View All NSE6_FAC-6.1 Actual Exam Questions, Answers and Explanations for Free [Q12-Q31]

Share

View All NSE6_FAC-6.1 Actual Exam Questions, Answers and Explanations for Free

NSE6_FAC-6.1 Exam Free Practice Test with100% Accurate Answers

NEW QUESTION 12
Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)

  • A. Creating, signing, and revoking of X.509 certificates
  • B. Merging local and remote CRLs using SCEP
  • C. Importing other CA certificates and CRLs
  • D. Validating other CA CRLs using OSCP

Answer: A,C

 

NEW QUESTION 13
Which three of the following can be used as SSO sources? (Choose three)

  • A. RADIUS accounting
  • B. FortiClient SSO Mobility Agent
  • C. SSH Sessions
  • D. Fortigate
  • E. FortiAuthenticator in SAML SP role

Answer: A,B,E

 

NEW QUESTION 14
Which behaviors exist for certificate revocation lists (CRLs) on FortiAuthenticator? (Choose two)

  • A. Revoked certificates are automaticlly placed on the CRL
  • B. All local CAs share the same CRLs
  • C. CRLs contain the serial number of the certificate that has been revoked
  • D. CRLs can beexported only through the SCEP server

Answer: A,C

 

NEW QUESTION 15
A device or useridentity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialis.
In this case, which user idendity discovery method can Fortiauthenticator use?

  • A. Radius accounting
  • B. Kerberos-base authentication
  • C. Syslog messaging or SAML IDP
  • D. Portal authentication

Answer: D

 

NEW QUESTION 16
Which method is the most secure way of delivering FortiToken data once the token has been seeded?

  • A. Using the in-house token provisioning tool
  • B. Automatic token generation using FortiAuthenticator
  • C. Online activation of the tokens through the FortiGuard network
  • D. Shipment of the seed files on a CD using a tamper-evident envelope

Answer: D

 

NEW QUESTION 17
What happens when a certificate is revoked? (Choose two)

  • A. Revoked certificates cannot be reinstated for any reason
  • B. All certificates signed by a revoked CA certificate are automatically revoked
  • C. External CAs will priodically query Fortiauthenticator and automatically download revoked certificates
  • D. Revoked certificates are automatically added to the CRL

Answer: C,D

 

NEW QUESTION 18
Which two types of digital certificates can you create in Fortiauthenticator? (Choose two)

  • A. Organization validation certificate
  • B. Local service certificate
  • C. Third-party root certificate
  • D. Usercertificate

Answer: B,D

 

NEW QUESTION 19
You are a Wi-Fi provider and host multiple domains. How do you delegate user accounts, user groups and permissions per domain when theyare authenticating on a single FortiAuthenticator device?

  • A. Automatically import hosts from each domain as they authenticate
  • B. Create user groups
  • C. Create realms
  • D. Create multiple directory trees on FortiAuthenticator

Answer: C

 

NEW QUESTION 20
What are three key features of FortiAuthenticator? (Choose three)

  • A. Log server
  • B. Identity management device
  • C. RSSO Server
  • D. Portal services
  • E. Certificate authority

Answer: B,D,E

 

NEW QUESTION 21
Which EAP method is known as the outer authentication method?

  • A. EAP-GTC
  • B. MSCHAPV2
  • C. EAP-TLS
  • D. PEAP

Answer: D

 

NEW QUESTION 22
Which two SAML roles can Fortiauthenticator be configured as? (Choose two)

  • A. Assertion server
  • B. Idendity provider
  • C. Service provider
  • D. Principal

Answer: B,C

 

NEW QUESTION 23
Which two features of FortiAuthenticator are used for EAP deployment? (Choose two)

  • A. Certificate authority
  • B. RADIUS server
  • C. LDAP server
  • D. MAC authentication bypass

Answer: A,B

 

NEW QUESTION 24
......

NSE6_FAC-6.1 dumps Free Test Engine Verified By It Certified Experts: https://measureup.preppdf.com/Fortinet/NSE6_FAC-6.1-prepaway-exam-dumps.html