Skip to content

NSE5_FNC_AD-7.6 Fortinet NSE 5 - FortiNAC-F 7.6 Administrator Practice Questions

Prepare for NSE5_FNC_AD-7.6 with more than an answer.

125 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$200 USD
Time limit
65 minutes
Questions on the exam
30-35
Passing score
Pass/Fail (Fortinet does not publicly disclose numeric passing scores)
Level
NSE 5 - Professional
Valid for
2 years
Domains covered on the exam 4
  1. Concepts and Initial Configuration20%
  2. Deployment and Provisioning30%
  3. Integration25%
  4. Network Visibility and Monitoring25%
  1. 1

    A security engineer creates a Security Automation Policy in FortiNAC-F. The goal is to isolate any host that generates a specific 'Malware Detected' syslog message from a FireEye appliance. Which sequence correctly describes the configuration steps required?

    Show answer details

    Correct answer: D

    The correct workflow involves parsing the raw data into an internal Event, creating a Trigger that fires when that Event occurs (often with thresholds), defining the Action (what to do), and linking them in an Automation Policy.

  2. 2

    When configuring a Network Access Policy in FortiNAC-F using 802.1X, which RADIUS attribute is CRITICAL for FortiNAC to correctly identify the connecting endpoint's MAC address?

    Show answer details

    Correct answer: C

    The Calling-Station-Id RADIUS attribute (Attribute 31) typically carries the MAC address of the supplicant (the endpoint). FortiNAC uses this to match the request against its database of known hosts.

  3. 3

    A company policy states that all printers must be profiled automatically and assigned to the 'Printers' Device Group. However, they must NOT be granted network access until an administrator manually approves them. Which configuration combination achieves this?

    Show answer details

    Correct answer: A

    Device Profiling Rules can identify devices (e.g., via OUI or DHCP fingerprint). By setting the registration action to a state requiring approval (or not auto-registering into a production state), the device remains in a restricted state (like Registration VLAN) until an admin intervenes.

  4. 4

    A network architect is designing a FortiNAC-F deployment for a large campus environment. The design requires Layer 3 isolation for a specific branch office where the switching infrastructure does not support VLAN changing via SNMP. Which architectural component or configuration is strictly required to facilitate isolation in this specific Layer 3 scenario?

    Show answer details

    Correct answer: B

    In a Layer 3 isolation scenario where VLAN switching is not possible or desired at the access edge, Policy-Based Routing (PBR) is used on the gateway. This redirects web traffic from unauthenticated or non-compliant endpoints to the FortiNAC-F Control Server's isolation interface (portal) for registration or remediation.

  5. 5

    During the initial configuration wizard of a FortiNAC-F appliance, an administrator is configuring the network interfaces. The appliance is deployed as a virtual machine. Which statement correctly describes the requirement for the 'isolation' interface in a standard deployment?

    Show answer details

    Correct answer: A

    The isolation interface (often Port 2) on FortiNAC-F is designed to listen for DHCP requests and DNS queries from devices in the isolation VLANs (Registration, Remediation). It serves as the gateway to the captive portal for these isolated devices.

  6. 6

    While modeling a third-party switch in FortiNAC-F using SNMP v3, the device validation fails despite the IP address being reachable. The administrator has verified the username and authentication password are correct. Which other parameter is a common cause for this failure in a high-security environment?

    Show answer details

    Correct answer: A

    SNMP v3 supports both Authentication (Auth) and Privacy (Priv/Encryption). In high-security environments, 'AuthPriv' is commonly used. If the Privacy password or algorithm (DES, AES) is mismatched or missing in the FortiNAC device model configuration, validation will fail.

Create an account to continue.