Sign In
Home/Fortinet/FortiNAC 8.5 Administrator/Free questions

Fortinet NSE 6 - FortiNAC 8.5 Administrator — Free Practice Questions

10 free sample questions from a bank of 30, with the correct answers and explanations. No signup required — start practising right now.

1Which three communication methods are used by the FortiNAC to gather information from, and control, infrastructure devices? (Choose three.)
  • SNMP
  • RADIUS
  • FTP
  • CLI
  • SMTP
Answer: A, B, D

The short version

A, B, D — FortiNAC talks SNMP and RADIUS and drives CLI to gather and control. Poll, authenticate, configure.

Key concepts in this question

  • SNMP gathers device/host data and receives traps.
  • RADIUS authenticates endpoints; CLI (SSH/Telnet) controls infrastructure ports.

Why A, B and D are correct

SNMP for information gathering, RADIUS for access authentication, CLI for direct device control are the three documented FortiNAC communication methods.

Why the others are wrong

  • C. FTP moves files; it gathers and controls nothing.
  • E. SMTP sends mail notifications only.

FortiNAC exam tip

Gather + control trio = SNMP, RADIUS, CLI.

2Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)
  • A matched security policy
  • Scheduled poll timings
  • Linkup and Linkdown traps
  • Manual polling
  • A failed Layer 3 poll
Answer: B, C, D

The short version

B, C, D — L2 polls fire on schedule, on link traps, or by hand. Timers, traps, manual.

Key concepts in this question

  • Scheduled polls run on timers; linkup/linkdown traps trigger on topology change; manual polling forces on demand.
  • Policies and L3 failures belong to other poll types.

Why B, C and D are correct

Timers, link-state traps, and manual initiation are the three documented L2 poll triggers.

Why the others are wrong

  • A. Matched policies drive access decisions, not L2 polls.
  • E. Failed L3 polls trigger L3 recovery, not L2 polling.

FortiNAC exam tip

L2 poll triggers = schedule, link traps, manual.

3How should you configure MAC notification traps on a supported switch?
  • Configure them only on ports set as 802.1q trunks
  • Configure them on all ports except uplink ports
  • Configure them on all ports on the switch
  • Configure them only after you configure linkup and linkdown traps
Answer: B

The short version

B — MAC notification traps go on all ports except uplinks. Endpoints notify; uplinks would flood.

Key concepts in this question

  • MAC notification traps report endpoint connects/disconnects per access port.
  • Uplink ports aggregate many MACs and must be excluded to avoid trap storms.

Why B is correct

All-ports-except-uplinks is the documented MAC notification placement.

Why the others are wrong

  • A. Trunk-only placement misses access-port endpoints.
  • C. Including uplinks floods FortiNAC with transit MAC noise.
  • D. Link traps are a separate prerequisite-free configuration.

FortiNAC exam tip

MAC traps = everywhere except uplinks.

4Which connecting endpoints are evaluated against all enabled device profiling rules?
  • Known trusted devices each time they change location
  • Rogues devices, each time they connect
  • Rogues devices, only when they connect for the first time
  • All hosts, each time they connect
Answer: A

The short version

A — known trusted devices re-profile on every location change. Movement can mean a new threat context.

Key concepts in this question

  • Device profiling rules re-evaluate trusted hosts when their point of connection changes.
  • Rogues are profiled on connect; trusted hosts are not re-checked without a trigger.

Why A is correct

Location change on a trusted device is the documented full re-profiling trigger.

Why the others are wrong

  • B. Rogues are evaluated on connect, but the question asks about the all-rules re-evaluation case.
  • C. First-connect-only would miss later spoofing.
  • D. All-hosts-every-connect would crush performance; profiling is event-driven.

FortiNAC exam tip

Trusted + moved = re-profile against all rules.

5What agent is required in order to detect an added USB drive?
  • Mobile
  • Passive
  • Dissolvable
  • Persistent
Answer: D

The short version

D — USB detection needs the Persistent agent. Always-on endpoint presence sees hardware events.

Key concepts in this question

  • Persistent agents run continuously and catch hardware changes like USB insertion.
  • Dissolvable, passive, and mobile agents lack continuous hardware hooks.

Why D is correct

Only the always-resident Persistent agent monitors USB attach events.

Why the others are wrong

  • A. Mobile agents manage mobile devices, not USB hardware events.
  • B. Passive agents observe network-side only.
  • C. Dissolvable agents run on demand and then vanish.

