Free Fortinet (NSE6_FNC-7.2) Certification Sample Questions with Online Practice Test
NSE6_FNC-7.2 Certification Study Guide Pass NSE6_FNC-7.2 Fast
NEW QUESTION # 19
Which two things must be done to allow FortiNAC to process incoming syslog messages from an unknown vendor? (Choose two.)
- A. The device must be added as a log receiver.
- B. The device sending the messages must be modeled in the Network Inventory view.
- C. A security event parser must be created for the device.
- D. The device must be added as a patch management server.
Answer: A,C
NEW QUESTION # 20
Which system group will force at-risk hosts into the quarantine network, based on point of connection?
- A. Forced Isolation
- B. Physical Address Filtering
- C. Forced Remediation
- D. Forced Quarantine
Answer: A
NEW QUESTION # 21
Which two of the following are required for endpoint compliance monitors? (Choose two.)
- A. Logged on user
- B. Custom scan
- C. Security rule
- D. Persistent agent
Answer: B,C
NEW QUESTION # 22
Which two agents can validate endpoint compliance transparently to the end user? (Choose two.)
- A. Passive
- B. Persistent
- C. Dissolvable
- D. Mobile
Answer: B,D
NEW QUESTION # 23
Refer to the exhibit.
What would happen if the highlighted port with connected hosts was placed in both the Forced Registration and Forced Remediation port groups?
- A. Only the higher ranked enforcement group would be applied.
- B. Multiple enforcement groups could not contain the same port.
- C. Enforcement would be applied only to rogue hosts.
- D. Both types of enforcement would be applied.
Answer: D
NEW QUESTION # 24
Which connecting endpoints are evaluated against all enabled device profiling rules?
- A. Known trusted devices each time they change location
- B. Rogues devices, only when they connect for the first time
- C. Rogues devices, each time they connect
- D. All hosts, each time they connect
Answer: C
NEW QUESTION # 25
Where are logical network values defined?
- A. In the model configuration view of each infrastructure device
- B. In the port properties view of each port
- C. In the security and access field of each host record
- D. On the profiled devices view
Answer: A
NEW QUESTION # 26
Which agent is used only as part of a login script?
- A. Passive
- B. Persistent
- C. Dissolvable
- D. Mobile
Answer: B
NEW QUESTION # 27
In an isolation VLAN. which three services does FortiNAC supply? (Choose three.)
- A. Web
- B. DNTP
- C. IDHCP
- D. SMTP
- E. DDNS
Answer: A,B,E
NEW QUESTION # 28
Refer to the exhibit.
Considering the host status of the two hosts connected to the same wired port, what will happen if the port is a member of the Forced Registration port group?
- A. The port will be administratively shut down.
- B. The port will be provisioned for the normal state host, and both hosts will have access to that VLAN.
- C. The port will be provisioned to the registration network, and both hosts will be isolated.
- D. The port will not be managed, and an event will be generated.
Answer: C
NEW QUESTION # 29
Which two policy types can be created on a FortiNAC Control Manager? (Choose two.)
- A. Supplicant EasvConnect
- B. Network Access
- C. Endpoint Compliance
- D. Authentication
Answer: B,C
NEW QUESTION # 30
How should you configure MAC notification traps on a supported switch?
- A. Configure them only after you configure linkup and linkdown traps
- B. Configure them only on ports set as 802 1q trunks
- C. Configure them on all ports except uplink ports
- D. Configure them on all ports on the switch
Answer: A
NEW QUESTION # 31
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?
- A. The port becomes a threshold uplink.
- B. The port is disabled.
- C. The port is added to the Forced Registration group.
- D. The port is switched into the Dead-End VLAN.
Answer: D
NEW QUESTION # 32
Which three of the following are components of a security rule? (Choose three.)
- A. Trigger
- B. Action
- C. Methods
- D. User or host profile
- E. Security String
Answer: A,B,D
NEW QUESTION # 33
When FortiNAC is managing FortiGate VPN users, why is an endpoint compliance policy necessary?
- A. To validate the VPN user credentials
- B. To designate the required agent type
- C. To validate the VPN client being used
- D. To confirm installed security software
Answer: D
NEW QUESTION # 34
During the on-boarding process through the captive portal, what are two reasons why a host that successfully registered would remain stuck in the Registration VLAN? (Choose two.)
- A. The wrong agent is installed.
- B. The port default VLAN is the same as the Registration VLAN.
- C. Bridging is enabled on the host.
- D. There is another unregistered host on the same port.
Answer: B,D
NEW QUESTION # 35
Refer to the exhibit.
If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what will occur?
- A. The host is moved to a default isolation VLAN.
- B. The host is disabled.
- C. No VLAN change is performed
- D. The host is moved to VLAN 111.
Answer: C
NEW QUESTION # 36
Which devices would be evaluated by device profiling rules?
- A. Rogue devices, each time they connect
- B. Known trusted devices, each time they change location
- C. Rogue devices, only when they are initially added to the database
- D. All hosts, each time they connect
Answer: A
NEW QUESTION # 37
What agent is required in order to detect an added USB drive?
- A. Passive
- B. Persistent
- C. Dissolvable
- D. Mobile
Answer: B
NEW QUESTION # 38
Refer to the exhibit, and then answer the question below.
Which host is rogue?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION # 39
Refer to the exhibit.
If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?
- A. The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.
- B. The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
- C. The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.
- D. The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
Answer: B
NEW QUESTION # 40
Which connecting endpoints are evaluated against all enabled device profiling rules?
- A. Known trusted devices each time they change location
- B. Rogues devices, only when they connect for the first time
- C. Rogues devices, each time they connect
- D. All hosts, each time they connect
Answer: C
Explanation:
FortiNAC process to classify rogue devices and create an organized inventory of known trusted registered devices.
NEW QUESTION # 41
Where do you look to determine when and why the FortiNAC made an automated network access change?
- A. The Port Changes view
- B. The Event view
- C. The Connections view
- D. The Admin Auditing view
Answer: A
Explanation:
Reference:
Study Guide p. 356: Any time FortiNAC changes network access for an endpoint, the change is documented on the Port Changes view. This provides an administrator with valuable information when validating control configurations and enforcement.
NEW QUESTION # 42
Refer to the exhibit, and then answer the question below.
Which host is rogue?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
NEW QUESTION # 43
......
Fortinet NSE6_FNC-7.2 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
Get Perfect Results with Premium NSE6_FNC-7.2 Dumps Updated 48 Questions: https://www.examcollectionpass.com/Fortinet/NSE6_FNC-7.2-practice-exam-dumps.html
NSE6_FNC-7.2 Dumps PDF 2024 Program Your Preparation EXAM SUCCESS: https://drive.google.com/open?id=1v7uSEOehFjeM_44-rhoZOaAEpA_M0bET