
[2023] Use Real Fortinet Dumps - 100% Free NSE6_FAC-6.1 Exam Dumps
Realistic NSE6_FAC-6.1 Dumps Latest Fortinet Practice Tests Dumps
NEW QUESTION 16
You are the administrator of a large network that includes a large local user datadabase on the current Fortiauthenticatior. You want to import all the local users into a new Fortiauthenticator device.
Which method should you use to migrate the local users?
- A. Import users fromRADUIS.
- B. Import users using a CSV file.
- C. Import users using RADIUS accounting updates.
- D. Import the current directory structure.
Answer: B
NEW QUESTION 17
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.
What can couse this issue?
- A. FortiToken 200 licence has expired
- B. Time drift between FortiAuthenticator and hardware tokens
- C. FortiAuthenticator has lose contact with the FortiToken Cloud servers
- D. On of the FortiAuthenticator devices in the active-active cluster has failed
Answer: B
NEW QUESTION 18
Which statement about the guest portal policies is true?
- A. All conditions in the policy must match before a user is presented with the guest portal
- B. Conditions in the policy apply only to guest wireless users
- C. Guest portal policies can be used only for BYODs
- D. Guest portal policies apply only to authentication requests coming from unknown RADIUS clients
Answer: A
NEW QUESTION 19
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- A. Principal contacts idendity provider and is redirected to serviceprovider, principal establishes connection with service provider, service provider validates authentication with identify provider
- B. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
- C. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
- D. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider
Answer: D
NEW QUESTION 20
Which two statement about the RADIUS service on FortiAuthenticator are true? (Choose two)
- A. Only local users can be authenticated through RADIUS
- B. Two-factor authentication cannot be enforced when using RADIUS authentication
- C. FortiAuthenticator answers only to RADIUS client that are registered with FortiAuthenticator
- D. RADIUS users can migrated to LDAP users
Answer: C,D
NEW QUESTION 21
A device or useridentity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialis.
In this case, which user idendity discovery method can Fortiauthenticator use?
- A. Radius accounting
- B. Kerberos-base authentication
- C. Syslog messaging or SAML IDP
- D. Portal authentication
Answer: D
NEW QUESTION 22
You want to monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP.
Which two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface?
(Choose two)
- A. Associate an ASN, 1 mapping rule to the receiving host
- B. Enable logging services
- C. Upload management information base (MIB) files to SNMP server
- D. Set the tresholds to trigger SNMP traps
Answer: C,D
NEW QUESTION 23
Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)
- A. Creating, signing, and revoking of X.509 certificates
- B. Importing other CA certificates and CRLs
- C. Validating other CA CRLs using OSCP
- D. Merging local and remote CRLs using SCEP
Answer: A,B
NEW QUESTION 24
Which two statements about the self-service portal are true? (Choose two)
- A. Realms can be used to configure which seld-registeredusers or groups can authenticate on the network
- B. Administrator approval is required for all self-registration
- C. Authenticating users must specify domain name along with username
- D. Self-registration information can be sent to the user through email or SMS
Answer: A,D
NEW QUESTION 25
Which two are supported captive or guest portal authentication methods? (Choose two)
- A. Apple ID
- B. Instagram
- C. Email
- D. Linkedln
Answer: C,D
NEW QUESTION 26
Which three of the following can be used as SSO sources? (Choose three)
- A. FortiClient SSO Mobility Agent
- B. Fortigate
- C. SSH Sessions
- D. FortiAuthenticator in SAML SP role
- E. RADIUS accounting
Answer: A,D,E
NEW QUESTION 27
Which two features of FortiAuthenticator are used for EAP deployment? (Choose two)
- A. Certificate authority
- B. RADIUS server
- C. MAC authentication bypass
- D. LDAP server
Answer: A,B
NEW QUESTION 28
......
NSE6_FAC-6.1 Dumps PDF - NSE6_FAC-6.1 Real Exam Questions Answers: https://www.examboosts.com/Fortinet/NSE6_FAC-6.1-practice-exam-dumps.html
NSE6_FAC-6.1 Exam [2023] Dumps Fortinet PDF Questions: https://drive.google.com/open?id=1SaDHcPpqZR0XkE2gXt-wWIK4D5fRvGKC