NSE6_FNC-7.2問題集には練習試験問題解答
NSE6_FNC-7.2はFCP in Network Security実際の無料試験練習テスト
Fortinet NSE6_FNC-7.2 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
| トピック 8 |
|
| トピック 9 |
|
質問 # 27
Which devices would be evaluated by device profiling rules?
- A. Known trusted devices, each time they change location
- B. Rogue devices, each time they connect
- C. Rogue devices, only when they are initially added to the database
- D. All hosts, each time they connect
正解:B
質問 # 28
Which system group will force at-risk hosts into the quarantine network, based on point of connection?
- A. Physical Address Filtering
- B. Forced Remediation
- C. Forced Quarantine
- D. Forced Isolation
正解:B
解説:
Forced Quarantine, study guide 7.2 pag 245 and 248
質問 # 29
What causes a host's state to change to "at risk"?
- A. The host has failed an endpoint compliance policy or admin scan.
- B. The host has been administratively disabled.
- C. The host is not in the Registered Hosts group.
- D. The logged on user is not found in the Active Directory.
正解:A
解説:
Failure - Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.
Reference:
p. 244 of the Study Guide, "A state of at-risk indicates the host has failed a scan. This could be a compliance scan or an administrative scan."
質問 # 30
Two FortiNAC devices have been configured in an HA configuration. After five failed heartbeats between the primary device and secondary device, the primary device fail to ping the designated gateway. What happens next?
- A. The primary device changes its designation to secondary, and the secondary device changes to primary.
- B. The primary device continues to operate as the in-control device and changes the status or secondary device to contact lost.
- C. The primary device shuts down NAC processes and changes to a management down status.
- D. The primary device waits 3 minutes and attempts to re-establish the HA heartbeat before attempting a second ping of the gateway.
正解:C
質問 # 31
Refer to the exhibit.
If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what occurs?
- A. The host is moved to a default isolation VLAN.
- B. The host is moved to VLAN 111.
- C. The host is disabled.
- D. No VLAN change is performed.
正解:B
解説:
The exhibit shows a configuration panel where VLAN IDs are specified for different states, such as Default, Registration, and Authentication. When forcing the registration of unknown (rogue) hosts, if an unknown host connects to a port on the switch, the FortiNAC system will move the host to the VLAN designated for Registration. In the exhibit, the VLAN ID for Registration is set to 111, hence the host would be moved to VLAN 111 to undergo the registration process.
質問 # 32
Refer to the exhibit.
If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?
- A. The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.
- B. The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
- C. The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.
- D. The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
正解:B
解説:
Looking at the provided exhibit which shows the Modify User/Host Profile window, the following must be true for a host to match the user/host profile:
* The host must be connected to a port within the "Building 1 First Floor Ports" group.
* The host must fulfill at least one of the following attributes:
* Have a role value of "Contractor"
* Have an installed persistent agent with the security and access value of "Contractor"
* The host must be connected between the specified times of 6 AM and 5 PM on any day of the week.
The profile specifies that the host can match the profile by having any one of the listed attributes (Role as Contractor, Persistent Agent installed with specific security & access value), and the time condition must also be met. Therefore, the correct answer is D, which includes "or" conditions for the role value and persistent agent and specifies the correct time frame.
質問 # 33
Refer to the exhibit, and then answer the question below.
Which host is rogue?
- A. 0
- B. 1
- C. 2
- D. 3
正解:D
質問 # 34
Which connecting endpoints are evaluated against all enabled device profiling rules?
- A. Rogues devices, each time they connect
- B. All hosts, each time they connect
- C. Known trusted devices each time they change location
- D. Rogues devices, only when they connect for the first time
正解:A
質問 # 35
What capability do logical networks provide?
- A. Autopopulation of device groups based on point of connection
- B. Interactive topology view diagrams
- C. VLAN-based inventory reporting
- D. Application of different access values from a single access policy
正解:D
解説:
Explanation:
質問 # 36
Which two device classification options can register a device automatically and transparently to the end user? (Choose two.)
- A. Device importing
- B. Captive portal
- C. MDM integration
- D. DotlxAuto Registration
- E. Dissolvable agent
正解:C、D
質問 # 37
Which three of the following are components of a security rule? (Choose three.)
- A. User or host profile
- B. Trigger
- C. Action
- D. Security String
- E. Methods
正解:A、B、C
質問 # 38
Which agent can receive and display messages from FortiNAC to the end user?
- A. Passive
- B. Persistent
- C. Dissolvable
- D. MDM
正解:B
解説:
The persistent agent has the ability to display messages on the desktop of an endpoint. These messages can target an individual host, a group of hosts, or all hosts with the persistent agent installed. The messaging options include sending a message content with an optional web address link
質問 # 39
Where do you look to determine what network access policy, if any, is being applied to a particular host?
