リアルNSE6_FNC-7.2問題集でFortinet正確な解答2025年最新版を試そう
FCP in Network Security NSE6_FNC-7.2試験練習問題集
Fortinet NSE6_FNC-7.2 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
質問 # 19
What causes a host's state to change to "at risk"?
- A. The host has failed an endpoint compliance policy or admin scan.
- B. The logged on user is not found in the Active Directory.
- C. The host has been administratively disabled.
- D. The host is not in the Registered Hosts group.
正解:A
解説:
Failure - Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.
Reference:
p. 244 of the Study Guide, "A state of at-risk indicates the host has failed a scan. This could be a compliance scan or an administrative scan."
質問 # 20
What would happen if a port was placed in both the Forced Registration and the Forced Remediation port groups?
- A. Only rogue hosts would be impacted.
- B. Both enforcement groups cannot contain the same port.
- C. Both types of enforcement would be applied.
- D. Only al-risk hosts would be impacted.
正解:B
質問 # 21
Which group type can have members added directly from the FortiNAC Control Manager?
- A. Host
- B. Device
- C. Administrator
- D. Port
正解:B
解説:
The study guide explains that there are six different types of groups in FortiNAC, including device, host, IP phone, port, user, and administrator groups. Groups created by administrative users or imported as a result of an LDAP integration can be used to organize elements but do not enforce any type of control or functionality directly
質問 # 22
When FortiNAC is managing FortiGate VPN users, why is an endpoint compliance policy necessary?
- A. To confirm installed security software
- B. To designate the required agent type
- C. To validate the VPN user credentials
- D. To validate the VPN client being used
正解:A
質問 # 23
Which agent is used only as part of a login script?
- A. Persistent
- B. Passive
- C. Mobile
- D. Dissolvable
正解:B
解説:
In the context of network access control systems like FortiNAC, a dissolvable agent is typically a piece of software that is executed on the endpoint as part of a login script or when a user accesses a captive portal. It runs once to gather information or enforce policies and then removes itself from the system, hence the term
"dissolvable."
References
* FortiNAC documentation on agent deployment and types of agents.
質問 # 24
Refer to the exhibit.
What would happen if the highlighted port with connected hosts was placed in both the Forced Registration and Forced Remediation port groups?
- A. Only the higher ranked enforcement group would be applied.
- B. Multiple enforcement groups could not contain the same port.
- C. Both types of enforcement would be applied.
- D. Enforcement would be applied only to rogue hosts.
正解:A
解説:
In systems like FortiNAC, when a port is designated to be in multiple enforcement groups, it is common for only the higher-priority or higher-ranked group's policies to be applied. This is to prevent conflicting enforcement actions from being attempted on the same port. Although the specific details of the priority or ranking system are not provided in the extracted references, the principle of hierarchical policy enforcement suggests that only the policies of the higher-ranked group would be applied to the port.
References
* FortiNAC documentation would typically outline this behavior in sections discussing port group enforcement or policy application.
質問 # 25
Refer to the exhibit.
If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what occurs?
- A. The host is moved to VLAN 111.
- B. The host is disabled.
- C. The host is moved to a default isolation VLAN.
- D. No VLAN change is performed.
正解:C
質問 # 26
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)
- A. Scheduled poll timings
- B. A matched security policy
- C. A failed Layer 3 poll
- D. Manual polling
- E. Linkup and Linkdown traps
正解:A、D、E
解説:
A: Manual Polling: This is when an administrator or network operator initiates a poll manually to gather information or check the status of the network devices. This can be done for immediate troubleshooting or assessment.
B: Scheduled Poll Timings: Network management systems often have the capability to schedule regular polls of devices to check their status or monitor their performance. These scheduled polls can be set at regular intervals (such as every few minutes, hours, or daily) depending on the requirements of the network.
E: Linkup and Linkdown Traps: SNMP (Simple Network Management Protocol) traps, like Linkup and Linkdown, are automated notifications sent from network devices to a management system. A Linkup trap indicates that a particular interface has become active (up), while a Linkdown trap indicates that an interface has become inactive (down). These traps can trigger Layer 2 polling to ascertain the current status of network interfaces and devices.
質問 # 27
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?
- A. The host is provisioned based on the default access defined by the point of connection.
- B. The host is provisioned based on the network access policy.
- C. The host is administratively disabled.
- D. The host is isolated.
