About the Exam

This Fortinet exam was retired on July 11, 2026 and was replaced by the NSE 6 - FortiNAC 7.6 Administrator exam. It was intended for network and security professionals responsible for configuring and administering FortiNAC in a network security infrastructure. The exam covered FortiNAC configuration, operation, day-to-day administration, high availability, and FortiNAC Manager.

Exam Topics

  • Administration25%
  • Device manager25%
  • Policy and objects25%
  • Advanced configuration12%
  • Troubleshooting13%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 7, 2026 at 5:34 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Troubleshooting

During network infrastructure-device discovery, a switch is displayed in the inventory topology with a question mark (?) on its icon.

What could cause this?

  • A The wrong SNMP community string was entered during discovery.
  • B The SNMP ObjectID is not recognized by FortiNAC-F.
  • C A read-only SNMP community string was used.
  • D SNMP is not enabled on the switch.
Explanation

A question-mark topology icon denotes an unidentified network-device type: FortiNAC-F received the switch’s SNMP identification but does not recognize its SNMP ObjectID in its device definitions. Read-only SNMP is sufficient for discovery, whereas invalid SNMP access details or disabled SNMP prevents successful SNMP querying.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Administration

An administrator oversees a corporate environment in which all users sign in to the corporate domain whenever they connect to the network. The administrator wants to use login scripts with a FortiNAC-F agent to improve endpoint visibility.

Which agent can be deployed through a login script?

  • A Persistent
  • B Dissolvable
  • C Mobile
  • D Passive
Explanation

The Persistent Agent can be installed by a login script or another software-distribution method. It stays installed on the endpoint and communicates with FortiNAC in the background, providing continuing endpoint visibility.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Policy and objects

An administrator needs to create a security rule that quarantines contractors who try to access particular websites.

In addition to a user host profile, which two components must the administrator configure to create the security rule?

Choose two
  • A Methods
  • B Action
  • C Endpoint compliance policy
  • D Trigger
  • E Security String
Explanation

A FortiNAC security rule uses a Trigger to define the security events that activate the rule and an Action to define the response taken when it activates. The User/Host Profile limits the rule to contractors; the Action can automatically quarantine a matching host.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Policy and objects

A network administrator is troubleshooting a network-access issue involving a specific host. The administrator suspects that the host is being assigned a network access policy different from the expected one.

Where would the administrator look to identify which network access policy, if any, is being applied to a particular host?

  • A The Policy Logs view
  • B The Connections view
  • C The Policy Details view for the host
  • D The Port Properties view of the hosts port
Explanation

In FortiNAC, the host’s Policy Details view displays the policies that apply to the selected host, including its Network Access Policies. This makes it the appropriate view for confirming the policy currently selected for that host.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Troubleshooting

A user attempted to register their host using the registration captive portal. After registering successfully, the host stayed in the registration VLAN.

Which two conditions could cause this behavior?

Choose two
  • A The wrong agent is installed.
  • B There is no agent installed on the host.
  • C The port default VLAN is the same as the Registration VLAN.
  • D There is another unregistered host on the same port.
Explanation

A successful captive-portal registration must be followed by a change from the registration VLAN to the authorized VLAN. If the port’s default VLAN is the Registration VLAN, there is no effective VLAN change for untagged host traffic. A second unregistered host sharing the same port can also retain the port’s unauthorized/registration VLAN state, because port-based authorization and VLAN handling are affected by multiple hosts on one access port.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
AdministrationDevice managerPolicy and objectsAdvanced configurationTroubleshooting
Know a question that should be here? Contribute to this exam
Back home