Pass the Fortinet NSE 6 Network Security Specialist NSE6_FAC-6.4 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which statement about the assignment of permissions for sponsor and administrator accounts is true?

Options:

A.

Only administrator accounts permissions are assigned using admin profiles.


B.

Sponsor permissions are assigned using group settings.


C.

Administrator capabilities are assigned by applying permission sets to admin groups.


D.

Both sponsor and administrator account permissions are assigned using admin profiles.


Expert Solution
Questions # 2:

At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator? (Choose two)

Options:

A.

Configuring a portal policy


B.

Configuring at least on post-login service


C.

Configuring a RADIUS client


D.

Configuring an external authentication portal


Expert Solution
Questions # 3:

Which method is the most secure way of delivering FortiToken data once the token has been seeded?

Options:

A.

Online activation of the tokens through the FortiGuard network


B.

Shipment of the seed files on a CD using a tamper-evident envelope


C.

Using the in-house token provisioning tool


D.

Automatic token generation using FortiAuthenticator


Expert Solution
Questions # 4:

You have implemented two-factor authentication to enhance security to sensitive enterprise systems.

How could you bypass the need for two-factor authentication for users accessing form specific secured networks?

Options:

A.

Create an admin realm in the authentication policy


B.

Specify the appropriate RADIUS clients in the authentication policy


C.

Enable Adaptive Authentication in the portal policy


D.

Enable the Resolve user geolocation from their IP address option in the authentication policy.


Expert Solution
Questions # 5:

Which network configuration is required when deploying FortiAuthenticator for portal services?

Options:

A.

FortiAuthenticator must have the REST API access enable on port1


B.

One of the DNS servers must be a FortiGuard DNS server


C.

Fortigate must be setup as default gateway for FortiAuthenticator


D.

Policies must have specific ports open between FortiAuthenticator and the authentication clients


Expert Solution
Questions # 6:

You are an administrator for a large enterprise and you want to delegate the creation and management of guest users to a group of sponsors.

How would you associate the guest accounts with individual sponsors?

Options:

A.

As an administrator, you can assign guest groups to individual sponsors.


B.

Guest accounts are associated with the sponsor that creates the guest account.


C.

You can automatically add guest accounts to groups associated with specific sponsors.


D.

Select the sponsor on the guest portal, during registration.


Expert Solution
Questions # 7:

What are three key features of FortiAuthenticator? (Choose three)

Options:

A.

Identity management device


B.

Log server


C.

Certificate authority


D.

Portal services


E.

RSSO Server


Expert Solution
Questions # 8:

You want to monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP.

Which two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface? (Choose two)

Options:

A.

Enable logging services


B.

Set the tresholds to trigger SNMP traps


C.

Upload management information base (MIB) files to SNMP server


D.

Associate an ASN, 1 mapping rule to the receiving host


Expert Solution
Questions # 9:

Examine the screenshot shown in the exhibit.

Question # 9

Which two statements regarding the configuration are true? (Choose two.)

Options:

A.

All guest accounts created using the account registration feature will be placed under the Guest_Portal_Users group


B.

All accounts registered through the guest portal must be validated through email


C.

Guest users must fill in all the fields on the registration form


D.

Guest user account will expire after eight hours


Expert Solution
Questions # 10:

Which two SAML roles can Fortiauthenticator be configured as? (Choose two)

Options:

A.

Idendity provider


B.

Principal


C.

Assertion server


D.

Service provider


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions