NSE7_SAC-6.2 Fortinet NSE 7 - Secure Access 6.2 Practice Questions
Prepare for NSE7_SAC-6.2 with more than an answer.
- Exam fee
- $400 USD
- Time limit
- 60 minutes
- Questions on the exam
- 30-35
- Passing score
- 60%
- Level
- Advanced
- Valid for
- 2 years
Domains covered on the exam 7
- Secure Access Architecture15%
- Advanced Authentication and Authorization20%
- Wired Network Security with FortiSwitch15%
- Wireless Network Security with FortiAP15%
- Centralized Management with FortiManager10%
- Security Fabric Integration and Automation15%
- Troubleshooting Secure Access10%
- 1
Which two statements about the use of digital certificates are true? (Choose two.)
Show answer details
Correct answer: B, D
Both statements about intermediate Certificate Authorities are correct. An intermediate CA can sign another intermediate CA certificate, creating a certificate chain hierarchy where multiple levels of intermediate CAs exist between the root CA and end entity certificates. Additionally, an intermediate CA can validate end entity certificates signed by another intermediate CA within the same trust chain, as long as both intermediate CAs trace back to the same trusted root CA. Intermediate CAs can indeed sign server certificates directly, but this is not one of the selected options. End entity certificates can be created by either root CAs or intermediate CAs, not exclusively by intermediate CAs.
Both statements about intermediate Certificate Authorities are correct. An intermediate CA can sign another intermediate CA certificate, creating a certificate chain hierarchy where multiple levels of intermediate CAs exist between the root CA and end entity certificates. Additionally, an intermediate CA can validate end entity certificates signed by another intermediate CA within the same trust chain, as long as both intermediate CAs trace back to the same trusted root CA. Intermediate CAs can indeed sign server certificates directly, but this is not one of the selected options. End entity certificates can be created by either root CAs or intermediate CAs, not exclusively by intermediate CAs.
- 2
Which step can be taken to ensure that only FortiAP devices receive IP addresses from a DHCP server on FortiGate?
Show answer details
Correct answer: C
Configure a VCI (Vendor Class Identifier) string value of FortiAP in the DHCP server settings to ensure only FortiAP devices receive IP addresses. The VCI is a DHCP option that FortiAP devices automatically include in their DHCP requests, allowing the FortiGate DHCP server to identify and selectively assign IP addresses to legitimate FortiAP devices while denying DHCP requests from other devices. Interface addressing mode changes affect IP assignment methods, not device filtering. Reservation lists require knowing specific MAC addresses in advance. DHCP option 138 is for specific configuration parameters, not device identification.
