Fortinet NSE5_FNC_AD-7.6 Practice Test Questions and Exam Dumps Part 19 Q361-380

View Full Fortinet NSE5_FNC_AD-7.6 Exam Dumps and Practice Test Dumps

 

Question 361: Which FortiNAC capability provides awareness of connected endpoints and their network connections?

  1. Device profiling
    2. Network visibility
    3. Groups
    4. Upstream logging

Correct Answer: 2. Network visibility

Explanation:
Network visibility provides FortiNAC with information about connected endpoints and relevant network relationships. It allows administrators to maintain awareness of devices present within the environment and understand their network connections. This information can support other administrative functions such as device profiling, grouping, troubleshooting, and access control. Visibility is therefore a foundational capability for understanding the endpoint environment and making informed network-access management decisions.

Question 362: What is the purpose of modeling infrastructure devices in FortiNAC?

  1. To create administrator accounts
    2. To classify endpoints automatically
    3. To represent and understand relevant network infrastructure
    4. To forward events to an external logging system

Correct Answer: 3. To represent and understand relevant network infrastructure

Explanation:
Modeling infrastructure devices provides FortiNAC with a representation of the network devices that it needs to understand and interact with. This establishes useful context for network visibility and endpoint administration. Infrastructure modeling focuses on network devices rather than endpoint classification. Device profiling serves the latter purpose by using observed characteristics to classify endpoints. Both capabilities contribute to a structured understanding of the managed environment.

Question 363: Which FortiNAC capability helps classify endpoints according to observed characteristics?

  1. Groups
    2. Host filters
    3. Device profiling
    4. Captive network

Correct Answer: 3. Device profiling

Explanation:
Device profiling helps FortiNAC classify endpoints using characteristics observed about connected devices. Classification provides administrators with additional information about the nature or type of an endpoint. This information can support subsequent organization and access-control decisions. Device profiling works alongside network visibility, which provides endpoint awareness, and Groups, which provide logical organization. These functions should be understood as complementary rather than interchangeable.

Question 364: Which feature allows administrators to locate hosts that match specified criteria?

  1. Isolation network
    2. Host filters
    3. Device profiling
    4. Captive network

Correct Answer: 2. Host filters

Explanation:
Host filters allow administrators to narrow the displayed host information according to selected criteria. This makes it easier to locate relevant endpoints, especially when many devices are present in the environment. Filters can support operational administration and troubleshooting by reducing the amount of host information that must be reviewed manually. They do not classify endpoints or change their network-access state; their primary purpose is efficient host discovery and management within the Hosts page.

Question 365: Which FortiNAC feature provides logical organization for managed objects?

  1. Groups
    2. Network visibility
    3. Upstream logging
    4. Isolation network

Correct Answer: 1. Groups

Explanation:
Groups provide a logical structure for organizing managed objects in FortiNAC. Administrators can categorize related endpoints or objects to make ongoing management more consistent and efficient. Groups complement capabilities such as network visibility and device profiling. Visibility provides information about endpoints, profiling helps classify them, and Groups provide a structure for organizing those managed objects. This logical organization can be particularly useful in larger deployments.

Question 366: Which network is intended to provide restricted connectivity to an endpoint?

  1. Captive network
    2. Production network
    3. Isolation network
    4. Management network

Correct Answer: 3. Isolation network

Explanation:
An isolation network provides a restricted network environment for an endpoint. It can be used when the endpoint should remain separated from normal network resources while a condition is addressed or remediation is performed. This differs from a captive network, which provides a controlled access experience that may require interaction from the user or endpoint. Understanding these network types helps administrators apply the appropriate access behavior to different endpoint conditions.

Question 367: Which network can provide a controlled access experience that may require user interaction?

  1. Infrastructure network
    2. Isolation network
    3. Captive network
    4. Logging network

Correct Answer: 3. Captive network

Explanation:
A captive network provides a controlled network-access experience that may require the user or endpoint to complete an interaction. It can be appropriate for processes such as controlled registration or authentication. Unlike an isolation network, which focuses on restricting connectivity, a captive network can provide a defined user-facing access process. The distinction is important when administrators configure network access according to an endpoint’s current state and required behavior.

