NSE6_FAC-6.1 Self-Study Guide for Becoming an Fortinet NSE 6 - FortiAuthenticator 6.1 Expert [Q10-Q26]

Share

NSE6_FAC-6.1 Self-Study Guide for Becoming an Fortinet NSE 6 - FortiAuthenticator 6.1 Expert

NSE6_FAC-6.1 Study Guide Realistic Verified NSE6_FAC-6.1 Dumps

NEW QUESTION 10
How can a SAML metada file be used?

  • A. To defined a list of trusted user names
  • B. To resolve the IDP realm for authentication
  • C. To import the required IDP configuration
  • D. To correlate the IDP address to its hostname

Answer: C

 

NEW QUESTION 11
Which of the following is an QATH-based standart to generate event-based, one-time password tokens?

  • A. HOTP
  • B. SOTP
  • C. TOTP
  • D. OLTP

Answer: A

 

NEW QUESTION 12
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the masterFortiAuthenticator?

  • A. Load balancing master
  • B. Cluster member
  • C. Active-passive master
  • D. Standalone master

Answer: B

 

NEW QUESTION 13
You are the administrator of a large network that includes a large local user datadabase on the current Fortiauthenticatior. You want to import all the local users into a new Fortiauthenticator device.
Which method should you use to migrate the local users?

  • A. Import users using a CSV file.
  • B. Import users using RADIUS accounting updates.
  • C. Import users fromRADUIS.
  • D. Import the current directory structure.

Answer: A

 

NEW QUESTION 14
You are a Wi-Fi provider and host multiple domains. How do you delegate user accounts, user groups and permissions per domain when theyare authenticating on a single FortiAuthenticator device?

  • A. Create realms
  • B. Create user groups
  • C. Create multiple directory trees on FortiAuthenticator
  • D. Automatically import hosts from each domain as they authenticate

Answer: A

 

NEW QUESTION 15
Which two statements about the EAP-TTLS authentication method are true? (Choose two)

  • A. Uses digital certificates only on the server side
  • B. Requires an EAP server certificate
  • C. Support a port access control (wired) solution only
  • D. Uses mutualauthentication

Answer: A,B

 

NEW QUESTION 16
Which method is the most secure way of delivering FortiToken data once the token has been seeded?

  • A. Automatic token generation using FortiAuthenticator
  • B. Shipment of the seed files on a CD using a tamper-evident envelope
  • C. Using the in-house token provisioning tool
  • D. Online activation of the tokens through the FortiGuard network

Answer: B

 

NEW QUESTION 17
What happens when a certificate is revoked? (Choose two)

  • A. All certificates signed by a revoked CA certificate are automatically revoked
  • B. Revoked certificates cannot be reinstated for any reason
  • C. Revoked certificates are automatically added to the CRL
  • D. External CAs will priodically query Fortiauthenticator and automatically download revoked certificates

Answer: C,D

 

NEW QUESTION 18
Which two statement about the RADIUS service on FortiAuthenticator are true? (Choose two)

  • A. FortiAuthenticator answers only to RADIUS client that are registered with FortiAuthenticator
  • B. Only local users can be authenticated through RADIUS
  • C. Two-factor authentication cannot be enforced when using RADIUS authentication
  • D. RADIUS users can migrated to LDAP users

Answer: A,D

 

NEW QUESTION 19
Which statement about the guest portal policies is true?

  • A. Guest portal policies apply only to authentication requests coming from unknown RADIUS clients
  • B. All conditions in the policy must match before a user is presented with the guest portal
  • C. Conditions in the policy apply only to guest wireless users
  • D. Guest portal policies can be used only for BYODs

Answer: B

 

NEW QUESTION 20
Which network configuration is required when deploying FortiAuthenticator for portal services?

  • A. Fortigate must be setup as default gateway for FortiAuthenticator
  • B. One of the DNS servers must be a FortiGuard DNS server
  • C. Policies must have specific ports open between FortiAuthenticator and the authentication clients
  • D. FortiAuthenticator must have the REST API access enable on port1

Answer: C

 

NEW QUESTION 21
At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator?
(Choose two)

  • A. Configuring at least on post-login service
  • B. Configuring a portal policy
  • C. Configuring an external authentication portal
  • D. Configuring a RADIUS client

Answer: A,B

 

NEW QUESTION 22
......

Valid NSE6_FAC-6.1 Exam Dumps Ensure you a HIGH SCORE: https://exams4sure.briandumpsprep.com/NSE6_FAC-6.1-prep-exam-braindumps.html