Verified NSE6_FAC-6.4 Q&As - Pass Guarantee NSE6_FAC-6.4 Exam Dumps
Check the Free demo of our NSE6_FAC-6.4 Exam Dumps with 49 Questions
Fortinet NSE6_FAC-6.4 certification exam is aimed at IT professionals who have experience working with FortiAuthenticator 6.4. NSE6_FAC-6.4 exam is a must-have certification for professionals who want to demonstrate their expertise in managing user access and authentication in a network environment. The NSE6_FAC-6.4 certification is designed to validate the skills and knowledge necessary to design, implement and manage FortiAuthenticator 6.4 in a network environment.
NEW QUESTION # 19
You are the administrator of a global enterprise with three FortiAuthenticator devices. You would like to deploy them to provide active-passive HA at headquarters, with geographically distributed load balancing.
What would the role settings be?
- A. One standalone and two load balancers
- B. One standalone primary, one cluster member, and one load balancer
- C. Two cluster members and one load balancer
- D. Two cluster members and one backup
Answer: B
Explanation:
To deploy three FortiAuthenticator devices to provide active-passive HA at headquarters, with geographically distributed load balancing, the role settings would be:
One standalone primary, which acts as the master device for HA and load balancing One cluster member, which acts as the backup device for HA and load balancing One load balancer, which acts as a remote device that forwards authentication requests to the primary or cluster member device
NEW QUESTION # 20
Which method is the most secure way of delivering FortiToken data once the token has been seeded?
- A. Automatic token generation using FortiAuthenticator
- B. Online activation of the tokens through the FortiGuard network
- C. Shipment of the seed files on a CD using a tamper-evident envelope
- D. Using the in-house token provisioning tool
Answer: B
Explanation:
Online activation of the tokens through the FortiGuard network is the most secure way of delivering FortiToken data once the token has been seeded because it eliminates the risk of seed files being compromised during transit or storage. The other methods involve physical or manual delivery of seed files which can be intercepted, lost, or stolen. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372403/fortitoken
NEW QUESTION # 21
An administrator has an active directory (AD) server integrated with FortiAuthenticator. They want members of only specific AD groups to participate in FSSO with their corporate FortiGate firewalls.
How does the administrator accomplish this goal?
- A. Configure a FortiGate filter on FortiAuthenticatoc
- B. Configure fine-grained controls on FortiAuthenticator to designate AD groups.
- C. Configure SSO groups and assign them to FortiGate groups.
- D. Configure a domain groupings list to identify the desired AD groups.
Answer: C
Explanation:
To allow members of only specific AD groups to participate in FSSO with their corporate FortiGate firewalls, the administrator can configure SSO groups and assign them to FortiGate groups. SSO groups are groups of users or devices that are defined on FortiAuthenticator based on various criteria, such as user group membership, source IP address, MAC address, or device type. FortiGate groups are groups of users or devices that are defined on FortiGate based on various criteria, such as user group membership, firewall policy, or authentication method. By mapping SSO groups to FortiGate groups, the administrator can control which users or devices can access the network resources protected by FortiGate.
NEW QUESTION # 22
Which FSSO discovery method transparently detects logged off users without having to rely on external features such as WMI polling?
- A. Windows AD polling
- B. DC Polling
- C. Radius Accounting
- D. FortiClient SSO Mobility Agent
Answer: D
Explanation:
FortiClient SSO Mobility Agent is a FSSO discovery method that transparently detects logged off users without having to rely on external features such as WMI polling. FortiClient SSO Mobility Agent is a software agent that runs on Windows devices and communicates with FortiAuthenticator to provide FSSO information. The agent can detect user logon and logoff events without using WMI polling, which can reduce network traffic and improve performance.
NEW QUESTION # 23
Which two SAML roles can Fortiauthenticator be configured as? (Choose two)
- A. Principal
- B. Service provider
- C. Assertion server
- D. Idendity provider
Answer: B,D
Explanation:
FortiAuthenticator can be configured as a SAML identity provider (IdP) or a SAML service provider (SP). As an IdP, FortiAuthenticator authenticates users and issues SAML assertions to SPs. As an SP, FortiAuthenticator receives SAML assertions from IdPs and grants access to users based on the attributes in the assertions. Principal and assertion server are not valid SAML roles. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372407/saml
NEW QUESTION # 24
A digital certificate, also known as an X.509 certificate, contains which two pieces of information? (Choose two.)
- A. Public key
- B. Shared secret
- C. Issuer
- D. Private key
Answer: A,C
Explanation:
A digital certificate, also known as an X.509 certificate, contains two pieces of information:
Issuer, which is the identity of the certificate authority (CA) that issued the certificate Public key, which is the public part of the asymmetric key pair that is associated with the certificate subject
NEW QUESTION # 25
How can a SAML metada file be used?
