2024年更新のFCP in Network Securityが有効なNSE6_FNC-7.2問題集を無料提供しています
最新のGoShiken NSE6_FNC-7.2のPDF問題集をダウンロードしちゃおう:https://www.goshiken.com/Fortinet/NSE6_FNC-7.2-mondaishu.html(60問題と解答)
Fortinet NSE6_FNC-7.2 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
質問 # 25
Two FortiNAC devices have been configured in an HA configuration. After five failed heartbeats between the primary device and secondary device, the primary device fail to ping the designated gateway. What happens next?
- A. The primary device changes its designation to secondary, and the secondary device changes to primary.
- B. The primary device waits 3 minutes and attempts to re-establish the HA heartbeat before attempting a second ping of the gateway.
- C. The primary device shuts down NAC processes and changes to a management down status.
- D. The primary device continues to operate as the in-control device and changes the status or secondary device to contact lost.
正解:C
質問 # 26
During an evaluation of state-based enforcement, an administrator discovers that ports that should not be under enforcement have been added to enforcement groups. In which view would the administrator be able to determine who added the ports to the groups?
- A. The Event Management view
- B. The Security Events view
- C. The Alarms view
- D. The Admin Auditing view
正解:D
質問 # 27
When you create a user or host profile, which three criteria can you use? (Choose three.)
- A. Location
- B. Host or user attributes
- C. An applied access policy
- D. Host or user group memberships
- E. Administrative group membership
正解:A、C、E
質問 # 28
How are logical networks assigned to endpoints?
- A. Through network access policies
- B. Through device profiling rules
- C. Through FortiGate IPv4 policies
- D. Through Layer 3 polling configurations
正解:A
質問 # 29
Which command line shell and scripting language does FortiNAC use for WinRM?
- A. Bash
- B. Linux
- C. DOS
- D. Powershell
正解:D
解説:
Open Windows PowerShell or a command prompt. Run the following command to determine if you already have WinRM over HTTPS configured.
質問 # 30
When FortiNAC is managing FortiGate VPN users, why is an endpoint compliance policy necessary?
- A. To confirm installed security software
- B. To validate the VPN user credentials
- C. To validate the VPN client being used
- D. To designate the required agent type
正解:A
質問 # 31
Refer to the exhibit, and then answer the question below.
Which host is rogue?
- A. 0
- B. 1
- C. 2
- D. 3
正解:C
質問 # 32
Which two device classification options can register a device automatically and transparently to the end user?
(Choose two.)
- A. Captive portal
- B. DotlxAuto Registration
- C. MDM integration
- D. Device importing
- E. Dissolvable agent
正解:B、C
解説:
The FortiNAC 7.2 Study Guide does not explicitly mention Dot1x Auto Registration and MDM integration as the specific device classification options for automatic and transparent registration to the end user. However, based on the general functioning of FortiNAC, Dot1x Auto Registration and MDM integration are typically used for such purposes. The guide discusses automatic device registration in the context of profiling rules
質問 # 33
Which agent can receive and display messages from FortiNAC to the end user?
- A. Dissolvable
- B. Persistent
- C. Passive
- D. MDM
正解:B
解説:
The persistent agent has the ability to display messages on the desktop of an endpoint. These messages can target an individual host, a group of hosts, or all hosts with the persistent agent installed. The messaging options include sending a message content with an optional web address link
質問 # 34
Which devices would be evaluated by device profiling rules?
- A. All hosts, each time they connect
- B. Rogue devices, only when they are initially added to the database
- C. Known trusted devices, each time they change location
- D. Rogue devices, each time they connect
正解:A
解説:
Device profiling rules in FortiNAC are used to evaluate and classify rogue devices. These rules can be configured to automatically, manually, or through sponsorship evaluate and classify unknown untrusted devices as they are identified and created.
References
* FortiNAC 7.2 Study Guide, page 98
質問 # 35
Which system group will force at-risk hosts into the quarantine network, based on point of connection?
- A. Physical Address Filtering
- B. Forced Quarantine
- C. Forced Isolation
- D. Forced Remediation
正解:C
質問 # 36
Which agent is used only as part of a login script?
- A. Dissolvable
- B. Persistent
- C. Mobile
- D. Passive
正解:B
質問 # 37
Refer to the exhibit.
If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what occurs?
- A. No VLAN change is performed.
- B. The host is moved to a default isolation VLAN.
- C. The host is moved to VLAN 111.
- D. The host is disabled.
正解:C
解説:
The exhibit shows a configuration panel where VLAN IDs are specified for different states, such as Default, Registration, and Authentication. When forcing the registration of unknown (rogue) hosts, if an unknown host connects to a port on the switch, the FortiNAC system will move the host to the VLAN designated for Registration. In the exhibit, the VLAN ID for Registration is set to 111, hence the host would be moved to VLAN 111 to undergo the registration process.
質問 # 38
Which three communication methods are used by FortiNAC to gather information from and control, infrastructure devices? (Choose three.)
- A. RADIUS
- B. CLI
- C. FTP
- D. SNMP
- E. SMTP
正解:A、B、D
解説:
FortiNAC Study Guide 7.2 | Page 11
質問 # 39
When FortiNAC passes a firewall tag to FortiGate, what determines the value that is passed?
- A. RADIUS group attribute
- B. Security rule
- C. Logical network
- D. Device profiling rule
正解:D
質問 # 40
Where do you look to determine when and why the FortiNAC made an automated network access change?
- A. The Admin Auditing view
- B. The Connections view
- C. The Event view
- D. The Port Changes view
正解:D
解説:
Reference:
Study Guide p. 356: Any time FortiNAC changes network access for an endpoint, the change is documented on the Port Changes view. This provides an administrator with valuable information when validating control configurations and enforcement.
質問 # 41
What would occur if both an unknown (rogue) device and a known (trusted) device simultaneously appeared on a port that is a member of the Forced Registration port group?
- A. The port would be administratively shut down.
- B. The port would not be managed, and an event would be generated.
- C. The port would be provisioned to the registration network, and both hosts would be isolated.
- D. The port would be provisioned for the normal state host, and both hosts would have access to that VLAN.
正解:D
質問 # 42
In a wireless integration, what method does FortiNAC use to obtain connecting MAC address information?
- A. SNMP traps
- B. Endstation traffic monitoring
- C. RADIUS
正解:C
解説:
D Link traps
質問 # 43
An administrator wants the Host At Risk event to generate an alarm. What is used to achieve this result?
- A. A security trigger activity
- B. An event to alarm mapping
- C. A security filter
- D. An event to action mapping
正解:B
質問 # 44
Which connecting endpoints are evaluated against all enabled device profiling rules?
- A. Rogues devices, only when they connect for the first time
- B. Rogues devices, each time they connect
- C. Known trusted devices each time they change location
- D. All hosts, each time they connect
正解:B
解説:
FortiNAC process to classify rogue devices and create an organized inventory of known trusted registered devices.
質問 # 45
In an isolation VLAN. which three services does FortiNAC supply? (Choose three.)
- A. Web
- B. DNTP
- C. DDNS
- D. IDHCP
- E. SMTP
正解:A、B、C
質問 # 46
......
実験された試験材料はNSE6_FNC-7.2:https://www.goshiken.com/Fortinet/NSE6_FNC-7.2-mondaishu.html
最新NSE6_FNC-7.2リアル試験問題をフォローせよ!:https://drive.google.com/open?id=1KTRn-6DSO60DaEF09S_Us9l4hjMWBQyB