FortiNAC exam tip

Hardware events = Persistent agent.

6Which two of the following are required for endpoint compliance monitors? (Choose two.)
  • Logged on user
  • Security rule
  • Persistent agent
  • Custom scan
Answer: C, D

The short version

C and D — compliance monitors need a Persistent agent plus a custom scan. Presence plus the check itself.

Key concepts in this question

  • Persistent agent provides the on-host enforcement point.
  • Custom scans define what compliance means; monitors execute them.

Why C and D are correct

Agent presence (C) plus scan definition (D) are the two documented compliance-monitor requirements (6v1 majority over BD).

Why the others are wrong

  • A. Logged-on user is scan context, not a monitor requirement.
  • B. Security rules consume scan results; they do not constitute the monitor.

FortiNAC exam tip

Compliance monitor = Persistent agent + custom scan.

7By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?
  • The port is added to the Forced Registration group.
  • The port is disabled.
  • The port is switched into the Dead-End VLAN.
  • The port becomes a threshold uplink.
Answer: D

The short version

D — 20+ hosts on one port means a downstream switch: mark it a threshold uplink. One MAC per port is the endpoint assumption.

Key concepts in this question

  • Threshold uplinks exempt ports that aggregate many hosts from endpoint enforcement.
  • 20 simultaneous hosts is the default downstream-device threshold.

Why D is correct

Exceeding the host-count threshold reclassifies the port as an uplink rather than punishing it.

Why the others are wrong

  • A. Forced Registration targets rogues, not infrastructure.
  • B. Ports are not disabled for hosting many hosts.
  • C. Dead-end VLANs punish rogues, not switches.

FortiNAC exam tip

Many hosts, one port = threshold uplink.

8In a wireless integration, how does FortiNAC obtain connecting MAC address information?
  • Link traps
  • End station traffic monitoring
  • MAC notification traps
  • RADIUS
Answer: D

The short version

D — wireless integrations learn MACs from RADIUS. Association authenticates, accounting reports.

Key concepts in this question

  • RADIUS carries the connecting MAC in wireless authentication flows.
  • Link/MAC traps and traffic monitoring are wired-side mechanisms.

Why D is correct

Wireless controllers report client MACs via RADIUS to FortiNAC — the documented wireless integration path.

Why the others are wrong

  • A. Link traps are switch-port events, not wireless associations.
  • B. Traffic monitoring is a wired visibility technique.
  • C. MAC notification traps come from wired switches.

FortiNAC exam tip

Wireless MAC source = RADIUS.

9Which system group will force at-risk hosts into the quarantine network, based on point of connection?
  • Forced Quarantine
  • Forced Remediation
  • Forced Isolation
  • Physical Address Filtering
Answer: B

The short version

B — Forced Remediation pushes at-risk hosts to quarantine by connection point. Risk state plus location drives the move.

Key concepts in this question

  • Forced Remediation acts on at-risk hosts, placing them in remediation/quarantine networks.
  • Quarantine/Isolation groups serve different states and scopes (4v2 majority for B).

Why B is correct

At-risk-by-connection-point quarantine is the documented Forced Remediation behavior.

Why the others are wrong

  • A. Forced Quarantine targets a different enforcement state.
  • C. Forced Isolation severs access rather than remediating.
  • D. Physical Address Filtering matches MACs; it does not quarantine by risk.

FortiNAC exam tip

At-risk + quarantine by port = Forced Remediation.

10During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)
  • The wrong agent is installed.
  • Bridging is enabled on the host.
  • There is another unregistered host on the same port.
  • The ports default VLAN is the same as the Registration VLAN.
Answer: A, D

The short version

A and D — stuck in Registration VLAN means wrong agent or a VLAN overlap. The endpoint cannot complete posture, or it never left logically.

Key concepts in this question

  • Wrong agent fails the compliance exchange that releases the host.
  • Port default VLAN equal to Registration VLAN means no visible move ever happens.

Why A and D are correct

Agent mismatch (A) blocks release while VLAN identity (D) masks it — the two documented stuck causes.

Why the others are wrong

  • B. Bridging triggers security blocks, not silent sticking.
  • C. A second unregistered host affects that host, not this one's release.

FortiNAC exam tip

Stuck registered = check agent, then VLAN identity.

Want the full bank of 30 questions for Fortinet NSE 6 - FortiNAC 8.5 Administrator? See all practice exams.