(2024) NSE6_FNC-7.2 Exam Dumps, Practice Test Questions BUNDLE PACK [Q24-Q41]

Share

(2024) NSE6_FNC-7.2 Exam Dumps, Practice Test Questions BUNDLE PACK

FCP in Network Security Certification NSE6_FNC-7.2 Sample Questions Reliable


Fortinet NSE6_FNC-7.2 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Explain and configure logical networks
  • Explain isolation networks and the configuration wizard
Topic 2
  • Troubleshoot endpoint connectivity and classification
  • Explain access control
Topic 3
  • Explain and configure device profiling
  • Integrate with third-party devices using Syslog and SNMP trap input
Topic 4
  • Network visibility and monitoring
  • Configure and use group and tag information for network devices
Topic 5
  • Use logging options available on FortiNAC
  • Configure FortiGate VPN integration with FortiNAC

 

NEW QUESTION # 24
Which connecting endpoints are evaluated against all enabled device profiling rules?

  • A. Rogues devices, only when they connect for the first time
  • B. Rogues devices, each time they connect
  • C. All hosts, each time they connect
  • D. Known trusted devices each time they change location

Answer: B


NEW QUESTION # 25
Which two methods can be used to gather a list of installed applications and application details from a host? (Choose two.)

  • A. MDM integration
  • B. Agent technology
  • C. Application layer traffic inspection
  • D. Portal page on-boarding options

Answer: A,B


NEW QUESTION # 26
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?

  • A. The host is administratively disabled.
  • B. The host is provisioned based on the network access policy.
  • C. The host is isolated.
  • D. The host is provisioned based on the default access defined by the point of connection.

Answer: A


NEW QUESTION # 27
Which three of the following are components of a security rule? (Choose three.)

  • A. Methods
  • B. Security String
  • C. Action
  • D. Trigger
  • E. User or host profile

Answer: C,D,E


NEW QUESTION # 28
Which agent is used only as part of a login script?

  • A. Passive
  • B. Persistent
  • C. Dissolvable
  • D. Mobile

Answer: A

Explanation:
If the logon script runs the logon application in persistent mode, configure your Active Directory server not to run scripts synchronously.


NEW QUESTION # 29
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?

  • A. The port is added to the Forced Registration group.
  • B. The port is switched into the Dead-End VLAN.
  • C. The port becomes a threshold uplink.
  • D. The port is disabled.

Answer: B


NEW QUESTION # 30
Which agent can receive and display messages from FortiNAC to the end user?

  • A. MDM
  • B. Passive
  • C. Persistent
  • D. Dissolvable

Answer: C


NEW QUESTION # 31
Which two of the following are required for endpoint compliance monitors? (Choose two.)

  • A. Custom scan
  • B. Persistent agent
  • C. Security rule
  • D. Logged on user

Answer: A,C


NEW QUESTION # 32
During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)

  • A. Bridging is enabled on the host
  • B. The ports default VLAN is the same as the Registration VLAN.
  • C. There is another unregistered host on the same port.
  • D. The wrong agent is installed.

Answer: B,D


NEW QUESTION # 33
Which three of the following are components of a security rule? (Choose three.)

  • A. Trigger
  • B. Security String
  • C. Methods
  • D. User or host profile
  • E. Action

Answer: B,C,D


NEW QUESTION # 34
Which two things must be done to allow FortiNAC to process incoming syslog messages from an unknown vendor? (Choose two.)

  • A. The device sending the messages must be modeled in the Network Inventory view.
  • B. The device must be added as a patch management server.
  • C. A security event parser must be created for the device.
  • D. The device must be added as a log receiver.

Answer: C,D


NEW QUESTION # 35
Which two device classification options can register a device automatically and transparently to the end user? (Choose two.)

  • A. MDM integration
  • B. Captive portal
  • C. DotlxAuto Registration
  • D. Device importing
  • E. Dissolvable agent

Answer: A,C


NEW QUESTION # 36
In an isolation VLAN. which three services does FortiNAC supply? (Choose three.)

  • A. DDNS
  • B. SMTP
  • C. IDHCP
  • D. DNTP
  • E. Web

Answer: A,D,E


NEW QUESTION # 37
How should you configure MAC notification traps on a supported switch?

  • A. Configure them on all ports on the switch
  • B. Configure them only on ports set as 802 1q trunks
  • C. Configure them only after you configure linkup and linkdown traps
  • D. Configure them on all ports except uplink ports

Answer: C


NEW QUESTION # 38
How are logical networks assigned to endpoints?

  • A. Through device profiling rules
  • B. Through FortiGate IPv4 policies
  • C. Through network access policies
  • D. Through Layer 3 polling configurations

Answer: C


NEW QUESTION # 39
When FortiNAC passes a firewall tag to FortiGate, what determines the value that is passed?

  • A. RADIUS group attribute
  • B. Logical network
  • C. Security rule
  • D. Device profiling rule

Answer: B


NEW QUESTION # 40
In a wireless integration, what method does FortiNAC use to obtain connecting MAC address information?

  • A. SNMP traps
  • B. RADIUS
  • C. Endstation traffic monitoring

Answer: B

Explanation:
D Link traps


NEW QUESTION # 41
......

Prepare for the Actual FCP in Network Security NSE6_FNC-7.2 Exam Practice Materials Collection: https://troytec.validtorrent.com/NSE6_FNC-7.2-valid-exam-torrent.html