Skip to content

NSE7_SAC-6.2 Fortinet NSE 7 - Secure Access 6.2 Practice Questions

Prepare for NSE7_SAC-6.2 with more than an answer.

30 questions in the full set4 sample questionsUpdated Dec 7, 2025
Exam fee
$400 USD
Time limit
60 minutes
Questions on the exam
30-35
Passing score
60%
Level
Advanced
Valid for
2 years
Domains covered on the exam 7
  1. Secure Access Architecture15%
  2. Advanced Authentication and Authorization20%
  3. Wired Network Security with FortiSwitch15%
  4. Wireless Network Security with FortiAP15%
  5. Centralized Management with FortiManager10%
  6. Security Fabric Integration and Automation15%
  7. Troubleshooting Secure Access10%
  1. 1

    Which two statements about the use of digital certificates are true? (Choose two.)

    Show answer details

    Correct answer: B, D

    Both statements about intermediate Certificate Authorities are correct. An intermediate CA can sign another intermediate CA certificate, creating a certificate chain hierarchy where multiple levels of intermediate CAs exist between the root CA and end entity certificates. Additionally, an intermediate CA can validate end entity certificates signed by another intermediate CA within the same trust chain, as long as both intermediate CAs trace back to the same trusted root CA. Intermediate CAs can indeed sign server certificates directly, but this is not one of the selected options. End entity certificates can be created by either root CAs or intermediate CAs, not exclusively by intermediate CAs.

    Both statements about intermediate Certificate Authorities are correct. An intermediate CA can sign another intermediate CA certificate, creating a certificate chain hierarchy where multiple levels of intermediate CAs exist between the root CA and end entity certificates. Additionally, an intermediate CA can validate end entity certificates signed by another intermediate CA within the same trust chain, as long as both intermediate CAs trace back to the same trusted root CA. Intermediate CAs can indeed sign server certificates directly, but this is not one of the selected options. End entity certificates can be created by either root CAs or intermediate CAs, not exclusively by intermediate CAs.

  2. 2

    Which step can be taken to ensure that only FortiAP devices receive IP addresses from a DHCP server on FortiGate?

    Show answer details

    Correct answer: C

    Configure a VCI (Vendor Class Identifier) string value of FortiAP in the DHCP server settings to ensure only FortiAP devices receive IP addresses. The VCI is a DHCP option that FortiAP devices automatically include in their DHCP requests, allowing the FortiGate DHCP server to identify and selectively assign IP addresses to legitimate FortiAP devices while denying DHCP requests from other devices. Interface addressing mode changes affect IP assignment methods, not device filtering. Reservation lists require knowing specific MAC addresses in advance. DHCP option 138 is for specific configuration parameters, not device identification.

Create an account to continue.