
View All NSE6_FAC-6.1 Actual Exam Questions, Answers and Explanations for Free
NSE6_FAC-6.1 Exam Free Practice Test with100% Accurate Answers
NEW QUESTION 12
Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)
- A. Creating, signing, and revoking of X.509 certificates
- B. Merging local and remote CRLs using SCEP
- C. Importing other CA certificates and CRLs
- D. Validating other CA CRLs using OSCP
Answer: A,C
NEW QUESTION 13
Which three of the following can be used as SSO sources? (Choose three)
- A. RADIUS accounting
- B. FortiClient SSO Mobility Agent
- C. SSH Sessions
- D. Fortigate
- E. FortiAuthenticator in SAML SP role
Answer: A,B,E
NEW QUESTION 14
Which behaviors exist for certificate revocation lists (CRLs) on FortiAuthenticator? (Choose two)
- A. Revoked certificates are automaticlly placed on the CRL
- B. All local CAs share the same CRLs
- C. CRLs contain the serial number of the certificate that has been revoked
- D. CRLs can beexported only through the SCEP server
Answer: A,C
NEW QUESTION 15
A device or useridentity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialis.
In this case, which user idendity discovery method can Fortiauthenticator use?
- A. Radius accounting
- B. Kerberos-base authentication
- C. Syslog messaging or SAML IDP
- D. Portal authentication
Answer: D
NEW QUESTION 16
Which method is the most secure way of delivering FortiToken data once the token has been seeded?
- A. Using the in-house token provisioning tool
- B. Automatic token generation using FortiAuthenticator
- C. Online activation of the tokens through the FortiGuard network
- D. Shipment of the seed files on a CD using a tamper-evident envelope
Answer: D
NEW QUESTION 17
What happens when a certificate is revoked? (Choose two)
- A. Revoked certificates cannot be reinstated for any reason
- B. All certificates signed by a revoked CA certificate are automatically revoked
- C. External CAs will priodically query Fortiauthenticator and automatically download revoked certificates
- D. Revoked certificates are automatically added to the CRL
Answer: C,D
NEW QUESTION 18
Which two types of digital certificates can you create in Fortiauthenticator? (Choose two)
- A. Organization validation certificate
- B. Local service certificate
- C. Third-party root certificate
- D. Usercertificate
Answer: B,D
NEW QUESTION 19
You are a Wi-Fi provider and host multiple domains. How do you delegate user accounts, user groups and permissions per domain when theyare authenticating on a single FortiAuthenticator device?
- A. Automatically import hosts from each domain as they authenticate
- B. Create user groups
- C. Create realms
- D. Create multiple directory trees on FortiAuthenticator
Answer: C
NEW QUESTION 20
What are three key features of FortiAuthenticator? (Choose three)
- A. Log server
- B. Identity management device
- C. RSSO Server
- D. Portal services
- E. Certificate authority
Answer: B,D,E
NEW QUESTION 21
Which EAP method is known as the outer authentication method?
- A. EAP-GTC
- B. MSCHAPV2
- C. EAP-TLS
- D. PEAP
Answer: D
NEW QUESTION 22
Which two SAML roles can Fortiauthenticator be configured as? (Choose two)
- A. Assertion server
- B. Idendity provider
- C. Service provider
- D. Principal
Answer: B,C
NEW QUESTION 23
Which two features of FortiAuthenticator are used for EAP deployment? (Choose two)
- A. Certificate authority
- B. RADIUS server
- C. LDAP server
- D. MAC authentication bypass
Answer: A,B
NEW QUESTION 24
......
NSE6_FAC-6.1 dumps Free Test Engine Verified By It Certified Experts: https://measureup.preppdf.com/Fortinet/NSE6_FAC-6.1-prepaway-exam-dumps.html