無料ダウンロードFortinet NSE6_FNC-8.5リアル試験問題ゲットせよ
最新のFortinet NSE6_FNC-8.5リアル試験問題集PDF
質問 10
What causes a host's state to change to "at risk"?
- A. The host has failed an endpoint compliance policy or admin scan.
- B. The logged on user is not found in the Active Directory.
- C. The host has been administratively disabled.
- D. The host is not in the Registered Hosts group.
正解: A
解説:
Failure - Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.
Reference: https://docs.fortinet.com/document/fortinac/8.3.0/administration-guide/241168/host-health-and- scanning
質問 11
Which system group will force at-risk hosts into the quarantine network, based on point of connection?
- A. Forced Remediation
- B. Forced Isolation
- C. Physical Address Filtering
- D. Forced Quarantine
正解: A
解説:
A remediation plan is established, including a forensic analysis and a reload of the system. Also, users are forced to change their passwords as the system held local user accounts.
質問 12
Which three communication methods are used by the FortiNAC to gather information from, and control, infrastructure devices? (Choose three)
- A. DCLI
- B. RADIUS
- C. SNMP
- D. SMTP
- E. FTP
正解: B,C,E
解説:
Explanation
Set up SNMP communication with FortiNAC
RADIUS Server that is used by FortiNAC to communicate
FortiNAC can be configured via CLI to use HTTP or HTTPS for OS updates instead of FTP.
質問 13
Which system group will force at-risk hosts into the quarantine network, based on point of connection?
- A. Forced Remediation
- B. Physical Address Filtering
- C. Forced Quarantine
- D. Forced Isolation
正解: D
質問 14
Refer to the exhibit.
If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what will occur?
- A. The host is moved to a default isolation VLAN.
- B. The host is disabled.
- C. No VLAN change is performed.
- D. The host is moved to VLAN 111.
正解: B
解説:
The ability to limit the number of workstations that can connect to specific ports on the switch is managed with Port Security. If these limits are breached, or access from unknown workstations is attempted, the port can do any or all of the following: drop the untrusted data, notify the network administrator, or disable the port.
Reference: https://www.alliedtelesis.com/sites/default/files/documents/solutions-guides/ lan_protection_solution_reva.pdf
質問 15
Which two of the following are required for endpoint compliance monitors? (Choose two.)
- A. Security rule
- B. Persistent agent
- C. Logged on user
- D. Custom scan
正解: A,D
解説:
Explanation
DirectDefense's analysis of FireEye Endpoint attests that the products help meet the HIPAA Security Rule.
In the menu on the left click the + sign next to Endpoint Compliance to open it.
質問 16
Which two methods can be used to gather a list of installed applications and application details from a host? (Choose two)
- A. MDM integration
- B. Agent technology
- C. Portal page on-boarding options
- D. Application layer traffic inspection
正解: A,C
解説:
Reference:
https://docs.oracle.com/en/middleware/idm/identity-governance/12.2.1.3/omusg/managing-application-onboarding.html#GUID-4D0D5B18-A6F5-4231-852E-DB0D95AAE2D1
質問 17
Where are logical network values defined?
- A. In the security and access field of each host record
- B. In the port properties view of each port
- C. On the profiled devices view
- D. In the model configuration view of each infrastructure device
正解: D
質問 18
What capability do logical networks provide?
- A. VLAN-based inventory reporting
- B. Autopopulation of device groups based on point of connection
- C. Interactive topology view diagrams
- D. Application of different access values from a single access policy
正解: A
解説:
NTM also includes reporting utilities such as network and inventory reports. You can generate reports for subnets, switch ports, and VLANs.
Reference: https://logicalread.com/network-diagram/#.YBk9ZOgzbIU
質問 19
What agent is required in order to detect an added USB drive?
- A. Mobile
- B. Persistent
- C. Passive
- D. Dissolvable
正解: B
質問 20
During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)
- A. Bridging is enabled on the host.
- B. The wrong agent is installed.
- C. There is another unregistered host on the same port.
- D. The ports default VLAN is the same as the Registration VLAN.
