View Full Fortinet NSE5_FNC_AD-7.6 Exam Dumps and Practice Test Dumps
Question 101. Which FortiNAC function helps maintain awareness of endpoints connected to the network?
- Groups
2. Network visibility
3. Captive networks
4. Administrative scopes
Correct Answer: 2. Network visibility
Explanation:
Network visibility provides FortiNAC with information about connected endpoints and their network relationships. This awareness is fundamental to network access control because administrators need to know which devices are present and how they are connecting to the infrastructure. Visibility information can support endpoint classification, grouping, troubleshooting, and access-control decisions. Establishing reliable visibility is therefore an important part of the FortiNAC deployment process. It gives administrators the context required to understand the environment before applying more detailed network-access policies.
Question 102. What is the primary purpose of endpoint discovery in FortiNAC?
- To identify connected endpoints and gather information about them
2. To permanently isolate every endpoint
3. To replace network infrastructure
4. To remove administrator accounts
Correct Answer: 1. To identify connected endpoints and gather information about them
Explanation:
Endpoint discovery allows FortiNAC to identify devices that are connected to the network and collect information that can be used to understand those devices. Discovery contributes to network visibility and provides information that can later support profiling, grouping, and access-control decisions. This process is especially important in environments where many different endpoint types connect to shared infrastructure. Rather than replacing or removing devices, discovery gives FortiNAC awareness of the devices operating within the network.
Question 103. Which feature helps classify an endpoint based on information observed about the device?
- Host filters
2. Device profiling
3. Upstream logging
4. Isolation networks
Correct Answer: 2. Device profiling
Explanation:
Device profiling helps FortiNAC determine the characteristics or type of an endpoint by using information observed about the device. Classification can be useful when different endpoint types need different network-access treatment. For example, administrators may need to distinguish among workstations, printers, mobile devices, and other connected equipment. Profiling therefore complements network visibility by adding classification information to the awareness FortiNAC has about connected devices. Accurate profiling can contribute to more consistent endpoint organization and access-management decisions.
Question 104. What is the main function of host filters?
- To create network infrastructure devices
2. To authenticate every administrator
3. To narrow the hosts displayed according to selected criteria
4. To permanently disable endpoint discovery
Correct Answer: 3. To narrow the hosts displayed according to selected criteria
Explanation:
Host filters allow administrators to reduce the displayed host list by applying selected criteria. This makes it easier to locate specific endpoints within a large FortiNAC environment. Filtering is particularly useful during administration and troubleshooting because an administrator can focus on hosts relevant to a particular investigation or operational task rather than reviewing the entire list. Host filters affect the way information is displayed and located; they are not intended to replace endpoint discovery or change the physical network infrastructure.
Question 105. Which feature provides logical organization for endpoints and other managed objects?
- Groups
2. Device discovery
3. Captive networks
4. Configuration wizard
Correct Answer: 1. Groups
Explanation:
Groups provide a logical method for organizing endpoints and other managed objects in FortiNAC. Administrators can categorize related objects according to characteristics or operational requirements. This organization becomes particularly useful as the number of managed devices increases because related endpoints can be handled collectively rather than individually. Groups can also support consistent administration and policy application. They work together with visibility and profiling by providing an organizational structure for the information FortiNAC gathers about connected devices.
Question 106. What is the purpose of an isolation network?
- To provide unrestricted production access
2. To provide a restricted network environment for an endpoint
3. To manage administrator passwords
4. To discover network infrastructure devices
Correct Answer: 2. To provide a restricted network environment for an endpoint
Explanation:
An isolation network is used when an endpoint should not receive normal production network access. It provides a restricted environment where the endpoint can remain connected while a required condition, such as remediation, is addressed. This allows FortiNAC to enforce network-access restrictions without necessarily removing the endpoint completely from the network. Isolation is therefore an important mechanism for handling endpoints that do not currently meet the conditions for unrestricted access.
Question 107. Which network type can require a user or endpoint to complete an authentication or registration process?
- Isolation network
2. Management network
3. Captive network
4. Infrastructure network
Correct Answer: 3. Captive network
Explanation:
A captive network provides a controlled access environment that can require user interaction, authentication, or registration before broader access is granted. It is useful when administrators want to control how an endpoint enters the network rather than immediately providing unrestricted connectivity. Captive access differs from isolation because the purpose is not simply to restrict the endpoint but to provide a controlled process through which the user or device can complete a required action. This makes captive networks useful in controlled onboarding and access workflows.
