Latest [Aug 03, 2022] NSE6_FNC-8.5 Exam with Accurate Fortinet NSE 6 - FortiNAC 8.5 PDF Questions [Q17-Q33]

Share

Latest [Aug 03, 2022] NSE6_FNC-8.5 Exam with Accurate Fortinet NSE 6 - FortiNAC 8.5 PDF Questions

Take a Leap Forward in Your Career by Earning Fortinet 30 Questions


What is the cost of Network Security Specialist Fortinet NSE6_FNC-8.5 Professional Exam

  • Number of Questions: 30
  • Passing score: 72%
  • Product version: FortiNAC 8.5

 

NEW QUESTION 17
Which two methods can be used to gather a list of installed applications and application details from a host?
(Choose two)

  • A. Portal page on-boarding options
  • B. MDM integration
  • C. Agent technology
  • D. Application layer traffic inspection

Answer: A,B

 

NEW QUESTION 18
Refer to the exhibit.

If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what will occur?

  • A. The host is moved to VLAN 111.
  • B. The host is disabled.
  • C. The host is moved to a default isolation VLAN.
  • D. No VLAN change is performed

Answer: B

Explanation:
The ability to limit the number of workstations that can connect to specific ports on the switch is managed with Port Security. If these limits are breached, or access from unknown workstations is attempted, the port can do any or all of the following: drop the untrusted data, notify the network administrator, or disable the port.

 

NEW QUESTION 19
What causes a host's state to change to "at risk"?

  • A. The logged on user is not found in the Active Directory.
  • B. The host is not in the Registered Hosts group.
  • C. The host has been administratively disabled.
  • D. The host has failed an endpoint compliance policy or admin scan.

Answer: A

 

NEW QUESTION 20
Which command line shell and scripting language does FortiNAC use for WinRM?

  • A. DOS
  • B. Powershell
  • C. Bash
  • D. Linux

Answer: B

Explanation:
Open Windows PowerShell or a command prompt. Run the following command to determine if you already have WinRM over HTTPS configured.

 

NEW QUESTION 21
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?

  • A. The host is administratively disabled.
  • B. The host is provisioned based on the default access defined by the point of connection.
  • C. The host is provisioned based on the network access policy.
  • D. The host is isolated.

Answer: C

 

NEW QUESTION 22
Which agent is used only as part of a login script?

  • A. Dissolvable
  • B. Passive
  • C. Mobile
  • D. Persistent

Answer: D

Explanation:
If the logon script runs the logon application in persistent mode, configure your Active Directory server not to run scripts synchronously.
Reference: https://www.websense.com/content/support/library/deployctr/v76/ init_setup_creating_and_running_logon_agent_script_deployment_tasks.aspx

 

NEW QUESTION 23
Which three of the following are components of a security rule? (Choose three.)

  • A. Security String
  • B. Action
  • C. Methods
  • D. User or host profile
  • E. Trigger

Answer: A,C,D

 

NEW QUESTION 24
In which view would you find who made modifications to a Group?

  • A. The Security Events view
  • B. The Admin Auditing view
  • C. The Alarms view
  • D. The Event Management view

Answer: A

 

NEW QUESTION 25
Where do you look to determine what network access policy, if any, is being applied to a particular host?

  • A. The Port Properties view of the hosts port
  • B. The network access policy configuration
  • C. The Policy Details view for the host
  • D. The Policy Logs view

Answer: D

 

NEW QUESTION 26
What causes a host's state to change to "at risk"?

  • A. The host is not in the Registered Hosts group.
  • B. The host has failed an endpoint compliance policy or admin scan.
  • C. The host has been administratively disabled.
  • D. The logged on user is not found in the Active Directory.

Answer: B

Explanation:
Failure - Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.

 

NEW QUESTION 27
Which two of the following are required for endpoint compliance monitors? (Choose two.)

  • A. Logged on user
  • B. Persistent agent
  • C. Security rule
  • D. Custom scan

Answer: B,D

Explanation:
DirectDefense's analysis of FireEye Endpoint attests that the products help meet the HIPAA Security Rule.
In the menu on the left click the + sign next to Endpoint Compliance to open it.
Reference:
https://docs.fortinet.com/document/fortinac/8.5.2/administration-guide/92047/add-or-modify-a-scan

 

NEW QUESTION 28
During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)

  • A. There is another unregistered host on the same port.
  • B. The wrong agent is installed.
  • C. The ports default VLAN is the same as the Registration VLAN.
  • D. Bridging is enabled on the host

Answer: A,B

Explanation:
Scenario 4: NAT detection disabled, using endpoint compliance policy and agent.

 

NEW QUESTION 29
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?

  • A. The port is switched into the Dead-End VLAN.
  • B. The port is disabled.
  • C. The port becomes a threshold uplink.
  • D. The port is added to the Forced Registration group.

Answer: B

 

NEW QUESTION 30
Refer to the exhibit, and then answer the question below.

Which host is rogue?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

Explanation:
Explanation
Explanation/Reference: https://docs.fortinet.com/document/fortinac/8.6.0/administration-guide/283146/evaluating- rogue-hosts

 

NEW QUESTION 31
When you create a user or host profile, which three criteria can you use? (Choose three.)

  • A. An applied access policy
  • B. Host or user attributes
  • C. Host or user group memberships
  • D. Location
  • E. Administrative group membership

Answer: A,B,D

 

NEW QUESTION 32
During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)

  • A. There is another unregistered host on the same port.
  • B. The wrong agent is installed.
  • C. Bridging is enabled on the host
  • D. The ports default VLAN is the same as the Registration VLAN.

Answer: B,D

Explanation:
Explanation
Scenario 4: NAT detection disabled, using endpoint compliance policy and agent.

 

NEW QUESTION 33
......


For more info about Network Security Specialist Fortinet NSE6_FNC-8.5 Professional Exam

Network Security Specialist Fortinet NSE6_FNC-8.5 Professional Exam

 

Authentic Best resources for NSE6_FNC-8.5 Online Practice Exam: https://examschief.vce4plus.com/Fortinet/NSE6_FNC-8.5-valid-vce-dumps.html