Sign In
Home/Fortinet/FortiNAC 7.6 Administrator/Free questions

Fortinet NSE 6 - FortiNAC 7.6 Administrator — Free Practice Questions

10 free sample questions from a bank of 70, with the correct answers and explanations. No signup required — start practising right now.

1A manager is using a FortiNAC-F control manager to deploy an N+1 HA cluster. Which cluster member must be added first to begin the configuration?
  • Secondary
  • Worker
  • Primary
  • Manager
Answer: C

The short version

C — N+1 clusters build primary-first. The manager seeds from the primary.

Key concepts in this question

  • Primary holds the authoritative dataset for cluster formation.
  • Secondaries, workers, and managers join an existing primary.

Why C is correct

Primary-first is the documented N+1 build order.

Why the others are wrong

  • A. Secondaries replicate; they do not seed.
  • B. Workers compute; they do not found clusters.
  • D. The manager orchestrates; the primary seeds.

FortiNAC exam tip

N+1 build order = primary first.

2Refer to the exhibit. After a successful layer 2 poll, two hosts were learned on the same port. The port is a member of the Role-Based Access and Forced Registration groups. The switch has been configured to leverage a single isolation VLAN. How will FortiNAC-F manage this port?
Fortinet NSE 6 - FortiNAC 7.6 Administrator question 2
  • The port will be provisioned to the isolation network.
  • The port will be added to the Access Point Management group.
  • The port will be provisioned for the normal state host, but the second host will have access to only the isolation portal page.
  • The port will be provisioned as an uplink to a hub or unmanaged switch.
Answer: D

The short version

D — two MACs on one access port means a hub, so FortiNAC treats it as an uplink. A single port cannot carry two different VLAN outcomes at once.

Key concepts in this question

  • Layer-2 poll learning: two hosts on the same port reveals a downstream hub or unmanaged switch.
  • Single isolation VLAN limit: one port holds one VLAN, so split enforcement is impossible.
  • Enforcement-group conflict: Role-Based Access plus Forced Registration demand different networks for different states.

Why D is correct

The exhibit lists two physical addresses learned on the same port after a successful layer-2 poll, proving a hub sits downstream. The port sits in both Role-Based Access and Forced Registration groups, so compliant and rogue hosts would need different networks, but the switch offers only a single isolation VLAN. FortiNAC cannot satisfy both outcomes on one VLAN-switched port, so it provisions the port as an uplink to a hub or unmanaged switch and exempts it from per-host provisioning rather than breaking one host.

Why the others are wrong

  • A. Isolation would wrongly force the compliant host offline together with the rogue host.
  • B. Access Point Management is for access points, with no access-point evidence here.
  • C. Split provisioning is impossible on a single-VLAN port serving two hosts.

FortiNAC exam tip

Two hosts, one port, conflicting states equals hub uplink.

3Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)
  • A FortiNAC-F device designated as a secondary
  • At least two FortiNAC-F devices designated as primary
  • A dedicated VLAN for primary and secondary synchronization
  • A FortiNAC-F manager
Answer: A, D

The short version

A and D — N+1 needs a designated secondary plus the FortiNAC manager. Failover target plus orchestrator.

Key concepts in this question

  • Secondary designation provides the +1 failover capacity.
  • The manager coordinates the N+1 topology.

Why A and D are correct

The two documented N+1 requirements.

Why the others are wrong

  • B. Multiple primaries describe other topologies, not N+1.
  • C. Dedicated sync VLANs are not the framed requirement.

FortiNAC exam tip

N+1 = secondary + manager.

4An administrator wants FortiNAC-F to pass firewall tags to FortiGate to leverage dynamic address groups used in firewall policies. On FortiNAC-F, what determines the values that are passed?
  • RADIUS group attribute
  • Device profiling rule
  • Model configuration
  • Security rule
Answer: D

The short version

D — the security rule decides the tags. FortiNAC-F passes the firewall tags its security rule produces for dynamic address groups.

Key concepts in this question

  • Firewall tags: NAC-computed labels consumed by FortiGate.
  • Security rule: the policy object that yields tag values.
  • Profiling/model contrast: identification feeds rules; rules decide tags.

Why D is correct

The values passed to FortiGate come from the FortiNAC-F security rule driving dynamic address-group membership.

Why the others are wrong

  • A. RADIUS group attributes authenticate users; they set no firewall tags.
  • B. Profiling rules identify devices; tags flow from security rules.
  • C. Model configuration describes inventory, not tag values.

FortiNAC exam tip

Tags follow security rules; profiling only feeds them.

5An organization has FortiNAC-F deployed and is using layer 3 isolation networks across multiple sites with firewalls. At a minimum, which three protocols must be allowed between the isolation networks and FortiNAC-F? (Choose three.)
  • DDNS
  • HTTP/HTTPS
  • DHCP
  • NTP
  • DNS
Answer: B, C, E

The short version

B, C, E — L3 isolation lifelines are HTTP/S, DHCP, and DNS. Portal, address, resolve.

Key concepts in this question

  • HTTP/HTTPS serves the captive/remediation portal.
  • DHCP + DNS give isolated hosts function.