正解: B,D
解説:
Scenario 4: NAT detection disabled, using endpoint compliance policy and agent.
Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/868f1267-7299-11e9-
81a4-00505692583a/fortinac-admin-operation-85.pdf
質問 21
In a wireless integration, how does FortiNAC obtain connecting MAC address information?
- A. MAC notification traps
- B. Link traps
- C. End station traffic monitoring
- D. RADIUS
正解: A
質問 22
In an isolation VLAN. which three services does FortiNAC supply? (Choose three.)
- A. Web
- B. DDNS
- C. IDHCP
- D. DNTP
- E. SMTP
正解: A,B,D
質問 23
Which agent is used only as part of a login script?
- A. Mobile
- B. Persistent
- C. Passive
- D. Dissolvable
正解: B
解説:
If the logon script runs the logon application in persistent mode, configure your Active Directory server not to run scripts synchronously.
Reference: https://www.websense.com/content/support/library/deployctr/v76/ init_setup_creating_and_running_logon_agent_script_deployment_tasks.aspx
質問 24
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)
- A. A failed Layer 3 poll
- B. Linkup and Linkdown traps
- C. A matched security policy
- D. Scheduled poll timings
- E. Manual polling
正解: B,D,E
質問 25
In which view would you find who made modifications to a Group?
- A. The Admin Auditing view
- B. The Security Events view
- C. The Event Management view
- D. The Alarms view
正解: B
質問 26
Which command line shell and scripting language does FortiNAC use for WinRM?
- A. DOS
- B. Linux
- C. Bash
- D. Powershell
正解: D
質問 27
Which two of the following are required for endpoint compliance monitors? (Choose two.)
- A. Security rule
- B. Logged on user
- C. Persistent agent
- D. Custom scan
正解: C,D
解説:
DirectDefense's analysis of FireEye Endpoint attests that the products help meet the HIPAA Security Rule.
In the menu on the left click the + sign next to Endpoint Compliance to open it.
Reference:
https://docs.fortinet.com/document/fortinac/8.5.2/administration-guide/92047/add-or-modify-a-scan
質問 28
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?
- A. The host is provisioned based on the default access defined by the point of connection.
- B. The host is isolated.
- C. The host is administratively disabled.
- D. The host is provisioned based on the network access policy.
正解: D
質問 29
Which agent is used only as part of a login script?
- A. Mobile
- B. Persistent
- C. Passive
- D. Dissolvable
正解: B
質問 30
What causes a host's state to change to "at risk"?
- A. The host has failed an endpoint compliance policy or admin scan.
- B. The logged on user is not found in the Active Directory.
- C. The host has been administratively disabled.
- D. The host is not in the Registered Hosts group.
正解: A
解説:
Explanation
Failure - Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.
質問 31
What agent is required in order to detect an added USB drive?
- A. Mobile
- B. Persistent
- C. Passive
- D. Dissolvable
正解: B
解説:
Expand the Persistent Agent folder. Select USB Detection from the tree.
質問 32
What capability do logical networks provide?
- A. VLAN-based inventory reporting
- B. Autopopulation of device groups based on point of connection
- C. Interactive topology view diagrams
- D. Application of different access values from a single access policy
正解: A
解説:
NTM also includes reporting utilities such as network and inventory reports. You can generate reports for subnets, switch ports, and VLANs.
質問 33
Where are logical network values defined?
- A. In the model configuration view of each infrastructure device
- B. In the port properties view of each port
- C. On the profiled devices view
- D. In the security and access field of each host record
正解: D
質問 34
What would happen if a port was placed in both the Forced Registration and the Forced Remediation port groups?
- A. Only rogue hosts would be impacted.
- B. Only al-risk hosts would be impacted.
- C. Both types of enforcement would be applied.
- D. Both enforcement groups cannot contain the same port.
正解: D
質問 35
......
PDF問題(2022年最新)実際のFortinet NSE6_FNC-8.5試験問題:https://www.passtest.jp/Fortinet/NSE6_FNC-8.5-shiken.html