NSE6 Fortinet NSE 6 - FortiAuthenticator 6.4 Practice Questions
Prepare for NSE6 with more than an answer.
- Exam fee
- $200 USD
- Level
- Specialist
- Valid for
- 2 years
Domains covered on the exam 4
- FortiAuthenticator Management25%
- Certificate Management20%
- Active Authentication (RADIUS, LDAP, 802.1X, Portal Services)35%
- Single Sign-On (SSO)20%
- 1
True or False: When configuring FortiAuthenticator to use a remote LDAP server for user authentication, it is mandatory to use an LDAP account with domain administrator privileges for the bind credentials.
Show answer details
Correct answer: B
This statement is false. Following the principle of least privilege, the LDAP bind account does not need domain administrator privileges. It only requires sufficient read permissions to search the specified base distinguished name (DN) and read the attributes of users and groups that FortiAuthenticator needs for authentication and authorization.
- 2
Which two of the following are valid user sources that can be configured in a FortiAuthenticator realm for authentication? (Select TWO)
Show answer details
Correct answer: A, B
- 3
A user is attempting to log in with their FortiToken Mobile using push notifications, but they do not receive the notification on their phone. They are able to successfully authenticate by manually entering the TOTP code from the app. Which of the following is the most likely cause for the push notification failure?
Show answer details
Correct answer: B
Push notifications for FortiToken Mobile are brokered through the FortiToken Cloud service. The FortiAuthenticator must be able to resolve the service's FQDN via DNS and have outbound HTTPS (TCP/443) connectivity to it. If this communication is blocked by a firewall or fails due to DNS issues, the push notification cannot be sent. Manual TOTP entry works because it's a local calculation that doesn't require this external communication.
- 4
A system administrator is configuring a local CA on FortiAuthenticator. They need to ensure that certificates issued for web servers are valid for both
www.example.comandportal.example.com. Which certificate field must be configured correctly to achieve this?Show answer details
Correct answer: B
While the Common Name (CN) field can hold one primary name, the modern and correct way to specify multiple hostnames for a single SSL/TLS certificate is by using the Subject Alternative Name (SAN) extension. Browsers prioritize the SAN field. To be valid for both
www.example.comandportal.example.com, both names must be listed as DNS entries in the SAN field of the certificate. - 5
Which statement accurately describes the relationship between a Certificate Authority (CA) and a Certificate Revocation List (CRL)?
graph TD subgraph CertificateLifecycle CA[Certificate Authority] -->|Issues| Cert(User Certificate) Cert -->|Is Valid| Access[Access Granted] Cert -->|Compromised| Revoke{Revoke Certificate} Revoke --> CA CA -->|Publishes| CRL[CRL] CRL -->|Checked by| RP(Relying Party / RADIUS Server) RP -->|If Cert is on CRL| Deny[Access Denied] endShow answer details
Correct answer: C
A Certificate Revocation List (CRL) is a digitally signed list, published by a Certificate Authority (CA), of all the certificates that it has issued but which are now considered invalid and should no longer be trusted. Relying parties (like a RADIUS server) must download and check the latest CRL from the CA to ensure a presented certificate has not been revoked.
- 6
A financial services company is deploying FortiAuthenticator as a SAML IdP to provide SSO access to several third-party SaaS applications. The security policy requires that user access roles within the SaaS applications be determined by their Active Directory group membership. During testing, all users are being granted a default, low-privilege role regardless of their AD group. What is the most likely cause of this issue?
Show answer details
Correct answer: B
The most probable cause is that the SAML assertion is not sending the required group membership information to the Service Provider (SaaS application). FortiAuthenticator, acting as the IdP, must be configured to query the user's groups from the remote LDAP/AD server and then map that information into a specific SAML attribute (like 'memberOf' or 'role') that the SP expects to receive to assign the correct privileges.
- 7
A university is implementing 802.1X for its campus-wide wireless network using FortiAuthenticator. They need to support three main device types: corporate-issued laptops (which can be issued client certificates), student-owned devices (BYOD), and legacy lab equipment that does not support 802.1X. Which combination of authentication methods on FortiAuthenticator would securely address all three use cases?
Show answer details
Correct answer: C
This is the most appropriate solution. EAP-TLS provides the highest security for corporate-issued devices using client certificates. PEAP (MSCHAPv2) is ideal for BYOD scenarios as it uses username/password credentials, which students have, without requiring certificate management on personal devices. MAC Authentication Bypass (MAB) is the standard method for authenticating devices like printers and legacy equipment that do not have an 802.1X supplicant.
- 8
An organization is using FortiAuthenticator as a local Certificate Authority (CA). They need to automate the provisioning of user certificates to a large number of non-domain-joined Windows workstations. The security team wants to ensure that certificate requests are automatically approved only for authenticated users without manual intervention. Which two components are essential to achieve this? (Select TWO)
Show answer details
Correct answer: A, C
- 9
True or False: When FortiAuthenticator is configured in a high availability (HA) active-passive cluster, the configuration is automatically synchronized from the primary to the secondary unit, but runtime data such as RADIUS accounting records and user session information are not synchronized in real-time.
Show answer details
Correct answer: A
This statement is true. In a standard FortiAuthenticator HA cluster, system and object configurations are synchronized from the primary to the secondary unit. However, most runtime data, including active user sessions and RADIUS accounting data, is not synchronized in real-time. This means that upon a failover, active sessions may need to re-authenticate.
- 10
A network administrator is troubleshooting an FSSO deployment where FortiAuthenticator is used to gather logon events. Users are authenticating to a Windows AD domain, but their logon events are not appearing on the FortiGate, causing identity-based policies to fail. The FortiAuthenticator is in a different subnet from the domain controllers. Which troubleshooting step should be performed first to diagnose the issue?
Show answer details
Correct answer: B
FortiAuthenticator's FSSO function relies on polling Windows Security Event Logs from domain controllers, typically using Windows Management Instrumentation (WMI) or Remote Procedure Calls (RPC). If the FortiAuthenticator is on a different subnet, network firewalls and, most commonly, the Windows Firewall on the domain controllers themselves, may block this traffic. Ensuring the necessary ports for WMI/RPC are open from the FortiAuthenticator's IP is a critical first step.
