Apr-2024 Download Free Latest Exam NSE6_FNC-7.2 Certified Sample Questions
Prepare for your exam certification with our NSE6_FNC-7.2 Certified Fortinet
NEW QUESTION # 22
Which system group will force at-risk hosts into the quarantine network, based on point of connection?
- A. Forced Remediation
- B. Forced Isolation
- C. Forced Quarantine
- D. Physical Address Filtering
Answer: B
NEW QUESTION # 23
When you create a user or host profile, which three criteria can you use? (Choose three.)
- A. Host or user group memberships
- B. Location
- C. An applied access policy
- D. Host or user attributes
- E. Administrative group membership
Answer: B,C,E
NEW QUESTION # 24
What causes a host's state to change to "at risk"?
- A. The host is not in the Registered Hosts group.
- B. The host has failed an endpoint compliance policy or admin scan.
- C. The host has been administratively disabled.
- D. The logged on user is not found in the Active Directory.
Answer: B
Explanation:
Failure - Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.
Reference:
p. 244 of the Study Guide, "A state of at-risk indicates the host has failed a scan. This could be a compliance scan or an administrative scan."
NEW QUESTION # 25
Which two policy types can be created on a FortiNAC Control Manager? (Choose two.)
- A. Authentication
- B. Network Access
- C. Supplicant EasvConnect
- D. Endpoint Compliance
Answer: B,D
NEW QUESTION # 26
Which connecting endpoints are evaluated against all enabled device profiling rules?
- A. Rogues devices, only when they connect for the first time
- B. Known trusted devices each time they change location
- C. Rogues devices, each time they connect
- D. All hosts, each time they connect
Answer: C
NEW QUESTION # 27
Which system group will force at-risk hosts into the quarantine network, based on point of connection?
- A. Forced Remediation
- B. Forced Isolation
- C. Forced Quarantine
- D. Physical Address Filtering
Answer: C
Explanation:
Forced Quarantine, study guide 7.2 pag 245 and 248
NEW QUESTION # 28
Refer to the exhibit, and then answer the question below.
Which host is rogue?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION # 29
Refer to the exhibit, and then answer the question below.
Which host is rogue?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION # 30
In a wireless integration, how does FortiNAC obtain connecting MAC address information?
- A. Link traps
- B. End station traffic monitoring
- C. MAC notification traps
- D. RADIUS
Answer: C
NEW QUESTION # 31
Refer to the exhibit.
If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?
- A. The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.
- B. The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
- C. The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
- D. The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.
Answer: B
NEW QUESTION # 32
An administrator is configuring FortiNAC to manage FortiGate VPN users. As part of the configuration, the administrator must configure a few FortiGate firewall policies.
What is the purpose of the FortiGate firewall policy that applies to unauthorized VPN clients?
- A. To allow access to only the production DNS server
- B. To deny access to only the FortiNAC VPN interface
- C. To deny access to only the production DNS server
- D. To allow access to only the FortiNAC VPN interface
Answer: D
NEW QUESTION # 33
An administrator wants the Host At Risk event to generate an alarm. What is used to achieve this result?
- A. An event to alarm mapping
- B. A security filter
- C. A security trigger activity
- D. An event to action mapping
Answer: A
NEW QUESTION # 34
Which two methods can be used to gather a list of installed applications and application details from a host? (Choose two)
- A. Portal page on-boarding options
- B. MDM integration
- C. Agent technology
- D. Application layer traffic inspection
Answer: A,D
NEW QUESTION # 35
What would occur if both an unknown (rogue) device and a known (trusted) device simultaneously appeared on a port that is a member of the Forced Registration port group?
- A. The port would be administratively shut down.
- B. The port would be provisioned for the normal state host, and both hosts would have access to that VLAN.
- C. The port would be provisioned to the registration network, and both hosts would be isolated.
- D. The port would not be managed, and an event would be generated.
Answer: B
NEW QUESTION # 36
In an isolation VLAN which three services does FortiNAC supply? (Choose three.)
- A. NTP
- B. DHCP
- C. DNS
- D. ISMTP
- E. Web
Answer: B,C,E
NEW QUESTION # 37
How should you configure MAC notification traps on a supported switch?
- A. Configure them on all ports on the switch
- B. Configure them on all ports except uplink ports
- C. Configure them only on ports set as 802 1q trunks
- D. Configure them only after you configure linkup and linkdown traps
Answer: D
NEW QUESTION # 38
Refer to the exhibit.
Considering the host status of the two hosts connected to the same wired port, what will happen if the port is a member of the Forced Registration port group?
- A. The port will be provisioned for the normal state host, and both hosts will have access to that VLAN.
- B. The port will be provisioned to the registration network, and both hosts will be isolated.
- C. The port will not be managed, and an event will be generated.
- D. The port will be administratively shut down.
Answer: B
NEW QUESTION # 39
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)
- A. A failed Layer 3 poll
- B. Manual polling
- C. A matched security policy
- D. Linkup and Linkdown traps
- E. Scheduled poll timings
Answer: B,D,E
NEW QUESTION # 40
Where do you look to determine what network access policy, if any, is being applied to a particular host?
- A. The network access policy configuration
- B. The Policy Details view for the host
- C. The Policy Logs view
- D. The Port Properties view of the hosts port
Answer: C
NEW QUESTION # 41
......
Free Fortinet NSE6_FNC-7.2 Exam 2024 Practice Materials Collection: https://examsboost.dumpstorrent.com/NSE6_FNC-7.2-exam-prep.html