Sep 13, 2021 Step by Step Guide to Prepare for NSE6_FWF-6.4 Exam BrainDumps
NSE 6 Network Security Specialist NSE6_FWF-6.4 Real Exam Questions and Answers FREE Updated on 2021
NEW QUESTION 17
A tunnel mode wireless network is configured on a FortiGate wireless controller.
Which task must be completed before the wireless network can be used?
- A. The wireless network interface must be assigned a Layer 3 address
- B. The wireless network to Internet firewall policy must be configured
- C. Security Fabric and HTTPS must be enabled on the wireless network interface
- D. The new network must be manually assigned to a FortiAP profile.
Answer: B
Explanation:
A FortiGate unit is an industry leading enterprise firewall. In addition to consolidating all the functions of a network firewall, IPS, anti-malware, VPN, WAN optimization, Web filtering, and application control in a single platform, FortiGate also has an integrated Wi-Fi controller.
NEW QUESTION 18
When using FortiPresence as a captive portal, which two types of public authentication services can be used to access guest Wi-Fi? (Choose two.)
- A. Hardware security token authentication
- B. Social networks authentication
- C. Short message service authentication
- D. Software security token authentication
Answer: A,B
Explanation:
This information along with the social network authentication logins with Facebook, Google, Instagram, LinkedIn, or FortiPresence using your WiFi.
Captive Portal configurations for social media logins and internet access. You can add and manage sites using the integrated Google maps and manoeuvre your hardware infrastructure easily.
NEW QUESTION 19
Which two phases are part of the process to plan a wireless design project? (Choose two.)
- A. Project information phase
- B. Installation phase
- C. Site survey phase
- D. Hardware selection phase
Answer: B,C
Explanation:
Reference:
https://www.automation.com/en-us/articles/2015-2/wireless-device-network-planning-and-design
NEW QUESTION 20
How are wireless clients assigned to a dynamic VLAN configured for hash mode?
- A. Using the current number of wireless clients connected to the SSID and the number of IPs available in the least busy VLAN
- B. Using the current number of wireless clients connected to the SSID and the group the FortiAP is a member of
- C. Using the current number of wireless clients connected to the SSID and the number of clients allocated to each of the VLANs
- D. Using the current number of wireless clients connected to the SSID and the number of VLANs available in the pool
Answer: D
Explanation:
VLAN from the VLAN pool based on a hash of the current number of SSID clients and the number of entries in the VLAN pool.
NEW QUESTION 21
Which statement is correct about security profiles on FortiAP devices?
- A. Security profiles on FortiAP devices can use FortiGate subscription to inspect the traffic
- B. Disable DTLS on FortiAP
- C. FortiGate performs inspection the wireless traffic
- D. Only bridge mode SSIDs can apply the security profiles
Answer: D
NEW QUESTION 22
Which administrative access method must be enabled on a FortiGate interface to allow APs to connect and function?
- A. Security Fabric
- B. HTTPS
- C. SSH
- D. FortiTelemetry
Answer: A
NEW QUESTION 23
Refer to the exhibits.
Exhibit A
Exhibit B
A wireless network has been created to support a group of users in a specific area of a building. The wireless network is configured but users are unable to connect to it. The exhibits show the relevant controller configuration for the APs and the wireless network.
Which two configuration changes will resolve the issue? (Choose two.)
- A. For both interfaces in the wtp-profile, configure set vaps to be "Authors"
- B. Increase the transmission power of the AP radio interfaces
- C. For both interfaces in the wtp-profile, configure vap-all to be manual
- D. Disable intra-vap-privacy for the Authors vap-wireless network
Answer: C,D
NEW QUESTION 24
Which two statements about distributed automatic radio resource provisioning (DARRP) are correct? (Choose two.)
- A. DARRP performs continuous spectrum analysis to detect sources of interference. It uses this information to allow the AP to select the optimum channel.
- B. DARRP performs measurements of the number of BSSIDs and their signal strength (RSSI). The controller then uses this information to select the optimum channel for the AP.
- C. DARRP measurements can be scheduled to occur at specific times.
- D. DARRP requires that wireless intrusion detection (WIDS) be enabled to detect neighboring devices.
Answer: A,D
Explanation:
DARRP (Distributed Automatic Radio Resource Provisioning) technology ensures the wireless infrastructure is always optimized to deliver maximum performance. Fortinet APs enabled with this advanced feature continuously monitor the RF environment for interference, noise and signals from neighboring APs, enabling the FortiGate WLAN Controller to determine the optimal RF power levels for each AP on the network. When a new AP is provisioned, DARRP also ensures that it chooses the optimal channel, without administrator intervention.
NEW QUESTION 25
When deploying a wireless network that is authenticated using EAP PEAP, which two configurations are required? (Choose two.)
- A. 509 certificates and work for connections that use Secure Socket Layer/Transport Level Security (SSL/TLS). Both client and server certificates have additional requirements.
- B. An X.509 to authenticate the authentication server
- C. An X.509 certificate to authenticate the client
- D. A WPA2 or WPA3 personal wireless network
- E. A WPA2 or WPA3 Enterprise wireless network
Answer: B,C
NEW QUESTION 26
Which two configurations are compatible for Wireless Single Sign-On (WSSO)? (Choose two.)
- A. A VAP configured to authenticate locally on FortiGate
- B. A VAP configured to authenticate using a radius server
- C. A VAP configured for WPA2 or 3 Enterprise
- D. A VAP configured for captive portal authentication
Answer: B,C
Explanation:
In the SSID choose WPA2-Enterprise authentication.
WSSO is RADIUS-based authentication that passes the user's user group memberships to the FortiGate.
NEW QUESTION 27
What is the first discovery method used by FortiAP to locate the FortiGate wireless controller in the default configuration?
- A. Broadcast
- B. Static
- C. DHCP
- D. Multicast
Answer: C
NEW QUESTION 28
Refer to the exhibit.
What does the asterisk (*) symbol beside the channel mean?
- A. Indicates channels that are subject to dynamic frequency selection (DFS) regulations
- B. Indicates channels that can be used only when Radio Resource Provisioning is enabled
- C. Indicates channels that cannot be used because of regulatory channel restrictions
- D. Indicates channels that will be scanned by the Wireless Intrusion Detection System (WIDS)
Answer: B
NEW QUESTION 29
......
Ultimate Guide to Prepare NSE6_FWF-6.4 Certification Exam for NSE 6 Network Security Specialist: https://www.itexamdownload.com/NSE6_FWF-6.4-valid-questions.html
NSE6_FWF-6.4 Ultimate Study Guide: https://drive.google.com/open?id=1SL3SN40ALaParklmu0hRtGaSI14thhfX