Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

An administrator wants FortiNAC-F to return a group of user-defined RADIUS attributes in RADIUS responses.

Which condition must be true to achieve this?

A.

The requesting device must support RFC 5176.

B.

Inbound RADIUS requests must contain the Calling-Station-ID attribute.

C.

The device models in the inventory view must be configured for proxy-based authentication.

D.

RADIUS accounting must be enabled on the FortiNAC-F RADIUS server configuration.

During an evaluation of state-based enforcement, an administrator discovers that ports that should not be under enforcement have been added to enforcement groups.

In which view would the administrator be able to identify who added the ports to the groups?

(Selected)

A.

The Admin Auditing view

B.

The Event Management view

C.

The Port Changes view

D.

The Security Events view

Refer to the exhibits.

An administrator is troubleshooting visibility issues on a modeled switch The switch is configured to use link traps and to provision hosts based on network access policies. The administrator is seeing hosts on ports with no hosts connected and not seeing hosts on ports where hosts are known to be connected.

What is the most likely cause?

A.

The logical networks are set to deny.

B.

The host has uninstalled the FortiNAC-F agent.

C.

The switch cannot be contacted by FortiNAC-F

D.

The credentials are incorrect.

Refer to the exhibit.

An administrator is configuring FortiNAC-F (or the onboarding of guest users. Which IP address would be used for the gateway defined in the DHCP scope?

A.

10.0.1.254

B.

10.0.1.110

C.

10.10.1.250

D.

10.20.1.250

Refer to the exhibit.

Which devices are automatically evaluated by these device profiling rules?

A.

Rogue devices, only when they are initially added to the database

B.

Known trusted devices, each time they connect

C.

All hosts, each time they connect

D.

Rogue devices, each time they change location

Refer to the exhibits.

Given the current configuration, what would happen if a contractor triggered two of the defined security filters?

A.

Two security events would be generated, but no security alarm would be generated

B.

A security alarm and two security events would be generated.

C.

Three security events and one security alarm would be generated.

D.

A security event and a security alarm would be generated.

An administrator wants FortiNAC-F to pass firewall tags to FortiGate to leverage dynamic address groups used in firewall policies. On FortiNAC-F, what determines the values that are passed?

A.

Model configuration

B.

Device profiling rule

C.

Security rule

D.

RADIUS group attribute

Two FortiNAC-F devices have been configured as a 1 + 1 HA pair. The primary server went offline and a successful failover to the secondary has occurred. What happens if the primary server comes back online?

A.

The primary and secondary servers will resume communication and the secondary will maintain control.

B.

The secondary server will update the primary and the servers will load balance until an administrator forces the primary to resume full control.

C.

The primary server will determine that the secondary has control and power down for maintenance.

D.

After five successful heartbeats between the servers, the primary server will resume control.

Refer to the exhibits.

What would happen if the highlighted port with connected hosts was placed in both the Forced Registration and Forced Remediation port groups?

A.

Both types of enforcement would be applied

B.

Enforcement would be applied only to rogue hosts

C.

Multiple enforcement groups could not contain the same port.

D.

Only the higher ranked enforcement group would be applied.

While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen to use the shared IP address option.

Which condition must be met for this type of deployment?

A.

The isolation network type is layer 3.

B.

There is a direct cable link between FortiNAC-F devices.

C.

The primary and secondary administrative interfaces are on the same subnet.

D.

The isolation network type is Layer 2.