Fortinet NSE7_SAC-6.2 - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/nse7-sac-62.html
Which step can be taken to ensure that only FortiAP devices receive IP addresses from a DHCP server on FortiGate?
Refer to the exhibit.

In the WTP profile configuration shown in the exhibit, the AP profile is assigned to two FAP-320 APs that are installed in an open plan office.
1. The first AP has 32 clients associated to the 5GHz radios and 22 clients associated to the 2.4GHz
radio.
2. The second AP has 12 clients associated to the 5GHz radios and 20 clients associated to the 2.4GHz
radio.
A dual band-capable client enters the office near the first AP and the first AP measures the new client at -33 dBm signal strength. The second AP measures the new client at -43 dBm signal strength.
In the new client attempts to connect to the corporate wireless network, to which AP radio will the client be associated?
Which two EAP methods can use MSCHAPV2 for client authentication? (Choose two.)
Which two statements about the use of digital certificates are true? (Choose two.)
802.1X port authentication is enabled on only those ports that the FortiSwitch security policy is assigned to.
Which configurable items are available when you configure the security policy on FortiSwitch? (Choose two.)
A wireless network in a school provides guest access using a captive portal to allow unregistered users to self-register and access the network. The administrator is requested to update the existing configuration to provide captive portal authentication through a secure connection (HTTPS) to protect and encrypt guest user credentials after they receive the login information when registered for the first time.
Which two changes must the administrator make to enforce HTTPS authentication? (Choose two.)
An administrator is deploying APs that are connecting over an IPsec network. All APs have been configured to connect to FortiGate manually. FortiGate can discover the APs and authorize them.
However, FortiGate is unable to establish CAPWAP tunnels to manage the APs.
Which configuration setting can the administrator perform to resolve the problem?
Refer to the exhibit.

A host machine connected to port2 on FortiSwitch cannot connect to the network. All ports on FortiSwitch are assigned a security policy to enforce 802.1X port authentication. While troubleshooting the issue, the administrator runs the debug command and obtains the output shown in the exhibit.
Which two scenarios are the likely cause of this issue? (Choose two.)
What action does FortiSwitch take when it receives a loop guard data packet (LGDP) that was sent by itself?
Default VLANs are created on FortiGate when the FortiLink interface is created.
By default, which VLAN is set as Allowed VLANs on all FortiSwitch ports?