- A. The Port Properties view of the hosts port
- B. The Policy Details view for the host
- C. The network access policy configuration
- D. The Policy Logs view
正解:D
質問 # 40
Which two of the following are required for endpoint compliance monitors? (Choose two.)
- A. Persistent agent
- B. Logged on user
- C. Custom scan
- D. Security rule
正解:A、C
解説:
DirectDefense's analysis of FireEye Endpoint attests that the products help meet the HIPAA Security Rule.
In the menu on the left click the + sign next to Endpoint Compliance to open it.
Reference:
https://docs.fortinet.com/document/fortinac/8.5.2/administration-guide/92047/add-or-modify-a-scan
質問 # 41
Which agent is used only as part of a login script?
- A. Mobile
- B. Passive
- C. Persistent
- D. Dissolvable
正解:B
解説:
In the context of network access control systems like FortiNAC, a dissolvable agent is typically a piece of software that is executed on the endpoint as part of a login script or when a user accesses a captive portal. It runs once to gather information or enforce policies and then removes itself from the system, hence the term
"dissolvable."
References
* FortiNAC documentation on agent deployment and types of agents.
質問 # 42
What method of communication does FortiNAC use to control VPN host access on FortiGate?
- A. RSSO
- B. RADIUS accounting
- C. SAMLSSO
- D. Security Fabric
正解:D
質問 # 43
Where should you configure MAC notification traps on a supported switch?
- A. Configure them on all ports on the switch.
- B. Configure them only on ports set as 802 1g trunks.
- C. Configure them on all ports except uplink ports.
- D. Configure them only after you configure linkup and linkdown traps.
正解:C
質問 # 44
Refer to the exhibit, and then answer the question below.
Which host is rogue?
- A. 0
- B. 1
- C. 2
- D. 3
正解:D
質問 # 45
Which two agents can validate endpoint compliance transparently to the end user? (Choose two.)
- A. Mobile
- B. Dissolvable
- C. Passive
- D. Persistent
正解:B、D
解説:
Both dissolvable and persistent agents can be used to validate endpoint compliance transparently to the end user. The persistent agent stays resident on the endpoint and performs scheduled scans in the background. The dissolvable agent is a run-once agent that dissolves after reporting its results, leaving no footprint on the endpoint
質問 # 46
Which agent is used only as part of a login script?
- A. Mobile
- B. Passive
- C. Persistent
- D. Dissolvable
正解:C
質問 # 47
What would happen if a port was placed in both the Forced Registration and the Forced Remediation port groups?
- A. Only rogue hosts would be impacted.
- B. Both enforcement groups cannot contain the same port.
- C. Both types of enforcement would be applied.
- D. Only al-risk hosts would be impacted.
正解:A
質問 # 48
Which two policy types can be created on a FortiNAC Control Manager? (Choose two.)
- A. Supplicant EasvConnect
- B. Authentication
- C. Endpoint Compliance
- D. Network Access
正解:C、D
質問 # 49
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)
- A. Linkup and Linkdown traps
- B. A matched security policy
- C. A failed Layer 3 poll
- D. Scheduled poll timings
- E. Manual polling
正解:A、D、E
質問 # 50
Where are logical network values defined?
- A. In the security and access field of each host record
- B. In the model configuration view of each infrastructure device
- C. In the port properties view of each port
- D. On the profiled devices view
正解:B
質問 # 51
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)
- A. Linkup and Linkdown traps
- B. A matched security policy
- C. A failed Layer 3 poll
- D. Scheduled poll timings
- E. Manual polling
正解:A、D、E
解説:
A: Manual Polling: This is when an administrator or network operator initiates a poll manually to gather information or check the status of the network devices. This can be done for immediate troubleshooting or assessment.
B: Scheduled Poll Timings: Network management systems often have the capability to schedule regular polls of devices to check their status or monitor their performance. These scheduled polls can be set at regular intervals (such as every few minutes, hours, or daily) depending on the requirements of the network.
E: Linkup and Linkdown Traps: SNMP (Simple Network Management Protocol) traps, like Linkup and Linkdown, are automated notifications sent from network devices to a management system. A Linkup trap indicates that a particular interface has become active (up), while a Linkdown trap indicates that an interface has become inactive (down). These traps can trigger Layer 2 polling to ascertain the current status of network interfaces and devices.
質問 # 52
......
無料FCP in Network Security NSE6_FNC-7.2試験問題:https://jp.fast2test.com/NSE6_FNC-7.2-premium-file.html