Fortinet NSE 6 - FortiAuthenticator 6.4 Free Sample Questions

20 free sample questions214 in the full practice test

Try simulator

NSE6 Sample Questions

  1. Question 1

    A financial services company is deploying FortiAuthenticator as a SAML IdP to provide SSO access to several third-party SaaS applications. The security policy requires that user access roles within the SaaS applications be determined by their Active Directory group membership. During testing, all users are being granted a default, low-privilege role regardless of their AD group. What is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    The most probable cause is that the SAML assertion is not sending the required group membership information to the Service Provider (SaaS application). FortiAuthenticator, acting as the IdP, must be configured to query the user's groups from the remote LDAP/AD server and then map that information into a specific SAML attribute (like 'memberOf' or 'role') that the SP expects to receive to assign the correct privileges.

  2. Question 2

    A university is implementing 802.1X for its campus-wide wireless network using FortiAuthenticator. They need to support three main device types: corporate-issued laptops (which can be issued client certificates), student-owned devices (BYOD), and legacy lab equipment that does not support 802.1X. Which combination of authentication methods on FortiAuthenticator would securely address all three use cases?

    Answer and explanation

    Correct answer: C

    This is the most appropriate solution. EAP-TLS provides the highest security for corporate-issued devices using client certificates. PEAP (MSCHAPv2) is ideal for BYOD scenarios as it uses username/password credentials, which students have, without requiring certificate management on personal devices. MAC Authentication Bypass (MAB) is the standard method for authenticating devices like printers and legacy equipment that do not have an 802.1X supplicant.

  3. Question 3

    Multiple answers

    An organization is using FortiAuthenticator as a local Certificate Authority (CA). They need to automate the provisioning of user certificates to a large number of non-domain-joined Windows workstations. The security team wants to ensure that certificate requests are automatically approved only for authenticated users without manual intervention. Which two components are essential to achieve this? (Select TWO)

    Answer and explanation

    Correct answers: A, C

  4. Question 4

    True or False: When FortiAuthenticator is configured in a high availability (HA) active-passive cluster, the configuration is automatically synchronized from the primary to the secondary unit, but runtime data such as RADIUS accounting records and user session information are not synchronized in real-time.

    Answer and explanation

    Correct answer: A

    This statement is true. In a standard FortiAuthenticator HA cluster, system and object configurations are synchronized from the primary to the secondary unit. However, most runtime data, including active user sessions and RADIUS accounting data, is not synchronized in real-time. This means that upon a failover, active sessions may need to re-authenticate.

  5. Question 5

    A network administrator is troubleshooting an FSSO deployment where FortiAuthenticator is used to gather logon events. Users are authenticating to a Windows AD domain, but their logon events are not appearing on the FortiGate, causing identity-based policies to fail. The FortiAuthenticator is in a different subnet from the domain controllers. Which troubleshooting step should be performed first to diagnose the issue?

    Answer and explanation

    Correct answer: B

    FortiAuthenticator's FSSO function relies on polling Windows Security Event Logs from domain controllers, typically using Windows Management Instrumentation (WMI) or Remote Procedure Calls (RPC). If the FortiAuthenticator is on a different subnet, network firewalls and, most commonly, the Windows Firewall on the domain controllers themselves, may block this traffic. Ensuring the necessary ports for WMI/RPC are open from the FortiAuthenticator's IP is a critical first step.

  6. Question 6

    A company is using FortiAuthenticator to provide RADIUS authentication for VPN users. The security team wants to enforce a policy where users connecting from the corporate office network bypass two-factor authentication (2FA), but users connecting from any other network must provide a FortiToken code. How can this be configured within a single RADIUS policy?

    Answer and explanation

    Correct answer: C

    FortiAuthenticator's RADIUS policies support adaptive authentication. By enabling 'Authentication factors' and specifying the corporate office subnet in the 'Trusted source addresses' list, you can create a rule that exempts users from 2FA when their connection originates from that trusted network. All other connections will be prompted for the second factor as per the policy.

  7. Question 7

    An administrator revokes a user's certificate that was issued by the FortiAuthenticator's local CA. However, the user is still able to authenticate to the network using EAP-TLS. What is the most likely reason for this failure in security enforcement?

    Answer and explanation

    Correct answer: B

    Simply revoking a certificate marks it for inclusion in the next Certificate Revocation List (CRL). The CRL must then be generated and published. Furthermore, the EAP-TLS authentication policy on the RADIUS server (FortiAuthenticator) must be explicitly configured to perform a CRL check during the authentication process. If either of these steps is missed, the server will not know the certificate has been revoked and will continue to accept it.

  8. Question 8

    A hospital is setting up a guest wireless network. They require a self-registration process where guests can create their own temporary accounts, but each account must be approved by a receptionist before network access is granted. Which FortiAuthenticator feature should be used to meet this requirement?

    Answer and explanation

    Correct answer: C

    The guest portal feature with sponsor-based approval is designed specifically for this scenario. Guests can self-register on the portal, and the system will then notify a designated sponsor (or a group of sponsors, like the receptionists) to approve or deny the request. The guest account is only activated after the sponsor grants approval.

  9. Question 9

    An administrator is configuring RADIUS Single Sign-On (RSSO) on FortiAuthenticator. The goal is to create FSSO logon events based on RADIUS authentication from a third-party wireless controller. Which RADIUS message type is essential for FortiAuthenticator to receive to successfully create and terminate user sessions for RSSO?

    Answer and explanation

    Correct answer: C

    RSSO relies on RADIUS Accounting messages to track user sessions. The third-party RADIUS client (wireless controller) must be configured to send Accounting-Request messages with a status type of 'Start' when a user connects and 'Stop' when they disconnect. FortiAuthenticator listens for these accounting packets to create and terminate the corresponding FSSO sessions.

  10. Question 10

    A retail company is deploying a new wireless network and wants to use FortiAuthenticator for authentication. They have two main requirements:

    1. Corporate employees must authenticate using their Active Directory credentials.
    2. In-store customers should connect to a separate guest SSID and authenticate using their social media accounts (Facebook or Google).

    How should the administrator configure realms on FortiAuthenticator to support this?

    Answer and explanation

    Correct answer: B

    Realms are used to direct authentication requests to the correct user source based on the source of the request (like the SSID). The correct approach is to create two distinct realms. The employee realm would be associated with the corporate SSID and configured to use the remote AD server for authentication. The guest realm would be associated with the guest SSID and configured to use a captive portal with social media authenticators enabled.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 214 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon