
[UPDATED 2023] Free Fortinet NSE6_FAC-6.1 Exam Questions Self-Assess Preparation
NSE6_FAC-6.1 Free Sample Questions to Practice One Year Update
NEW QUESTION 14
Which two statements about the self-service portal are true? (Choose two)
- A. Administrator approval is required for all self-registration
- B. Authenticating users must specify domain name along with username
- C. Self-registration information can be sent to the user through email or SMS
- D. Realms can be used to configure which seld-registeredusers or groups can authenticate on the network
Answer: C,D
NEW QUESTION 15
Which FSSO discovery method transparently detects logged off users without having to rely on external features such as WMI polling?
- A. FortiClient SSO Mobility Agent
- B. Radius Accounting
- C. Windows AD polling
- D. DC Polling
Answer: A
NEW QUESTION 16
Which behaviors exist for certificate revocation lists (CRLs) on FortiAuthenticator? (Choose two)
- A. All local CAs share the same CRLs
- B. Revoked certificates are automaticlly placed on the CRL
- C. CRLs contain the serial number of the certificate that has been revoked
- D. CRLs can beexported only through the SCEP server
Answer: B,C
NEW QUESTION 17
You are a Wi-Fi provider and host multiple domains. How do you delegate user accounts, user groups and permissions per domain when theyare authenticating on a single FortiAuthenticator device?
- A. Create user groups
- B. Create multiple directory trees on FortiAuthenticator
- C. Create realms
- D. Automatically import hosts from each domain as they authenticate
Answer: C
NEW QUESTION 18
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.
What can couse this issue?
- A. FortiAuthenticator has lose contact with the FortiToken Cloud servers
- B. Time drift between FortiAuthenticator and hardware tokens
- C. On of the FortiAuthenticator devices in the active-active cluster has failed
- D. FortiToken 200 licence has expired
Answer: B
NEW QUESTION 19
What are three key features of FortiAuthenticator? (Choose three)
- A. Portal services
- B. RSSO Server
- C. Certificate authority
- D. Log server
- E. Identity management device
Answer: A,C,E
NEW QUESTION 20
Which network configuration is required when deploying FortiAuthenticator for portal services?
- A. Policies must have specific ports open between FortiAuthenticator and the authentication clients
- B. Fortigate must be setup as default gateway for FortiAuthenticator
- C. One of the DNS servers must be a FortiGuard DNS server
- D. FortiAuthenticator must have the REST API access enable on port1
Answer: A
NEW QUESTION 21
At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator?
(Choose two)
- A. Configuring an external authentication portal
- B. Configuring at least on post-login service
- C. Configuring a RADIUS client
- D. Configuring a portal policy
Answer: B,D
NEW QUESTION 22
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- A. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider
- B. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
- C. Principal contacts idendity provider and is redirected to serviceprovider, principal establishes connection with service provider, service provider validates authentication with identify provider
- D. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
Answer: A
NEW QUESTION 23
Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)
- A. Importing other CA certificates and CRLs
- B. Creating, signing, and revoking of X.509 certificates
- C. Validating other CA CRLs using OSCP
- D. Merging local and remote CRLs using SCEP
Answer: A,B
NEW QUESTION 24
Which two features of FortiAuthenticator are used for EAP deployment? (Choose two)
- A. MAC authentication bypass
- B. Certificate authority
- C. RADIUS server
- D. LDAP server
Answer: B,C
NEW QUESTION 25
Which EAP method is known as the outer authentication method?
- A. EAP-GTC
- B. EAP-TLS
- C. PEAP
- D. MSCHAPV2
Answer: C
NEW QUESTION 26
......
Real exam questions are provided for NSE 6 Network Security Specialist tests, which can make sure you 100% pass: https://passguide.dumpexams.com/NSE6_FAC-6.1-vce-torrent.html