[2024年11月30日] NSE6_FNC-7.2テストエンジンお試しセット、NSE6_FNC-7.2問題集PDF [Q18-Q36]

Share

[2024年11月30日] NSE6_FNC-7.2テストエンジンお試しセット、NSE6_FNC-7.2問題集PDF

最新のFortinet NSE6_FNC-7.2のPDFと問題集で(2024)無料試験問題解答


Fortinet NSE6_FNC-7.2 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • セキュリティ デバイスの統合と自動応答: 試験のこのセクションでは、さまざまなセキュリティ デバイスで FortiNAC を使用する方法と、インシデント対応を自動化する方法について説明します。
トピック 2
  • FortiGate VPN、高可用性、および FortiNAC Control Manager の統合: 試験のこのセクションでは、VPN アクセスの管理に重点が置かれています。また、メイン管理システムとの FortiNAC の適切な統合を確実にする方法についても説明します。
トピック 3
  • 論理ネットワーク、Fortinet セキュリティ ファブリック、およびファイアウォール タグ: このセクションでは、ネットワーク部分をセグメント化して統合し、FortiGate ファイアウォールと統合する方法などのトピックについて説明します。
トピック 4
  • 可視性、トラブルシューティング、およびログ記録: この試験セクションでは、ネットワーク アクティビティの監視、ネットワークの問題の維持、およびログの管理に重点が置かれます。
トピック 5
  • 不正デバイスの識別と分類: 試験のこのセクションでは、FortiNAC ネットワークで認証されていないデバイスの検出と分類に重点が置かれます。
トピック 6
  • ゲストと請負業者の管理: 試験のこのセクションでは、安全で一時的なネットワーク アクセスの提供について説明します。これには、ゲストだけでなく請負業者にもアクセス権を付与することが含まれます。
トピック 7
  • 概要と初期構成: 試験のこのセクションでは、基本的な操作のための FortiNAC の構成について説明します。
トピック 8
  • 状態ベースの制御: この試験セクションでは、使用されているデバイスの状態に基づいてネットワークへのアクセスを制御することに重点が置かれます。
トピック 9
  • セキュリティ ポリシー: このセクションでは、ネットワーク アクセスとデバイスの制御を改善するために使用されるルールに関連するポリシーについて説明します。

 

質問 # 18
Which two device classification options can register a device automatically and transparently to the end user?
(Choose two.)

  • A. Captive portal
  • B. Dissolvable agent
  • C. DotlxAuto Registration
  • D. MDM integration
  • E. Device importing

正解:C、D

解説:
The FortiNAC 7.2 Study Guide does not explicitly mention Dot1x Auto Registration and MDM integration as the specific device classification options for automatic and transparent registration to the end user. However, based on the general functioning of FortiNAC, Dot1x Auto Registration and MDM integration are typically used for such purposes. The guide discusses automatic device registration in the context of profiling rules


質問 # 19
An administrator is configuring FortiNAC to manage FortiGate VPN users. As part of the configuration, the administrator must configure a few FortiGate firewall policies.
What is the purpose of the FortiGate firewall policy that applies to unauthorized VPN clients?

  • A. To deny access to only the production DNS server
  • B. To allow access to only the production DNS server
  • C. To deny access to only the FortiNAC VPN interface
  • D. To allow access to only the FortiNAC VPN interface

正解:D


質問 # 20
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?

  • A. The host is provisioned based on the network access policy.
  • B. The host is provisioned based on the default access defined by the point of connection.
  • C. The host is isolated.
  • D. The host is administratively disabled.

正解:D


質問 # 21
In which view would you find who made modifications to a Group?

  • A. The Event Management view
  • B. The Alarms view
  • C. The Security Events view
  • D. The Admin Auditing view

正解:C


質問 # 22
Which connecting endpoints are evaluated against all enabled device profiling rules?

  • A. Rogues devices, only when they connect for the first time
  • B. Rogues devices, each time they connect
  • C. Known trusted devices each time they change location
  • D. All hosts, each time they connect

正解:B

解説:
FortiNAC process to classify rogue devices and create an organized inventory of known trusted registered devices.


質問 # 23
View the command and output shown in the exhibit.

What is the current state of this host?

  • A. Not authenticated
  • B. Rogue
  • C. At-Risk
  • D. Registered

正解:A


質問 # 24
Where do you look to determine which network access policy, if any is being applied to a particular host?

  • A. The Policy Logs view
  • B. The Connections view
  • C. The Policy Details view for the host
  • D. The Port Properties view of the hosts port

正解:C

解説:
To determine which network access policy is applied to a particular host, you should look at the Policy Details window. This window provides information about the types of policies applied (such as Network Access, Authentication, Supplicant, etc.), including the profile name, policy name, configuration name, and any settings that make up the configuration.
FortiNAC p 382: "Under Network Access Settings - Policy Name - Name of the Network Access Policy that currently applies to the host."


質問 # 25
What capability do logical networks provide?

  • A. Application of different access values from a single access policy
  • B. Interactive topology view diagrams
  • C. VLAN-based inventory reporting
  • D. Autopopulation of device groups based on point of connection

正解:A

解説:
Explanation:


質問 # 26
An administrator wants the Host At Risk event to generate an alarm. What is used to achieve this result?

