
Fortinet NSE6_FAC-6.4試験情報と無料練習テスト問題で合格せよ
2023年最新のの問題NSE6_FAC-6.4問題集で更新されたFortinet試験問題集を試そう
Fortinet NSE6_FAC-6.4:Fortinet NSE 6 - FortiAuthenticator 6.4認定試験は、候補者にとって挑戦的でありながら報酬のある経験です。これは、Fortinet認証ソリューションの使用と管理の熟練度を試験し、ネットワークエンジニアリング、セキュリティ管理、またはサイバーセキュリティの分野での専門知識を検証します。適切な準備とリソースを備えた候補者は、自信を持って認定試験に臨み、価値ある業界認定資格を取得できます。
Fortinet NSE6_FAC-6.4試験では、ユーザーとデバイスの認証、シングルサインオン(SSO)、ID管理、ゲストアクセスなど、Fortiauthenticator 6.4に関連する幅広いトピックをカバーしています。この試験では、高可用性、負荷分散、リモートアクセスなど、Fortiauthenticator 6.4展開シナリオに関する個人の知識も評価します。さらに、試験では、Fortiauthenticator 6.4に関連する一般的な問題をトラブルシューティングする個人の能力をテストします。
Fortinet NSE6_FAC -6.4(Fortinet NSE 6 -Fortiauthenticator 6.4)試験は、Fortiauthenticator 6.4の分野で個人の知識とスキルをテストするために設計された認定試験です。この試験は、ネットワークセキュリティのキャリアを求めており、Fortiauthenticatorの分野でのスキルと専門知識を検証したい専門家を対象としています。この試験はベンダー固有の認定試験です。つまり、Fortinet製品に固有のスキルと知識をテストするように設計されています。
質問 # 25
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the master FortiAuthenticator?
- A. Active-passive master
- B. Standalone master
- C. Load balancing master
- D. Cluster member
正解:A
解説:
When you are setting up two FortiAuthenticator devices in active-passive HA, you need to select the active-passive master role on the master FortiAuthenticator device. This role means that the device will handle all requests and synchronize data with the slave device until a failover occurs. The slave device must be configured as an active-passive slave role. The other roles are used for different HA modes, such as standalone (no HA), cluster (active-active), or load balancing (active-active with load balancing). Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372411/high-availability
質問 # 26
Which statement about the assignment of permissions for sponsor and administrator accounts is true?
- A. Sponsor permissions are assigned using group settings.
- B. Administrator capabilities are assigned by applying permission sets to admin groups.
- C. Only administrator accounts permissions are assigned using admin profiles.
- D. Both sponsor and administrator account permissions are assigned using admin profiles.
正解:D
解説:
Both sponsor and administrator account permissions are assigned using admin profiles. An admin profile is a set of permissions that defines what actions an administrator or a sponsor can perform on FortiAuthenticator. An admin profile can be assigned to an admin group or an individual admin user. A sponsor is a special type of admin user who can create and manage guest accounts on behalf of other users.
質問 # 27
When generating a TOTP for two-factor authentication, what two pieces of information are used by the algorithm to generate the TOTP?
- A. Time and seed
- B. Time and FortiAuthenticator serial number
- C. Time and mobile location
- D. UUID and time
正解:A
解説:
TOTP stands for Time-based One-time Password, which is a type of OTP that is generated based on two pieces of information: time and seed. The time is the current timestamp that is synchronized between the client and the server. The seed is a secret key that is shared between the client and the server. The TOTP algorithm combines the time and the seed to generate a unique and short-lived OTP that can be used for two-factor authentication.
質問 # 28
You want to monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP.
Which two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface? (Choose two)
- A. Enable logging services
- B. Upload management information base (MIB) files to SNMP server
- C. Set the tresholds to trigger SNMP traps
- D. Associate an ASN, 1 mapping rule to the receiving host
正解:B、C
解説:
To monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP, two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface:
Set the thresholds to trigger SNMP traps for various system events, such as CPU usage, disk usage, memory usage, or temperature.
Upload management information base (MIB) files to SNMP server to enable the server to interpret the SNMP traps sent by FortiAuthenticator.
質問 # 29
Why would you configure an OCSP responder URL in an end-entity certificate?
- A. To designate a server for certificate status checking
- B. To provide the CRL location for the certificate
- C. To identify the end point that a certificate has been assigned to
- D. To designate the SCEP server to use for CRL updates for that certificate
正解:A
解説:
An OCSP responder URL in an end-entity certificate is used to designate a server for certificate status checking. OCSP stands for Online Certificate Status Protocol, which is a method of verifying whether a certificate is valid or revoked in real time. An OCSP responder is a server that responds to OCSP requests from clients with the status of the certificate in question. The OCSP responder URL in an end-entity certificate points to the location of the OCSP responder that can provide the status of that certificate.
質問 # 30
How can a SAML metada file be used?
- A. To import the required IDP configuration
- B. To resolve the IDP realm for authentication
- C. To defined a list of trusted user names
- D. To correlate the IDP address to its hostname
正解:A
解説:
A SAML metadata file can be used to import the required IDP configuration for SAML service provider mode. A SAML metadata file is an XML file that contains information about the identity provider (IDP) and the service provider (SP), such as their entity IDs, endpoints, certificates, and attributes. By importing a SAML metadata file from the IDP, FortiAuthenticator can automatically configure the necessary settings for SAML service provider mode.
質問 # 31
You have implemented two-factor authentication to enhance security to sensitive enterprise systems.
How could you bypass the need for two-factor authentication for users accessing form specific secured networks?
- A. Specify the appropriate RADIUS clients in the authentication policy
- B. Enable Adaptive Authentication in the portal policy
- C. Enable the Resolve user geolocation from their IP address option in the authentication policy.
- D. Create an admin realm in the authentication policy
正解:B
解説:
Adaptive Authentication is a feature that allows administrators to bypass the need for two-factor authentication for users accessing from specific secured networks. Adaptive Authentication uses geolocation information from IP addresses to determine whether a user is accessing from a trusted network or not. If the user is accessing from a trusted network, FortiAuthenticator can skip the second factor of authentication and grant access based on the first factor only.
質問 # 32
Which method is the most secure way of delivering FortiToken data once the token has been seeded?
- A. Shipment of the seed files on a CD using a tamper-evident envelope
- B. Using the in-house token provisioning tool
- C. Automatic token generation using FortiAuthenticator
- D. Online activation of the tokens through the FortiGuard network
正解:D
解説:
Online activation of the tokens through the FortiGuard network is the most secure way of delivering FortiToken data once the token has been seeded because it eliminates the risk of seed files being compromised during transit or storage. The other methods involve physical or manual delivery of seed files which can be intercepted, lost, or stolen. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372403/fortitoken
質問 # 33
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- A. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider
- B. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
- C. Principal contacts idendity provider and is redirected to service provider, principal establishes connection with service provider, service provider validates authentication with identify provider
- D. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
正解:A
解説:
SP-initiated SSO SAML packet flow for a host without a SAML assertion is as follows:
Principal contacts service provider, requesting access to a protected resource.
Service provider redirects principal to identity provider, sending a SAML authentication request.
Principal authenticates with identity provider using their credentials.
After successful authentication, identity provider redirects principal back to service provider, sending a SAML response with a SAML assertion containing the principal's attributes.
Service provider validates the SAML response and assertion, and grants access to the principal.
質問 # 34
An administrator is integrating FortiAuthenticator with an existing RADIUS server with the intent of eventually replacing the RADIUS server with FortiAuthenticator.
How can FortiAuthenticator help facilitate this process?
- A. By enabling learning mode in the RADIUS server configuration
- B. By configuring the RADIUS accounting proxy
- C. By enabling automatic REST API calls from the RADIUS server
- D. By importing the RADIUS user records
正解:A
解説:
FortiAuthenticator can help facilitate the process of replacing an existing RADIUS server by enabling learning mode in the RADIUS server configuration. This allows FortiAuthenticator to learn user credentials from the existing RADIUS server and store them locally for future authentication requests2. This way, FortiAuthenticator can gradually take over the role of the RADIUS server without disrupting the user experience.
質問 # 35
A device or user identity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialis.
In this case, which user idendity discovery method can Fortiauthenticator use?
- A. Portal authentication
- B. Kerberos-base authentication
- C. Syslog messaging or SAML IDP
- D. Radius accounting
正解:A
解説:
Portal authentication is a user identity discovery method that can be used when a device or user identity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentials. Portal authentication requires users to enter their credentials on a web page before accessing network resources. The other methods are used for transparent identification of domain devices or users. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372406/user-identity-discovery
質問 # 36
Which two are supported captive or guest portal authentication methods? (Choose two)
- A. Email
- B. Instagram
- C. Apple ID
- D. Linkedln
正解:A、D
解説:
FortiAuthenticator supports various captive or guest portal authentication methods, including social media login with Linkedln, Facebook, Twitter, Google+, or WeChat; email verification; SMS verification; voucher code; username and password; and MAC address bypass. Apple ID and Instagram are not supported as authentication methods. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372404/guest-management/372405/authentication-methods
質問 # 37
Which statement about captive portal policies is true, assuming a single policy has been defined?
- A. Portal policies can be used only for BYODs.
- B. Conditions in the policy apply only to wireless users.
- C. Portal policies apply only to authentication requests coming from unknown RADIUS clients
- D. All conditions in the policy must match before a user is presented with the captive portal.
正解:D
解説:
Captive portal policies are used to define the conditions and settings for presenting a captive portal to users who need to authenticate before accessing the network. A captive portal policy consists of a set of conditions and a set of actions. The conditions can be based on various attributes, such as source IP address, MAC address, user group, device type, or RADIUS client. The actions can include redirecting the user to a specific portal, applying a specific authentication method, or assigning a specific VLAN or firewall policy. A single policy can have multiple conditions, and all conditions in the policy must match before a user is presented with the captive portal.
質問 # 38
Which two SAML roles can Fortiauthenticator be configured as? (Choose two)
- A. Service provider
- B. Assertion server
- C. Principal
- D. Idendity provider
正解:A、D
解説:
FortiAuthenticator can be configured as a SAML identity provider (IdP) or a SAML service provider (SP). As an IdP, FortiAuthenticator authenticates users and issues SAML assertions to SPs. As an SP, FortiAuthenticator receives SAML assertions from IdPs and grants access to users based on the attributes in the assertions. Principal and assertion server are not valid SAML roles. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372407/saml
質問 # 39
When generating a TOTP for two-factor authentication, what two pieces of information are used by the algorithm to generate the TOTP?
- A. Time and seed
- B. Time and FortiAuthenticator serial number
- C. Time and mobile location
- D. UUID and time
正解:A
解説:
TOTP stands for Time-based One-time Password, which is a type of OTP that is generated based on two pieces of information: time and seed. The time is the current timestamp that is synchronized between the client and the server. The seed is a secret key that is shared between the client and the server. The TOTP algorithm combines the time and the seed to generate a unique and short-lived OTP that can be used for two-factor authentication.
質問 # 40
Which two types of digital certificates can you create in Fortiauthenticator? (Choose two)
- A. Local service certificate
- B. User certificate
- C. Organization validation certificate
- D. Third-party root certificate
正解:A、B
解説:
FortiAuthenticator can create two types of digital certificates: user certificates and local service certificates. User certificates are issued to users or devices for authentication purposes, such as VPN, wireless, or web access. Local service certificates are issued to FortiAuthenticator itself for securing its own services, such as HTTPS, RADIUS, or LDAP.
質問 # 41
An administrator has an active directory (AD) server integrated with FortiAuthenticator. They want members of only specific AD groups to participate in FSSO with their corporate FortiGate firewalls.
How does the administrator accomplish this goal?
- A. Configure a FortiGate filter on FortiAuthenticatoc
- B. Configure SSO groups and assign them to FortiGate groups.
- C. Configure fine-grained controls on FortiAuthenticator to designate AD groups.
- D. Configure a domain groupings list to identify the desired AD groups.
正解:B
解説:
To allow members of only specific AD groups to participate in FSSO with their corporate FortiGate firewalls, the administrator can configure SSO groups and assign them to FortiGate groups. SSO groups are groups of users or devices that are defined on FortiAuthenticator based on various criteria, such as user group membership, source IP address, MAC address, or device type. FortiGate groups are groups of users or devices that are defined on FortiGate based on various criteria, such as user group membership, firewall policy, or authentication method. By mapping SSO groups to FortiGate groups, the administrator can control which users or devices can access the network resources protected by FortiGate.
質問 # 42
Which statement about the guest portal policies is true?
- A. Guest portal policies apply only to authentication requests coming from unknown RADIUS clients
- B. All conditions in the policy must match before a user is presented with the guest portal
- C. Guest portal policies can be used only for BYODs
- D. Conditions in the policy apply only to guest wireless users
正解:B
解説:
Guest portal policies are rules that determine when and how to present the guest portal to users who want to access the network. Each policy has a set of conditions that can be based on various factors, such as the source IP address, MAC address, RADIUS client, user agent, or SSID. All conditions in the policy must match before a user is presented with the guest portal. Guest portal policies can apply to any authentication request coming from any RADIUS client, not just unknown ones. They can also be used for any type of device, not just BYODs. They can also apply to wired or VPN users, not just wireless users. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372404/guest-management/372406/portal-policies
質問 # 43
Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)
- A. Creating, signing, and revoking of X.509 certificates
- B. Merging local and remote CRLs using SCEP
- C. Importing other CA certificates and CRLs
- D. Validating other CA CRLs using OSCP
正解:A、C
解説:
FortiAuthenticator can act as a self-signed or local CA that can issue certificates to users, devices, or other CAs. It can also import other CA certificates and CRLs to trust them and validate their certificates. It can also create, sign, and revoke X.509 certificates for various purposes, such as VPN authentication, web server encryption, or wireless security. It cannot validate other CA CRLs using OCSP or merge local and remote CRLs using SCEP because these are protocols that require communication with external CAs. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372408/certificate-management
質問 # 44
......
最新のNSE6_FAC-6.4試験問題集でFortinet試験が合格できます:https://www.passtest.jp/Fortinet/NSE6_FAC-6.4-shiken.html
合格できるFortinet NSE6_FAC-6.4のPDF問題集で最近更新された49問あります:https://drive.google.com/open?id=1NJSSxft4MzhSSIJBWM-5DBT7EEB3Ym9C