
FortinetNSE 6 - FortiNAC Administrator
Domain 2Objective 1
Configure Security Automation NSE6-FORTINAC-ADMINISTRATOR Practice Questions (Page 3)
Part of the Deployment and Provisioning domain, which accounts for 30-40% of the NSE6-FORTINAC-ADMINISTRATOR exam.
17questions here
4free pages
4concepts
30-40%of the exam
Questions 11–15
- 11
A company uses FortiNAC to automate response to security incidents. They want to automatically quarantine a device for 24 hours when it is detected with a high-risk vulnerability. They have created a security rule that triggers on the 'High-Risk Vulnerability' event and applies a quarantine action. However, they want the quarantine to be temporary. What should they configure?
Select an answer first - 12
A large enterprise uses FortiNAC to automate threat response. They have a security rule that quarantines any device that triggers a 'Critical Vulnerability' event. However, the security team is concerned that the rule is too aggressive and is quarantining devices that are only slightly out of compliance. They want to reduce the number of false positives while still responding to critical threats. What is the BEST approach?
Select an answer first - 13
A company uses a custom security appliance that sends logs in a proprietary format. The logs include a timestamp, a device IP, and a message string. The security team wants FortiNAC to automatically block a device when the message contains the word 'exploit'. They have created a custom parser that extracts the device IP and the message. However, the security rule that triggers on the 'Exploit Detected' event is not firing. What is the MOST likely cause?
Select an answer first - 14
A company uses a third-party IDS that sends alerts in a non-standard format. The IDS sends alerts to FortiNAC via syslog, but FortiNAC is not recognizing the alerts. The administrator has verified that the IDS is sending the syslog messages and that FortiNAC is receiving them. What should the administrator do NEXT?
Select an answer first - 15
An administrator wants FortiNAC to automatically disable a switch port when a threat is detected. Which type of device must be integrated with FortiNAC to allow this action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE6-FORTINAC-ADMINISTRATOR” is a trademark of its owner, used for identification only.