
NSE6_FAC-6.1 Self-Study Guide for Becoming an Fortinet NSE 6 - FortiAuthenticator 6.1 Expert
NSE6_FAC-6.1 Study Guide Realistic Verified NSE6_FAC-6.1 Dumps
NEW QUESTION 10
How can a SAML metada file be used?
- A. To defined a list of trusted user names
- B. To resolve the IDP realm for authentication
- C. To import the required IDP configuration
- D. To correlate the IDP address to its hostname
Answer: C
NEW QUESTION 11
Which of the following is an QATH-based standart to generate event-based, one-time password tokens?
- A. HOTP
- B. SOTP
- C. TOTP
- D. OLTP
Answer: A
NEW QUESTION 12
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the masterFortiAuthenticator?
- A. Load balancing master
- B. Cluster member
- C. Active-passive master
- D. Standalone master
Answer: B
NEW QUESTION 13
You are the administrator of a large network that includes a large local user datadabase on the current Fortiauthenticatior. You want to import all the local users into a new Fortiauthenticator device.
Which method should you use to migrate the local users?
- A. Import users using a CSV file.
- B. Import users using RADIUS accounting updates.
- C. Import users fromRADUIS.
- D. Import the current directory structure.
Answer: A
NEW QUESTION 14
You are a Wi-Fi provider and host multiple domains. How do you delegate user accounts, user groups and permissions per domain when theyare authenticating on a single FortiAuthenticator device?
- A. Create realms
- B. Create user groups
- C. Create multiple directory trees on FortiAuthenticator
- D. Automatically import hosts from each domain as they authenticate
Answer: A
NEW QUESTION 15
Which two statements about the EAP-TTLS authentication method are true? (Choose two)
- A. Uses digital certificates only on the server side
- B. Requires an EAP server certificate
- C. Support a port access control (wired) solution only
- D. Uses mutualauthentication
Answer: A,B
NEW QUESTION 16
Which method is the most secure way of delivering FortiToken data once the token has been seeded?
- A. Automatic token generation using FortiAuthenticator
- B. Shipment of the seed files on a CD using a tamper-evident envelope
- C. Using the in-house token provisioning tool
- D. Online activation of the tokens through the FortiGuard network
Answer: B
NEW QUESTION 17
What happens when a certificate is revoked? (Choose two)
- A. All certificates signed by a revoked CA certificate are automatically revoked
- B. Revoked certificates cannot be reinstated for any reason
- C. Revoked certificates are automatically added to the CRL
- D. External CAs will priodically query Fortiauthenticator and automatically download revoked certificates
Answer: C,D
NEW QUESTION 18
Which two statement about the RADIUS service on FortiAuthenticator are true? (Choose two)
- A. FortiAuthenticator answers only to RADIUS client that are registered with FortiAuthenticator
- B. Only local users can be authenticated through RADIUS
- C. Two-factor authentication cannot be enforced when using RADIUS authentication
- D. RADIUS users can migrated to LDAP users
Answer: A,D
NEW QUESTION 19
Which statement about the guest portal policies is true?
- A. Guest portal policies apply only to authentication requests coming from unknown RADIUS clients
- B. All conditions in the policy must match before a user is presented with the guest portal
- C. Conditions in the policy apply only to guest wireless users
- D. Guest portal policies can be used only for BYODs
Answer: B
NEW QUESTION 20
Which network configuration is required when deploying FortiAuthenticator for portal services?
- A. Fortigate must be setup as default gateway for FortiAuthenticator
- B. One of the DNS servers must be a FortiGuard DNS server
- C. Policies must have specific ports open between FortiAuthenticator and the authentication clients
- D. FortiAuthenticator must have the REST API access enable on port1
Answer: C
NEW QUESTION 21
At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator?
(Choose two)
- A. Configuring at least on post-login service
- B. Configuring a portal policy
- C. Configuring an external authentication portal
- D. Configuring a RADIUS client
Answer: A,B
NEW QUESTION 22
......
Valid NSE6_FAC-6.1 Exam Dumps Ensure you a HIGH SCORE: https://exams4sure.briandumpsprep.com/NSE6_FAC-6.1-prep-exam-braindumps.html
