Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Fortinet NSE6_FAC-6.1 - Fortinet NSE 6 - FortiAuthenticator 6.1

Page: 1 / 1
Total 30 questions

Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)

A.

Validating other CA CRLs using OSCP

B.

Importing other CA certificates and CRLs

C.

Merging local and remote CRLs using SCEP

D.

Creating, signing, and revoking of X.509 certificates

Which behaviors exist for certificate revocation lists (CRLs) on FortiAuthenticator? (Choose two)

A.

CRLs contain the serial number of the certificate that has been revoked

B.

Revoked certificates are automaticlly placed on the CRL

C.

CRLs can beexported only through the SCEP server

D.

All local CAs share the same CRLs

Which interface services must be enabled for the SCEP client to connect to Authenticator?

A.

OCSP

B.

REST API

C.

SSH

D.

HTTP/HTTPS

You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.

What can couse this issue?

A.

On of the FortiAuthenticator devices in the active-active cluster has failed

B.

FortiAuthenticator has lose contact with the FortiToken Cloud servers

C.

FortiToken 200 licence has expired

D.

Time drift between FortiAuthenticator and hardware tokens

Which FSSO discovery method transparently detects logged off users without having to rely on external features such as WMI polling?

A.

Windows AD polling

B.

FortiClient SSO Mobility Agent

C.

Radius Accounting

D.

DC Polling

What happens when a certificate is revoked? (Choose two)

A.

Revoked certificates cannot be reinstated for any reason

B.

All certificates signed by a revoked CA certificate are automatically revoked

C.

Revoked certificates are automatically added to the CRL

D.

External CAs will priodically query Fortiauthenticator and automatically download revoked certificates

At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator? (Choose two)

A.

Configuring a portal policy

B.

Configuring at least on post-login service

C.

Configuring a RADIUS client

D.

Configuring an external authentication portal

How can a SAML metada file be used?

A.

To defined a list of trusted user names

B.

To import the required IDP configuration

C.

To correlate the IDP address to its hostname

D.

To resolve the IDP realm for authentication

You are the administrator of a large network that includes a large local user datadabase on the current Fortiauthenticatior. You want to import all the local users into a new Fortiauthenticator device.

Which method should you use to migrate the local users?

A.

Import users using RADIUS accounting updates.

B.

Import the current directory structure.

C.

Import users fromRADUIS.

D.

Import users using a CSV file.