Special Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Question # 4

You are investigating a report of poor wireless performance in a network that you manage. The issue is related to an AP interface in the 5 GHz range You are monitoring the channel utilization over time.

What is the recommended maximum utilization value that an interface should not exceed?

A.

85%

B.

95%

C.

75%

D.

65%

Full Access
Question # 5

An administrator has deployed multiple dual-band wireless APs in a wireless network. APs are installed at measured distances to ensure fast roaming for the clients. Multiple 2.4 GHz-only wireless clients are connecting to the network, and subsequent monitoring shows that individual AP 2.4 GHz interfaces are being overloaded with wireless connections.

Which configuration change would best resolve the overloading issue?

A.

Configure load balancing AP handoff on both AP interfaces on all Aps.

B.

Configure a client limit on all AP 2.4 GHz interfaces.

C.

Configure load balancing frequency handoff on both AP interfaces.

D.

Configure load balancing AP handoff on only the 2.4 GHz interfaces of all APs.

Full Access
Question # 6

Which statement correctly describes the guest portal behavior on FortiAuthenticator?

A.

FortiAuthenticator uses POST parameters and a RADIUS client configuration to map the request to a guest portal for authentication.

B.

Sponsored accounts cannot authenticate using guest portals.

C.

All self-registered and sponsored accounts are listed on the local Users GUI page on FortiAuthenticator.

D.

All guest accounts must be activated using SMS or email activation codes.

Full Access
Question # 7

Which three FortiOS tools can you use to troubleshoot RADIUS authentication issues? (Choose three.)

A.

You can enable debug for the fssod process to view RADIUS authentication details.

B.

You can use the diagnose test authserver radius command to verify RADIUS server configuration, user credentials, and user group membership.

C.

You can check the Firewall Users widget to view the list of active RADIUS users.

D.

You can enable debug for the fnbamd process to view RADIUS authentication details.

E.

You can use the diagnose test application radiusd command to verify the RADIUS server configuration, user credentials, and user group membership.

Full Access
Question # 8

Refer to the exhibits

The exhibits show the wireless network (VAP) SSID profiles defined on FortiManager and an AP profile assigned to a group of APs that are supported by FortiGate

None of the APs are broadcasting the SSlDs defined by the AP profile

Which changes do you need to make to enable the SSIDs to broadcast?

A.

In the SSIDs section enable Tunnel

B.

Enable one channel in the Channels section

C.

Enable multiple channels in the Channels section and enable Radio Resource Provision

D.

In the SSIDs section enable Manual and assign the networks manually

Full Access
Question # 9

You are configuring a FortiGate wireless network to support automated wireless client quarantine using IOC Which two configurations must you put in place for a wireless client to be quarantined successfully? (Choose two)

A.

Configure the wireless network to be in tunnel mode

B.

Configure the FortiGate device in the Security Fabric with a FortiAnalyzer device

C.

Configure a firewall policy to allow communication

D.

Configure the wireless network to be in bridge mode

Full Access
Question # 10

Which two statements about FortiSwitch manager are true1? (Choose two)

A.

Per-device management is the default management mode on FortiManager

B.

FortiManager obtains the FortiSwitch status information by querying the FortiGate REST API every three minutes

C.

If the administrator makes any changes on FortiSwitch manager they must also install those changes on FortiGate so that those changes are applied on the managed switches

D.

Any switch discovered or authorized on FortiGate must be added manually on FortiSwitch manager

Full Access
Question # 11

Refer to the exhibit.

The exhibit shows a network topology and SSID settings. FortiGate is configured to use an external captive portal.

However, wireless users are not able to see the captive portal login page.

Which configuration change should the administrator make to fix the problem?

A.

Remove the guest.portal user group in the firewall policy.

B.

Enable the captive-portal-exempt option in the firewall policy with the ID 10.

C.

Create a firewall policy to allow traffic from the Guest SSID to FortiAuthenticator and Windows AD devices.

D.

Add the FortiAuthenticator and WindowsAD address objects as exempt sources.

Full Access
Question # 12

Refer to the exhibit.

An administrator wants to telnet into the S224EPTF19005867 switch over the FortiGate FortiLink interface.

