NSE6_FNC-7.2問題集には練習試験問題解答 [Q27-Q52]

Share

NSE6_FNC-7.2問題集には練習試験問題解答

NSE6_FNC-7.2はFCP in Network Security実際の無料試験練習テスト


Fortinet NSE6_FNC-7.2 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • State-Based Control: In this exam section the focus is given to controlling access to the network based on the state of its devices used.
トピック 2
  • FortiGate VPN, High Availability, and FortiNAC Control Manager Integrations: In this section of the exam, the focus is given to managing VPN access; it also covers how to ensure proper FortiNAC integration with the main management system.
トピック 3
  • Security Policies: In this section, policies are discussed related to rules that are used to improve the control over network access and devices.
トピック 4
  • Security Device Integration and Automated Response: In this section of the exam, involves using FortiNAC with different security devices and how to automate incident response.
トピック 5
  • Introduction and Initial Configuration: This particular section of the exam covers configuring FortiNAC for basic operation.
トピック 6
  • Identification and Classification of Rogues: In this section of the exam, the focus is given to detecting and classifying devices that are unauthenticated in the FortiNAC network.
トピック 7
  • Visibility, Troubleshooting, and Logging: In this exam section, the focus is given to monitoring network activity, maintaining network problems, and managing logs.
トピック 8
  • Guest and Contractor Management: In this section of the exam, a topic discussed offering secure and temporary network access. This includes giving access to contractors as well as guests.
トピック 9
  • Logical Networks, Fortinet Security Fabric, and Firewall Tags: This section deals with topics such as how to segment the network parts and integrate them with integrating with FortiGate firewalls.

 

質問 # 27
Which devices would be evaluated by device profiling rules?

  • A. Known trusted devices, each time they change location
  • B. Rogue devices, each time they connect
  • C. Rogue devices, only when they are initially added to the database
  • D. All hosts, each time they connect

正解:B


質問 # 28
Which system group will force at-risk hosts into the quarantine network, based on point of connection?

  • A. Physical Address Filtering
  • B. Forced Remediation
  • C. Forced Quarantine
  • D. Forced Isolation

正解:B

解説:
Forced Quarantine, study guide 7.2 pag 245 and 248


質問 # 29
What causes a host's state to change to "at risk"?

  • A. The host has failed an endpoint compliance policy or admin scan.
  • B. The host has been administratively disabled.
  • C. The host is not in the Registered Hosts group.
  • D. The logged on user is not found in the Active Directory.

正解:A

解説:
Failure - Indicates that the host has failed the scan. This option can also be set manually. When the status is set to Failure the host is marked "At Risk" for the selected scan.
Reference:
p. 244 of the Study Guide, "A state of at-risk indicates the host has failed a scan. This could be a compliance scan or an administrative scan."


質問 # 30
Two FortiNAC devices have been configured in an HA configuration. After five failed heartbeats between the primary device and secondary device, the primary device fail to ping the designated gateway. What happens next?

  • A. The primary device changes its designation to secondary, and the secondary device changes to primary.
  • B. The primary device continues to operate as the in-control device and changes the status or secondary device to contact lost.
  • C. The primary device shuts down NAC processes and changes to a management down status.
  • D. The primary device waits 3 minutes and attempts to re-establish the HA heartbeat before attempting a second ping of the gateway.

正解:C


質問 # 31
Refer to the exhibit.

If you are forcing the registration of unknown (rogue) hosts, and an unknown (rogue) host connects to a port on the switch, what occurs?

  • A. The host is moved to a default isolation VLAN.
  • B. The host is moved to VLAN 111.
  • C. The host is disabled.
  • D. No VLAN change is performed.

正解:B

解説:
The exhibit shows a configuration panel where VLAN IDs are specified for different states, such as Default, Registration, and Authentication. When forcing the registration of unknown (rogue) hosts, if an unknown host connects to a port on the switch, the FortiNAC system will move the host to the VLAN designated for Registration. In the exhibit, the VLAN ID for Registration is set to 111, hence the host would be moved to VLAN 111 to undergo the registration process.


質問 # 32
Refer to the exhibit.

If a host is connected to a port in the Building 1 First Floor Ports group, what must also be true to match this user/host profile?

  • A. The host must have a role value of contractor or an installed persistent agent, a security access value of contractor, and be connected between 9 AM and 5 PM.
  • B. The host must have a role value of contractor or an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.
  • C. The host must have a role value of contractor or an installed persistent agent and a security access value of contractor, and be connected between 6 AM and 5 PM.
  • D. The host must have a role value of contractor, an installed persistent agent or a security access value of contractor, and be connected between 6 AM and 5 PM.

正解:B

解説:
Looking at the provided exhibit which shows the Modify User/Host Profile window, the following must be true for a host to match the user/host profile:
* The host must be connected to a port within the "Building 1 First Floor Ports" group.
* The host must fulfill at least one of the following attributes:
* Have a role value of "Contractor"
* Have an installed persistent agent with the security and access value of "Contractor"
* The host must be connected between the specified times of 6 AM and 5 PM on any day of the week.
The profile specifies that the host can match the profile by having any one of the listed attributes (Role as Contractor, Persistent Agent installed with specific security & access value), and the time condition must also be met. Therefore, the correct answer is D, which includes "or" conditions for the role value and persistent agent and specifies the correct time frame.


質問 # 33
Refer to the exhibit, and then answer the question below.

Which host is rogue?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

正解:D


質問 # 34
Which connecting endpoints are evaluated against all enabled device profiling rules?

  • A. Rogues devices, each time they connect
  • B. All hosts, each time they connect
  • C. Known trusted devices each time they change location
  • D. Rogues devices, only when they connect for the first time

正解:A


質問 # 35
What capability do logical networks provide?

