Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the Fortinet NSE 6 Network Security Specialist NSE6_FNC_AD-7.6 Questions and answers with Dumpstech

Exam NSE6_FNC_AD-7.6 Premium Access

View all detail and faqs for the NSE6_FNC_AD-7.6 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

An administrator is configuring FortiNAC-F to manage FortiGate VPN users. As part of the configuration, the administrator must configure a few FortiGate firewall policies. What is the purpose of the FortiGate firewall policy that applies to clients not yet authorized by FortiNAC-F? (Choose one answer)

Options:

A.

To allow access to only the production DNS server

B.

To allow access to only the production DNS server

C.

To allow access to only the FortiNAC-F VPN interface

D.

To allow access to only the FortiGate VPN interface

Questions # 2:

Refer to the exhibit.

Question # 2

An administrator wants to use FortiNAC-F to automatically provision printers throughout their organization. Each building uses its own local VLAN for printers.

Which FortiNAC-F feature would allow this to be accomplished with a single network access policy?

Options:

A.

Dynamic host groups

B.

Logical networks

C.

Device profiling rules

D.

Preferred VLAN designations

Questions # 3:

When configuring isolation networks in the configuration wizard, why does a layer 3 network typo allow for mora than ono DHCP scope for each isolation network typo?

Options:

A.

The layer 3 network type allows for one scope for each possible host status.

B.

Configuring more than one DHCP scope allows for DHCP server redundancy

C.

There can be more than one isolation network of each type

D.

Any scopes beyond the first scope are used if the initial scope runs out of IP addresses.

Questions # 4:

Refer to the exhibit.

Question # 4

After a successful layer 2 poll, two hosts were learned on the same port The port is a member of the Role-Based Access and Forced Registration groups. The switch has been configured to leverage a single isolation VLAN.

How will FortiNAC-F manage this port?

Options:

A.

The port will be provisioned to the isolation network

B.

The port will be provisioned for the normal state host, but the second host will have access to only the isolation portal page.

C.

The port will be provisioned as an uplink to a hub or unmanaged switch.

D.

The port will be added to the Access Point Management group

Questions # 5:

An organization wants to add a FortiNAC-F Manager to simplify their large FortiNAC-F deployment.

Which two policy types can be managed globally? (Choose two.)

Options:

A.

Authentication

B.

Endpoint Compliance

C.

Supplicant EasyConnect

D.

Network Access

Questions # 6:

Where should you configure MAC notification traps on a supported switch?

Options:

A.

Only on ports that generate linkup and linkdown traps

B.

Only on ports defined as learned uplinks

C.

On all ports on the switch

D.

On all ports except uplink ports

Questions # 7:

Which two actions must the administrator perform to allow FortiNAC-F to process incoming syslog messages from an unknown vendor? (Choose two answers)

Options:

A.

The device must be added as a server in the Host view

B.

The device sending the messages must be modeled in the Network Inventory view

C.

The device must be added as a log receiver in FortiNAC-F

D.

The device must have an event parser created for it

Questions # 8:

In which three ways would deploying a FortiNAC-F Manager into a large environment consisting of several FortiNAC-F CAs simplify management? (Choose three.)

Options:

A.

Global infrastructure device inventory

B.

Global version control

C.

Global authentication security policies

D.

Pooled licenses

E.

Global visibility

Questions # 9:

An administrator wants to control user access to corporate resources by integrating FortiNAC-F with FortiGate using firewall tags defined on FortiNAC-F.

Where would the administrator assign the firewall tag value that will be sent to FortiGate?

Options:

A.

RADIUS group attribute

B.

Logical network

C.

Device profiling rule

D.

Security rule

Questions # 10:

An administrator wants to build device profiling rules based on network traffic, but the network session view is not populated with any records.

Which two settings can be enabled to gather network session information? (Choose two.)

Options:

A.

Network traffic polling on any modeled infrastructure device

B.

Firewall session polling on modeled FortiGate devices

C.

Netflow setting on the FortiNAC-F interfaces

D.

Layer 3 polling on the infrastructure devices

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions