SNMP for information gathering, RADIUS for access authentication, CLI for direct device control are the three documented FortiNAC communication methods.
Why the others are wrong
C. FTP moves files; it gathers and controls nothing.
E. SMTP sends mail notifications only.
FortiNAC exam tip
Gather + control trio = SNMP, RADIUS, CLI.
2Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)
A matched security policy
Scheduled poll timings
Linkup and Linkdown traps
Manual polling
A failed Layer 3 poll
Answer: B, C, D
The short version
B, C, D — L2 polls fire on schedule, on link traps, or by hand. Timers, traps, manual.
Key concepts in this question
Scheduled polls run on timers; linkup/linkdown traps trigger on topology change; manual polling forces on demand.
Policies and L3 failures belong to other poll types.
Why B, C and D are correct
Timers, link-state traps, and manual initiation are the three documented L2 poll triggers.
Why the others are wrong
A. Matched policies drive access decisions, not L2 polls.
E. Failed L3 polls trigger L3 recovery, not L2 polling.
FortiNAC exam tip
L2 poll triggers = schedule, link traps, manual.
3How should you configure MAC notification traps on a supported switch?
Configure them only on ports set as 802.1q trunks
Configure them on all ports except uplink ports
Configure them on all ports on the switch
Configure them only after you configure linkup and linkdown traps
Answer: B
The short version
B — MAC notification traps go on all ports except uplinks. Endpoints notify; uplinks would flood.
Key concepts in this question
MAC notification traps report endpoint connects/disconnects per access port.
Uplink ports aggregate many MACs and must be excluded to avoid trap storms.
Why B is correct
All-ports-except-uplinks is the documented MAC notification placement.
Why the others are wrong
A. Trunk-only placement misses access-port endpoints.
C. Including uplinks floods FortiNAC with transit MAC noise.
D. Link traps are a separate prerequisite-free configuration.
FortiNAC exam tip
MAC traps = everywhere except uplinks.
4Which connecting endpoints are evaluated against all enabled device profiling rules?
Known trusted devices each time they change location
Rogues devices, each time they connect
Rogues devices, only when they connect for the first time
All hosts, each time they connect
Answer: A
The short version
A — known trusted devices re-profile on every location change. Movement can mean a new threat context.
Key concepts in this question
Device profiling rules re-evaluate trusted hosts when their point of connection changes.
Rogues are profiled on connect; trusted hosts are not re-checked without a trigger.
Why A is correct
Location change on a trusted device is the documented full re-profiling trigger.
Why the others are wrong
B. Rogues are evaluated on connect, but the question asks about the all-rules re-evaluation case.
C. First-connect-only would miss later spoofing.
D. All-hosts-every-connect would crush performance; profiling is event-driven.
FortiNAC exam tip
Trusted + moved = re-profile against all rules.
5What agent is required in order to detect an added USB drive?
Mobile
Passive
Dissolvable
Persistent
Answer: D
The short version
D — USB detection needs the Persistent agent. Always-on endpoint presence sees hardware events.
Key concepts in this question
Persistent agents run continuously and catch hardware changes like USB insertion.
Dissolvable, passive, and mobile agents lack continuous hardware hooks.
Why D is correct
Only the always-resident Persistent agent monitors USB attach events.
Why the others are wrong
A. Mobile agents manage mobile devices, not USB hardware events.
B. Passive agents observe network-side only.
C. Dissolvable agents run on demand and then vanish.
FortiNAC exam tip
Hardware events = Persistent agent.
6Which two of the following are required for endpoint compliance monitors? (Choose two.)
Logged on user
Security rule
Persistent agent
Custom scan
Answer: C, D
The short version
C and D — compliance monitors need a Persistent agent plus a custom scan. Presence plus the check itself.
Key concepts in this question
Persistent agent provides the on-host enforcement point.
Custom scans define what compliance means; monitors execute them.
Why C and D are correct
Agent presence (C) plus scan definition (D) are the two documented compliance-monitor requirements (6v1 majority over BD).
Why the others are wrong
A. Logged-on user is scan context, not a monitor requirement.
B. Security rules consume scan results; they do not constitute the monitor.
7By default, if more than 20 hosts are seen connected on a single port simultaneously, what will happen to the port?
The port is added to the Forced Registration group.
The port is disabled.
The port is switched into the Dead-End VLAN.
The port becomes a threshold uplink.
Answer: D
The short version
D — 20+ hosts on one port means a downstream switch: mark it a threshold uplink. One MAC per port is the endpoint assumption.
Key concepts in this question
Threshold uplinks exempt ports that aggregate many hosts from endpoint enforcement.
20 simultaneous hosts is the default downstream-device threshold.
Why D is correct
Exceeding the host-count threshold reclassifies the port as an uplink rather than punishing it.
Why the others are wrong
A. Forced Registration targets rogues, not infrastructure.
B. Ports are not disabled for hosting many hosts.
C. Dead-end VLANs punish rogues, not switches.
FortiNAC exam tip
Many hosts, one port = threshold uplink.
8In a wireless integration, how does FortiNAC obtain connecting MAC address information?
Link traps
End station traffic monitoring
MAC notification traps
RADIUS
Answer: D
The short version
D — wireless integrations learn MACs from RADIUS. Association authenticates, accounting reports.
Key concepts in this question
RADIUS carries the connecting MAC in wireless authentication flows.
Link/MAC traps and traffic monitoring are wired-side mechanisms.
Why D is correct
Wireless controllers report client MACs via RADIUS to FortiNAC — the documented wireless integration path.
Why the others are wrong
A. Link traps are switch-port events, not wireless associations.
B. Traffic monitoring is a wired visibility technique.
C. MAC notification traps come from wired switches.
FortiNAC exam tip
Wireless MAC source = RADIUS.
9Which system group will force at-risk hosts into the quarantine network, based on point of connection?
Forced Quarantine
Forced Remediation
Forced Isolation
Physical Address Filtering
Answer: B
The short version
B — Forced Remediation pushes at-risk hosts to quarantine by connection point. Risk state plus location drives the move.
Key concepts in this question
Forced Remediation acts on at-risk hosts, placing them in remediation/quarantine networks.
Quarantine/Isolation groups serve different states and scopes (4v2 majority for B).
Why B is correct
At-risk-by-connection-point quarantine is the documented Forced Remediation behavior.
Why the others are wrong
A. Forced Quarantine targets a different enforcement state.
C. Forced Isolation severs access rather than remediating.
D. Physical Address Filtering matches MACs; it does not quarantine by risk.
FortiNAC exam tip
At-risk + quarantine by port = Forced Remediation.
10During the on-boarding process through the captive portal, why would a host that successfully registered remain stuck in the Registration VLAN? (Choose two.)
The wrong agent is installed.
Bridging is enabled on the host.
There is another unregistered host on the same port.
The ports default VLAN is the same as the Registration VLAN.
Answer: A, D
The short version
A and D — stuck in Registration VLAN means wrong agent or a VLAN overlap. The endpoint cannot complete posture, or it never left logically.
Key concepts in this question
Wrong agent fails the compliance exchange that releases the host.
Port default VLAN equal to Registration VLAN means no visible move ever happens.
Why A and D are correct
Agent mismatch (A) blocks release while VLAN identity (D) masks it — the two documented stuck causes.
Why the others are wrong
B. Bridging triggers security blocks, not silent sticking.
C. A second unregistered host affects that host, not this one's release.
FortiNAC exam tip
Stuck registered = check agent, then VLAN identity.