Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dcdisc65

Page: 1 / 2
Total 14 questions
Exam Code: NSE6_FAC-6.4                Update: Oct 15, 2025
Exam Name: Fortinet NSE 6 - FortiAuthenticator 6.4

Fortinet Fortinet NSE 6 - FortiAuthenticator 6.4 NSE6_FAC-6.4 Exam Dumps: Updated Questions & Answers (October 2025)

Question # 1

A system administrator wants to integrate FortiAuthenticator with an existing identity management system with the goal of authenticating and deauthenticating users into FSSO.

What feature does FortiAuthenticator offer for this type of integration?

A.

The ability to import and export users from CSV files

B.

RADIUS learning mode for migrating users

C.

C. REST API

D.

D. SNMP monitoring and traps

Question # 2

An administrator wants to keep local CA cryptographic keys stored in a central location.

Which FortiAuthenticator feature would provide this functionality?

A.

SCEP support

B.

REST API

C.

Network HSM

D.

SFTP server

Question # 3

Which EAP method is known as the outer authentication method?

A.

PEAP

B.

EAP-GTC

C.

EAP-TLS

D.

MSCHAPV2

Question # 4

You are the administrator of a large network that includes a large local user datadabase on the current Fortiauthenticatior. You want to import all the local users into a new Fortiauthenticator device.

Which method should you use to migrate the local users?

A.

Import users using RADIUS accounting updates.

B.

Import the current directory structure.

C.

Import users from RADUIS.

D.

Import users using a CSV file.

Question # 5

Which behaviors exist for certificate revocation lists (CRLs) on FortiAuthenticator? (Choose two)

A.

CRLs contain the serial number of the certificate that has been revoked

B.

Revoked certificates are automaticlly placed on the CRL

C.

CRLs can be exported only through the SCEP server

D.

All local CAs share the same CRLs

Question # 6

What are three key features of FortiAuthenticator? (Choose three)

A.

Identity management device

B.

Log server

C.

Certificate authority

D.

Portal services

E.

RSSO Server

Question # 7

Why would you configure an OCSP responder URL in an end-entity certificate?

A.

To designate the SCEP server to use for CRL updates for that certificate

B.

To identify the end point that a certificate has been assigned to

C.

To designate a server for certificate status checking

D.

To provide the CRL location for the certificate

Question # 8

You have implemented two-factor authentication to enhance security to sensitive enterprise systems.

How could you bypass the need for two-factor authentication for users accessing form specific secured networks?

A.

Create an admin realm in the authentication policy

B.

Specify the appropriate RADIUS clients in the authentication policy

C.

Enable Adaptive Authentication in the portal policy

D.

Enable the Resolve user geolocation from their IP address option in the authentication policy.

Question # 9

What capability does the inbound proxy setting provide?

A.

It allows FortiAuthenticator to determine the origin source IP address after traffic passes through a proxy for system access,

B.

It allows FortiAuthenticator to act as a proxy for remote authentication servers.

C.

It allows FortiAuthenticator the ability to round robin load balance remote authentication servers.

D.

It allows FortiAuthenticator system access to authenticating users, based on a geo IP address designation.

Question # 10

At a minimum, which two configurations are required to enable guest portal services on FortiAuthenticator? (Choose two)

A.

Configuring a portal policy

B.

Configuring at least on post-login service

C.

Configuring a RADIUS client

D.

Configuring an external authentication portal

Page: 1 / 2
Total 14 questions

Most Popular Certification Exams

Payment

       

Contact us

dumpscollection live chat

Site Secure

mcafee secure

TESTED 16 Oct 2025