FCP_FAC_AD-6.5 Exam Dumps, FCP_FAC_AD-6.5 Practice Test Questions
PDF (New 2026) Actual Fortinet FCP_FAC_AD-6.5 Exam Questions
NEW QUESTION # 12
You are a network administrator with a large wireless environment. FortiAuthenticator acts as the RADIUS server for your wireless controllers. You want specific wireless controllers to authenticate users against specific realms.
How would you satisfy this requirement?
- A. Define RADIUS clients
- B. RADUIS policy
- C. Create Access point groups
- D. Enable Adaptive Authentication
Answer: B
NEW QUESTION # 13
When working with administrator profiles, which permission sets can be customized?
- A. Only the pre-existing permission sets can be customized.
- B. Only user-created or cloned permission sets can be customized.
- C. All permission sets can be customized.
- D. Only non-administrator permission sets can be customized.
Answer: B
NEW QUESTION # 14
When configuring an active-passive HA deployment, what is the recommended data synchronization path?
- A. Dedicated point-to-point VPN connection
- B. Dedicated fiber channel
- C. Same VLAN
- D. Direct cable connection
Answer: D
Explanation:
A direct cable connection is the recommended data synchronization path in an active-passive HA deployment because it provides the fastest, most reliable, and secure method for synchronizing data between FortiAuthenticator units without depending on external network infrastructure.
NEW QUESTION # 15
Which two statements about the self-service portal are true? (Choose two)
- A. Realms can be used to configure which seld-registered users or groups can authenticate on the network
- B. Administrator approval is required for all self-registration
- C. Self-registration information can be sent to the user through email or SMS
- D. Authenticating users must specify domain name along with username
Answer: A,C
NEW QUESTION # 16
Which network configuration is required when deploying FortiAuthenticator for portal services?
- A. FortiGate must be set up as the default gateway for FortiAuthenticator
- B. Policies must have specific ports open between FortiAuthenticator and the authentication clients
- C. FortiAuthenticator must have the REST API access enabled on port 1
- D. One of the DNS servers must be a FortiGuard DNS server
Answer: B
NEW QUESTION # 17
You want to monitor FortiAuthenticator system information and receive FortiAuthenticator traps through SNMP.
Which two configurations must be performed after enabling SNMP access on the FortiAuthenticator interface? (Choose two)
- A. Upload management information base (MIB) files to SNMP server
- B. Enable logging services
- C. Associate an ASN, 1 mapping rule to the receiving host
- D. Set the tresholds to trigger SNMP traps
Answer: A,D
NEW QUESTION # 18
What is the purpose of a Certificate Signing Request (CSR)?
- A. To request a software update for a server
- B. To request a new network IP address
- C. To request a digital certificate from a Certificate Authority (CA)
- D. To request access to a restricted website
Answer: C
NEW QUESTION # 19
You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate.
You have verified that only the users with two-factor authentication are experiencing the issue.
What can cause this issue?
- A. FortiAuthenticator has lost contact with the FortiToken Cloud servers.
- B. FortiToken 200 license has expired.
- C. One of the FortiAuthenticator devices in the active-active cluster has failed.
- D. Time drift between FortiAuthenticator and hardware tokens.
Answer: D
NEW QUESTION # 20
An administrator wants users and devices that cannot be identified transparently, such as Android BYOD devices, to be able to register and create their own credentials.
In this case, which FortiAuthenticator user identity discovery method can the administrator use?
- A. Kerberos-based authentication
- B. SSOMA
- C. Portal authentication
- D. Syslog messaging or SAML IdP
Answer: C
Explanation:
Portal authentication allows unidentified users or devices, such as Android BYOD devices, to self-register and create credentials through a captive or guest portal on FortiAuthenticator.
NEW QUESTION # 21
Refer to the exhibits.
Event Log
Event Detail
An administrator has configured several wireless APs to use FortiAuthenticator as their RADIUS server. One user is unable to successfully authenticate. The user record exists in the system, but the FortiAuthenticator log shows Authentication failed, user not found.
What is the most likely cause of the problem?
- A. No client entry exists for the authenticating AP.
- B. The RADIUS traffic is being sourced from an IP address not listed as NAS.
- C. RADIUS authentication is not enabled for the user.
- D. The RADIUS secret is incorrect.
Answer: C
Explanation:
The log message indicates that FortiAuthenticator cannot find the user during RADIUS authentication, even though the user exists in the system. This typically happens when RADIUS authentication is not enabled for that user account, preventing FortiAuthenticator from using it for RADIUS login requests.
NEW QUESTION # 22
When you are setting up two FortiAuthenticator devices in active-passive HA, which HA role must you select on the master FortiAuthenticator?
- A. Standalone master
- B. Load balancing master
- C. Active-passive master
- D. Cluster member
Answer: C
NEW QUESTION # 23
An employee lost their assigned token and needs to authenticate to a resource which requires two factor authentication. The user does not have access to SMS or email.
How can an administrator provide access for the user?
- A. Generate and provide an HOTP to the user
- B. Disable two-factor authentication on the resource
- C. Enable and provide an emergency code to the user
- D. Refresh the FTM provisioning status for the user
Answer: C
Explanation:
An administrator can issue an emergency code in FortiAuthenticator, which temporarily bypasses the user's lost token and allows them to authenticate when two-factor authentication is required but no token, SMS, or email is available.
NEW QUESTION # 24
What can third-party logon events be used for in Fortinet Single Sign-On (FSSO)?
- A. Automatically updating software
- B. Tracking user logon events from other systems
- C. Generating weather forecasts
- D. Creating virtual networks
Answer: B
NEW QUESTION # 25
Which component of a digital certificate contains information about the certificate holder's identity?
- A. Public key
- B. Private key
- C. Certificate Authority's signature
- D. Subject field
Answer: D
NEW QUESTION # 26
What is the main purpose of active authentication in network security?
- A. Accelerating internet speeds
- B. Detecting software vulnerabilities
- C. Monitoring network traffic
- D. Enforcing access controls based on user identity
Answer: D
NEW QUESTION # 27
What is the primary benefit of single sign-on (SSO) in a network environment?
- A. Faster internet speeds
- B. Reducing the number of users
- C. Minimizing the need for strong passwords
- D. Allowing users to access multiple resources with a single authentication
Answer: D
NEW QUESTION # 28
Which of the following is a recommended practice when configuring FortiAuthenticator for deployment?
- A. Using the default factory settings for quicker deployment
- B. Disabling all user roles to simplify access control
- C. Disabling all authentication methods except one
- D. Enabling all available authentication methods for flexibility
Answer: C
NEW QUESTION # 29
What does SAML stand for in the context of SAML SSO service?
- A. Single Authentication Management Logic
- B. System Authorization and Management Layer
- C. Security Assertion Markup Language
- D. Secure Access Markup Language
Answer: C
NEW QUESTION # 30
Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?
- A. Principal contacts identity provider and is redirected to service provider, principal establishes connection with service provider, service provider validates authentication with identity provider.
- B. Principal contacts identity provider and authenticates, identity provider relays principal to service provider after valid authentication.
- C. Service provider contacts identity provider, identity provider validates principal for service provider, service provider establishes communication with principal.
- D. Principal contacts service provider, service provider redirects principal to identity provider, after successful authentication identity provider redirects principal to service provider.
Answer: D
NEW QUESTION # 31
......
Fortinet FCP_FAC_AD-6.5 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
Updated Jun-2026 Pass FCP_FAC_AD-6.5 Exam - Real Practice Test Questions: https://itexambus.passleadervce.com/FCP-in-Network-Security/reliable-FCP_FAC_AD-6.5-exam-learning-guide.html