[Nov 28, 2024] Free FCP in Network Security NSE6_FNC-7.2 Exam Question
NSE6_FNC-7.2 dumps & FCP in Network Security sure practice dumps
NEW QUESTION # 14
Which two agents can validate endpoint compliance transparently to the end user? (Choose two.)
- A. Dissolvable
- B. Persistent
- C. Mobile
- D. Passive
Answer: B,C
NEW QUESTION # 15
Which command line shell and scripting language does FortiNAC use for WinRM?
- A. Linux
- B. Powershell
- C. Bash
- D. DOS
Answer: B
NEW QUESTION # 16
While troubleshooting a network connectivity issue, an administrator determines that a device was being automatically provisioned to an incorrect VLAN.
Where would the administrator look to determine when and why FortiNAC made the network access change?
- A. The Connections view
- B. The Admin Auditing view
- C. The Event view
- D. The Port Changes view
Answer: D
NEW QUESTION # 17
When FortiNAC is managing VPN clients connecting through FortiGate. why must the clients run a FortiNAC agent?
- A. To transparently update the client IP address upon successful authentication
- B. To meet the client security profile rule for scanning connecting clients
- C. To collect user authentication details
- D. To collect the client IP address and MAC address
Answer: B
NEW QUESTION # 18
What would occur if both an unknown (rogue) device and a known (trusted) device simultaneously appeared on a port that is a member of the Forced Registration port group?
- A. The port would not be managed, and an event would be generated.
- B. The port would be administratively shut down.
- C. The port would be provisioned for the normal state host, and both hosts would have access to that VLAN.
- D. The port would be provisioned to the registration network, and both hosts would be isolated.
Answer: C
NEW QUESTION # 19
What agent is required in order to detect an added USB drive?
- A. Dissolvable
- B. Persistent
- C. Passive
- D. Mobile
Answer: B
Explanation:
Expand the Persistent Agent folder. Select USB Detection from the tree.
NEW QUESTION # 20
In which view would you find who made modifications to a Group?
- A. The Admin Auditing view
- B. The Alarms view
- C. The Security Events view
- D. The Event Management view
Answer: A
Explanation:
It's important to audit Group Policy changes in order to determine the details of changes made to Group Policies by delegated users.
NEW QUESTION # 21
Refer to the exhibit.
Considering the host status of the two hosts connected to the same wired port, what will happen if the port is a member of the Forced Registration port group?
- A. The port will not be managed, and an event will be generated.
- B. The port will be provisioned for the normal state host, and both hosts will have access to that VLAN.
- C. The port will be provisioned to the registration network, and both hosts will be isolated.
- D. The port will be administratively shut down.
Answer: C
Explanation:
The exhibit shows the status of two hosts connected to a wired infrastructure and indicates their respective MAC addresses and the rule name associated with them. When a port is a member of the Forced Registration port group, and multiple hosts with different statuses are connected to that port, FortiNAC will provision the port to the registration network, which is designed to isolate hosts until they are verified or registered. This ensures that unregistered or unauthorized hosts do not gain access to the network. Therefore, both hosts will be isolated in the registration network according to FortiNAC policy for such scenarios.
NEW QUESTION # 22
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?
- A. The host is provisioned based on the network access policy.
- B. The host is provisioned based on the default access defined by the point of connection.
- C. The host is administratively disabled.
- D. The host is isolated.
Answer: D
Explanation:
https://training.fortinet.com/pluginfile.php/1912463/mod_resource/content/26/FortiNAC_7.2_Study_Guide-Online.pdf C. Page 327 - moved to the quarantine isolation network
NEW QUESTION # 23
Where do you look to determine when and why the FortiNAC made an automated network access change?
- A. The Connections view
- B. The Admin Auditing view
- C. The Port Changes view
- D. The Event view
Answer: D
NEW QUESTION # 24
Where are logical network values defined?
- A. In the port properties view of each port
- B. On the profiled devices view
- C. In the model configuration view of each infrastructure device
- D. In the security and access field of each host record
Answer: C
Explanation:
In FortiNAC, logical networks are an integral part of device management and network segmentation. These logical networks are defined and appear within the model configuration of each infrastructure device that is modeled in the topology tree. The configuration allows for the assignment of unique names and, optionally, descriptions to each logical network, thereby clarifying their purpose or use within the network infrastructure.
References: FortiNAC 7.2 Study Guide, Logical Networks Security Fabric and Firewall Tags section.
NEW QUESTION # 25
Which agent is used only as part of a login script?
- A. Dissolvable
- B. Persistent
- C. Passive
- D. Mobile
Answer: B
NEW QUESTION # 26
During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)
- A. There is another unregistered host on the same port.
- B. The ports default VLAN is the same as the Registration VLAN.
- C. The wrong agent is installed.
- D. Bridging is enabled on the host
Answer: B,C
NEW QUESTION # 27
Where are logical network values defined?
- A. In the port properties view of each port
- B. On the profiled devices view
- C. In the security and access field of each host record
- D. In the model configuration view of each infrastructure device
Answer: B
NEW QUESTION # 28
Refer to the exhibit, and then answer the question below.
Which host is rogue?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION # 29
View the command and output.
What is the state of database replication?
- A. Secondary to primary synchronization failed.
- B. Secondary to primary synchronization was successful.
- C. Primary to secondary database synchronization was successful.
- D. Primary to secondary synchronization failed.
Answer: C
NEW QUESTION # 30
How does FortiGate update FortiNAC about VPN session information?
- A. Syslog messages
- B. Security Fabric Integration
- C. SNMP traps
- D. API calls to FortiNAC
Answer: A
NEW QUESTION # 31
Which two of the following are required for endpoint compliance monitors? (Choose two.)
- A. Persistent agent
- B. Security rule
- C. Custom scan
- D. Logged on user
Answer: A,C
Explanation:
DirectDefense's analysis of FireEye Endpoint attests that the products help meet the HIPAA Security Rule.
In the menu on the left click the + sign next to Endpoint Compliance to open it.
NEW QUESTION # 32
What method of communication does FortiNAC use to control VPN host access on FortiGate?
- A. RADIUS accounting
- B. SAMLSSO
- C. RSSO
- D. Security Fabric
Answer: D
NEW QUESTION # 33
Which connecting endpoints are evaluated against all enabled device profiling rules?
- A. Rogues devices, each time they connect
- B. Rogues devices, only when they connect for the first time
- C. Known trusted devices each time they change location
- D. All hosts, each time they connect
Answer: A
NEW QUESTION # 34
Refer to the exhibit.
If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what will occur?
- A. No VLAN change is performed
- B. The host is moved to VLAN 111.
- C. The host is moved to a default isolation VLAN.
- D. The host is disabled.
Answer: A
NEW QUESTION # 35
......
Fortinet NSE6_FNC-7.2 Actual Questions and Braindumps: https://www.validdumps.top/NSE6_FNC-7.2-exam-torrent.html
Pass NSE6_FNC-7.2 Exam with Updated NSE6_FNC-7.2 Exam Dumps PDF 2024: https://drive.google.com/open?id=18ZRtz0rxGkVHC_9OH6mHSxt0_NZlagKS