  • A. Autopopulation of device groups based on point of connection
  • B. Interactive topology view diagrams
  • C. VLAN-based inventory reporting
  • D. Application of different access values from a single access policy

正解:D

解説:
Explanation:


質問 # 36
Which two device classification options can register a device automatically and transparently to the end user? (Choose two.)

  • A. Device importing
  • B. Captive portal
  • C. MDM integration
  • D. DotlxAuto Registration
  • E. Dissolvable agent

正解:C、D


質問 # 37
Which three of the following are components of a security rule? (Choose three.)

  • A. User or host profile
  • B. Trigger
  • C. Action
  • D. Security String
  • E. Methods

正解:A、B、C


質問 # 38
Which agent can receive and display messages from FortiNAC to the end user?

  • A. Passive
  • B. Persistent
  • C. Dissolvable
  • D. MDM

正解:B

解説:
The persistent agent has the ability to display messages on the desktop of an endpoint. These messages can target an individual host, a group of hosts, or all hosts with the persistent agent installed. The messaging options include sending a message content with an optional web address link


質問 # 39
Where do you look to determine what network access policy, if any, is being applied to a particular host?

  • A. The Port Properties view of the hosts port
  • B. The Policy Details view for the host
  • C. The network access policy configuration
  • D. The Policy Logs view

正解:D


質問 # 40
Which two of the following are required for endpoint compliance monitors? (Choose two.)

  • A. Persistent agent
  • B. Logged on user
  • C. Custom scan
  • D. Security rule

正解:A、C

解説:
DirectDefense's analysis of FireEye Endpoint attests that the products help meet the HIPAA Security Rule.
In the menu on the left click the + sign next to Endpoint Compliance to open it.
Reference:
https://docs.fortinet.com/document/fortinac/8.5.2/administration-guide/92047/add-or-modify-a-scan


質問 # 41
Which agent is used only as part of a login script?

  • A. Mobile
  • B. Passive
  • C. Persistent
  • D. Dissolvable

正解:B

解説:
In the context of network access control systems like FortiNAC, a dissolvable agent is typically a piece of software that is executed on the endpoint as part of a login script or when a user accesses a captive portal. It runs once to gather information or enforce policies and then removes itself from the system, hence the term
"dissolvable."
References
* FortiNAC documentation on agent deployment and types of agents.


質問 # 42
What method of communication does FortiNAC use to control VPN host access on FortiGate?

  • A. RSSO
  • B. RADIUS accounting
  • C. SAMLSSO
  • D. Security Fabric

正解:D


質問 # 43
Where should you configure MAC notification traps on a supported switch?

  • A. Configure them on all ports on the switch.
  • B. Configure them only on ports set as 802 1g trunks.
  • C. Configure them on all ports except uplink ports.
  • D. Configure them only after you configure linkup and linkdown traps.

正解:C


質問 # 44
Refer to the exhibit, and then answer the question below.

Which host is rogue?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

正解:D


質問 # 45
Which two agents can validate endpoint compliance transparently to the end user? (Choose two.)

  • A. Mobile
  • B. Dissolvable
  • C. Passive
  • D. Persistent

正解:B、D

解説:
Both dissolvable and persistent agents can be used to validate endpoint compliance transparently to the end user. The persistent agent stays resident on the endpoint and performs scheduled scans in the background. The dissolvable agent is a run-once agent that dissolves after reporting its results, leaving no footprint on the endpoint


質問 # 46
Which agent is used only as part of a login script?

  • A. Mobile
  • B. Passive
  • C. Persistent
  • D. Dissolvable

正解:C


質問 # 47
What would happen if a port was placed in both the Forced Registration and the Forced Remediation port groups?

  • A. Only rogue hosts would be impacted.
  • B. Both enforcement groups cannot contain the same port.
  • C. Both types of enforcement would be applied.
  • D. Only al-risk hosts would be impacted.

正解:A


質問 # 48
Which two policy types can be created on a FortiNAC Control Manager? (Choose two.)

  • A. Supplicant EasvConnect
  • B. Authentication
  • C. Endpoint Compliance
  • D. Network Access

正解:C、D


質問 # 49
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)

  • A. Linkup and Linkdown traps
  • B. A matched security policy
  • C. A failed Layer 3 poll
  • D. Scheduled poll timings
  • E. Manual polling

正解:A、D、E


質問 # 50
Where are logical network values defined?

  • A. In the security and access field of each host record
  • B. In the model configuration view of each infrastructure device
  • C. In the port properties view of each port
  • D. On the profiled devices view

正解:B


質問 # 51
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)

  • A. Linkup and Linkdown traps
  • B. A matched security policy
  • C. A failed Layer 3 poll
  • D. Scheduled poll timings
  • E. Manual polling

正解:A、D、E

解説:
A: Manual Polling: This is when an administrator or network operator initiates a poll manually to gather information or check the status of the network devices. This can be done for immediate troubleshooting or assessment.
B: Scheduled Poll Timings: Network management systems often have the capability to schedule regular polls of devices to check their status or monitor their performance. These scheduled polls can be set at regular intervals (such as every few minutes, hours, or daily) depending on the requirements of the network.
E: Linkup and Linkdown Traps: SNMP (Simple Network Management Protocol) traps, like Linkup and Linkdown, are automated notifications sent from network devices to a management system. A Linkup trap indicates that a particular interface has become active (up), while a Linkdown trap indicates that an interface has become inactive (down). These traps can trigger Layer 2 polling to ascertain the current status of network interfaces and devices.


質問 # 52
......

無料FCP in Network Security NSE6_FNC-7.2試験問題:https://jp.fast2test.com/NSE6_FNC-7.2-premium-file.html


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어