Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Fortinet NSE 5 - FortiNAC-F 7.6 Administrator Question and Answers

Fortinet NSE 5 - FortiNAC-F 7.6 Administrator

Last Update May 30, 2026
Total Questions : 59

We are offering FREE NSE5_FNC_AD_7.6 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE5_FNC_AD_7.6 free exam questions and then go for complete pool of Fortinet NSE 5 - FortiNAC-F 7.6 Administrator test questions that will help you more.

NSE5_FNC_AD_7.6 pdf

NSE5_FNC_AD_7.6 PDF

$36.75  $104.99
NSE5_FNC_AD_7.6 Engine

NSE5_FNC_AD_7.6 Testing Engine

$43.75  $124.99
NSE5_FNC_AD_7.6 PDF + Engine

NSE5_FNC_AD_7.6 PDF + Testing Engine

$57.75  $164.99
Questions 1

An organization has FortiNAC-F deployed and is using Layer 3 isolation networks across multiple sites with firewalls. At a minimum, which three protocols must be allowed between the isolation networks and FortiNAC-F? (Choose three.)

Options:

A.  

DDNS

B.  

NTP

C.  

HTTP/HTTPS

D.  

DNS

E.  

DHCP

Discussion 0
Questions 2

Refer to the exhibit.

When configuring guest access using a network access policy, where would an administrator configure the Guest-VLAN value?

Options:

A.  

In the Model configuration

B.  

In the Guest template

C.  

In the User/Host profile

D.  

in the Guest portal configuration

Discussion 0
Questions 3

While troubleshooting a network connectivity issue, an administrator determines that a device was being automatically provisioned to an incorrect VLAN. Where would the administrator look to identify when and why FortiNAC-F made the network access change?

Options:

A.  

The Security Event view

B.  

The Reports view

C.  

The Port Changes view

D.  

The Admin Auditing view

Discussion 0
Questions 4

Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)

Options:

A.  

A FortiNAC-F manager

B.  

A FortiNAC-F device designated as a secondary

C.  

A dedicated VLAN for primary and secondary synchronization

D.  

At least two FortiNAC-F devices designated as primary

Discussion 0
Questions 5

What must an administrator configure to allow FortiNAC-F to process incoming syslog messages that are not supported by default?

Options:

A.  

A Syslog Service Connector

B.  

A Security Action

C.  

A Security Event Parser

D.  

A Log Receiver

Discussion 0
Questions 6

Where should you configure MAC notification traps on a supported switch?

Options:

A.  

Only on ports that generate linkup and linkdown traps

B.  

Only on ports defined as learned uplinks

C.  

On all ports on the switch

D.  

On all ports except uplink ports

Discussion 0
Questions 7

Refer to the exhibit.

A FortiNAC-F N+1 HA configuration is shown.

What will occur if CA-2 fails?

Options:

A.  

CA-1 and CA-3 will operate as a 1+1 HA cluster with CA-3 acting as a hot standby.

B.  

CA-3 will continue to operate as a secondary in an N+1 HA configuration.

C.  

CA-3 will be promoted to a primary and share management responsibilities with CA-1.

D.  

CA-3 will be promoted to a primary and FortiNAC-F manager will load balance between CA-1 and CA-3.

Discussion 0
Questions 8

Refer to the exhibit.

Given this topology, and a layer 3 registration network configuration, which IP address would be designated in the DHCP relay configuration for the registration network?

Options:

A.  

192.168.10.254

B.  

192.168.100 75

C.  

192.168.100.20

D.  

192.168.200.10

Discussion 0
Questions 9

A network administrator is troubleshooting a network access issue for a specific host. The administrator suspects the host is being assigned a different network access policy than expected.

Where would the administrator look to identify which network access policy, if any, is being applied to a particular host?

Options:

A.  

The Policy Logs view

B.  

The Connections view

C.  

The Policy Details view for the host

D.  

The Port Properties view of the hosts port

Discussion 0
Questions 10

An administrator wants FortiNAC-F to pass firewall tags to FortiGate to leverage dynamic address groups used in firewall policies. On FortiNAC-F, what determines the values that are passed?

Options:

A.  

Model configuration

B.  

Device profiling rule

C.  

Security rule

D.  

RADIUS group attribute

Discussion 0
Questions 11

Refer to the exhibit.

After a successful layer 2 poll, two hosts were learned on the same port The port is a member of the Role-Based Access and Forced Registration groups. The switch has been configured to leverage a single isolation VLAN.

How will FortiNAC-F manage this port?

Options:

A.  

The port will be provisioned to the isolation network

B.  

The port will be provisioned for the normal state host, but the second host will have access to only the isolation portal page.

C.  

The port will be provisioned as an uplink to a hub or unmanaged switch.

D.  

The port will be added to the Access Point Management group

Discussion 0
Questions 12

An administrator wants to control user access to corporate resources by integrating FortiNAC-F with FortiGate using firewall tags defined on FortiNAC-F.

Where would the administrator assign the firewall tag value that will be sent to FortiGate?

Options:

A.  

RADIUS group attribute

B.  

Logical network

C.  

Device profiling rule

D.  

Security rule

Discussion 0
Questions 13

An administrator has created several device profiling rules and evaluated all existing devices in the database. Some of the devices appear in the profiled devices view because they matched a rule, but they remain unknown and the registration column in the profiled devices view shows " No " .

What is the most likely cause?

Options:

A.  

The confirm device profiling rule option is not enabled.

B.  

The devices match more than one device profiling rule.

C.  

The device profiling rule has registration set to manual.

D.  

The devices have persistent agents installed, and the point of connection has PA optimization enabled.

Discussion 0
Questions 14

When managing multiple FortiNAC-F CAs with a FortiNAC-F Manager, how is endpoint information updated in the FortiNAC-F Manager database?

Options:

A.  

Endpoint information is pulled from the managed CAs by the FortiNAC-F Manager at a set interval.

B.  

Endpoint information is updated in real time when a host status changes.

C.  

Endpoint information is updated when an administrator synchronizes with each CA.

D.  

Endpoint information is pushed to the FortiNAC-F Manager based on an administratively configured scheduled task.

Discussion 0
Questions 15

An administrator is configuring FortiNAC-F to manage FortiGate VPN users. As part of this configuration, what is the purpose of the FortiGate firewall policy that applies to clients not yet authorized?

Options:

A.  

To allow access to only the production DNS server

B.  

To allow access to only the production DNS server

C.  

To allow access to only the FortiNAC-F VPN interface

D.  

To allow access to only the FortiGate VPN interface

Discussion 0
Questions 16

Refer to the exhibit.

Which devices are automatically evaluated by these device profiling rules?

Options:

A.  

Rogue devices, only when they are initially added to the database

B.  

Known trusted devices, each time they connect

C.  

All hosts, each time they connect

D.  

Rogue devices, each time they change location

Discussion 0
Questions 17

Refer to the output below.

Examine the communication between a primary FortiNAC-F (192.168.10.10) and a secondary FortlNAC-F (192.168.10.110) configured as a 1+1 HA pair. What is the current state of the FortiNAC-F HA pair?

Options:

A.  

The secondary server is running and in control.

B.  

The database replication failed

C.  

Failover from the primary server to the secondary server is in progress.

D.  

The primary server is running and in control.

Discussion 0