NSE6_FAC-6.1 Questions Prepare with Learning Information! 2023 Regularly updated [Q17-Q34]

Share

NSE6_FAC-6.1 Questions Prepare with Learning Information! 2023 Regularly updated

Get NSE6_FAC-6.1 Products Practice Material for NSE6_FAC-6.1 Exam Question Preparation

NEW QUESTION 17
Which two types of digital certificates can you create in Fortiauthenticator? (Choose two)

  • A. Third-party root certificate
  • B. Usercertificate
  • C. Organization validation certificate
  • D. Local service certificate

Answer: B,D

 

NEW QUESTION 18
Which method is the most secure way of delivering FortiToken data once the token has been seeded?

  • A. Automatic token generation using FortiAuthenticator
  • B. Online activation of the tokens through the FortiGuard network
  • C. Shipment of the seed files on a CD using a tamper-evident envelope
  • D. Using the in-house token provisioning tool

Answer: C

 

NEW QUESTION 19
At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator?
(Choose two)

  • A. Configuring at least on post-login service
  • B. Configuring a RADIUS client
  • C. Configuring an external authentication portal
  • D. Configuring a portal policy

Answer: A,D

 

NEW QUESTION 20
Which two statement about the RADIUS service on FortiAuthenticator are true? (Choose two)

  • A. RADIUS users can migrated to LDAP users
  • B. Two-factor authentication cannot be enforced when using RADIUS authentication
  • C. Only local users can be authenticated through RADIUS
  • D. FortiAuthenticator answers only to RADIUS client that are registered with FortiAuthenticator

Answer: A,D

 

NEW QUESTION 21
Which behaviors exist for certificate revocation lists (CRLs) on FortiAuthenticator? (Choose two)

  • A. CRLs can beexported only through the SCEP server
  • B. Revoked certificates are automaticlly placed on the CRL
  • C. All local CAs share the same CRLs
  • D. CRLs contain the serial number of the certificate that has been revoked

Answer: B,D

 

NEW QUESTION 22
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the masterFortiAuthenticator?

  • A. Standalone master
  • B. Active-passive master
  • C. Cluster member
  • D. Load balancing master

Answer: C

 

NEW QUESTION 23
Refer to the exhibit.
Examine the screenshot shown in the exhibit.

Which two statements regarding the configuration are true? (Choose two)

  • A. All accounts registered through the guest portal must be validated through email
  • B. Guest users must fill in all the fields on the registration form
  • C. All guest accounts created using the account registration feature will be placed under the Guest_Portal_Users group
  • D. Guest user account will expire after eight hours

Answer: A,C

 

NEW QUESTION 24
Which two are supported captive or guest portal authentication methods? (Choose two)

  • A. Email
  • B. Apple ID
  • C. Linkedln
  • D. Instagram

Answer: A,C

 

NEW QUESTION 25
How can a SAML metada file be used?

  • A. To import the required IDP configuration
  • B. To correlate the IDP address to its hostname
  • C. To resolve the IDP realm for authentication
  • D. To defined a list of trusted user names

Answer: A

 

NEW QUESTION 26
A device or useridentity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialis.
In this case, which user idendity discovery method can Fortiauthenticator use?

  • A. Syslog messaging or SAML IDP
  • B. Kerberos-base authentication
  • C. Portal authentication
  • D. Radius accounting

Answer: C

 

NEW QUESTION 27
You want to monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP.
Which two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface?
(Choose two)

  • A. Set the tresholds to trigger SNMP traps
  • B. Enable logging services
  • C. Upload management information base (MIB) files to SNMP server
  • D. Associate an ASN, 1 mapping rule to the receiving host

Answer: A,C

 

NEW QUESTION 28
Which of the following is an QATH-based standart to generate event-based, one-time password tokens?

  • A. SOTP
  • B. HOTP
  • C. TOTP
  • D. OLTP

Answer: B

 

NEW QUESTION 29
......

Most Reliable Fortinet NSE6_FAC-6.1 Training Materials: https://www.actualpdf.com/NSE6_FAC-6.1_exam-dumps.html