A hospital is deploying a Fortinet wireless network for both medical staff and patients. The security policy mandates that staff devices using 802.1X authentication are placed in VLAN 10, while patient guest devices using a captive portal are placed in VLAN 20. Both SSIDs are broadcast from the same FortiAP-U series access points. Which FortiAP SSID mode is required to achieve this network segmentation?
Q2Multiple answers
A retail company is experiencing poor wireless performance in its high-density warehouse environment. The administrator observes that a few older 802.11n clients are consuming a disproportionate amount of airtime, slowing down newer 802.11ax clients. Which two FortiAP profile features should be configured to mitigate this issue? (Select TWO)
Q3
A wireless administrator is troubleshooting a client connectivity issue where a user fails to authenticate to an 802.1X EAP-TLS SSID. The RADIUS server logs show no authentication attempt from the client. The administrator suspects a problem with the CAPWAP tunnel between the FortiAP and the FortiGate. Which CLI command on the FortiGate would provide real-time debug information about CAPWAP control messages to diagnose this issue?
Q4
True or False: When a FortiAP is operating in dedicated monitor mode, it can simultaneously serve wireless clients and perform background scanning for rogue APs.
Q5
A university is deploying a large-scale wireless network across its campus. They need a solution that simplifies the onboarding of new FortiAPs, minimizes manual configuration, and ensures that APs automatically connect to the correct FortiGate cluster. Which Fortinet feature should be implemented to achieve this? ```mermaid graph TD subgraph Internet FortiDeploy end subgraph Campus_Network FW[FortiGate HA Cluster] Switch[Core Switch] end subgraph New_Building FAP[New FortiAP] end FAP -- DHCP --> Switch Switch --> FW FW -- CAPWAP over Internet --> FortiDeploy FortiDeploy -- Pre-config --> FW ```
Q6
**Case Study:** Global Retail Corp is upgrading the wireless infrastructure across its 200 stores. Each store has a single FortiGate managing local FortiAPs. The corporate IT team needs to enforce a standardized wireless configuration across all stores but allow local store managers to customize the guest Wi-Fi captive portal message. The corporate team must be able to push updates to AP radio settings and security policies centrally, while preventing store managers from altering these critical configurations. The requirements are as follows: 1. Centralized management of AP profiles, SSIDs, and security settings. 2. Delegated management for guest captive portals on a per-store basis. 3. Ability to deploy new FortiAPs to stores with zero-touch provisioning. 4. Scalable management for all 200 store FortiGates and their associated APs. Which Fortinet solution best meets all of Global Retail Corp's requirements?
Q7
A wireless network administrator has configured WPA3-Enterprise with 802.1X authentication. During testing, it is discovered that some older, mission-critical devices do not support WPA3. The administrator needs to allow both WPA3-capable and WPA2-capable clients to connect to the same corporate SSID. What security mode should be configured on the SSID?
Q8
An administrator is analyzing the output of `diagnose wireless-controller wlac -d sta ` to troubleshoot a client's roaming issue. The client is frequently disconnecting and reconnecting while moving through the facility. Which piece of information in the command output is most critical for diagnosing poor roaming performance?
Q9
A security audit reveals that an unauthorized device has been connected to a corporate LAN port and is broadcasting a rogue SSID with the same name as the corporate network (an "evil twin"). The FortiAP WIDS has detected this rogue AP. Which specific Fortinet feature can actively prevent clients from connecting to this on-wire rogue AP?
Q10Multiple answers
A consultant needs to configure dynamic VLAN assignment for wireless clients based on their department, which is stored as an attribute in a RADIUS server. Which three components are essential for this configuration to work? (Select THREE)