Questions for the NSE6-FNC-7-2 were updated on : Nov 23 ,2025
When configuring isolation networks in the configuration wizard, why does a Layer 3 network type
allow for more than one DHCP scope for each isolation network type?
A
During an evaluation of state-based enforcement, an administrator discovers that ports that should
not be under enforcement have been added to enforcement groups. In which view would the
administrator be able to determine who added the ports to the groups?
B
Refer to the exhibit.
When a contractor account is created using this template, what value will be set in the accounts Rote
field?
C
Which three capabilities does FortiNAC Control Manager provide? (Choose three.)
A, D, E
When FortiNAC is managing VPN clients connecting through FortiGate. why must the clients run a
FortiNAC agent?
B
Two FortiNAC devices have been configured in an HA configuration. After five failed heartbeats
between the primary device and secondary device, the primary device fail to ping the designated
gateway. What happens next?
C
How does FortiGate update FortiNAC about VPN session information?
B
View the output.
Examine the communication between a primary FortiNAC (192.168.10.10) and a secondary FortiNAC
(192.166.10.110) configured as an HA pair What is the current state of the FortiNAC HA pair?
A
What method of communication does FortiNAC use to control VPN host access on FortiGate?
B
Which two are required for endpoint compliance monitors? (Choose two.}
A, C
What causes a host's state to change to "at risk"?
A
Explanation:
Failure – Indicates that the host has failed the scan. This option can also be set manually. When the
status is set to Failure the host is marked "At Risk" for the selected scan.
Reference:
https://docs.fortinet.com/document/fortinac/8.3.0/administration-guide/241168/host-
health-and-scanning
p. 244 of the Study Guide, "A state of at-risk indicates the host has failed a scan. This could be a
compliance scan or an administrative scan."
By default, if more than 20 hosts are seen connected on a single port simultaneously, what will
happen to the port?
B
Explanation:
Admin Guide p. 754: Threshold Uplink—The Uplink mode has been set as Dynamic and FortiNAC has
determined that the number of MAC addresses on the port exceeds the System Defined Uplink
count. All hosts read on this port are ignored.
When you create a user or host profile; which three criteria can you use? (Choose three.)
CDE
Explanation:
Fortinac-admin-operations, P. 391
Which three circumstances trigger Layer 2 polling of infrastructure devices? (Choose three.)
ABE
Explanation:
A . Manual Polling: This is when an administrator or network operator initiates a poll manually to
gather information or check the status of the network devices. This can be done for immediate
troubleshooting or assessment.
B . Scheduled Poll Timings: Network management systems often have the capability to schedule
regular polls of devices to check their status or monitor their performance. These scheduled polls can
be set at regular intervals (such as every few minutes, hours, or daily) depending on the
requirements of the network.
E . Linkup and Linkdown Traps: SNMP (Simple Network Management Protocol) traps, like Linkup and
Linkdown, are automated notifications sent from network devices to a management system. A
Linkup trap indicates that a particular interface has become active (up), while a Linkdown trap
indicates that an interface has become inactive (down). These traps can trigger Layer 2 polling to
ascertain the current status of network interfaces and devices.
With enforcement for network access policies and at-risk hosts enabled, what will happen if a host
matches a network access policy and has a state of "at risk"?
C
Explanation:
https://training.fortinet.com/pluginfile.php/1912463/mod_resource/content/26/FortiNAC_7.2_Stud
y_Guide-Online.pdf C. Page 327 - moved to the quarantine isolation network