NSE6_FNC-8.5 Braindumps Real Exam Updated on Dec 05, 2021 with 30 Questions [Q11-Q36]

Share

NSE6_FNC-8.5 Braindumps Real Exam Updated on Dec 05, 2021 with 30 Questions

Latest NSE6_FNC-8.5 PDF Dumps & Real Tests Free Updated Today


Exam Topics for Network Security Specialist Fortinet NSE6_FNC-8.5 Professional Exam

The following will be practiced in FORTINET NSE6_FNC-8.5 practice exam and FORTINET NSE6_FNC-8.5 practice tests:

  • Integrated and Cloud Wireless
  • FortiNAC
  • FortiWLC
  • FortiADC
  • FortiAuthenticator
  • FortiVoice
  • FortiWeb

 

NEW QUESTION 11
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?

  • A. The port becomes a threshold uplink.
  • B. The port is added to the Forced Registration group.
  • C. The port is switched into the Dead-End VLAN.
  • D. The port is disabled.

Answer: A

 

NEW QUESTION 12
Where are logical network values defined?

  • A. In the model configuration view of each infrastructure device
  • B. In the security and access field of each host record
  • C. On the profiled devices view
  • D. In the port properties view of each port

Answer: C

 

NEW QUESTION 13
What causes a host's state to change to "at risk"?

  • A. The host has been administratively disabled.
  • B. The logged on user is not found in the Active Directory.
  • C. The host has failed an endpoint compliance policy or admin scan.
  • D. The host is not in the Registered Hosts group.

Answer: C

Explanation:
Explanation
Failure - Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.

 

NEW QUESTION 14
Where do you look to determine what network access policy, if any, is being applied to a particular host?

  • A. The Port Properties view of the hosts port
  • B. The Policy Logs view
  • C. The Policy Details view for the host
  • D. The network access policy configuration

Answer: B

 

NEW QUESTION 15
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)

  • A. Linkup and Linkdown traps
  • B. A failed Layer 3 poll
  • C. Manual polling
  • D. A matched security policy
  • E. Scheduled poll timings

Answer: A,C,E

 

NEW QUESTION 16
Refer to the exhibit, and then answer the question below.

Which host is rogue?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

 

NEW QUESTION 17
How should you configure MAC notification traps on a supported switch?

  • A. Configure them on all ports except uplink ports
  • B. Configure them on all ports on the switch
  • C. Configure them only on ports set as 802 1q trunks
  • D. Configure them only after you configure linkup and linkdown traps

Answer: A

Explanation:
Configure SNMP MAC Notification traps on all access ports (do not include uplinks).

 

NEW QUESTION 18
What capability do logical networks provide?

  • A. Application of different access values from a single access policy
  • B. Interactive topology view diagrams
  • C. VLAN-based inventory reporting
  • D. Autopopulation of device groups based on point of connection

Answer: C

Explanation:
Explanation
NTM also includes reporting utilities such as network and inventory reports. You can generate reports for subnets, switch ports, and VLANs.

 

NEW QUESTION 19
Which command line shell and scripting language does FortiNAC use for WinRM?

  • A. Bash
  • B. DOS
  • C. Linux
  • D. Powershell

Answer: D

Explanation:
Explanation
Open Windows PowerShell or a command prompt. Run the following command to determine if you already have WinRM over HTTPS configured.

 

NEW QUESTION 20
Which agent is used only as part of a login script?

  • A. Persistent
  • B. Mobile
  • C. Passive
  • D. Dissolvable

Answer: A

Explanation:
If the logon script runs the logon application in persistent mode, configure your Active Directory server not to run scripts synchronously.
Reference: https://www.websense.com/content/support/library/deployctr/v76/ init_setup_creating_and_running_logon_agent_script_deployment_tasks.aspx

 

NEW QUESTION 21
Which agent can receive and display messages from FortiNAC to the end user?

  • A. MDM
  • B. Persistent
  • C. Passive
  • D. Dissolvable

Answer: B

 

NEW QUESTION 22
Which system group will force at-risk hosts into the quarantine network, based on point of connection?

  • A. Forced Remediation
  • B. Forced Isolation
  • C. Physical Address Filtering
  • D. Forced Quarantine

Answer: A

Explanation:
Explanation
A remediation plan is established, including a forensic analysis and a reload of the system. Also, users are forced to change their passwords as the system held local user accounts.

 

NEW QUESTION 23
Refer to the exhibit.

If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what will occur?

