

Answer: A,C


NEW QUESTION # 19
Which three of the following are components of a security rule? (Choose three.)

  • A. Methods
  • B. Security String
  • C. Action
  • D. User or host profile
  • E. Trigger

Answer: C,D,E


NEW QUESTION # 20
Which system group will force at-risk hosts into the quarantine network, based on point of connection?

  • A. Forced Quarantine
  • B. Forced Isolation
  • C. Forced Remediation
  • D. Physical Address Filtering

Answer: A

Explanation:
Forced Quarantine, study guide 7.2 pag 245 and 248


NEW QUESTION # 21
What capability do logical networks provide?

  • A. Application of different access values from a single access policy
  • B. Autopopulation of device groups based on point of connection
  • C. VLAN-based inventory reporting
  • D. Interactive topology view diagrams

Answer: A

Explanation:
Explanation:


NEW QUESTION # 22
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)

  • A. Manual polling
  • B. Linkup and Linkdown traps
  • C. A matched security policy
  • D. Scheduled poll timings
  • E. A failed Layer 3 poll

Answer: A,B,D


NEW QUESTION # 23
Where are logical network values defined?

  • A. In the port properties view of each port
  • B. In the security and access field of each host record
  • C. In the model configuration view of each infrastructure device
  • D. On the profiled devices view

Answer: D


NEW QUESTION # 24
Refer to the exhibit.

If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what will occur?

  • A. The host is moved to VLAN 111.
  • B. The host is moved to a default isolation VLAN.
  • C. The host is disabled.
  • D. No VLAN change is performed

Answer: D


NEW QUESTION # 25
Which agent can receive and display messages from FortiNAC to the end user?

  • A. Dissolvable
  • B. Persistent
  • C. MDM
  • D. Passive

Answer: B


NEW QUESTION # 26
What causes a host's state to change to "at risk"?

  • A. The host has been administratively disabled.
  • B. The host has failed an endpoint compliance policy or admin scan.
  • C. The logged on user is not found in the Active Directory.
  • D. The host is not in the Registered Hosts group.

Answer: C


NEW QUESTION # 27
Which system group will force at-risk hosts into the quarantine network, based on point of connection?

  • A. Forced Remediation
  • B. Physical Address Filtering
  • C. Forced Quarantine
  • D. Forced Isolation

Answer: D


NEW QUESTION # 28
In which view would you find who made modifications to a Group?

  • A. The Security Events view
  • B. The Alarms view
  • C. The Admin Auditing view
  • D. The Event Management view

Answer: C

Explanation:
It's important to audit Group Policy changes in order to determine the details of changes made to Group Policies by delegated users.


NEW QUESTION # 29
Which agent is used only as part of a login script?

  • A. Dissolvable
  • B. Persistent
  • C. Mobile
  • D. Passive

Answer: B


NEW QUESTION # 30
When you create a user or host profile; which three criteria can you use? (Choose three.)

  • A. Location
  • B. Host or user attributes
  • C. Administrative group membership
  • D. Host or user group memberships
  • E. An applied access policy

Answer: A,B,D

Explanation:
Fortinac-admin-operations, P. 391


NEW QUESTION # 31
Refer to the exhibit.

Considering the host status of the two hosts connected to the same wired port, what will happen if the port is a member of the Forced Registration port group?

  • A. The port will be administratively shut down.
  • B. The port will not be managed, and an event will be generated.
  • C. The port will be provisioned for the normal state host, and both hosts will have access to that VLAN.
  • D. The port will be provisioned to the registration network, and both hosts will be isolated.

Answer: D


NEW QUESTION # 32
What would occur if both an unknown (rogue) device and a known (trusted) device simultaneously appeared on a port that is a member of the Forced Registration port group?

  • A. The port would not be managed, and an event would be generated.
  • B. The port would be provisioned to the registration network, and both hosts would be isolated.
  • C. The port would be provisioned for the normal state host, and both hosts would have access to that VLAN.
  • D. The port would be administratively shut down.

Answer: B


NEW QUESTION # 33
......

NSE6_FNC-7.2 Questions Prepare with Learning Information: https://www.examdiscuss.com/Fortinet/exam/NSE6_FNC-7.2/

Practice Material for NSE6_FNC-7.2 Exam Question Preparation: https://drive.google.com/open?id=1BJoECBGzWsA2w3Ovdwe2yeiRscXY_okw

0
0
0
10