Download Exam NSE6_FNC-7.2 Practice Test Questions with 100% Verified Answers [Q22-Q38]

Share

Download Exam NSE6_FNC-7.2 Practice Test Questions with 100% Verified Answers

Share Latest NSE6_FNC-7.2Test Practice Test Questions, Exam Dumps


Fortinet NSE6_FNC-7.2 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Identification and Classification of Rogues: In this section of the exam, the focus is given to detecting and classifying devices that are unauthenticated in the FortiNAC network.
Topic 2
  • Guest and Contractor Management: In this section of the exam, a topic discussed offering secure and temporary network access. This includes giving access to contractors as well as guests.
Topic 3
  • Introduction and Initial Configuration: This particular section of the exam covers configuring FortiNAC for basic operation.
Topic 4
  • Visibility, Troubleshooting, and Logging: In this exam section, the focus is given to monitoring network activity, maintaining network problems, and managing logs.
Topic 5
  • Security Device Integration and Automated Response: In this section of the exam, involves using FortiNAC with different security devices and how to automate incident response.
Topic 6
  • Security Policies: In this section, policies are discussed related to rules that are used to improve the control over network access and devices.
Topic 7
  • State-Based Control: In this exam section the focus is given to controlling access to the network based on the state of its devices used.
Topic 8
  • FortiGate VPN, High Availability, and FortiNAC Control Manager Integrations: In this section of the exam, the focus is given to managing VPN access; it also covers how to ensure proper FortiNAC integration with the main management system.

 

NEW QUESTION # 22
When you create a user or host profile, which three criteria can you use? (Choose three.)

  • A. An applied access policy
  • B. Host or user group memberships
  • C. Location
  • D. Administrative group membership
  • E. Host or user attributes

Answer: A,C,D


NEW QUESTION # 23
Which two device classification options can register a device automatically and transparently to the end user? (Choose two.)

  • A. Captive portal
  • B. Device importing
  • C. MDM integration
  • D. Dissolvable agent
  • E. DotlxAuto Registration

Answer: C,E


NEW QUESTION # 24
Which devices would be evaluated by device profiling rules?

  • A. Rogue devices, only when they are initially added to the database
  • B. All hosts, each time they connect
  • C. Rogue devices, each time they connect
  • D. Known trusted devices, each time they change location

Answer: B

Explanation:
Device profiling rules in FortiNAC are used to evaluate and classify rogue devices. These rules can be configured to automatically, manually, or through sponsorship evaluate and classify unknown untrusted devices as they are identified and created.
References
* FortiNAC 7.2 Study Guide, page 98


NEW QUESTION # 25
Which system group will force at-risk hosts into the quarantine network, based on point of connection?

  • A. Forced Quarantine
  • B. Forced Isolation
  • C. Physical Address Filtering
  • D. Forced Remediation

Answer: B


NEW QUESTION # 26
Which agent can receive and display messages from FortiNAC to the end user?

  • A. Persistent
  • B. Dissolvable
  • C. MDM
  • D. Passive

Answer: A


NEW QUESTION # 27
Refer to the exhibit.

If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what occurs?

  • A. The host is moved to a default isolation VLAN.
  • B. The host is disabled.
  • C. The host is moved to VLAN 111.
  • D. No VLAN change is performed.

Answer: A


NEW QUESTION # 28
What would happen if a port was placed in both the Forced Registration and the Forced Remediation port groups?

  • A. Both enforcement groups cannot contain the same port.
  • B. Only al-risk hosts would be impacted.
  • C. Both types of enforcement would be applied.
  • D. Only rogue hosts would be impacted.

Answer: D


NEW QUESTION # 29
Which agent can receive and display messages from FortiNAC to the end user?

  • A. Persistent
  • B. Dissolvable
  • C. MDM
  • D. Passive

Answer: A

Explanation:
The persistent agent has the ability to display messages on the desktop of an endpoint. These messages can target an individual host, a group of hosts, or all hosts with the persistent agent installed. The messaging options include sending a message content with an optional web address link


NEW QUESTION # 30
When FortiNAC passes a firewall tag to FortiGate, what determines the value that is passed?

  • A. Device profiling rule
  • B. Logical network
  • C. Security rule
  • D. RADIUS group attribute

Answer: B


NEW QUESTION # 31
During an evaluation of state-based enforcement, an administrator discovers that ports that should not be under enforcement have been added to enforcement groups. In which view would the administrator be able to determine who added the ports to the groups?

  • A. The Event Management view
  • B. The Alarms view
  • C. The Security Events view
  • D. The Admin Auditing view

Answer: D


NEW QUESTION # 32
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?

  • A. The host is administratively disabled.
  • B. The host is provisioned based on the network access policy.
  • C. The host is isolated.
  • D. The host is provisioned based on the default access defined by the point of connection.

Answer: A


NEW QUESTION # 33
During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)

  • A. The wrong agent is installed.
  • B. Bridging is enabled on the host
  • C. The ports default VLAN is the same as the Registration VLAN.
  • D. There is another unregistered host on the same port.

Answer: A,C


NEW QUESTION # 34
Which two agents can validate endpoint compliance transparently to the end user? (Choose two.)

  • A. Persistent
  • B. Dissolvable
  • C. Mobile
  • D. Passive

Answer: A,B

Explanation:
Both dissolvable and persistent agents can be used to validate endpoint compliance transparently to the end user. The persistent agent stays resident on the endpoint and performs scheduled scans in the background. The dissolvable agent is a run-once agent that dissolves after reporting its results, leaving no footprint on the endpoint


NEW QUESTION # 35
What agent is required in order to detect an added USB drive?

  • A. Persistent
  • B. Mobile
  • C. Dissolvable
  • D. Passive

Answer: A


NEW QUESTION # 36
Which command line shell and scripting language does FortiNAC use for WinRM?

  • A. Linux
  • B. DOS
  • C. Powershell
  • D. Bash

Answer: C


NEW QUESTION # 37
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?

  • A. The port is added to the Forced Registration group.
  • B. The port is disabled.
  • C. The port is switched into the Dead-End VLAN.
  • D. The port becomes a threshold uplink.

Answer: D

Explanation:
Admin Guide p. 754: Threshold Uplink-The Uplink mode has been set as Dynamic and FortiNAC has determined that the number of MAC addresses on the port exceeds the System Defined Uplink count. All hosts read on this port are ignored.


NEW QUESTION # 38
......

Positive Aspects of Valid Dumps NSE6_FNC-7.2 Exam Dumps!: https://lead2pass.troytecdumps.com/NSE6_FNC-7.2-troytec-exam-dumps.html