
[Aug-2022] Updated NSE 6 Network Security Specialist NSE6_FAC-6.1 Exam Questions BUNDLE PACK
Master The Fortinet Content NSE6_FAC-6.1 EXAM DUMPS WITH GUARANTEED SUCCESS!
NEW QUESTION 16
You are the administrator of a large network that includes a large local user datadabase on the current Fortiauthenticatior. You want to import all the local users into a new Fortiauthenticator device.
Which method should you use to migrate the local users?
- A. Import users using a CSV file.
- B. Import the current directory structure.
- C. Import users using RADIUS accounting updates.
- D. Import users fromRADUIS.
Answer: A
NEW QUESTION 17
Which EAP method is known as the outer authentication method?
- A. EAP-GTC
- B. PEAP
- C. MSCHAPV2
- D. EAP-TLS
Answer: B
NEW QUESTION 18
Which FSSO discovery method transparently detects logged off users without having to rely on external features such as WMI polling?
- A. DC Polling
- B. Radius Accounting
- C. FortiClient SSO Mobility Agent
- D. Windows AD polling
Answer: C
NEW QUESTION 19
At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator?
(Choose two)
- A. Configuring an external authentication portal
- B. Configuring a RADIUS client
- C. Configuring a portal policy
- D. Configuring at least on post-login service
Answer: C,D
NEW QUESTION 20
Which two are supported captive or guest portal authentication methods? (Choose two)
- A. Linkedln
- B. Apple ID
- C. Email
- D. Instagram
Answer: A,C
NEW QUESTION 21
Which statement about the guest portal policies is true?
- A. Guest portal policies can be used only for BYODs
- B. Guest portal policies apply only to authentication requests coming from unknown RADIUS clients
- C. All conditions in the policy must match before a user is presented with the guest portal
- D. Conditions in the policy apply only to guest wireless users
Answer: C
NEW QUESTION 22
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- A. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
- B. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
- C. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider
- D. Principal contacts idendity provider and is redirected to serviceprovider, principal establishes connection with service provider, service provider validates authentication with identify provider
Answer: C
NEW QUESTION 23
Which two types of digital certificates can you create in Fortiauthenticator? (Choose two)
- A. Third-party root certificate
- B. Local service certificate
- C. Organization validation certificate
- D. Usercertificate
Answer: B,D
NEW QUESTION 24
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.
What can couse this issue?
- A. FortiToken 200 licence has expired
- B. Time drift between FortiAuthenticator and hardware tokens
- C. On of the FortiAuthenticator devices in the active-active cluster has failed
- D. FortiAuthenticator has lose contact with the FortiToken Cloud servers
Answer: B
NEW QUESTION 25
Which network configuration is required when deploying FortiAuthenticator for portal services?
- A. Policies must have specific ports open between FortiAuthenticator and the authentication clients
- B. FortiAuthenticator must have the REST API access enable on port1
- C. Fortigate must be setup as default gateway for FortiAuthenticator
- D. One of the DNS servers must be a FortiGuard DNS server
Answer: A
NEW QUESTION 26
How can a SAML metada file be used?
- A. To correlate the IDP address to its hostname
- B. To resolve the IDP realm for authentication
- C. To import the required IDP configuration
- D. To defined a list of trusted user names
Answer: C
NEW QUESTION 27
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the masterFortiAuthenticator?
- A. Standalone master
- B. Cluster member
- C. Active-passive master
- D. Load balancing master
Answer: B
NEW QUESTION 28
......
Pass Fortinet NSE6_FAC-6.1 Exam – Experts Are Here To Help You: https://testking.exams-boost.com/NSE6_FAC-6.1-valid-materials.html