Ultimate Guide to Prepare NSE6_FNC-7.2 Certification Exam for FCP in Network Security in 2024
Use Real NSE6_FNC-7.2 Dumps - Fortinet Correct Answers updated on 2024
Fortinet NSE6_FNC-7.2 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
NEW QUESTION # 13
What agent is required in order to detect an added USB drive?
- A. Persistent
- B. Mobile
- C. Dissolvable
- D. Passive
Answer: A
NEW QUESTION # 14
Where are logical network values defined?
- A. In the port properties view of each port
- B. In the security and access field of each host record
- C. On the profiled devices view
- D. In the model configuration view of each infrastructure device
Answer: D
NEW QUESTION # 15
What would occur if both an unknown (rogue) device and a known (trusted) device simultaneously appeared on a port that is a member of the Forced Registration port group?
- A. The port would not be managed, and an event would be generated.
- B. The port would be administratively shut down.
- C. The port would be provisioned for the normal state host, and both hosts would have access to that VLAN.
- D. The port would be provisioned to the registration network, and both hosts would be isolated.
Answer: D
NEW QUESTION # 16
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?
- A. The port is added to the Forced Registration group.
- B. The port is disabled.
- C. The port becomes a threshold uplink.
- D. The port is switched into the Dead-End VLAN.
Answer: D
NEW QUESTION # 17
Refer to the exhibit.
If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what will occur?
- A. The host is moved to a default isolation VLAN.
- B. No VLAN change is performed
- C. The host is disabled.
- D. The host is moved to VLAN 111.
Answer: B
NEW QUESTION # 18
Where are logical network values defined?
- A. On the profiled devices view
- B. In the port properties view of each port
- C. In the security and access field of each host record
- D. In the model configuration view of each infrastructure device
Answer: A
NEW QUESTION # 19
Which two policy types can be created on a FortiNAC Control Manager? (Choose two.)
- A. Authentication
- B. Endpoint Compliance
- C. Supplicant EasvConnect
- D. Network Access
Answer: B,D
NEW QUESTION # 20
An administrator is configuring FortiNAC to manage FortiGate VPN users. As part of the configuration, the administrator must configure a few FortiGate firewall policies.
What is the purpose of the FortiGate firewall policy that applies to unauthorized VPN clients?
- A. To deny access to only the FortiNAC VPN interface
- B. To allow access to only the FortiNAC VPN interface
- C. To allow access to only the production DNS server
- D. To deny access to only the production DNS server
Answer: B
NEW QUESTION # 21
What causes a host's state to change to "at risk"?
- A. The host has been administratively disabled.
- B. The host is not in the Registered Hosts group.
- C. The logged on user is not found in the Active Directory.
- D. The host has failed an endpoint compliance policy or admin scan.
Answer: C
NEW QUESTION # 22
Which three are components of a security rule? (Choose three.)
- A. User or host profile
- B. Security String
- C. Trigger
- D. Action
- E. Methods
Answer: A,C,D
NEW QUESTION # 23
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)
- A. Linkup and Linkdown traps
- B. A failed Layer 3 poll
- C. Manual polling
- D. A matched security policy
- E. Scheduled poll timings
Answer: A,C,E
NEW QUESTION # 24
In a wireless integration, how does FortiNAC obtain connecting MAC address information?
- A. MAC notification traps
- B. Link traps
- C. End station traffic monitoring
- D. RADIUS
Answer: A
NEW QUESTION # 25
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?
- A. The host is provisioned based on the default access defined by the point of connection.
- B. The host is isolated.
- C. The host is administratively disabled.
- D. The host is provisioned based on the network access policy.
Answer: B
Explanation:
https://training.fortinet.com/pluginfile.php/1912463/mod_resource/content/26/FortiNAC_7.2_Study_Guide-Online.pdf C. Page 327 - moved to the quarantine isolation network
NEW QUESTION # 26
Refer to the exhibit, and then answer the question below.
Which host is rogue?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION # 27
How are logical networks assigned to endpoints?
- A. Through FortiGate IPv4 policies
- B. Through network access policies
- C. Through Layer 3 polling configurations
- D. Through device profiling rules
Answer: A
NEW QUESTION # 28
View the command and output shown in the exhibit.
What is the current state of this host?
- A. At-Risk
- B. Registered
- C. Rogue
- D. Not authenticated
Answer: D
NEW QUESTION # 29
What agent is required in order to detect an added USB drive?
- A. Persistent
- B. Mobile
- C. Dissolvable
- D. Passive
Answer: A
Explanation:
Expand the Persistent Agent folder. Select USB Detection from the tree.
Reference:
1. Click System > Settings.
2. Expand the Persistent Agent folder.
3. Select USB Detection from the tree.
4. Click Add or select an existing USB drive and click Modify.
NEW QUESTION # 30
An administrator wants the Host At Risk event to generate an alarm. What is used to achieve this result?
- A. A security filter
- B. An event to action mapping
- C. An event to alarm mapping
- D. A security trigger activity
Answer: C
NEW QUESTION # 31
Which command line shell and scripting language does FortiNAC use for WinRM?
- A. DOS
- B. Linux
- C. Bash
- D. Powershell
Answer: D
Explanation:
Open Windows PowerShell or a command prompt. Run the following command to determine if you already have WinRM over HTTPS configured.
Reference:
Admin Guide on p. 362, "Matches if the device successfully responds to a WinRM client session request. User name and password credentials are required. If there are multiple credentials, each set of credentials will be attempted to find a potential match. The commands are used to automate interaction with the device. Each command is run via Powershell."
NEW QUESTION # 32
What causes a host's state to change to "at risk"?
- A. The host has been administratively disabled.
- B. The host is not in the Registered Hosts group.
- C. The logged on user is not found in the Active Directory.
- D. The host has failed an endpoint compliance policy or admin scan.
Answer: D
Explanation:
Failure - Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.
Reference:
p. 244 of the Study Guide, "A state of at-risk indicates the host has failed a scan. This could be a compliance scan or an administrative scan."
NEW QUESTION # 33
Which agent is used only as part of a login script?
- A. Persistent
- B. Mobile
- C. Dissolvable
- D. Passive
Answer: A
NEW QUESTION # 34
When FortiNAC passes a firewall tag to FortiGate, what determines the value that is passed?
- A. Security rule
- B. Logical network
- C. RADIUS group attribute
- D. Device profiling rule
Answer: B
NEW QUESTION # 35
......
FCP in Network Security -NSE6_FNC-7.2 Exam-Practice-Dumps: https://www.itpassleader.com/Fortinet/NSE6_FNC-7.2-dumps-pass-exam.html
NSE6_FNC-7.2 Premium Files Test pdf - Free Dumps Collection: https://drive.google.com/open?id=1FdpTr-6Hl19TH0SqcI_RPDLYWh4VufAB