Free NSE6_FAC-6.4 Exam Braindumps

Pass your Fortinet NSE 6 - FortiAuthenticator 6.4 exam with these free Questions and Answers

Page 3 of 10
QUESTION 6

Which two protocols are the default management access protocols for administrative access for FortiAuthenticator? (Choose two)

  1. A. Telnet
  2. B. HTTPS
  3. C. SSH
  4. D. SNMP

Correct Answer: BC
HTTPS and SSH are the default management access protocols for administrative access for FortiAuthenticator. HTTPS allows administrators to access the web-based GUI of FortiAuthenticator using a web browser and a secure connection. SSH allows administrators to access the CLI of FortiAuthenticator using an SSH client and an encrypted connection. Both protocols require the administrator to enter a valid username and password to log in.
References:
https://docs.fortinet.com/document/fortiauthenticator/6.4.0/administration-guide/906179/system-settings#manag

QUESTION 7

Which behaviors exist for certificate revocation lists (CRLs) on FortiAuthenticator? (Choose two)

  1. A. CRLs contain the serial number of the certificate that has been revoked
  2. B. Revoked certificates are automaticlly placed on the CRL
  3. C. CRLs can be exported only through the SCEP server
  4. D. All local CAs share the same CRLs

Correct Answer: AB
CRLs are lists of certificates that have been revoked by the issuing CA and should not be trusted by any entity. CRLs contain the serial number of the certificate that has been revoked, the date and time of revocation, and the reason for revocation. Revoked certificates are automatically placed on the CRL by the CA and the CRL is updated periodically. CRLs can be exported through various methods, such as HTTP, LDAP, or SCEP. Each local CA has its own CRL that is specific to its issued certificates. References:
https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372408/certificate-management/3

QUESTION 8

You are a Wi-Fi provider and host multiple domains.
How do you delegate user accounts, user groups and permissions per domain when they are authenticating on a single FortiAuthenticator device?

  1. A. Create realms.
  2. B. Create user groups
  3. C. Create multiple directory trees on FortiAuthenticator
  4. D. Automatically import hosts from each domain as they authenticate.

Correct Answer: A
Realms are a way to delegate user accounts, user groups and permissions per domain when they are authenticating on a single FortiAuthenticator device. A realm is a logical grouping of users and groups based on a common attribute, such as a domain name or an IP address range. Realms allow administrators to apply different authentication policies and settings to different groups of users based on their realm membership.
References:
https://docs.fortinet.com/document/fortiauthenticator/6.4.0/administration-guide/906179/user-management#real

QUESTION 9

Which two statement about the RADIUS service on FortiAuthenticator are true? (Choose two)

  1. A. Two-factor authentication cannot be enforced when using RADIUS authentication
  2. B. RADIUS users can migrated to LDAP users
  3. C. Only local users can be authenticated through RADIUS
  4. D. FortiAuthenticator answers only to RADIUS client that are registered with FortiAuthenticator

Correct Answer: BD
Two statements about the RADIUS service on FortiAuthenticator are true:
NSE6_FAC-6.4 dumps exhibit RADIUS users can be migrated to LDAP users using the RADIUS learning mode feature. This feature allows FortiAuthenticator to learn user credentials from an existing RADIUS server and store them locally as LDAP users for future authentication requests.
NSE6_FAC-6.4 dumps exhibit FortiAuthenticator answers only to RADIUS clients that are registered with FortiAuthenticator. A RADIUS client is a device that sends RADIUS authentication or accounting requests to FortiAuthenticator. A RADIUS client must be added and configured on FortiAuthenticator before it can communicate with it.
References:
https://docs.fortinet.com/document/fortiauthenticator/6.4.0/administration-guide/906179/radius-service

QUESTION 10

Which two statements regarding the configuration are true? (Choose two.)

  1. A. All guest accounts created using the account registration feature will be placed under the Guest_Portal_Users group
  2. B. All accounts registered through the guest portal must be validated through email
  3. C. Guest users must fill in all the fields on the registration form
  4. D. Guest user account will expire after eight hours

Correct Answer: AB
The screenshot shows that the account registration feature is enabled for the guest portal and that the guest group is set to Guest_Portal_Users. This means that all guest accounts created using this feature will be placed under that group1. The screenshot also shows that email validation is enabled for the guest portal and that the email validation link expires after 24 hours. This means that all accounts registered through the guest portal must be validated through email within that time frame1.
References: 1 https://docs.fortinet.com/document/fortiauthenticator/6.4.0/administration-guide/906179/guest

Page 3 of 10

Post your Comments and Discuss Fortinet NSE6_FAC-6.4 exam with other Community members: