Fortinet NSE6_FAC-6.4 Exam Practice Questions (P. 2)
- Full Access (30 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Which network configuration is required when depioying FortiAuthenticator for portal services?
- AOne of the DNS servers must be a FortiGuard DNS server
- BPolicies must have specific ports open between FortiAuthenticator and the authentication clientsMost Voted
- CFortiGate must be set up as the default gateway for FortiAuthenticator
- DFortiAuthenticator must have the REST API access enabled on port 1
Correct Answer:
B
B
send
light_mode
delete
Question #7
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.
What can cause this issue?
What can cause this issue?
- AFortiToken 200 license has expired.
- BOne of the FortiAuthenticator devices in the active-active cluster has failed.
- CTime drift between FortiAuthenticator and hardware tokens.Most Voted
- DFortiAuthenticator has lost contact with the FortiToken Cloud servers.
Correct Answer:
C
C
send
light_mode
delete
Question #8
Why would you configure an OCSP responder URL in an end-entity certificate?
- ATo designate the SCEP server to use for CRL updates for that certificate
- BTo identify the end point that a certificate has been assigned to
- CTo designate a server for certificate status checkingMost Voted
- DTo provide the CRL location for the certificate
Correct Answer:
C
C
send
light_mode
delete
Question #9
An administrator wants to keep local CA cryptographic keys stored in a central location.
Which FortiAuthenticator feature would provide this functionality?
Which FortiAuthenticator feature would provide this functionality?
send
light_mode
delete
Question #10
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- APrincipal contacts service provider, service provider redirects principal to identity provider, after successful authentication identity provider redirects principal to service provider.Most Voted
- BPrincipal contacts identity provider and is redirected to service provider, principal establishes connection with service provider, service provider validates authentication with identity provider.
- CPrincipal contacts identity provider and authenticates, identity provider relays principal to service provider after valid authentication.
- DService provider contacts identity provider, identity provider validates principal for service provider, service provider establishes communication with principal.
Correct Answer:
C
C
send
light_mode
delete
All Pages