
Updated Jul-2023 Official licence for NSE6_FAC-6.1 Certified by NSE6_FAC-6.1 Dumps PDF
Grab latest Amazon NSE6_FAC-6.1 Dumps as PDF Updated on 2023
NEW QUESTION # 13
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.
What can couse this issue?
- A. FortiAuthenticator has lose contact with the FortiToken Cloud servers
- B. On of the FortiAuthenticator devices in the active-active cluster has failed
- C. Time drift between FortiAuthenticator and hardware tokens
- D. FortiToken 200 licence has expired
Answer: C
NEW QUESTION # 14
Which EAP method is known as the outer authentication method?
- A. PEAP
- B. EAP-GTC
- C. MSCHAPV2
- D. EAP-TLS
Answer: A
NEW QUESTION # 15
Which statement about the guest portal policies is true?
- A. Guest portal policies apply only to authentication requests coming from unknown RADIUS clients
- B. Conditions in the policy apply only to guest wireless users
- C. Guest portal policies can be used only for BYODs
- D. All conditions in the policy must match before a user is presented with the guest portal
Answer: D
NEW QUESTION # 16
Which three of the following can be used as SSO sources? (Choose three)
- A. RADIUS accounting
- B. FortiAuthenticator in SAML SP role
- C. Fortigate
- D. FortiClient SSO Mobility Agent
- E. SSH Sessions
Answer: A,B,D
NEW QUESTION # 17
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- A. Principal contacts idendity provider and is redirected to serviceprovider, principal establishes connection with service provider, service provider validates authentication with identify provider
- B. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
- C. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider
- D. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
Answer: C
NEW QUESTION # 18
A device or useridentity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialis.
In this case, which user idendity discovery method can Fortiauthenticator use?
- A. Portal authentication
- B. Kerberos-base authentication
- C. Radius accounting
- D. Syslog messaging or SAML IDP
Answer: A
NEW QUESTION # 19
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the masterFortiAuthenticator?
- A. Active-passive master
- B. Standalone master
- C. Load balancing master
- D. Cluster member
Answer: D
NEW QUESTION # 20
Which method is the most secure way of delivering FortiToken data once the token has been seeded?
- A. Automatic token generation using FortiAuthenticator
- B. Online activation of the tokens through the FortiGuard network
- C. Shipment of the seed files on a CD using a tamper-evident envelope
- D. Using the in-house token provisioning tool
Answer: C
NEW QUESTION # 21
Which two statements about the EAP-TTLS authentication method are true? (Choose two)
- A. Support a port access control (wired) solution only
- B. Requires an EAP server certificate
- C. Uses digital certificates only on the server side
- D. Uses mutualauthentication
Answer: B,C
NEW QUESTION # 22
Which two SAML roles can Fortiauthenticator be configured as? (Choose two)
- A. Service provider
- B. Assertion server
- C. Principal
- D. Idendity provider
Answer: A,D
NEW QUESTION # 23
Which network configuration is required when deploying FortiAuthenticator for portal services?
- A. FortiAuthenticator must have the REST API access enable on port1
- B. Policies must have specific ports open between FortiAuthenticator and the authentication clients
- C. Fortigate must be setup as default gateway for FortiAuthenticator
- D. One of the DNS servers must be a FortiGuard DNS server
Answer: B
NEW QUESTION # 24
You are the administrator of a large network that includes a large local user datadabase on the current Fortiauthenticatior. You want to import all the local users into a new Fortiauthenticator device.
Which method should you use to migrate the local users?
- A. Import the current directory structure.
- B. Import users using RADIUS accounting updates.
- C. Import users using a CSV file.
- D. Import users fromRADUIS.
Answer: C
NEW QUESTION # 25
......
Latest NSE6_FAC-6.1 Exam Dumps Fortinet Exam from Training: https://actual4test.practicetorrent.com/NSE6_FAC-6.1-practice-exam-torrent.html