NSE5_FNC_AD-7.6 Sample Questions

NSE5_FNC_AD-7.6 Sample Questions & Answers

Configuring security automation, access control, and HA monitoring carries the most weight, alongside mapping out infrastructure devices and their isolation networks, third-party and MDM integration, and visibility features for guests and device profiling.

Launch the full NSE5_FNC_AD-7.6 simulator →

Showing 6 of 12 free samples.

  1. Question 1Beginner

    Concepts and Initial Configuration · Model and organize infrastructure devices

    An administrator needs to organize the infrastructure devices in FortiNAC-F to reflect the physical layout of a multi-building campus. Which hierarchy strategy represents the best practice for utilizing Containers and Device Groups?

    Show answer & explanation

    Correct answer: C

    Containers are designed to create a hierarchical, tree-like structure representing physical topology or geography. Device Groups are used for logical grouping of devices (often across different containers) to apply bulk configurations or firmware updates.

  2. Question 2Intermediate

    Concepts and Initial Configuration · Model and organize infrastructure devices

    True or False: In a FortiNAC-F deployment, the Control Server component is primarily responsible for processing database transactions and generating reports, while the Application Server handles direct interaction with network infrastructure devices.

    Show answer & explanation

    Correct answer: B

    This is False. The roles are reversed or combined depending on deployment, but typically the Control Server (or the control function in a combined appliance) handles direct network interactions (SNMP, RADIUS, DHCP) and enforcement. The Application Server (or management function) handles the database, GUI, and reporting. In FortiNAC-F containerized architecture, these services run as containers but the logical separation remains: Control handles the 'edge' interaction.

  3. Question 3Beginner

    Concepts and Initial Configuration · Explain isolation networks and the configuration wizard

    A financial institution requires strict network segmentation. They want to ensure that any device failing an endpoint compliance scan is placed into a VLAN that allows access ONLY to the FortiNAC remediation portal and antivirus update servers. Which isolation network type should be configured for this purpose?

    Show answer & explanation

    Correct answer: A

    The Remediation VLAN is specifically designed for devices that are known/registered but have failed a health or compliance check. It restricts access to remediation resources (like the portal or update servers) necessary to fix the compliance issue.

  4. Question 4Intermediate

    Concepts and Initial Configuration · Model and organize infrastructure devices

    You are configuring a new switch in FortiNAC-F. The switch is discovered, but the ports are not showing up in the inventory. You verified the SNMP community string is correct for read access. What is the most likely reason for this issue?

    Show answer & explanation

    Correct answer: D

    The 'Generic SNMP' model provides basic up/down status but often lacks the specific OID mappings required to enumerate ports and read L2 forwarding tables for many vendors. Assigning the correct vendor-specific model (e.g., Cisco, Juniper) allows FortiNAC to properly query port information.

  5. Question 5Beginner

    Deployment and Provisioning · Configure access control on FortiNAC-F

    When planning the deployment of FortiNAC-F agents, which agent type is recommended for corporate-owned assets that require continuous posture assessment and automatic logon handling?

    Show answer & explanation

    Correct answer: B

    The Persistent Agent is installed permanently on the endpoint. It starts at boot, can handle single-sign-on (SSO) information, and provides continuous feedback on the device's security posture to FortiNAC.

  6. Question 6Advanced

    Deployment and Provisioning · Configure and monitor HA

    In a FortiNAC-F High Availability (HA) cluster, what is the primary function of the 'Witness' or 'Arbiter' configuration if typically used in such architectures?

    Show answer & explanation

    Correct answer: D

    FortiNAC-F High Availability typically uses a dedicated physical connection (eth1 usually) for heartbeat and database replication. To prevent split-brain (where both nodes go active), it checks reachability to the default gateway. It does not natively require a third external 'Witness' appliance like some storage clusters.

Ready for the real thing?

The full NSE5_FNC_AD-7.6 simulator has every exam-style question, timed mode, and instant scoring.