wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

FortiAuthenticator 6.1

Total questions: 31

Worksheet time: 10mins

Name
Class
Date
1.

Which two features of Fortiauthenticator are used for EAP deployment? (Choose two)

a)

Certificate authority

b)

LDAP server

c)

MAC authentication bypass

d)

RADIUS server

2.

Which Network configuration is required when deploying fortiauthenticator for portal services?

a)

Fortiauthenticator must have the REST API access enable on port1

b)

One of the DNS servers must be a Fortiguard DNS server

c)

Fortigate must be setup as default gateway for FortiAuthenticator

d)

Policies must have specific ports open between Fortiauthenticator and the authentication clients

3.

Which method is the most secure way of delivering fortitoken data once the token has been seeded?

a)

Online activation of the tokens through the fortiguard network

b)

Shipment of the seed files on a CD using a tamper-evident envelope

c)

Using the in-house token provisioning toll

d)

Automatic token generation using Fortiauthenticator

4.

At a minimum which two configurations are required to enable guest portal services on Fortiauthenticator? (Choose two)

a)

Configuring a portal policy

b)

Configuring at least on post-login service

c)

Configuring a RADIUS client

d)

Configuring an external authentication portal

5.

What happens when a certificate is revoked? (Choose two)

a)

Revoked certificates cannot be reinstated for any reason

b)

All certificates signed by a revoked CA certificate are automatically revoked

c)

Revoked certificates are automatically added to the CRL

d)

External CAs will periodically query Fortiauthenticator and automatically download revoked certificates

6.

Which three of the following can be used as SSO sources? (Choose three)

a)

Forticlient SSO Mobility Agent

b)

SSH Sessions

c)

FortiAuthenticator in SAML SP role

d)

Fortigate

e)

RADIUS accounting

7.

Which statement about the guest portal policies is true?

a)

Guest portal policies apply only to authentication request coming from unknown RADIUS clients

b)

Guest portal policies can be used only fo BYODs

c)

Conditions in the policy apply only to guest wireless users

d)

All conditions in the policy must match before a user is presented with the guest portal

8.

Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?

a)

Service provider contacts idendity provider, idendity provider validates principal for service provider, service provider establishes communication with principal.

b)

Principal contacts idendity provider and is redirected to service provider, principal establishes connection with service provider, service provider validates authentication with identity provider.

c)

Principal contacts service provider, service provider redirects principal to idendity provider, after successful authentication identify provider redirects principal to service provider.

d)

Principal contacts idendity provider and authenticates, identity provider relays principal to service provider after valid authentication

9.

How can a SAML metada file be used?

a)

To defined a list of trusted user names

b)

To import the required IDP configuration

c)

To correlate the IDP address to its hostname

d)

To resolve the IDP realm for authentication

10.

What are three key features of fortiauthenticator? (Choose three)

a)

Identity management device

b)

Log Sever

c)

Certificate Authority

d)

Portal services

e)

RSSO Server

11.

Which behaviors exist for certificate revocation list (CRLs) on Fortiauthenticator? (Choose two)

a)

CRLs contain the serial number of the certificate that has been revoked.

b)

Revoked certificates are automatically placed on the CRL

c)

CRLs can been exported only through the SCEP server

d)

All local CAs share the same CRLs

12.

Which two SAML roles can Fortiauthenticator be configured as? (Choose two)

a)

Idendity provider

b)

Principal

c)

Assertion server

d)

Service provider

13.

A device or user identity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentials. In this case, which user idendity discovery method can Fortiauthenticator use?

a)

Syslog messaging or SAML IDP

b)

Kerberos-base authentication

c)

Radius accounting

d)

Portal authentication

14.

You are a Fortiauthenticator administrator for a lagge organization. Users who are configured to use Fortitoken 200 for two-factor authentication can no longer authenticate. You have verified that only the user with two-factor authentication are experiencing the issue.

What can couse this issue?

a)

On of the fortiauthenticator devices in the active-active cluster has failed.

b)

Fortiauthenticator has lose contact with the fortitoken cloud servers

c)

Fortitoken 200 licence has expired

d)

Time drift between Fortiauthenticator and hardware tokens

15.

