10 free sample questions from a bank of 70, with the correct answers and explanations. No signup required — start practising right now.
1A manager is using a FortiNAC-F control manager to deploy an N+1 HA cluster. Which cluster member must be added first to begin the configuration?
Secondary
Worker
Primary
Manager
Answer: C
The short version
C — N+1 clusters build primary-first. The manager seeds from the primary.
Key concepts in this question
Primary holds the authoritative dataset for cluster formation.
Secondaries, workers, and managers join an existing primary.
Why C is correct
Primary-first is the documented N+1 build order.
Why the others are wrong
A. Secondaries replicate; they do not seed.
B. Workers compute; they do not found clusters.
D. The manager orchestrates; the primary seeds.
FortiNAC exam tip
N+1 build order = primary first.
2Refer to the exhibit. After a successful layer 2 poll, two hosts were learned on the same port. The port is a member of the Role-Based Access and Forced Registration groups. The switch has been configured to leverage a single isolation VLAN. How will FortiNAC-F manage this port?
The port will be provisioned to the isolation network.
The port will be added to the Access Point Management group.
The port will be provisioned for the normal state host, but the second host will have access to only the isolation portal page.
The port will be provisioned as an uplink to a hub or unmanaged switch.
Answer: D
The short version
D — two MACs on one access port means a hub, so FortiNAC treats it as an uplink. A single port cannot carry two different VLAN outcomes at once.
Key concepts in this question
Layer-2 poll learning: two hosts on the same port reveals a downstream hub or unmanaged switch.
Single isolation VLAN limit: one port holds one VLAN, so split enforcement is impossible.
Enforcement-group conflict: Role-Based Access plus Forced Registration demand different networks for different states.
Why D is correct
The exhibit lists two physical addresses learned on the same port after a successful layer-2 poll, proving a hub sits downstream. The port sits in both Role-Based Access and Forced Registration groups, so compliant and rogue hosts would need different networks, but the switch offers only a single isolation VLAN. FortiNAC cannot satisfy both outcomes on one VLAN-switched port, so it provisions the port as an uplink to a hub or unmanaged switch and exempts it from per-host provisioning rather than breaking one host.
Why the others are wrong
A. Isolation would wrongly force the compliant host offline together with the rogue host.
B. Access Point Management is for access points, with no access-point evidence here.
C. Split provisioning is impossible on a single-VLAN port serving two hosts.
FortiNAC exam tip
Two hosts, one port, conflicting states equals hub uplink.
3Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)
A FortiNAC-F device designated as a secondary
At least two FortiNAC-F devices designated as primary
A dedicated VLAN for primary and secondary synchronization
A FortiNAC-F manager
Answer: A, D
The short version
A and D — N+1 needs a designated secondary plus the FortiNAC manager. Failover target plus orchestrator.
Key concepts in this question
Secondary designation provides the +1 failover capacity.
The manager coordinates the N+1 topology.
Why A and D are correct
The two documented N+1 requirements.
Why the others are wrong
B. Multiple primaries describe other topologies, not N+1.
C. Dedicated sync VLANs are not the framed requirement.
FortiNAC exam tip
N+1 = secondary + manager.
4An administrator wants FortiNAC-F to pass firewall tags to FortiGate to leverage dynamic address groups used in firewall policies. On FortiNAC-F, what determines the values that are passed?
RADIUS group attribute
Device profiling rule
Model configuration
Security rule
Answer: D
The short version
D — the security rule decides the tags. FortiNAC-F passes the firewall tags its security rule produces for dynamic address groups.
Key concepts in this question
Firewall tags: NAC-computed labels consumed by FortiGate.
Security rule: the policy object that yields tag values.
The values passed to FortiGate come from the FortiNAC-F security rule driving dynamic address-group membership.
Why the others are wrong
A. RADIUS group attributes authenticate users; they set no firewall tags.
B. Profiling rules identify devices; tags flow from security rules.
C. Model configuration describes inventory, not tag values.
FortiNAC exam tip
Tags follow security rules; profiling only feeds them.
5An organization has FortiNAC-F deployed and is using layer 3 isolation networks across multiple sites with firewalls. At a minimum, which three protocols must be allowed between the isolation networks and FortiNAC-F? (Choose three.)
DDNS
HTTP/HTTPS
DHCP
NTP
DNS
Answer: B, C, E
The short version
B, C, E — L3 isolation lifelines are HTTP/S, DHCP, and DNS. Portal, address, resolve.
Key concepts in this question
HTTP/HTTPS serves the captive/remediation portal.
DHCP + DNS give isolated hosts function.
Why B, C and E are correct
The three documented minimum isolation protocols (FNC-8.5 Q28 confirms DNS/DHCP/Web pattern).
Why the others are wrong
A. DDNS is not an isolation requirement.
D. NTP is not in the minimum set.
FortiNAC exam tip
Isolation minimum = HTTP/S, DHCP, DNS.
6By default, when would a port in the FortiNAC-F network inventory view become a learned uplink?
When the port is connected to another modeled infrastructure device
When the port is configured as a trunk port on the infrastructure device
When the port shows more than 20 MAC addresses connected at the same time
When the port is added to the Access Point Management group
Answer: C
The short version
C — 20+ MACs makes a learned uplink. Same threshold as FNC-8.5 Q7.
Key concepts in this question
Learned uplinks exempt aggregation ports from endpoint enforcement.
The 20-MAC default marks downstream infrastructure.
A. Modeled devices show differently than learned uplinks.
B. Trunk config alone does not promote.
D. AP groups are explicit assignments, not learned states.
FortiNAC exam tip
20 MACs = learned uplink.
7Refer to the exhibit. Given this topology, and a layer 3 registration network configuration, which IP address would be designated in the DHCP relay configuration for the registration network?
192.168.200.10
192.168.100.20
192.168.100.75
192.168.10.254
Answer: A
The short version
A — DHCP relay for the registration network points at the FortiNAC registration interface (.200.10). Same answer as Q35's duplicate.
Key concepts in this question
Layer 3 registration relays DHCP to FortiNAC's registration-network address.
The .200.10 address is the registration interface in this topology.
B/C. The .100.x addresses belong to other networks.
D. The .10.254 address is not the registration relay target.
FortiNAC exam tip
Duplicate relay stems = same relay address.
8An administrator has created several device profiling rules and evaluated all existing devices in the database. Some of the devices appear in the profiled devices view because they matched a rule, but they remain unknown and the registration column in the profiled devices view shows "No". What is the most likely cause?
The devices match more than one device profiling rule.
The device profiling rule has registration set to manual.
The devices have persistent agents installed, and the point of connection has PA optimization enabled.
The confirm device profiling rule option is not enabled.
Answer: B
The short version
B — matched-but-unknown with No registration means manual. The rule requires an admin to register the device.