  • A. The host is disabled.
  • B. The host is moved to VLAN 111.
  • C. The host is moved to a default isolation VLAN.
  • D. No VLAN change is performed

Answer: D

 

NEW QUESTION 24
In an isolation VLAN. which three services does FortiNAC supply? (Choose three.)

  • A. SMTP
  • B. DHCP
  • C. NTP
  • D. DNS
  • E. Web

Answer: B,D,E

 

NEW QUESTION 25
Which command line shell and scripting language does FortiNAC use for WinRM?

  • A. Bash
  • B. DOS
  • C. Linux
  • D. Powershell

Answer: D

Explanation:
Open Windows PowerShell or a command prompt. Run the following command to determine if you already have WinRM over HTTPS configured.
Reference: https://docs.fortinet.com/document/fortinac/8.7.0/administration-guide/246310/winrm-device- profile-requirements-and-setup

 

NEW QUESTION 26
Which two of the following are required for endpoint compliance monitors? (Choose two.)

  • A. Security rule
  • B. Logged on user
  • C. Custom scan
  • D. Persistent agent

Answer: A,C

 

NEW QUESTION 27
How should you configure MAC notification traps on a supported switch?

  • A. Configure them on all ports except uplink ports
  • B. Configure them on all ports on the switch
  • C. Configure them only after you configure linkup and linkdown traps
  • D. Configure them only on ports set as 802 1q trunks

Answer: C

 

NEW QUESTION 28
Where do you look to determine what network access policy, if any, is being applied to a particular host?

  • A. The Port Properties view of the hosts port
  • B. The Policy Details view for the host
  • C. The network access policy configuration
  • D. The Policy Logs view

Answer: C

 

NEW QUESTION 29
In which view would you find who made modifications to a Group?

  • A. The Admin Auditing view
  • B. The Alarms view
  • C. The Security Events view
  • D. The Event Management view

Answer: A

Explanation:
It's important to audit Group Policy changes in order to determine the details of changes made to Group Policies by delegated users.
Reference: https://www.lepide.com/how-to/audit-chnages-made-to-group-policy-objects.html

 

NEW QUESTION 30
What would happen if a port was placed in both the Forced Registration and the Forced Remediation port groups?

  • A. Both types of enforcement would be applied.
  • B. Only rogue hosts would be impacted.
  • C. Only al-risk hosts would be impacted.
  • D. Both enforcement groups cannot contain the same port.

Answer: B

 

NEW QUESTION 31
What causes a host's state to change to "at risk"?

  • A. The host has been administratively disabled.
  • B. The host has failed an endpoint compliance policy or admin scan.
  • C. The logged on user is not found in the Active Directory.
  • D. The host is not in the Registered Hosts group.

Answer: C

 

NEW QUESTION 32
Which agent is used only as part of a login script?

  • A. Persistent
  • B. Mobile
  • C. Passive
  • D. Dissolvable

Answer: A

Explanation:
Explanation
If the logon script runs the logon application in persistent mode, configure your Active Directory server not to run scripts synchronously.

 

NEW QUESTION 33
Which three communication methods are used by the FortiNAC to gather information from, and control, infrastructure devices? (Choose three.)

  • A. SMTP
  • B. SNMP
  • C. CLI
  • D. RADIUS
  • E. FTP

Answer: B,D,E

Explanation:
Set up SNMP communication with FortiNAC
RADIUS Server that is used by FortiNAC to communicate
FortiNAC can be configured via CLI to use HTTP or HTTPS for OS updates instead of FTP.
Reference: https://docs.fortinet.com/document/fortinac/8.3.0/administration-guide/28966/snmp
https://docs.fortinet.com/document/fortinac/8.8.0/administration-guide/938271/configure-radius-settings
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/e7ebbdaa-cabf-11ea-8b7d-
00505692583a/FortiNAC_Deployment_Guide.pdf

 

NEW QUESTION 34
What agent is required in order to detect an added USB drive?

  • A. Persistent
  • B. Mobile
  • C. Passive
  • D. Dissolvable

Answer: A

Explanation:
Expand the Persistent Agent folder. Select USB Detection from the tree.

 

NEW QUESTION 35
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?

  • A. The port becomes a threshold uplink.
  • B. The port is added to the Forced Registration group.
  • C. The port is switched into the Dead-End VLAN.
  • D. The port is disabled.

Answer: D

 

NEW QUESTION 36
......

NSE6_FNC-8.5 Dumps With 100% Verified Q&As - Pass Guarantee or Full Refund: https://pass4sure.test4cram.com/NSE6_FNC-8.5_real-exam-dumps.html