[Apr-2024] Pass Fortinet NSE6_FNC-9.1 Tests Engine pdf - All Free Dumps [Q11-Q34]

Share

[Apr-2024] Pass Fortinet NSE6_FNC-9.1 Tests Engine pdf - All Free Dumps

Fortinet NSE 6 - FortiNAC 9.1 Practice Tests 2024 | Pass NSE6_FNC-9.1 with confidence!


Fortinet NSE6_FNC-9.1 certification exam covers a wide range of topics, including FortiNAC architecture, deployment scenarios, integration with other Fortinet products, and advanced features such as role-based access control, policy enforcement, and network segmentation. NSE6_FNC-9.1 exam consists of 45 multiple-choice questions that must be completed within 60 minutes. To pass the exam, you must score a minimum of 70%.

 

NEW QUESTION # 11
Which three communication methods are used by FortiNAC to gather information from and control, infrastructure devices? (Choose three.)

  • A. SNMP
  • B. RADIUS
  • C. CLI
  • D. FTP
  • E. SMTP

Answer: A,B,C

Explanation:
Explanation
FortiNAC Study Guide 7.2 | Page 11


NEW QUESTION # 12
Which two policy types can be created on a FortiNAC Control Manager? (Choose two.)

  • A. Authentication
  • B. Network Access
  • C. Supplicant EasvConnect
  • D. Endpoint Compliance

Answer: B,D


NEW QUESTION # 13
When FortiNAC passes a firewall tag to FortiGate, what determines the value that is passed?

  • A. Logical network
  • B. RADIUS group attribute
  • C. Security rule
  • D. Device profiling rule

Answer: A


NEW QUESTION # 14
An administrator wants the Host At Risk event to generate an alarm. What is used to achieve this result?

  • A. An event to alarm mapping
  • B. A security filter
  • C. An event to action mapping
  • D. A security trigger activity

Answer: A


NEW QUESTION # 15
What causes a host's state to change to "at risk"?

  • A. The host has failed an endpoint compliance policy or admin scan.
  • B. The host has been administratively disabled.
  • C. The logged on user is not found in the Active Directory.
  • D. The host is not in the Registered Hosts group.

Answer: A

Explanation:
Explanation
Failure- Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.


NEW QUESTION # 16
In which view would you find who made modifications to a Group?

  • A. The Security Events view
  • B. The Event Management view
  • C. The Alarms view
  • D. The Admin Auditing view

Answer: D

Explanation:
Explanation
It's important to audit Group Policy changes in order to determine the details of changes made to Group Policies by delegated users.


NEW QUESTION # 17
Which two methods can be used to gather a list of installed applications and application details from a host?
(Choose two.)

  • A. MDM integration
  • B. Agent technology
  • C. Portal page on-boarding options
  • D. Application layer traffic inspection

Answer: A,B


NEW QUESTION # 18
In an isolation VLAN which three services does FortiNAC supply? (Choose three.)

  • A. DHCP
  • B. NTP
  • C. DNS
  • D. ISMTP
  • E. Web

Answer: A,C,E


NEW QUESTION # 19
View the command and output.

What is the state of database replication?

  • A. Primary to secondary synchronization failed.
  • B. Primary to secondary database synchronization was successful.
  • C. Secondary to primary synchronization was successful.
  • D. Secondary to primary synchronization failed.

Answer: B


NEW QUESTION # 20
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?

  • A. The host is isolated.
  • B. The host is administratively disabled.
  • C. The host is provisioned based on the default access defined by the point of connection.
  • D. The host is provisioned based on the network access policy.

Answer: A

Explanation:
Explanation
https://training.fortinet.com/pluginfile.php/1912463/mod_resource/content/26/FortiNAC_7.2_Study_Guide-Onli
C: Page 327 - moved to the quarantine isolation network


NEW QUESTION # 21
Refer to the exhibit.

If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?

  • A. The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.
  • B. The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
  • C. The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
  • D. The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.

Answer: B


NEW QUESTION # 22
Which devices would be evaluated by device profiling rules?

  • A. Rogue devices, each time they connect
  • B. Known trusted devices, each time they change location
  • C. All hosts, each time they connect
  • D. Rogue devices, only when they are initially added to the database

Answer: A


NEW QUESTION # 23
Which group type can have members added directly from the FortiNAC Control Manager?

  • A. Port
  • B. Host
  • C. Device
  • D. Administrator

Answer: D


NEW QUESTION # 24
Where should you configure MAC notification traps on a supported switch?

  • A. Configure them only after you configure linkup and linkdown traps.
  • B. Configure them on all ports except uplink ports.
  • C. Configure them only on ports set as 802 1g trunks.
  • D. Configure them on all ports on the switch.

Answer: B


NEW QUESTION # 25
What would occur if both an unknown (rogue) device and a known (trusted) device simultaneously appeared on a port that is a member of the Forced Registration port group?

  • A. The port would be administratively shut down.
  • B. The port would be provisioned to the registration network, and both hosts would be isolated.
  • C. The port would not be managed, and an event would be generated.
  • D. The port would be provisioned for the normal state host, and both hosts would have access to that VLAN.

Answer: B


NEW QUESTION # 26
During the on-boarding process through the captive portal, what are two reasons why a host that successfully registered would remain stuck in the Registration VLAN? (Choose two.)

  • A. The port default VLAN is the same as the Registration VLAN.
  • B. There is another unregistered host on the same port.
  • C. Bridging is enabled on the host.
  • D. The wrong agent is installed.

Answer: A,B


NEW QUESTION # 27
While troubleshooting a network connectivity issue, an administrator determines that a device was being automatically provisioned to an incorrect VLAN.
Where would the administrator look to determine when and why FortiNAC made the network access change?

  • A. The Connections view
  • B. The Port Changes view
  • C. The Event view
  • D. The Admin Auditing view

Answer: B


NEW QUESTION # 28
Where are logical network values defined?

  • A. In the port properties view of each port
  • B. In the model configuration view of each infrastructure device
  • C. On the profiled devices view
  • D. In the security and access field of each host record

Answer: B


NEW QUESTION # 29
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?

  • A. The port is switched into the Dead-End VLAN.
  • B. The port is added to the Forced Registration group.
  • C. The port becomes a threshold uplink.
  • D. The port is disabled.

Answer: C

Explanation:
Explanation
Admin Guide p. 754: Threshold Uplink-The Uplink mode has been set as Dynamic and FortiNAC has determined that the number of MAC addresses on the port exceeds the System Defined Uplink count. All hosts read on this port are ignored.


NEW QUESTION # 30
......

Online Exam Practice Tests with detailed explanations!: https://actualtests.prep4away.com/Fortinet-certification/braindumps.NSE6_FNC-9.1.ete.file.html