The Fortinet NSE6_FAC-6.1 Questions & Practice Test are Available On-Demand
Valid NSE6_FAC-6.1 Exam Dumps Ensure you a HIGH SCORE
NEW QUESTION # 13
Refer to the exhibit.
Examine the screenshot shown in the exhibit.
Which two statements regarding the configuration are true? (Choose two)
- A. All guest accounts created using the account registration feature will be placed under the Guest_Portal_Users group
- B. Guest user account will expire after eight hours
- C. Guest users must fill in all the fields on the registration form
- D. All accounts registered through the guest portal must be validated through email
Answer: A,D
NEW QUESTION # 14
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.
What can couse this issue?
- A. FortiAuthenticator has lose contact with the FortiToken Cloud servers
- B. On of the FortiAuthenticator devices in the active-active cluster has failed
- C. Time drift between FortiAuthenticator and hardware tokens
- D. FortiToken 200 licence has expired
Answer: C
NEW QUESTION # 15
You want to monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP.
Which two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface?
(Choose two)
- A. Enable logging services
- B. Set the tresholds to trigger SNMP traps
- C. Associate an ASN, 1 mapping rule to the receiving host
- D. Upload management information base (MIB) files to SNMP server
Answer: B,D
NEW QUESTION # 16
Which two features of FortiAuthenticator are used for EAP deployment? (Choose two)
- A. LDAP server
- B. MAC authentication bypass
- C. Certificate authority
- D. RADIUS server
Answer: C,D
NEW QUESTION # 17
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the masterFortiAuthenticator?
- A. Active-passive master
- B. Standalone master
- C. Load balancing master
- D. Cluster member
Answer: D
NEW QUESTION # 18
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- A. Principal contacts idendity provider and is redirected to serviceprovider, principal establishes connection with service provider, service provider validates authentication with identify provider
- B. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
- C. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider
- D. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
Answer: C
NEW QUESTION # 19
Which of the following is an QATH-based standart to generate event-based, one-time password tokens?
- A. SOTP
- B. TOTP
- C. HOTP
- D. OLTP
Answer: C
NEW QUESTION # 20
Which two SAML roles can Fortiauthenticator be configured as? (Choose two)
- A. Service provider
- B. Assertion server
- C. Principal
- D. Idendity provider
Answer: A,D
NEW QUESTION # 21
What are three key features of FortiAuthenticator? (Choose three)
- A. Portal services
- B. Log server
- C. Identity management device
- D. Certificate authority
- E. RSSO Server
Answer: A,C,D
NEW QUESTION # 22
Which two are supported captive or guest portal authentication methods? (Choose two)
- A. Apple ID
- B. Instagram
- C. Linkedln
- D. Email
Answer: C,D
NEW QUESTION # 23
Which interface services must be enabled for the SCEP client to connect to Authenticator?
- A. REST API
- B. SSH
- C. OCSP
- D. HTTP/HTTPS
Answer: D
NEW QUESTION # 24
Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)
- A. Creating, signing, and revoking of X.509 certificates
- B. Validating other CA CRLs using OSCP
- C. Importing other CA certificates and CRLs
- D. Merging local and remote CRLs using SCEP
Answer: A,C
NEW QUESTION # 25
......
NSE6_FAC-6.1 Exam Practice Questions prepared by Fortinet Professionals: https://certkingdom.practicedump.com/NSE6_FAC-6.1-practice-dumps.html