Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Fortinet NSE 6 Network Security Specialist NSE6_FAC-6.4 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam NSE6_FAC-6.4 Premium Access

View all detail and faqs for the NSE6_FAC-6.4 exam


389 Students Passed

91% Average Score

95% Same Questions
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

What happens when a certificate is revoked? (Choose two)

Options:

A.

Revoked certificates cannot be reinstated for any reason

B.

All certificates signed by a revoked CA certificate are automatically revoked

C.

Revoked certificates are automatically added to the CRL

D.

External CAs will priodically query Fortiauthenticator and automatically download revoked certificates

Questions # 2:

An administrator wants to keep local CA cryptographic keys stored in a central location.

Which FortiAuthenticator feature would provide this functionality?

Options:

A.

SCEP support

B.

REST API

C.

Network HSM

D.

SFTP server

Questions # 3:

Which statement about the assignment of permissions for sponsor and administrator accounts is true?

Options:

A.

Only administrator accounts permissions are assigned using admin profiles.

B.

Sponsor permissions are assigned using group settings.

C.

Administrator capabilities are assigned by applying permission sets to admin groups.

D.

Both sponsor and administrator account permissions are assigned using admin profiles.

Questions # 4:

Which two are supported captive or guest portal authentication methods? (Choose two)

Options:

A.

Linkedln

B.

Apple ID

C.

Instagram

D.

Email

Questions # 5:

Which two features of FortiAuthenticator are used for EAP deployment? (Choose two)

Options:

A.

Certificate authority

B.

LDAP server

C.

MAC authentication bypass

D.

RADIUS server

Questions # 6:

A device or user identity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialis.

In this case, which user idendity discovery method can Fortiauthenticator use?

Options:

A.

Syslog messaging or SAML IDP

B.

Kerberos-base authentication

C.

Radius accounting

D.

Portal authentication

Questions # 7:

Which behaviors exist for certificate revocation lists (CRLs) on FortiAuthenticator? (Choose two)

Options:

A.

CRLs contain the serial number of the certificate that has been revoked

B.

Revoked certificates are automaticlly placed on the CRL

C.

CRLs can be exported only through the SCEP server

D.

All local CAs share the same CRLs

Questions # 8:

You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.

What can cause this issue?

Options:

A.

FortiToken 200 license has expired

B.

One of the FortiAuthenticator devices in the active-active cluster has failed

C.

Time drift between FortiAuthenticator and hardware tokens

D.

FortiAuthenticator has lost contact with the FortiToken Cloud servers

Questions # 9:

An administrator is integrating FortiAuthenticator with an existing RADIUS server with the intent of eventually replacing the RADIUS server with FortiAuthenticator.

How can FortiAuthenticator help facilitate this process?

Options:

A.

By configuring the RADIUS accounting proxy

B.

By enabling automatic REST API calls from the RADIUS server

C.

By enabling learning mode in the RADIUS server configuration

D.

By importing the RADIUS user records

Questions # 10:

Which EAP method is known as the outer authentication method?

Options:

A.

PEAP

B.

EAP-GTC

C.

EAP-TLS

D.

MSCHAPV2

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.