正解:D
解説:
https://training.fortinet.com/pluginfile.php/1912463/mod_resource/content/26/FortiNAC_7.2_Study_Guide-Online.pdf C. Page 327 - moved to the quarantine isolation network
質問 # 28
What would occur if both an unknown (rogue) device and a known (trusted) device simultaneously appeared on a port that is a member of the Forced Registration port group?
- A. The port would be provisioned for the normal state host, and both hosts would have access to that VLAN.
- B. The port would be administratively shut down.
- C. The port would not be managed, and an event would be generated.
- D. The port would be provisioned to the registration network, and both hosts would be isolated.
正解:D
解説:
When a rogue device connects to a port in the Forced Registration port group, FortiNAC's response is to isolate that device by moving it to a registration captive network. This is part of FortiNAC's state-based control mechanism, where the system acts based on the state of the device (normal, rogue, etc.) and the group or port it is connected to. In this specific scenario, the focus is on the isolation of the rogue device, and the guide does not explicitly detail the simultaneous handling of the normal device.
References: FortiNAC 7.2 Study Guide, State-Based Control section.
質問 # 29
During the on-boarding process through the captive portal, what are two reasons why a host that successfully registered would remain stuck in the Registration VLAN? (Choose two.)
- A. Bridging is enabled on the host.
- B. The wrong agent is installed.
- C. There is another unregistered host on the same port.
- D. The port default VLAN is the same as the Registration VLAN.
正解:C、D
質問 # 30
Which two of the following are required for endpoint compliance monitors? (Choose two.)
- A. Custom scan
- B. Persistent agent
- C. Security rule
- D. Logged on user
正解:A、B
解説:
DirectDefense's analysis of FireEye Endpoint attests that the products help meet the HIPAA Security Rule.
In the menu on the left click the + sign next to Endpoint Compliance to open it.
質問 # 31
Refer to the exhibit.
If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what occurs?
- A. The host is moved to VLAN 111.
- B. The host is disabled.
- C. The host is moved to a default isolation VLAN.
- D. No VLAN change is performed.
正解:A
解説:
The exhibit shows a configuration panel where VLAN IDs are specified for different states, such as Default, Registration, and Authentication. When forcing the registration of unknown (rogue) hosts, if an unknown host connects to a port on the switch, the FortiNAC system will move the host to the VLAN designated for Registration. In the exhibit, the VLAN ID for Registration is set to 111, hence the host would be moved to VLAN 111 to undergo the registration process.
質問 # 32
Which two agents can validate endpoint compliance transparently to the end user? (Choose two.)
- A. Persistent
- B. Mobile
- C. Passive
- D. Dissolvable
正解:A、D
解説:
Both dissolvable and persistent agents can be used to validate endpoint compliance transparently to the end user. The persistent agent stays resident on the endpoint and performs scheduled scans in the background. The dissolvable agent is a run-once agent that dissolves after reporting its results, leaving no footprint on the endpoint
質問 # 33
Which three of the following are components of a security rule? (Choose three.)
- A. Security String
- B. Action
- C. User or host profile
- D. Methods
- E. Trigger
正解:A、C、D
質問 # 34
When FortiNAC is managing VPN clients connecting through FortiGate. why must the clients run a FortiNAC agent?
- A. To transparently update the client IP address upon successful authentication
- B. To collect user authentication details
- C. To collect the client IP address and MAC address
- D. To meet the client security profile rule for scanning connecting clients
正解:D
質問 # 35
In a wireless integration, what method does FortiNAC use to obtain connecting MAC address information?
- A. SNMP traps
- B. RADIUS
- C. Endstation traffic monitoring
D Link traps
正解:B
解説:
In a wireless integration, FortiNAC uses RADIUS to obtain connecting MAC address information. This includes RADIUS requests to FortiNAC and subsequent RADIUS responses from FortiNAC to the requesting device
質問 # 36
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?
- A. The host is provisioned based on the default access defined by the point of connection.
- B. The host is administratively disabled.
- C. The host is provisioned based on the network access policy.
- D. The host is isolated.
正解:B
質問 # 37
......
NSE6_FNC-7.2試験合格を準備するため 今すぐ弊社のFCP in Network Security試験パッケージお試そう:https://www.goshiken.com/Fortinet/NSE6_FNC-7.2-mondaishu.html
NSE6_FNC-7.2プレミアム資料でテストPDF無料問題集お試しセット:https://drive.google.com/open?id=1YtJFCPTkc_NbZod60HnNtLPiU0-JJntr