- A. To resolve the IDP realm for authentication
- B. To import the required IDP configuration
- C. To correlate the IDP address to its hostname
- D. To defined a list of trusted user names
Answer: B
Explanation:
A SAML metadata file can be used to import the required IDP configuration for SAML service provider mode. A SAML metadata file is an XML file that contains information about the identity provider (IDP) and the service provider (SP), such as their entity IDs, endpoints, certificates, and attributes. By importing a SAML metadata file from the IDP, FortiAuthenticator can automatically configure the necessary settings for SAML service provider mode.
NEW QUESTION # 26
When generating a TOTP for two-factor authentication, what two pieces of information are used by the algorithm to generate the TOTP?
- A. UUID and time
- B. Time and seed
- C. Time and FortiAuthenticator serial number
- D. Time and mobile location
Answer: B
Explanation:
TOTP stands for Time-based One-time Password, which is a type of OTP that is generated based on two pieces of information: time and seed. The time is the current timestamp that is synchronized between the client and the server. The seed is a secret key that is shared between the client and the server. The TOTP algorithm combines the time and the seed to generate a unique and short-lived OTP that can be used for two-factor authentication.
NEW QUESTION # 27
Which statement about the guest portal policies is true?
- A. Guest portal policies can be used only for BYODs
- B. All conditions in the policy must match before a user is presented with the guest portal
- C. Conditions in the policy apply only to guest wireless users
- D. Guest portal policies apply only to authentication requests coming from unknown RADIUS clients
Answer: B
Explanation:
Guest portal policies are rules that determine when and how to present the guest portal to users who want to access the network. Each policy has a set of conditions that can be based on various factors, such as the source IP address, MAC address, RADIUS client, user agent, or SSID. All conditions in the policy must match before a user is presented with the guest portal. Guest portal policies can apply to any authentication request coming from any RADIUS client, not just unknown ones. They can also be used for any type of device, not just BYODs. They can also apply to wired or VPN users, not just wireless users. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372404/guest-management/372406/portal-policies
NEW QUESTION # 28
A device or user identity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialis.
In this case, which user idendity discovery method can Fortiauthenticator use?
- A. Radius accounting
- B. Portal authentication
- C. Syslog messaging or SAML IDP
- D. Kerberos-base authentication
Answer: B
Explanation:
Portal authentication is a user identity discovery method that can be used when a device or user identity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentials. Portal authentication requires users to enter their credentials on a web page before accessing network resources. The other methods are used for transparent identification of domain devices or users. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372406/user-identity-discovery
NEW QUESTION # 29
Which EAP method is known as the outer authentication method?
- A. EAP-GTC
- B. MSCHAPV2
- C. EAP-TLS
- D. PEAP
Answer: D
Explanation:
PEAP is known as the outer authentication method because it establishes a secure tunnel between the client and the server using TLS. The inner authentication method, such as EAP-GTC, EAP-TLS, or MSCHAPV2, is then used to authenticate the client within the tunnel.
NEW QUESTION # 30
Which three of the following can be used as SSO sources? (Choose three)
- A. FortiAuthenticator in SAML SP role
- B. Fortigate
- C. SSH Sessions
- D. RADIUS accounting
- E. FortiClient SSO Mobility Agent
Answer: B,D,E
Explanation:
FortiAuthenticator supports various SSO sources that can provide user identity information to other devices in the network, such as FortiGate firewalls or FortiAnalyzer log servers. Some of the supported SSO sources are:
FortiClient SSO Mobility Agent: A software agent that runs on Windows devices and sends user login information to FortiAuthenticator.
FortiGate: A firewall device that can send user login information from various sources, such as FSSO agents, captive portals, VPNs, or LDAP servers, to FortiAuthenticator.
RADIUS accounting: A protocol that can send user login information from RADIUS servers or clients, such as wireless access points or VPN concentrators, to FortiAuthenticator.
SSH sessions and FortiAuthenticator in SAML SP role are not valid SSO sources because they do not provide user identity information to other devices in the network. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372410/single-sign-on
NEW QUESTION # 31
Why would you configure an OCSP responder URL in an end-entity certificate?
- A. To provide the CRL location for the certificate
- B. To identify the end point that a certificate has been assigned to
- C. To designate a server for certificate status checking
- D. To designate the SCEP server to use for CRL updates for that certificate
Answer: C
Explanation:
An OCSP responder URL in an end-entity certificate is used to designate a server for certificate status checking. OCSP stands for Online Certificate Status Protocol, which is a method of verifying whether a certificate is valid or revoked in real time. An OCSP responder is a server that responds to OCSP requests from clients with the status of the certificate in question. The OCSP responder URL in an end-entity certificate points to the location of the OCSP responder that can provide the status of that certificate.
