あなたを合格させる試験には100%確認済みNSE6_FAC-6.4試験問題 [Q20-Q43]

Share

あなたを合格させる試験には100%確認済みNSE6_FAC-6.4試験問題

NSE6_FAC-6.4問題集PDFでNSE6_FAC-6.4リアル試験問題解答

質問 # 20
Which statement about captive portal policies is true, assuming a single policy has been defined?

  • A. All conditions in the policy must match before a user is presented with the captive portal.
  • B. Portal policies can be used only for BYODs.
  • C. Conditions in the policy apply only to wireless users.
  • D. Portal policies apply only to authentication requests coming from unknown RADIUS clients

正解:A

解説:
Captive portal policies are used to define the conditions and settings for presenting a captive portal to users who need to authenticate before accessing the network. A captive portal policy consists of a set of conditions and a set of actions. The conditions can be based on various attributes, such as source IP address, MAC address, user group, device type, or RADIUS client. The actions can include redirecting the user to a specific portal, applying a specific authentication method, or assigning a specific VLAN or firewall policy. A single policy can have multiple conditions, and all conditions in the policy must match before a user is presented with the captive portal.


質問 # 21
What are three key features of FortiAuthenticator? (Choose three)

  • A. Identity management device
  • B. Certificate authority
  • C. RSSO Server
  • D. Portal services
  • E. Log server

正解:A、B、D

解説:
FortiAuthenticator is a user and identity management solution that provides strong authentication, wireless 802.1X authentication, certificate management, RADIUS AAA (authentication, authorization, and accounting), and Fortinet Single Sign-On (FSSO). It also offers portal services for guest management, self-service password reset, and device registration. It is not a log server or an RSSO server. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/release-notes


質問 # 22
Which two features of FortiAuthenticator are used for EAP deployment? (Choose two)

  • A. Certificate authority
  • B. MAC authentication bypass
  • C. LDAP server
  • D. RADIUS server

正解:A、D

解説:
Two features of FortiAuthenticator that are used for EAP deployment are certificate authority and RADIUS server. Certificate authority allows FortiAuthenticator to issue and manage digital certificates for EAP methods that require certificate-based authentication, such as EAP-TLS or PEAP-EAP-TLS. RADIUS server allows FortiAuthenticator to act as an authentication server for EAP methods that use RADIUS as a transport protocol, such as EAP-GTC or PEAP-MSCHAPV2.


質問 # 23
Examine the screenshot shown in the exhibit.

Which two statements regarding the configuration are true? (Choose two.)

  • A. Guest users must fill in all the fields on the registration form
  • B. All accounts registered through the guest portal must be validated through email
  • C. Guest user account will expire after eight hours
  • D. All guest accounts created using the account registration feature will be placed under the Guest_Portal_Users group

正解:B、D

解説:
The screenshot shows that the account registration feature is enabled for the guest portal and that the guest group is set to Guest_Portal_Users. This means that all guest accounts created using this feature will be placed under that group1. The screenshot also shows that email validation is enabled for the guest portal and that the email validation link expires after 24 hours. This means that all accounts registered through the guest portal must be validated through email within that time frame1.


質問 # 24
Which statement about the guest portal policies is true?

  • A. Guest portal policies apply only to authentication requests coming from unknown RADIUS clients
  • B. Conditions in the policy apply only to guest wireless users
  • C. All conditions in the policy must match before a user is presented with the guest portal
  • D. Guest portal policies can be used only for BYODs

正解:C

解説:
Guest portal policies are rules that determine when and how to present the guest portal to users who want to access the network. Each policy has a set of conditions that can be based on various factors, such as the source IP address, MAC address, RADIUS client, user agent, or SSID. All conditions in the policy must match before a user is presented with the guest portal. Guest portal policies can apply to any authentication request coming from any RADIUS client, not just unknown ones. They can also be used for any type of device, not just BYODs. They can also apply to wired or VPN users, not just wireless users. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372404/guest-management/372406/portal-policies


質問 # 25
An administrator is integrating FortiAuthenticator with an existing RADIUS server with the intent of eventually replacing the RADIUS server with FortiAuthenticator.
How can FortiAuthenticator help facilitate this process?