Question 368: Which activity is part of FortiNAC administrator-user management?

  1. Creating and managing administrator accounts
    2. Classifying infrastructure devices
    3. Filtering all network traffic
    4. Isolating every endpoint

Correct Answer: 1. Creating and managing administrator accounts

Explanation:
Administrator-user management includes creating and managing accounts used to access FortiNAC administrative functions. These accounts provide authorized personnel with controlled access to configuration and management capabilities. This task is separate from endpoint-focused functions such as profiling, filtering, discovery, and isolation. Administrator account management is therefore an important component of maintaining appropriate administrative access to the FortiNAC environment.

Question 369: What is the main purpose of upstream logging in FortiNAC-F?

  1. To classify endpoints
    2. To forward event information to an external logging destination
    3. To organize managed objects into Groups
    4. To create captive networks

Correct Answer: 2. To forward event information to an external logging destination

Explanation:
Upstream logging allows FortiNAC-F event information to be forwarded to an external or upstream logging destination. This can make relevant FortiNAC events available to centralized monitoring and logging systems. The capability is focused on event forwarding rather than endpoint classification, logical organization, or network-access control. Upstream logging can therefore be useful when FortiNAC events need to be incorporated into a broader operational monitoring architecture.

Question 370: Which information is most relevant when troubleshooting a host connectivity problem?

  1. Host connectivity and related network information
    2. Only administrator account information
    3. Only Group names
    4. Only logging configuration

Correct Answer: 1. Host connectivity and related network information

Explanation:
Host connectivity troubleshooting requires information about the endpoint’s connection to the network and associated network details. Reviewing this information can help administrators understand the host’s connectivity state and investigate potential network-access or infrastructure issues. Other information, such as administrator accounts or logging settings, may be useful for different tasks but does not directly provide the same connectivity context. FortiNAC host information can therefore support systematic investigation of connectivity problems.

Question 371: Which capability helps FortiNAC understand relevant network infrastructure devices?

  1. Host filters
    2. Infrastructure-device modeling
    3. Captive networks
    4. Administrator-user management

Correct Answer: 2. Infrastructure-device modeling

Explanation:
Infrastructure-device modeling gives FortiNAC a structured representation of the network infrastructure devices with which it interacts. This allows the platform to understand the network environment and provides context for endpoint visibility and access administration. Infrastructure modeling is focused on network devices rather than endpoint classification. Device profiling handles endpoint classification, while Groups provide logical organization of managed objects.

Question 372: Which capability helps administrators maintain awareness of endpoints on the network?

  1. Groups
    2. Network visibility
    3. Isolation networks
    4. Upstream logging

Correct Answer: 2. Network visibility

Explanation:
Network visibility provides awareness of connected endpoints and relevant information about their network relationships. This capability gives administrators a useful operational view of devices present in the environment. The information can support endpoint profiling, grouping, troubleshooting, and access-control administration. Maintaining endpoint visibility is important because administrators need reliable information about connected devices before they can effectively classify, organize, or manage their network access.

Question 373: What is the primary function of Groups?

  1. To provide logical categorization of managed objects
    2. To forward events to an upstream logger
    3. To classify endpoints automatically
    4. To provide restricted connectivity

Correct Answer: 1. To provide logical categorization of managed objects

Explanation:
Groups provide logical categorization of managed objects within FortiNAC. They allow administrators to organize related endpoints or other objects into meaningful structures for easier and more consistent administration. Groups do not perform endpoint profiling or network isolation themselves. Instead, they provide organizational structure that can be used alongside visibility and classification capabilities to manage endpoints more effectively.

Question 374: Which feature helps classify endpoints using observed characteristics?

  1. Device profiling
    2. Host filters
    3. Groups
    4. Upstream logging

Correct Answer: 1. Device profiling

Explanation:
Device profiling helps FortiNAC classify endpoints using characteristics observed about the connected devices. Classification provides useful context that can assist administrators with endpoint management and access-control decisions. It differs from network visibility, which provides awareness and information, and Groups, which organize managed objects logically. Device profiling therefore plays a specific role in determining how endpoints can be understood and categorized within the FortiNAC environment.