Question 108. Which task is associated with initial FortiNAC system administration?
- Creating and managing administrator users
2. Replacing all endpoint hardware
3. Deleting network infrastructure
4. Disabling endpoint visibility
Correct Answer: 1. Creating and managing administrator users
Explanation:
Creating and managing administrator users is part of the administrative configuration of FortiNAC. Administrator accounts provide authorized personnel with access to system-management functions. Proper account management helps organizations control administrative access and assign responsibilities appropriately. During initial deployment, administrators may need to establish the required user accounts before proceeding with ongoing configuration and management. This task is separate from endpoint discovery and profiling, which focus on devices connected to the network rather than users who administer FortiNAC.
Question 109. What does infrastructure modeling allow FortiNAC to do?
- Permanently disconnect network devices
2. Represent and understand relevant network infrastructure
3. Delete endpoint classifications
4. Replace administrator accounts
Correct Answer: 2. Represent and understand relevant network infrastructure
Explanation:
Infrastructure modeling allows FortiNAC to represent the network devices that form part of the environment it manages. Understanding these infrastructure components is important because endpoints connect through network equipment, and FortiNAC needs appropriate context to provide visibility and manage access. Modeling therefore supports the foundation of the deployment by giving the system a structured representation of the network infrastructure. It does not mean physically replacing or removing network equipment.
Question 110. Which information is useful when investigating whether FortiNAC correctly identified a host?
- Endpoint identity and observed device characteristics
2. Only the administrator’s username
3. Only the appliance’s physical location
4. The number of email messages received
Correct Answer: 1. Endpoint identity and observed device characteristics
Explanation:
Endpoint identity and observed device characteristics can help administrators verify how FortiNAC has identified and classified a host. Reviewing these details can reveal whether the endpoint’s representation is consistent with the information available from the network. This is useful during troubleshooting because incorrect identification or classification can affect subsequent management and access decisions. Administrators can use the available endpoint information to investigate discrepancies and determine whether further configuration or investigation is required.
Question 111. What is a key benefit of network visibility during FortiNAC deployment?
- It eliminates the need for network infrastructure
2. It provides awareness of connected devices and their network information
3. It permanently blocks all unknown hosts
4. It removes the need for endpoint classification
Correct Answer: 2. It provides awareness of connected devices and their network information
Explanation:
Network visibility gives administrators awareness of devices connected to the network and relevant information about those devices. This information is essential when building an understanding of the environment and deciding how endpoints should be managed. Visibility can support discovery, profiling, grouping, troubleshooting, and network-access decisions. It is therefore a foundational capability rather than an enforcement action by itself. Establishing visibility helps administrators work from accurate information when configuring the broader FortiNAC deployment.
Question 112. Which capability is most useful for locating a subset of hosts in a large host list?
- Captive networks
2. Host filters
3. Device profiling
4. Configuration wizard
Correct Answer: 2. Host filters
Explanation:
Host filters are designed to narrow the displayed host information according to selected criteria. In a large deployment, this allows administrators to quickly focus on a particular subset of endpoints. Filtering can make operational tasks and troubleshooting more efficient because the administrator does not need to manually inspect every visible host. It is a search and display aid rather than a mechanism for modifying the network or endpoint itself. This makes host filters particularly useful for day-to-day FortiNAC administration.
Question 113. Which activity helps establish FortiNAC’s understanding of the network infrastructure?
- Modeling infrastructure devices
2. Deleting host records
3. Disabling administrator access
4. Removing endpoint groups
Correct Answer: 1. Modeling infrastructure devices
Explanation:
Modeling infrastructure devices helps FortiNAC establish a structured understanding of the network equipment with which it interacts. This information supports network visibility and provides context for connected endpoints. During deployment, administrators need to establish the relevant infrastructure before applying detailed access-management controls. Accurate infrastructure modeling therefore contributes to the overall network-awareness process. It is a configuration and representation activity rather than an operation that removes or replaces physical network equipment.
Question 114. When should an endpoint be placed into an isolation network?
- When it requires restricted access while a condition is addressed
2. Whenever it successfully authenticates
3. When unrestricted production access is required
4. When administrator accounts are created
Correct Answer: 1. When it requires restricted access while a condition is addressed
Explanation:
An endpoint can be placed into an isolation network when it should not receive normal production access and requires a condition to be addressed. This may involve remediation or another access-control requirement. Isolation provides a controlled network environment that limits the endpoint’s connectivity while allowing administrators to maintain oversight of its state. It is therefore useful when FortiNAC needs to enforce restricted access without simply treating the endpoint as having unrestricted production connectivity.
