[2024年11月06日] トップクラスのNSE6_FNC-7.2練習試験問題 [Q35-Q54]

Share

[2024年11月06日] トップクラスのNSE6_FNC-7.2練習試験問題

実際問題を使ってNSE6_FNC-7.2無料問題集サンプル問題と練習テストエンジン


Fortinet NSE6_FNC-7.2 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • 状態ベースの制御: この試験セクションでは、使用されているデバイスの状態に基づいてネットワークへのアクセスを制御することに重点が置かれます。
トピック 2
  • 論理ネットワーク、Fortinet セキュリティ ファブリック、およびファイアウォール タグ: このセクションでは、ネットワーク部分をセグメント化して統合し、FortiGate ファイアウォールと統合する方法などのトピックについて説明します。
トピック 3
  • セキュリティ デバイスの統合と自動応答: 試験のこのセクションでは、さまざまなセキュリティ デバイスで FortiNAC を使用する方法と、インシデント対応を自動化する方法について説明します。
トピック 4
  • ゲストと請負業者の管理: 試験のこのセクションでは、安全で一時的なネットワーク アクセスの提供について説明します。これには、ゲストだけでなく請負業者にもアクセス権を付与することが含まれます。
トピック 5
  • FortiGate VPN、高可用性、および FortiNAC Control Manager の統合: 試験のこのセクションでは、VPN アクセスの管理に重点が置かれています。また、メイン管理システムとの FortiNAC の適切な統合を確実にする方法についても説明します。
トピック 6
  • ネットワークの可視性の実現: このセクションでは、リンクされたデバイスに関する洞察の獲得と、ネットワーク内で実行されるアクティビティについて説明します。
トピック 7
  • 不正デバイスの識別と分類: 試験のこのセクションでは、FortiNAC ネットワークで認証されていないデバイスの検出と分類に重点が置かれます。

 

質問 # 35
Which two policy types can be created on a FortiNAC Control Manager? (Choose two.)

  • A. Network Access
  • B. Authentication
  • C. Supplicant EasvConnect
  • D. Endpoint Compliance

正解:A、D


質問 # 36
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host matches a network access policy and has a state of "at risk"?

  • A. The host is provisioned based on the default access defined by the point of connection.
  • B. The host is provisioned based on the network access policy.
  • C. The host is isolated.
  • D. The host is administratively disabled.

正解:D


質問 # 37
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?

  • A. The port is added to the Forced Registration group.
  • B. The port is disabled.
  • C. The port becomes a threshold uplink.
  • D. The port is switched into the Dead-End VLAN.

正解:D


質問 # 38
Where should you configure MAC notification traps on a supported switch?

  • A. Configure them only on ports set as 802 1g trunks.
  • B. Configure them only after you configure linkup and linkdown traps.
  • C. Configure them on all ports except uplink ports.
  • D. Configure them on all ports on the switch.

正解:A

解説:
In general, for network switches supporting MAC notification traps, it's advisable to configure these traps on all ports except uplink ports. Uplink ports are used for connecting to other switches or network infrastructure devices and typically don't need MAC notification traps, which are more relevant for end-device connectivity monitoring.
The study guide specifies that MAC notification traps should not be configured on interfaces that are uplinks.
They are the preferred method for learning and updating Layer 2 information and should be used whenever available, but not on uplink interfaces.


質問 # 39
Refer to the exhibit.

What would happen if the highlighted port with connected hosts was placed in both the Forced Registration and Forced Remediation port groups?

  • A. Only the higher ranked enforcement group would be applied.
  • B. Multiple enforcement groups could not contain the same port.
  • C. Both types of enforcement would be applied.
  • D. Enforcement would be applied only to rogue hosts.

正解:C


質問 # 40
By default, if after a successful Layer 2 poll, more than 20 endpoints are seen connected on a single switch port simultaneously, what happens to the port?

  • A. The port is added to the Forced Registration group
  • B. The port is disabled
  • C. The port is switched into the Dead-End VLAN
  • D. The port becomes a threshold uplink

正解:D

解説:
If more than 20 endpoints are seen connected on a single switch port simultaneously after a successful Layer 2 poll, the port is designated as an uplink. FortiNAC will ignore all physical addresses learned on an uplink port and will not perform any control operations on it


質問 # 41
During an evaluation of state-based enforcement, an administrator discovers that ports that should not be under enforcement have been added to enforcement groups. In which view would the administrator be able to determine who added the ports to the groups?

