Month end Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet NSE5_FNC_AD_7.6 Fortinet NSE 5 - FortiNAC-F 7.6 Administrator Exam Practice Test

Fortinet NSE 5 - FortiNAC-F 7.6 Administrator Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

When creating a device profiling rule, what are two advantages of registering the device in the host view? (Choose two.)

Options:

A.

The devices can be managed as a generic SNMP device.

B.

The devices will have connection logs.

C.

The devices can be associated with a user.

D.

The devices can be polled for connection status.

Question 2

While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen to use the shared IP address option.

Which condition must be met for this type of deployment?

Options:

A.

The isolation network type is layer 3.

B.

There is a direct cable link between FortiNAC-F devices.

C.

The primary and secondary administrative interfaces are on the same subnet.

D.

The isolation network type is Layer 2.

Question 3

An organization wants to add a FortiNAC-F Manager to simplify their large FortiNAC-F deployment.

Which two policy types can be managed globally? (Choose two.)

Options:

A.

Authentication

B.

Endpoint Compliance

C.

Supplicant EasyConnect

D.

Network Access

Question 4

An administrator wants to build device profiling rules based on network traffic, but the network session view is not populated with any records.

Which two settings can be enabled to gather network session information? (Choose two.)

Options:

A.

Network traffic polling on any modeled infrastructure device

B.

Firewall session polling on modeled FortiGate devices

C.

Netflow setting on the FortiNAC-F interfaces

D.

Layer 3 polling on the infrastructure devices

Question 5

An administrator wants FortiNAC-F to return a group of user-defined RADIUS attributes in RADIUS responses.

Which condition must be true to achieve this?

Options:

A.

The requesting device must support RFC 5176.

B.

Inbound RADIUS requests must contain the Calling-Station-ID attribute.

C.

The device models in the inventory view must be configured for proxy-based authentication.

D.

RADIUS accounting must be enabled on the FortiNAC-F RADIUS server configuration.

Question 6

When configuring FortiNAC-F to manage FortiGate VPN users, an endpoint compliance policy must be created for the integration.

Why is the endpoint compliance policy necessary for this type of integration?

Options:

A.

To designate the required agent type

B.

To validate the VPN user credentials

C.

To confirm the installed endpoint certificate

D.

To validate the VPN client being used

Question 7

Refer to the exhibit.

An administrator wants to use FortiNAC-F to automatically provision printers throughout their organization. Each building uses its own local VLAN for printers.

Which FortiNAC-F feature would allow this to be accomplished with a single network access policy?

Options:

A.

Dynamic host groups

B.

Logical networks

C.

Device profiling rules

D.

Preferred VLAN designations

Question 8

Refer to the exhibit.

If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?

Options:

A.

The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.

B.

The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.

C.

The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.

D.

The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.

Question 9

What must an administrator configure to allow FortiNAC-F to process incoming syslog messages that are not supported by default?

Options:

A.

A Syslog Service Connector

B.

A Security Action

C.

A Security Event Parser

D.

A Log Receiver