NEW QUESTION # 32
You want to monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP.
Which two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface? (Choose two)
- A. Upload management information base (MIB) files to SNMP server
- B. Set the tresholds to trigger SNMP traps
- C. Associate an ASN, 1 mapping rule to the receiving host
- D. Enable logging services
Answer: A,B
Explanation:
To monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP, two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface:
Set the thresholds to trigger SNMP traps for various system events, such as CPU usage, disk usage, memory usage, or temperature.
Upload management information base (MIB) files to SNMP server to enable the server to interpret the SNMP traps sent by FortiAuthenticator.
NEW QUESTION # 33
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- A. Principal contacts idendity provider and is redirected to service provider, principal establishes connection with service provider, service provider validates authentication with identify provider
- B. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
- C. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
- D. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider
Answer: D
Explanation:
SP-initiated SSO SAML packet flow for a host without a SAML assertion is as follows:
Principal contacts service provider, requesting access to a protected resource.
Service provider redirects principal to identity provider, sending a SAML authentication request.
Principal authenticates with identity provider using their credentials.
After successful authentication, identity provider redirects principal back to service provider, sending a SAML response with a SAML assertion containing the principal's attributes.
Service provider validates the SAML response and assertion, and grants access to the principal.
NEW QUESTION # 34
Examine the screenshot shown in the exhibit.
Which two statements regarding the configuration are true? (Choose two.)
- A. All accounts registered through the guest portal must be validated through email
- B. Guest user account will expire after eight hours
- C. All guest accounts created using the account registration feature will be placed under the Guest_Portal_Users group
- D. Guest users must fill in all the fields on the registration form
Answer: A,C
Explanation:
The screenshot shows that the account registration feature is enabled for the guest portal and that the guest group is set to Guest_Portal_Users. This means that all guest accounts created using this feature will be placed under that group1. The screenshot also shows that email validation is enabled for the guest portal and that the email validation link expires after 24 hours. This means that all accounts registered through the guest portal must be validated through email within that time frame1.
NEW QUESTION # 35
Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)
- A. Validating other CA CRLs using OSCP
- B. Creating, signing, and revoking of X.509 certificates
- C. Merging local and remote CRLs using SCEP
- D. Importing other CA certificates and CRLs
Answer: B,D
Explanation:
FortiAuthenticator can act as a self-signed or local CA that can issue certificates to users, devices, or other CAs. It can also import other CA certificates and CRLs to trust them and validate their certificates. It can also create, sign, and revoke X.509 certificates for various purposes, such as VPN authentication, web server encryption, or wireless security. It cannot validate other CA CRLs using OCSP or merge local and remote CRLs using SCEP because these are protocols that require communication with external CAs. Reference: https://docs.fortinet.com/document/fortiauthenticator/6.4/administration-guide/372408/certificate-management
NEW QUESTION # 36
A system administrator wants to integrate FortiAuthenticator with an existing identity management system with the goal of authenticating and deauthenticating users into FSSO.
What feature does FortiAuthenticator offer for this type of integration?
- A. REST API
- B. The ability to import and export users from CSV files
- C. SNMP monitoring and traps
- D. RADIUS learning mode for migrating users
Answer: A
Explanation:
REST API is a feature that allows FortiAuthenticator to integrate with an existing identity management system with the goal of authenticating and deauthenticating users into FSSO. REST API stands for Representational State Transfer Application Programming Interface, which is a method of exchanging data between different systems using HTTP requests and responses. FortiAuthenticator provides a REST API that can be used by external systems to perform various actions, such as creating, updating, deleting, or querying users and groups, or sending FSSO logon or logoff events.
NEW QUESTION # 37
Why would you configure an OCSP responder URL in an end-entity certificate?
- A. To provide the CRL location for the certificate
- B. To identify the end point that a certificate has been assigned to
- C. To designate a server for certificate status checking
- D. To designate the SCEP server to use for CRL updates for that certificate
Answer: C
Explanation:
An OCSP responder URL in an end-entity certificate is used to designate a server for certificate status checking. OCSP stands for Online Certificate Status Protocol, which is a method of verifying whether a certificate is valid or revoked in real time. An OCSP responder is a server that responds to OCSP requests from clients with the status of the certificate in question. The OCSP responder URL in an end-entity certificate points to the location of the OCSP responder that can provide the status of that certificate.
NEW QUESTION # 38
......
Get professional help from our NSE6_FAC-6.4 Dumps PDF: https://www.exams4sures.com/Fortinet/NSE6_FAC-6.4-practice-exam-dumps.html
Clear your concepts with NSE6_FAC-6.4 Questions Before Attempting Real exam: https://drive.google.com/open?id=1QcyAKpwE9mSCPTSlon7ETR35jDbI0Scb