[Feb 11, 2023] Latest NSE6_FAC-6.1 Exam with Accurate Fortinet NSE 6 - FortiAuthenticator 6.1 PDF Questions
Practice To NSE6_FAC-6.1 - ExamDumpsVCE Remarkable Practice On your Fortinet NSE 6 - FortiAuthenticator 6.1 Exam
NEW QUESTION 11
At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator?
(Choose two)
- A. Configuring at least on post-login service
- B. Configuring a portal policy
- C. Configuring an external authentication portal
- D. Configuring a RADIUS client
Answer: A,B
NEW QUESTION 12
A device or useridentity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialis.
In this case, which user idendity discovery method can Fortiauthenticator use?
- A. Syslog messaging or SAML IDP
- B. Kerberos-base authentication
- C. Portal authentication
- D. Radius accounting
Answer: C
NEW QUESTION 13
Which two features of FortiAuthenticator are used for EAP deployment? (Choose two)
- A. LDAP server
- B. RADIUS server
- C. Certificate authority
- D. MAC authentication bypass
Answer: B,C
NEW QUESTION 14
Which of the following is an QATH-based standart to generate event-based, one-time password tokens?
- A. TOTP
- B. OLTP
- C. HOTP
- D. SOTP
Answer: C
NEW QUESTION 15
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the masterFortiAuthenticator?
- A. Active-passive master
- B. Load balancing master
- C. Cluster member
- D. Standalone master
Answer: C
NEW QUESTION 16
Which three of the following can be used as SSO sources? (Choose three)
- A. FortiAuthenticator in SAML SP role
- B. FortiClient SSO Mobility Agent
- C. Fortigate
- D. RADIUS accounting
- E. SSH Sessions
Answer: A,B,D
NEW QUESTION 17
Refer to the exhibit.
Examine the screenshot shown in the exhibit.
Which two statements regarding the configuration are true? (Choose two)
- A. Guest users must fill in all the fields on the registration form
- B. All guest accounts created using the account registration feature will be placed under the Guest_Portal_Users group
- C. All accounts registered through the guest portal must be validated through email
- D. Guest user account will expire after eight hours
Answer: B,C
NEW QUESTION 18
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- A. Principal contacts service provider, service provider redirects principal to idendity provider, after succesfull authentication identify provider redirects principal to service provider
- B. Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal
- C. Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication
- D. Principal contacts idendity provider and is redirected to serviceprovider, principal establishes connection with service provider, service provider validates authentication with identify provider
Answer: A
NEW QUESTION 19
Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)
- A. Merging local and remote CRLs using SCEP
- B. Validating other CA CRLs using OSCP
- C. Creating, signing, and revoking of X.509 certificates
- D. Importing other CA certificates and CRLs
Answer: C,D
NEW QUESTION 20
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.
What can couse this issue?
- A. FortiAuthenticator has lose contact with the FortiToken Cloud servers
- B. Time drift between FortiAuthenticator and hardware tokens
- C. FortiToken 200 licence has expired
- D. On of the FortiAuthenticator devices in the active-active cluster has failed
Answer: B
NEW QUESTION 21
Which two are supported captive or guest portal authentication methods? (Choose two)
- A. Linkedln
- B. Instagram
- C. Apple ID
- D. Email
Answer: A,D
NEW QUESTION 22
How can a SAML metada file be used?
- A. To resolve the IDP realm for authentication
- B. To correlate the IDP address to its hostname
- C. To import the required IDP configuration
- D. To defined a list of trusted user names
Answer: C
NEW QUESTION 23
......
Exam Questions and Answers for NSE6_FAC-6.1 Study Guide Questions and Answers!: https://www.examdumpsvce.com/NSE6_FAC-6.1-valid-exam-dumps.html