When you are setting up two Fortiauthenticator devices in active-passive HA, which HA role must you select on the master Fortiauthenticator?

a)

Active-passive master

b)

Standalone master

c)

Cluster member

d)

Load balancing master

16.

Which two capabilities does FortiAuthenticator offer when acting as a self-signed or local CA? (Choose two)

a)

Validating other CA CRLs using OSCP

b)

Importing other CA certificates and CRLs

c)

Merging local and remote CRLs using SCEP

d)

Creating signing, and revoking of X.509 certificates

17.

Which of the following is an QATH-based standard to generate event-based, one-time password tokens?

a)

OLTP

b)

SOTP

c)

HOTP

d)

TOTP

18.

Which two statements about the EAP-TTLS authentication method are true? (choose two)

a)

Uses mutual authentication

b)

Uses digital certificates only on the server side

c)

Requires an EAP server certificate

d)

Support a port access control (Wired) solution only

19.

Which two statements about the self-service portal true? (Choose two)

a)

Self-registration information can be sent to the user through email or SMS

b)

Realms can be used to configure which seld-registered users or groups can authenticate on the network.

c)

Administrator a­pproval is required for all self-registration

d)

Authenticating users must specific domain name along with username

20.

Which statement about the guest portal policies is true?

a)

Guest portal policies apply only to authentication requests coming from unknown RADIUS clients.

b)

Guest portal policies can be used only for BYODs

c)

Conditions in the policy apply only to guest wireless users.

d)

All conditions in the policy must match before a user is presented with the guest portal

21.

Which EAP method is known as the outer authentication method?

a)

PEAP

b)

EAP-GTC

c)

EAP-TLS

d)

MSCHAPV2

22.

Which two types of digital certificates can you create in fortiauthenticator? (Choose two)

a)

User certificate

b)

Organization validation certificate

c)

Third-party root certificate

d)

Local service certificate

23.

Which two protocols are the default management access protocols for administrative access for fortiauthenticator? (Choose two)

a)

Telnet

b)

HTTPS

c)

SSH

d)

SNMP

24.

You are the administrator of a large network that includes a large local user database on the current Fortiauthenticator. You want to import all the users into a new Fortiauthenticator device.

Which method should you use to migrate the local user?

a)

Import users using RADIUS accounting update.

b)

Import the current directory structure.

c)

Import user from RADIUS

d)

Import users using a CSV file

25.

Which interface services must be enabled for the SCEP client to connect to Authenticator?

a)

OCSP

b)

REST API

c)

SSH

d)

HTTP/HTTPS

26.

You are WI-FI provider and host multiple domains. How do you delegate user accounts, user groups and permissions per domain when they are authenticating on a single Fortiauthenticator device?

a)

Automatically import host from each domain as they authenticate

b)

Create multiple directory trees on FortiAuthenticator

c)

Create realms

d)

Create user Groups

27.

Which two statement about the RADIUS service on Fortiauthenticator are true? (Choose two)

a)

Two-factor authentication cannot be enforced when using RADIUS authentication

b)

RADIUS users can migrated to ldap users

c)

Only local users can be authenticated through RADIUS

d)

Fortiauthenticator answers only to RADIUS client that are registered with Fortiauthenticator

28.

You want to monitor fortiauthenticator system information and receive fortiauthenticator traps thro­­ugh SNMP. Which two configurations must be performed after enabling SNMP access on the fortiauthenticator interface.

a)

Enable logging services

b)

Set the threshold to trigger SNMP traps

c)

Upload management information base (MIB) Files to SNMP server

d)

Associate an ASN, 1 mapping rule to the receiving host

29.

Which FSSO Discovery method transparently detects logged off users without having to rely on external features such as WMI polling?

a)

Windows AD polling

b)

Forticlient SSO Mobility Agent

c)

Radius Accounting

d)

DC Polling

30.

Which two are supported captive or guest portal authentication methods? (Choose two)

a)

Linkedin

b)

Apple ID

c)

Instagram

d)

Email

31.

Refer to the exhibit.

Examine the screenshot shown in the exhibit.

Which two statements regarding the configuration are true? (Choose two)

a)

All guest accounts created using the account registration feature will be placed under the guest_portal_users group

b)

All accounts registered through the guest portal must be validated through email

c)

Guest users must fill in all the fields on the registration form

d)

Guest user account will expire after eight hours