Fortinet NSE 7 - Secure Access 6.2 認定 NSE7_SAC-6.2 試験問題:
1. Which step can be taken to ensure that only FortiAP devices receive IP addresses from a DHCP server on FortiGate?
A) Create a reservation list in the DHCP server settings.
B) Change the interface addressing mode toFortiAP devices.
C) Use DHCP option 138 to assign IPs to FortiAP devices.
D) Configure a VCI string value of FortiAP in the DHCP server settings.
2. Examine the following RADIUSconfiguration:
An administrator has configured a RADIUS server on FortiGate that points to FortiAuthenticator.
FortiAuthenticator is acting as an authentication proxy and is configured to relay all authentication requests to a remote Windows ADserver using LDAP.
While testing the configuration, the administrator notices that the diagnose test authserver command works with PAP, however, authentication requests fail when using MSCHAPv2.
Which two changes should the administrator make to get MSCHAPv2 to work? (Choose two.)
A) Use MSCHAP instead of using MSCHAPv2.
B) EnableWindows Active Directory Domain Authentication on FortiAuthenticator to add FortiAuthenticator to the Windows domain
C) Change the remote authentication server from LDAP to RADIUS on FortiAuthenticator.
D) Force FortiGate to use the PAP authentication method in the RADIUS server configuration.
3. Which two statements about the use of digital certificates are true? (Choose two.)
A) The end entity's certificate can only be created by an intermediate CA.
B) An intermediate CA can sign server certificates.
C) An intermediate CA can validate the end entity certificate signed by another intermediate CA
D) An intermediate CA can sign another intermediate CA certificate.
質問と回答:
質問 # 1 正解: D | 質問 # 2 正解: B、C | 質問 # 3 正解: C、D |