[Mar-2022 Newly Released] Pass NSE6_FWF-6.4 Exam - Real Questions & Answers [Q10-Q29]

Share

[Mar-2022 Newly Released] Pass NSE6_FWF-6.4 Exam - Real Questions and Answers

Pass NSE6_FWF-6.4 Review Guide, Reliable NSE6_FWF-6.4 Test Engine

NEW QUESTION 10
Which two configurations are compatible for Wireless Single Sign-On (WSSO)? (Choose two.)

  • A. A VAP configured for WPA2 or 3 Enterprise
  • B. A VAP configured to authenticate using a radius server
  • C. A VAP configured to authenticate locally on FortiGate
  • D. A VAP configured for captive portal authentication

Answer: A,B

Explanation:
In the SSID choose WPA2-Enterprise authentication.
WSSO is RADIUS-based authentication that passes the user's user group memberships to the FortiGate.

 

NEW QUESTION 11
Which two phases are part of the process to plan a wireless design project? (Choose two.)

  • A. Installation phase
  • B. Project information phase
  • C. Hardware selection phase
  • D. Site survey phase

Answer: A,D

Explanation:
Reference:
https://www.automation.com/en-us/articles/2015-2/wireless-device-network-planning-and-design

 

NEW QUESTION 12
When enabling security fabric on the FortiGate interface to manage FortiAPs, which two types of communication channels are established between FortiGate and FortiAPs? (Choose two.)

  • A. Security channels
  • B. FortLink channels
  • C. Data channels
  • D. Control channels

Answer: C,D

Explanation:
The control channel for managing traffic, which is always encrypted by DTLS. l The data channel for carrying client data packets.

 

NEW QUESTION 13
Which two statements about background rogue scanning are correct? (Choose two.)

  • A. A dedicated radio configured for background scanning can support the connection of wireless clients
  • B. A dedicated radio configured for background scanning can detect rogue devices on all other channels in its configured frequency band
  • C. Background rogue scanning requires DARRP to be enabled on the AP instance
  • D. When detecting rogue APs, a dedicated radio configured for background scanning can suppress the rogue AP

Answer: A,D

Explanation:
To enable rogue AP scanning

 

NEW QUESTION 14
Which administrative access method must be enabled on a FortiGate interface to allow APs to connect and function?

  • A. SSH
  • B. FortiTelemetry
  • C. Security Fabric
  • D. HTTPS

Answer: C

 

NEW QUESTION 15
Refer to the exhibits.
Exhibit A

Exhibit B

A wireless network has been created to support a group of users in a specific area of a building. The wireless network is configured but users are unable to connect to it. The exhibits show the relevant controller configuration for the APs and the wireless network.
Which two configuration changes will resolve the issue? (Choose two.)

  • A. Increase the transmission power of the AP radio interfaces
  • B. For both interfaces in the wtp-profile, configure set vaps to be "Authors"
  • C. Disable intra-vap-privacy for the Authors vap-wireless network
  • D. For both interfaces in the wtp-profile, configure vap-all to be manual

Answer: C,D

 

NEW QUESTION 16
Six APs are located in a remotely based branch office and are managed by a centrally hosted FortiGate. Multiple wireless users frequently connect and roam between the APs in the remote office.
The network they connect to, is secured with WPA2-PSK. As currently configured, the WAN connection between the branch office and the centrally hosted FortiGate is unreliable.
Which configuration would enable the most reliable wireless connectivity for the remote clients?

  • A. Configure a bridge mode wireless network and enable the Local authentication configuration option
  • B. Install supported FortiAP and configure a bridge mode wireless network
  • C. Configure a bridge mode wireless network and enable the Local standalone configuration option
  • D. Configure a tunnel mode wireless network and enable split tunneling to the local network

Answer: D

 

NEW QUESTION 17
As a network administrator, you are responsible for managing an enterprise secure wireless LAN. The controller is based in the United States, and you have been asked to deploy a number of managed APs in a remote office in Germany.
What is the correct way to ensure that the RF channels and transmission power limits are appropriately configured for the remote APs?

  • A. Clone a suitable FortiAP profile and change the county code settings on the profile
  • B. Configure the controller for the correct country code for Germany
  • C. Create a new FortiAP profile and change the county code settings on the profile
  • D. Configure the APs individually by overriding the settings in Managed FortiAPs

Answer: A

 

NEW QUESTION 18
Refer to the exhibits.
Exhibit A

Exhibit B

The exhibits show the diagnose debug log of a station connection taken on the controller CLI.
Which security mode is used by the wireless connection?

  • A. WPA3 Enterprise
  • B. WPA2 Enterprise
  • C. WPA2 Personal and radius MAC filtering
  • D. Open, with radius MAC filtering

Answer: B

Explanation:
Best security option is WPA2-AES.

 

NEW QUESTION 19
Which statement describes FortiPresence location map functionality?

  • A. Provides real-time insight into user movements
  • B. Provides real-time insight into user usage stats
  • C. Provides real-time insight into user purchase activity
  • D. Provides real-time insight into user online activity

Answer: B

Explanation:
This geographical data analysis provides real-time insights into user behavior.

 

NEW QUESTION 20
Which of the following is a requirement to generate analytic reports using on-site FortiPresence deployment?

  • A. DTLS encryption on wireless traffic must be turned off
  • B. Two wireless APs must be sending data
  • C. Wireless network security must be set to open
  • D. SQL services must be running

Answer: B

Explanation:
FortiPresence VM is deployed locally on your site and consists of two virtual machines. All the analytics data collected and computed resides locally on the VMs.

 

NEW QUESTION 21
When using FortiPresence as a captive portal, which two types of public authentication services can be used to access guest Wi-Fi? (Choose two.)

  • A. Social networks authentication
  • B. Short message service authentication
  • C. Hardware security token authentication
  • D. Software security token authentication

Answer: A,C

Explanation:
This information along with the social network authentication logins with Facebook, Google, Instagram, LinkedIn, or FortiPresence using your WiFi.
Captive Portal configurations for social media logins and internet access. You can add and manage sites using the integrated Google maps and manoeuvre your hardware infrastructure easily.

 

NEW QUESTION 22
......

100% Free NSE6_FWF-6.4 Daily Practice Exam With 30 Questions: https://www.pass4training.com/NSE6_FWF-6.4-pass-exam-training.html

NSE6_FWF-6.4 Test Engine Practice Test Questions, Exam Dumps: https://drive.google.com/open?id=1fgI7ZE8RDqe8vLu7HiL3XIWOPfn8dzct