Why B, C and E are correct

The three documented minimum isolation protocols (FNC-8.5 Q28 confirms DNS/DHCP/Web pattern).

Why the others are wrong

  • A. DDNS is not an isolation requirement.
  • D. NTP is not in the minimum set.

FortiNAC exam tip

Isolation minimum = HTTP/S, DHCP, DNS.

6By default, when would a port in the FortiNAC-F network inventory view become a learned uplink?
  • When the port is connected to another modeled infrastructure device
  • When the port is configured as a trunk port on the infrastructure device
  • When the port shows more than 20 MAC addresses connected at the same time
  • When the port is added to the Access Point Management group
Answer: C

The short version

C — 20+ MACs makes a learned uplink. Same threshold as FNC-8.5 Q7.

Key concepts in this question

  • Learned uplinks exempt aggregation ports from endpoint enforcement.
  • The 20-MAC default marks downstream infrastructure.

Why C is correct

Threshold-uplink promotion, matching FNC-8.5 Q7's confirmed answer.

Why the others are wrong

  • A. Modeled devices show differently than learned uplinks.
  • B. Trunk config alone does not promote.
  • D. AP groups are explicit assignments, not learned states.

FortiNAC exam tip

20 MACs = learned uplink.

7Refer to the exhibit. Given this topology, and a layer 3 registration network configuration, which IP address would be designated in the DHCP relay configuration for the registration network?
Fortinet NSE 6 - FortiNAC 7.6 Administrator question 7
  • 192.168.200.10
  • 192.168.100.20
  • 192.168.100.75
  • 192.168.10.254
Answer: A

The short version

A — DHCP relay for the registration network points at the FortiNAC registration interface (.200.10). Same answer as Q35's duplicate.

Key concepts in this question

  • Layer 3 registration relays DHCP to FortiNAC's registration-network address.
  • The .200.10 address is the registration interface in this topology.

Why A is correct

Duplicate Q35 banked identically; cross-duplicate agreement.

Why the others are wrong

  • B/C. The .100.x addresses belong to other networks.
  • D. The .10.254 address is not the registration relay target.

FortiNAC exam tip

Duplicate relay stems = same relay address.

8An administrator has created several device profiling rules and evaluated all existing devices in the database. Some of the devices appear in the profiled devices view because they matched a rule, but they remain unknown and the registration column in the profiled devices view shows "No". What is the most likely cause?
  • The devices match more than one device profiling rule.
  • The device profiling rule has registration set to manual.
  • The devices have persistent agents installed, and the point of connection has PA optimization enabled.
  • The confirm device profiling rule option is not enabled.
Answer: B

The short version

B — matched-but-unknown with No registration means manual. The rule requires an admin to register the device.

Key concepts in this question

  • Profiled view: matched devices awaiting disposition.
  • Manual registration: admin confirms before the device is known.
  • Multi-match contrast: overlaps show differently, not as unknown-No.

Why B is correct

A profiling rule set to manual registration leaves matched devices unknown with registration No until confirmed.

Why the others are wrong

  • A. Multi-matches flag conflicts, not unknown-No rows.
  • C. Agent plus PA optimization affects visibility, not registration state.
  • D. No such confirm option gates this view.

FortiNAC exam tip

Unknown plus No means manual registration is waiting. Confirm to clear.

9When creating a device profiling rule, what is an advantage of modeling the endpoint as a device in the inventory view?
  • The devices can have scheduled connection status polling.
  • The device will have historic connection logs.
  • The devices can be associated with a logged on user.
  • The devices will have connection logs.
Answer: A

The short version

A — modeled endpoints gain scheduled connection-status polling. Inventory presence enables check-ins.

Key concepts in this question

  • Device modeling enrolls endpoints in polling schedules.
  • Historic/user/connection logs are side benefits, not the advantage framed.

Why A is correct

Scheduled polling is the documented modeling advantage.

Why the others are wrong

  • B. Historic logs accrue regardless.
  • C. User association is a separate mapping.
  • D. Connection logs are not the framed advantage.

FortiNAC exam tip

Model it = poll it on schedule.

10When managing multiple FortiNAC-F CAs with a FortiNAC-F manager, how is endpoint information updated in the FortiNAC-F manager database?
  • Endpoint information is pulled from the managed CAs by the FortiNAC-F manager at a set interval.
  • Endpoint information is updated in real time when a host status changes.
  • Endpoint information is pushed to the FortiNAC-F manager based on an administratively configured scheduled task.
  • Endpoint information is updated when an administrator synchronizes with each CA.
Answer: A

The short version

A — the manager pulls endpoint data from CAs on a schedule. Interval polling, top-down.

Key concepts in this question

  • Manager-to-CA pulls refresh the manager database periodically.
  • Real-time, push, and manual-sync framings misstate the mechanism.

Why A is correct

Scheduled pulls are the documented update mechanism.

Why the others are wrong

  • B. Status changes do not push in real time.
  • C. No admin-scheduled push task exists.
  • D. Manual sync is not the routine path.

FortiNAC exam tip

Manager updates = scheduled pulls.

Want the full bank of 70 questions for Fortinet NSE 6 - FortiNAC 7.6 Administrator? See all practice exams.