Question 115. What is a practical advantage of grouping endpoints in FortiNAC?
- It provides logical categorization for consistent management
2. It disables network visibility
3. It removes all endpoint information
4. It replaces physical network devices
Correct Answer: 1. It provides logical categorization for consistent management
Explanation:
Grouping endpoints provides a logical organizational structure that can simplify management. Related devices can be placed into categories according to characteristics or operational requirements, allowing administrators to manage collections of endpoints more consistently. Groups can also support policy application and other administrative operations. This becomes increasingly useful as the number of endpoints grows. Instead of treating every device as an isolated object, administrators can use logical groups to create a more structured and manageable FortiNAC environment.
Question 116. Which FortiNAC capability can be used to forward system events to an upstream logging destination?
- Device profiling
2. Upstream logging
3. Groups
4. Host filters
Correct Answer: 2. Upstream logging
Explanation:
Upstream logging allows relevant FortiNAC-F events to be forwarded to an upstream logging destination. This can support centralized event collection and monitoring, especially in environments where administrators use a common logging system to review activity from multiple devices or applications. The administrator configures the appropriate logging destination and related settings. Upstream logging therefore extends the visibility of FortiNAC events beyond the local system and can contribute to operational monitoring and troubleshooting workflows.
Question 117. Which statement best describes the relationship between profiling and grouping?
- Profiling classifies endpoints, while grouping organizes them logically
2. Profiling replaces network switches, while grouping disables them
3. Profiling manages administrator passwords, while grouping encrypts traffic
4. Profiling removes endpoint information, while grouping disables discovery
Correct Answer: 1. Profiling classifies endpoints, while grouping organizes them logically
Explanation:
Device profiling and grouping provide different but complementary functions. Profiling helps FortiNAC determine the characteristics or classification of an endpoint, while groups provide a logical structure for organizing managed objects. The information obtained through visibility and profiling can help administrators understand which devices belong together. Groups can then be used to manage related objects consistently. Together, these capabilities help transform raw endpoint information into an organized structure that supports administration and access-control operations.
Question 118. Which action should be performed before relying on detailed access policies for unknown endpoints?
- Establish endpoint and infrastructure visibility
2. Delete all host information
3. Disable device discovery
4. Remove all network models
Correct Answer: 1. Establish endpoint and infrastructure visibility
Explanation:
Establishing visibility provides the information needed to understand unknown endpoints and the infrastructure through which they connect. Before detailed policies can be applied effectively, administrators need to know what devices exist, how they are connected, and how FortiNAC identifies them. Visibility provides this foundation and can then be complemented by profiling and grouping. Building this awareness first makes it easier to apply appropriate access controls and investigate unexpected endpoint behavior.
Question 119. Which feature can guide an administrator through foundational FortiNAC configuration?
- Configuration wizard
2. Host filters
3. Isolation network
4. Groups
Correct Answer: 1. Configuration wizard
Explanation:
The configuration wizard assists administrators with foundational configuration tasks during the initial setup of FortiNAC. A guided configuration process can help ensure that important initial settings are addressed in an organized sequence. Once these foundational settings are established, administrators can proceed with activities such as infrastructure modeling, endpoint visibility, classification, grouping, and access-control configuration. The wizard therefore supports the initial deployment process rather than serving as a replacement for ongoing endpoint-management capabilities.
Question 120. Which sequence best reflects a structured FortiNAC endpoint-management process?
- Apply unrestricted access, then discover infrastructure and endpoints
2. Disable visibility, create groups, then remove unknown devices
3. Establish visibility, classify endpoints, organize them, and apply appropriate access controls
4. Delete endpoint information, then configure administrator accounts
Correct Answer: 3. Establish visibility, classify endpoints, organize them, and apply appropriate access controls
Explanation:
A structured FortiNAC endpoint-management process begins with visibility so administrators can understand the connected environment. Endpoint information can then be used for classification through profiling and organization through groups. Once administrators have sufficient context about the endpoints and infrastructure, appropriate access controls can be configured. This sequence helps ensure that access decisions are based on an understanding of the devices and their network relationships. It also provides a foundation for troubleshooting and ongoing administration as the environment changes.