  • A. An event to alarm mapping
  • B. A security trigger activity
  • C. A security filter
  • D. An event to action mapping

正解:A

解説:
To generate an alarm from a Host At Risk event, an administrative user must create an Event to Alarm Mapping for the Vulnerability Scan Failed event. Within this alarm mapping, a host security action must be designated to mark the host at risk


質問 # 27
Which command line shell and scripting language does FortiNAC use for WinRM?

  • A. Linux
  • B. Powershell
  • C. Bash
  • D. DOS

正解:B

解説:
Open Windows PowerShell or a command prompt. Run the following command to determine if you already have WinRM over HTTPS configured.


質問 # 28
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)

  • A. Linkup and Linkdown traps
  • B. A matched security policy
  • C. Scheduled poll timings
  • D. A failed Layer 3 poll
  • E. Manual polling

正解:A、C、E

解説:
A: Manual Polling: This is when an administrator or network operator initiates a poll manually to gather information or check the status of the network devices. This can be done for immediate troubleshooting or assessment.
B: Scheduled Poll Timings: Network management systems often have the capability to schedule regular polls of devices to check their status or monitor their performance. These scheduled polls can be set at regular intervals (such as every few minutes, hours, or daily) depending on the requirements of the network.
E: Linkup and Linkdown Traps: SNMP (Simple Network Management Protocol) traps, like Linkup and Linkdown, are automated notifications sent from network devices to a management system. A Linkup trap indicates that a particular interface has become active (up), while a Linkdown trap indicates that an interface has become inactive (down). These traps can trigger Layer 2 polling to ascertain the current status of network interfaces and devices.


質問 # 29
Which agent can receive and display messages from FortiNAC to the end user?

  • A. Persistent
  • B. Dissolvable
  • C. Passive
  • D. MDM

正解:A

解説:
The persistent agent has the ability to display messages on the desktop of an endpoint. These messages can target an individual host, a group of hosts, or all hosts with the persistent agent installed. The messaging options include sending a message content with an optional web address link


質問 # 30
Which agent can receive and display messages from FortiNAC to the end user?

  • A. Persistent
  • B. Dissolvable
  • C. Passive
  • D. MDM

正解:A


質問 # 31
Refer to the exhibit.

What would happen if the highlighted port with connected hosts was placed in both the Forced Registration and Forced Remediation port groups?

  • A. Multiple enforcement groups could not contain the same port.
  • B. Enforcement would be applied only to rogue hosts.
  • C. Both types of enforcement would be applied.
  • D. Only the higher ranked enforcement group would be applied.

正解:D

解説:
In systems like FortiNAC, when a port is designated to be in multiple enforcement groups, it is common for only the higher-priority or higher-ranked group's policies to be applied. This is to prevent conflicting enforcement actions from being attempted on the same port. Although the specific details of the priority or ranking system are not provided in the extracted references, the principle of hierarchical policy enforcement suggests that only the policies of the higher-ranked group would be applied to the port.
References
* FortiNAC documentation would typically outline this behavior in sections discussing port group enforcement or policy application.


質問 # 32
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?

  • A. The port is disabled.
  • B. The port is switched into the Dead-End VLAN.
  • C. The port becomes a threshold uplink.
  • D. The port is added to the Forced Registration group.

正解:B


質問 # 33
Which two of the following are required for endpoint compliance monitors? (Choose two.)

  • A. Logged on user
  • B. Security rule
  • C. Persistent agent
  • D. Custom scan

正解:C、D

解説:
DirectDefense's analysis of FireEye Endpoint attests that the products help meet the HIPAA Security Rule.
In the menu on the left click the + sign next to Endpoint Compliance to open it.
Reference:
https://docs.fortinet.com/document/fortinac/8.5.2/administration-guide/92047/add-or-modify-a-scan


質問 # 34
What agent is required in order to detect an added USB drive?

  • A. Mobile
  • B. Persistent
  • C. Dissolvable
  • D. Passive

正解:B

解説:
Expand the Persistent Agent folder. Select USB Detection from the tree.
Reference:
1. Click System > Settings.
2. Expand the Persistent Agent folder.
3. Select USB Detection from the tree.
4. Click Add or select an existing USB drive and click Modify.


質問 # 35
During an evaluation of state-based enforcement, an administrator discovers that ports that should not be under enforcement have been added to enforcement groups. In which view would the administrator be able to determine who added the ports to the groups?

  • A. The Event Management view
  • B. The Alarms view
  • C. The Admin Auditing view
  • D. The Security Events view

正解:C


質問 # 36
......

あなたを合格させるFCP in Network Security NSE6_FNC-7.2試験問題集で2024年11月30日には60問あります:https://www.goshiken.com/Fortinet/NSE6_FNC-7.2-mondaishu.html

NSE6_FNC-7.2無料試験学習ガイド!(更新された60問あります):https://drive.google.com/open?id=1v8umv9NeB1stfbflr6oIDaFfHzACdldq