[Aug-2022] Updated NSE 6 Network Security Specialist NSE6_FAC-6.1 Exam Questions BUNDLE PACK [Q16-Q31]

Share

[Aug-2022] Updated NSE 6 Network Security Specialist NSE6_FAC-6.1 Exam Questions BUNDLE PACK

Master The Fortinet Content NSE6_FAC-6.1 EXAM DUMPS WITH GUARANTEED SUCCESS!

NEW QUESTION 16
You are the administrator of a large network that includes a large local user datadabase on the current Fortiauthenticatior. You want to import all the local users into a new Fortiauthenticator device.
Which method should you use to migrate the local users?

  • A. Import users using a CSV file.
  • B. Import the current directory structure.
  • C. Import users using RADIUS accounting updates.
  • D. Import users fromRADUIS.

Answer: A

 

NEW QUESTION 17
Which EAP method is known as the outer authentication method?

  • A. EAP-GTC
  • B. PEAP
  • C. MSCHAPV2
  • D. EAP-TLS

Answer: B

 

NEW QUESTION 18
Which FSSO discovery method transparently detects logged off users without having to rely on external features such as WMI polling?

  • A. DC Polling
  • B. Radius Accounting
  • C. FortiClient SSO Mobility Agent
  • D. Windows AD polling

Answer: C

 

NEW QUESTION 19
At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator?
(Choose two)

  • A. Configuring an external authentication portal
  • B. Configuring a RADIUS client
  • C. Configuring a portal policy
  • D. Configuring at least on post-login service

Answer: C,D

 

NEW QUESTION 20
Which two are supported captive or guest portal authentication methods? (Choose two)

  • A. Linkedln
  • B. Apple ID
  • C. Email
  • D. Instagram

Answer: A,C

 

NEW QUESTION 21
Which statement about the guest portal policies is true?

  • A. Guest portal policies can be used only for BYODs
  • B. Guest portal policies apply only to authentication requests coming from unknown RADIUS clients
  • C. All conditions in the policy must match before a user is presented with the guest portal
  • D. Conditions in the policy apply only to guest wireless users

Answer: C

 

NEW QUESTION 22
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?

  • A. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
  • B. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
  • C. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider
  • D. Principal contacts idendity provider and is redirected to serviceprovider, principal establishes connection with service provider, service provider validates authentication with identify provider

Answer: C

 

NEW QUESTION 23
Which two types of digital certificates can you create in Fortiauthenticator? (Choose two)

  • A. Third-party root certificate
  • B. Local service certificate
  • C. Organization validation certificate
  • D. Usercertificate

Answer: B,D

 

NEW QUESTION 24
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.
What can couse this issue?

  • A. FortiToken 200 licence has expired
  • B. Time drift between FortiAuthenticator and hardware tokens
  • C. On of the FortiAuthenticator devices in the active-active cluster has failed
  • D. FortiAuthenticator has lose contact with the FortiToken Cloud servers

Answer: B

 

NEW QUESTION 25
Which network configuration is required when deploying FortiAuthenticator for portal services?

  • A. Policies must have specific ports open between FortiAuthenticator and the authentication clients
  • B. FortiAuthenticator must have the REST API access enable on port1
  • C. Fortigate must be setup as default gateway for FortiAuthenticator
  • D. One of the DNS servers must be a FortiGuard DNS server

Answer: A

 

NEW QUESTION 26
How can a SAML metada file be used?

  • A. To correlate the IDP address to its hostname
  • B. To resolve the IDP realm for authentication
  • C. To import the required IDP configuration
  • D. To defined a list of trusted user names

Answer: C

 

NEW QUESTION 27
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the masterFortiAuthenticator?

  • A. Standalone master
  • B. Cluster member
  • C. Active-passive master
  • D. Load balancing master

Answer: B

 

NEW QUESTION 28
......

Pass Fortinet NSE6_FAC-6.1 Exam – Experts Are Here To Help You: https://testking.exams-boost.com/NSE6_FAC-6.1-valid-materials.html