  • A. The Admin Auditing view
  • B. The Event Management view
  • C. The Security Events view
  • D. The Alarms view

正解:A


質問 # 42
Refer to the exhibit.

If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?

  • A. The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
  • B. The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.
  • C. The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
  • D. The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.

正解:C


質問 # 43
By default, if after a successful Layer 2 poll, more than 20 endpoints are seen connected on a single switch port simultaneously, what happens to the port?

  • A. The port is added to the Forced Registration group
  • B. The port is disabled
  • C. The port is switched into the Dead-End VLAN
  • D. The port becomes a threshold uplink

正解:D


質問 # 44
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)

  • A. Scheduled poll timings
  • B. A matched security policy
  • C. Linkup and Linkdown traps
  • D. Manual polling
  • E. A failed Layer 3 poll

正解:A、C、D


質問 # 45
What would happen if a port was placed in both the Forced Registration and the Forced Remediation port groups?

  • A. Only al-risk hosts would be impacted.
  • B. Only rogue hosts would be impacted.
  • C. Both enforcement groups cannot contain the same port.
  • D. Both types of enforcement would be applied.

正解:B


質問 # 46
Refer to the exhibit.

When a contractor account is created using this template, what value will be set in the accounts Rote field?

  • A. Accounting Contractor
  • B. Eng-Contractor
  • C. Conti actor
  • D. Engineer-Contractor

正解:D


質問 # 47
Which three communication methods are used by the FortiNAC to gather information from, and control, infrastructure devices? (Choose three)

  • A. DCLI
  • B. OSNMP
  • C. SMTP
  • D. RADIUS
  • E. FTP

正解:A、C、E


質問 # 48
Where do you look to determine when and why the FortiNAC made an automated network access change?

  • A. The Port Changes view
  • B. The Admin Auditing view
  • C. The Connections view
  • D. The Event view

正解:D


質問 # 49
Which system group will force at-risk hosts into the quarantine network, based on point of connection?

  • A. Forced Isolation
  • B. Physical Address Filtering
  • C. Forced Quarantine
  • D. Forced Remediation

正解:C

解説:
Forced Quarantine, study guide 7.2 pag 245 and 248


質問 # 50
Two FortiNAC devices have been configured in an HA configuration. After five failed heartbeats between the primary device and secondary device, the primary device fail to ping the designated gateway. What happens next?

  • A. The primary device shuts down NAC processes and changes to a management down status.
  • B. The primary device changes its designation to secondary, and the secondary device changes to primary.
  • C. The primary device waits 3 minutes and attempts to re-establish the HA heartbeat before attempting a second ping of the gateway.
  • D. The primary device continues to operate as the in-control device and changes the status or secondary device to contact lost.

正解:A


質問 # 51
During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)

  • A. Bridging is enabled on the host
  • B. The wrong agent is installed.
  • C. The ports default VLAN is the same as the Registration VLAN.
  • D. There is another unregistered host on the same port.

正解:B、C


質問 # 52
Which connecting endpoints are evaluated against all enabled device profiling rules?

  • A. Rogues devices, only when they connect for the first time
  • B. Known trusted devices each time they change location
  • C. Rogues devices, each time they connect
  • D. All hosts, each time they connect

正解:C


質問 # 53
Which system group will force at-risk hosts into the quarantine network, based on point of connection?

  • A. Forced Quarantine
  • B. Forced Isolation
  • C. Physical Address Filtering
  • D. Forced Remediation

正解:B


質問 # 54
......

合格させるFortinet NSE6_FNC-7.2試験問題でテスト復刻エンジンとPDF:https://www.passtest.jp/Fortinet/NSE6_FNC-7.2-shiken.html

2024年最新の実際に出ると確認されたFortinet NSE6_FNC-7.2無料試験問題:https://drive.google.com/open?id=1e4PAtiqUyC7Plzzp8WIIfhfidYeOpr7T