Which configuration change should the administrator make?

A.

Enable telnet access on the FortiLink interface.

B.

On the default local-access profile, add telnet to the list of allowed protocols for mgmt-allowaccess.

C.

On the default local-access profile, add telnet to the list of allowed protocols for internal-allowaccess.

D.

Factory reset the switch to enable telnet access.

Full Access
Question # 13

Refer to the exhibit.

Examine the FortiGate user group configuration and the Windows AD LDAP group membership information shown in the exhibit

FortiGate is configured to authenticate SSL VPN users against Windows AD using LDAP The administrator configured the SSL VPN user group for SSL VPN users However the administrator noticed that both the student and j smith users can connect to SSL VPN

Which change can the administrator make on FortiGate to restrict the SSL VPN service to the student user only?

A.

In the SSL VPN user group configuration set Group Nam© to CN-SSLVPN, CN="users, DC-trainingAD, DC-training, DC-lab

B.

In the SSL VPN user group configuration, change Name to cn=sslvpn, CN=users, DC=trainingAD, Detraining, DC-lab.

C.

In the SSL VPN user group configuration set Group Name to ::;=Domain users.CN-Users/DC=trainingAD, DC-training, DC=lab.

D.

In the SSL VPN user group configuration change Type to Fortinet Single Sign-On (FSSO)

Full Access
Question # 14

An administrator has configured an SSID in bridge mode for corporate employees All APs are online and provisioned using default AP profiles Employees are unable to locate the SSID to conned

Which two configurations can the administrator verify? (Choose two)

A.

Verify that the broadcast SSID option is enabled in the SSID configuration

B.

Verify that the Block Intra-SSID Traffic (intra-vap-privacy) option in the SSID configuration is disabled

C.

Verify that the SSID to an AP group that should be broadcasting the SSID is applied

D.

Verify that the SSID is manually applied on AP profiles for both 2 4 GHz and 5 GHz radios

Full Access
Question # 15

Refer to the exhibit.

By default FortiOS creates the following DHCP server scope for the FortiLink interface as shown in the exhibit

What is the objective of the vci-string setting?

A.

To ignore DHCP requests coming from FortiSwitch and FortiExtender devices

B.

To reserve IP addresses for FortiSwitch and FortiExtender devices

C.

To restrict the IP address assignment to FortiSwitch and FortiExtender devices

D.

To restrict the IP address assignment to devices that have FortiSwitch or FortiExtender as their hostname

Full Access
Question # 16

Which two pieces of information can the diagnose test authserver ldap command provide? (Choose two.)

A.

It displays whether the admin bind user credentials are correct

B.

It displays whether the user credentials are correct

C.

It displays the LDAP codes returned by the LDAP server

D.

It displays the LDAP groups found for the user

Full Access
Question # 17

You are setting up an SSID (VAP) to perform RADlUS-authenticated dynamic VLAN allocation

Which three RADIUS attributes must be supplied by the RADIUS server to enable successful VLAN allocation'' (Choose three.)

A.

Tunnel-Private-Group-ID

B.

Tunnel-Pvt-Group-ID

C.

Tunnel-Preference

D.

Tunnel-Type

E.

Tunnel-Medium-Type

Full Access
Question # 18

Refer to the exhibit.

Examine the RADIUS server configuration shown in the exhibit

An administrator has configured a RADIUS server on FortiGate that points to FortiAuthenticator FortiAuthenticator is acting as an authentication proxy and is configured to relay all authentication requests to a remote Windows AD server using LDAP

While testing the configuration the administrator noticed that the diagnose test authserver command worked with PAP, however authentication requests failed when using MSCHAP2

Which two solutions can the administrator implement to get MSCHAP2 authentication to work'' (Choose two.)

A.

On FortiAuthenticator enable Windows Active Directory Domain Authentication to add FortiAuthenticator to the Windows domain

B.

On FortiGate configure the NAS IP setting on the RADIUSserver

C.

On FortiAuthenticator change the back-end authentication server from LDAP to RADIUS

D.

On FortiGate update the Secret setting on the RADIUS server

Full Access