  • A. By importing the RADIUS user records
  • B. By enabling automatic REST API calls from the RADIUS server
  • C. By enabling learning mode in the RADIUS server configuration
  • D. By configuring the RADIUS accounting proxy

正解:C

解説:
FortiAuthenticator can help facilitate the process of replacing an existing RADIUS server by enabling learning mode in the RADIUS server configuration. This allows FortiAuthenticator to learn user credentials from the existing RADIUS server and store them locally for future authentication requests2. This way, FortiAuthenticator can gradually take over the role of the RADIUS server without disrupting the user experience.


質問 # 26
At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator? (Choose two)

  • A. Configuring at least on post-login service
  • B. Configuring an external authentication portal
  • C. Configuring a RADIUS client
  • D. Configuring a portal policy

正解:A、D

解説:
To enable guest portal services on FortiAuthenticator, you need to configure a portal policy that defines the conditions for presenting the guest portal to users and the authentication methods to use. You also need to configure at least one post-login service that defines what actions to take after a user logs in successfully, such as sending an email confirmation, assigning a VLAN, or creating a user account. Configuring a RADIUS client or an external authentication portal are optional steps that depend on your network setup and requirements. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372404/guest-management


質問 # 27
You have implemented two-factor authentication to enhance security to sensitive enterprise systems.
How could you bypass the need for two-factor authentication for users accessing form specific secured networks?

  • A. Create an admin realm in the authentication policy
  • B. Enable the Resolve user geolocation from their IP address option in the authentication policy.
  • C. Specify the appropriate RADIUS clients in the authentication policy
  • D. Enable Adaptive Authentication in the portal policy

正解:D

解説:
Adaptive Authentication is a feature that allows administrators to bypass the need for two-factor authentication for users accessing from specific secured networks. Adaptive Authentication uses geolocation information from IP addresses to determine whether a user is accessing from a trusted network or not. If the user is accessing from a trusted network, FortiAuthenticator can skip the second factor of authentication and grant access based on the first factor only.


質問 # 28
Which FSSO discovery method transparently detects logged off users without having to rely on external features such as WMI polling?

  • A. DC Polling
  • B. Radius Accounting
  • C. FortiClient SSO Mobility Agent
  • D. Windows AD polling

正解:C

解説:
FortiClient SSO Mobility Agent is a FSSO discovery method that transparently detects logged off users without having to rely on external features such as WMI polling. FortiClient SSO Mobility Agent is a software agent that runs on Windows devices and communicates with FortiAuthenticator to provide FSSO information. The agent can detect user logon and logoff events without using WMI polling, which can reduce network traffic and improve performance.


質問 # 29
You want to monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP.
Which two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface? (Choose two)

  • A. Associate an ASN, 1 mapping rule to the receiving host
  • B. Set the tresholds to trigger SNMP traps
  • C. Upload management information base (MIB) files to SNMP server
  • D. Enable logging services

正解:B、C

解説:
To monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP, two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface:
Set the thresholds to trigger SNMP traps for various system events, such as CPU usage, disk usage, memory usage, or temperature.
Upload management information base (MIB) files to SNMP server to enable the server to interpret the SNMP traps sent by FortiAuthenticator.