Question 375: Which network should be used when an endpoint requires restricted access while an issue is addressed?

  1. Captive network
    2. Isolation network
    3. Production network
    4. Infrastructure network

Correct Answer: 2. Isolation network

Explanation:
An isolation network is appropriate when an endpoint requires restricted access while a particular condition or issue is being addressed. It separates the endpoint from normal network resources and prevents ordinary network access while maintaining controlled connectivity. A captive network has a different purpose, providing a controlled access experience that may involve user interaction. Selecting the correct network type depends on the desired treatment of the endpoint.

Question 376: Which feature can quickly narrow the displayed host information?

  1. Device profiling
    2. Groups
    3. Host filters
    4. Captive network

Correct Answer: 3. Host filters

Explanation:
Host filters allow administrators to narrow the hosts displayed according to selected criteria. This can make it easier to locate specific endpoints or subsets of devices within a large FortiNAC environment. Filters are useful during routine administration and troubleshooting because they reduce the amount of information that must be reviewed manually. They do not themselves classify endpoints, organize them into Groups, or control their network access.

Question 377: Which statement accurately distinguishes network visibility from device profiling?

  1. Visibility provides endpoint awareness, while profiling helps classify endpoints
    2. Visibility creates Groups, while profiling forwards logs
    3. Visibility isolates endpoints, while profiling creates administrator accounts
    4. Both functions are used only for event logging

Correct Answer: 1. Visibility provides endpoint awareness, while profiling helps classify endpoints

Explanation:
Network visibility and device profiling provide different but complementary capabilities. Network visibility supplies awareness and relevant information about connected endpoints and their network relationships. Device profiling uses observed characteristics to help classify those endpoints. Classification can then provide useful context for grouping and access-control administration. Understanding this distinction helps administrators determine which FortiNAC capability is responsible for awareness and which is responsible for endpoint classification.

Question 378: Which capability can forward FortiNAC-F events to an external logging destination?

  1. Upstream logging
    2. Device profiling
    3. Groups
    4. Host filters

Correct Answer: 1. Upstream logging

Explanation:
Upstream logging is used to forward FortiNAC-F event information to an external or upstream logging destination. This can support centralized monitoring and operational analysis by making FortiNAC events available to another logging system. The capability does not classify endpoints, organize managed objects, or filter hosts. Its primary function is to make relevant event information available outside the FortiNAC system for broader monitoring purposes.

Question 379: Which sequence represents a structured approach to FortiNAC access administration?

  1. Apply access controls before establishing visibility
    2. Configure initial settings, establish visibility, organize endpoints, then apply access controls
    3. Isolate all endpoints before discovering infrastructure
    4. Disable visibility after configuring infrastructure devices

Correct Answer: 2. Configure initial settings, establish visibility, organize endpoints, then apply access controls

Explanation:
A structured approach begins with initial configuration and then establishes visibility into the network and connected endpoints. Administrators can use the resulting information to understand, classify, and organize endpoints before applying appropriate access controls. This provides a logical foundation for access decisions because the network environment and endpoint information are considered before access treatment is applied. The same sequence also supports ongoing administration and troubleshooting.

Question 380: Which combination provides endpoint awareness, classification, and logical organization?

  1. Network visibility, device profiling, and Groups
    2. Isolation networks, host filters, and upstream logging
    3. Captive networks, administrator accounts, and logging
    4. Configuration wizard, isolation networks, and Groups

Correct Answer: 1. Network visibility, device profiling, and Groups

Explanation:
Network visibility, device profiling, and Groups provide complementary capabilities for managing endpoints. Network visibility provides awareness and information about connected devices. Device profiling helps classify endpoints using observed characteristics. Groups provide logical organization for managed objects. Together, these capabilities allow administrators to develop a structured understanding of the endpoint environment and organize devices for consistent management and appropriate access-control administration.