質問 # 30
Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)

  • A. Creating, signing, and revoking of X.509 certificates
  • B. Importing other CA certificates and CRLs
  • C. Merging local and remote CRLs using SCEP
  • D. Validating other CA CRLs using OSCP

正解:A、B

解説:
FortiAuthenticator can act as a self-signed or local CA that can issue certificates to users, devices, or other CAs. It can also import other CA certificates and CRLs to trust them and validate their certificates. It can also create, sign, and revoke X.509 certificates for various purposes, such as VPN authentication, web server encryption, or wireless security. It cannot validate other CA CRLs using OCSP or merge local and remote CRLs using SCEP because these are protocols that require communication with external CAs. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372408/certificate-management


質問 # 31
Which two statements about the self-service portal are true? (Choose two)

  • A. Administrator approval is required for all self-registration
  • B. Self-registration information can be sent to the user through email or SMS
  • C. Realms can be used to configure which seld-registered users or groups can authenticate on the network
  • D. Authenticating users must specify domain name along with username

正解:B、C

解説:
Two statements about the self-service portal are true:
Self-registration information can be sent to the user through email or SMS using the notification templates feature. This feature allows administrators to customize the messages that are sent to users when they register or perform other actions on the self-service portal.
Realms can be used to configure which self-registered users or groups can authenticate on the network using the realm-based authentication feature. This feature allows administrators to apply different authentication policies and settings to different groups of users based on their realm membership.


質問 # 32
Why would you configure an OCSP responder URL in an end-entity certificate?

  • A. To designate a server for certificate status checking
  • B. To designate the SCEP server to use for CRL updates for that certificate
  • C. To identify the end point that a certificate has been assigned to
  • D. To provide the CRL location for the certificate

正解:A

解説:
An OCSP responder URL in an end-entity certificate is used to designate a server for certificate status checking. OCSP stands for Online Certificate Status Protocol, which is a method of verifying whether a certificate is valid or revoked in real time. An OCSP responder is a server that responds to OCSP requests from clients with the status of the certificate in question. The OCSP responder URL in an end-entity certificate points to the location of the OCSP responder that can provide the status of that certificate.


質問 # 33
An administrator has an active directory (AD) server integrated with FortiAuthenticator. They want members of only specific AD groups to participate in FSSO with their corporate FortiGate firewalls.
How does the administrator accomplish this goal?

  • A. Configure fine-grained controls on FortiAuthenticator to designate AD groups.
  • B. Configure SSO groups and assign them to FortiGate groups.
  • C. Configure a domain groupings list to identify the desired AD groups.
  • D. Configure a FortiGate filter on FortiAuthenticatoc

正解:B

解説:
To allow members of only specific AD groups to participate in FSSO with their corporate FortiGate firewalls, the administrator can configure SSO groups and assign them to FortiGate groups. SSO groups are groups of users or devices that are defined on FortiAuthenticator based on various criteria, such as user group membership, source IP address, MAC address, or device type. FortiGate groups are groups of users or devices that are defined on FortiGate based on various criteria, such as user group membership, firewall policy, or authentication method. By mapping SSO groups to FortiGate groups, the administrator can control which users or devices can access the network resources protected by FortiGate.


質問 # 34
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?

  • A. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
  • B. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
  • C. Principal contacts idendity provider and is redirected to service provider, principal establishes connection with service provider, service provider validates authentication with identify provider
  • D. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider

正解:D

解説:
SP-initiated SSO SAML packet flow for a host without a SAML assertion is as follows:
Principal contacts service provider, requesting access to a protected resource.
Service provider redirects principal to identity provider, sending a SAML authentication request.
Principal authenticates with identity provider using their credentials.
After successful authentication, identity provider redirects principal back to service provider, sending a SAML response with a SAML assertion containing the principal's attributes.
Service provider validates the SAML response and assertion, and grants access to the principal.


質問 # 35
Which two protocols are the default management access protocols for administrative access for FortiAuthenticator? (Choose two)

  • A. SNMP
  • B. SSH
  • C. Telnet
  • D. HTTPS

正解:B、D

解説:
HTTPS and SSH are the default management access protocols for administrative access for FortiAuthenticator. HTTPS allows administrators to access the web-based GUI of FortiAuthenticator using a web browser and a secure connection. SSH allows administrators to access the CLI of FortiAuthenticator using an SSH client and an encrypted connection. Both protocols require the administrator to enter a valid username and password to log in.


質問 # 36
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.
What can cause this issue?

  • A. FortiToken 200 license has expired
  • B. Time drift between FortiAuthenticator and hardware tokens
  • C. One of the FortiAuthenticator devices in the active-active cluster has failed
  • D. FortiAuthenticator has lost contact with the FortiToken Cloud servers

正解:B

解説:
One possible cause of the issue is time drift between FortiAuthenticator and hardware tokens. Time drift occurs when the internal clocks of FortiAuthenticator and hardware tokens are not synchronized. This can result in mismatched one-time passwords (OTPs) generated by the hardware tokens and expected by FortiAuthenticator. To prevent this issue, FortiAuthenticator provides a time drift tolerance option that allows a certain number of seconds of difference between the clocks.


質問 # 37
When configuring syslog SSO, which three actions must you take, in addition to enabling the syslog SSO method? (Choose three.)

  • A. Define a syslog source.
  • B. Select a syslog rule for message parsing.
  • C. Set the same password on both the FortiAuthenticator and the syslog server.
  • D. Enable syslog on the FortiAuthenticator interface.
  • E. Set the syslog UDP port on FortiAuthenticator.

正解:A、B、E

解説:
To configure syslog SSO, three actions must be taken, in addition to enabling the syslog SSO method:
Define a syslog source, which is a device that sends syslog messages to FortiAuthenticator containing user logon or logoff information.
Select a syslog rule for message parsing, which is a predefined or custom rule that defines how to extract the user name, IP address, and logon or logoff action from the syslog message.
Set the syslog UDP port on FortiAuthenticator, which is the port number that FortiAuthenticator listens on for incoming syslog messages.


質問 # 38
Which three of the following can be used as SSO sources? (Choose three)

  • A. Fortigate
  • B. FortiAuthenticator in SAML SP role
  • C. SSH Sessions
  • D. FortiClient SSO Mobility Agent
  • E. RADIUS accounting

正解:A、D、E

解説:
FortiAuthenticator supports various SSO sources that can provide user identity information to other devices in the network, such as FortiGate firewalls or FortiAnalyzer log servers. Some of the supported SSO sources are:
FortiClient SSO Mobility Agent: A software agent that runs on Windows devices and sends user login information to FortiAuthenticator.
FortiGate: A firewall device that can send user login information from various sources, such as FSSO agents, captive portals, VPNs, or LDAP servers, to FortiAuthenticator.
RADIUS accounting: A protocol that can send user login information from RADIUS servers or clients, such as wireless access points or VPN concentrators, to FortiAuthenticator.
SSH sessions and FortiAuthenticator in SAML SP role are not valid SSO sources because they do not provide user identity information to other devices in the network. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372410/single-sign-on


質問 # 39
......


Fortinet NSE6_FAC-6.4(Fortinet NSE 6 - FortiAuthenticator 6.4)認定試験は、FortiAuthenticator 6.4の展開と管理における専門知識を証明したいネットワークセキュリティ専門家を対象としています。FortiAuthenticatorは、Fortinet製品およびサードパーティのアプリケーションに対して、安全な認証および認可サービスを提供する強力なアイデンティティおよびアクセス管理ソリューションです。これにより、組織は既存の認証システムをFortinetのセキュリティソリューションと統合し、シームレスで安全なユーザーエクスペリエンスを提供することができます。

 

NSE6_FAC-6.4問題集100合保証には最新のサンプル:https://www.passtest.jp/Fortinet/NSE6_FAC-6.4-shiken.html

準備NSE6_FAC-6.4問題解答無料更新には100%試験合格保証 [2023年更新]:https://drive.google.com/open?id=1HJsvYZo0a7gD7Ji7wPVnYFLGtf-4rqlV