About the Exam

Prepare for the NSE6-FNC-AD-7-6 certification from Fortinet with 23 practice questions, community-verified answers, and detailed explanations.

Exam Topics

  • Concepts and initial configuration10–20%
  • Deployment and provisioning30–40%
  • Integration15–25%
  • Network visibility and monitoring25–35%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated August 27, 2026 at 8:27 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Network visibility and monitoring

While evaluating state-based enforcement, an administrator finds that ports which should not be enforced have been added to enforcement groups.

In which view can the administrator determine who added the ports to the groups?

  • A The Port Changes view
  • B The Security Events view
  • C The Admin Auditing view
  • D The Event Management view
Explanation

The Admin Auditing view records administrative actions and associates each action with the administrator who performed it, allowing the addition of ports to enforcement groups to be traced to its author.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Concepts and initial configuration

Refer to the exhibit.

Question Image

What would FortiNAC-F generate if just one of the security filters is satisfied?

  • A A normal event
  • B A security alarm
  • C A security event
  • D A normal alarm
Explanation

With Filter Match set to All, every security filter must match for the trigger to be satisfied. An incoming message that satisfies only one filter does not meet the trigger criteria, so it remains a normal event rather than creating a security event or security alarm.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Concepts and initial configuration

Refer to the exhibits.

Question Image

Question Image

An administrator has configured a DHCP scope for a registration isolation network, but the isolation process is not working.

What is wrong with the configuration?

  • A The domain name server designation is incorrect.
  • B The gateway defined for the scope is incorrect.
  • C The label uses a system-reserved value.
  • D The lease pool does not contain a complete subnet.
Explanation

A DHCP scope for 192.168.180.0/24 must provide a default gateway on that subnet. The configured gateway, 10.0.1.254, is on a different network; the gateway for the registration isolation network is 192.168.180.1. DHCP scopes assign addresses for a subnet and include the router/default-gateway option for those clients.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Network visibility and monitoring

An administrator needs to continuously monitor endpoints for the presence of a particular registry key and the state of a required security service.

Which two prerequisites must be available for the administrator to use FortiNAC-F compliance monitors?

Choose two
  • A MDM integration
  • B Remediation admin scan
  • C Persistent agent
  • D Custom scan
Explanation

FortiNAC-F monitors periodically test endpoint status by using custom scans, and those monitors run on hosts with the Persistent Agent. Custom scans can evaluate detailed endpoint conditions such as registry entries and service status; a remediation admin scan and MDM integration are not required.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Integration

An administrator wants to use FortiNAC-F to stop internal engineers from accessing particular websites identified by web-filter categories on FortiGate.

Besides a security trigger and its associated action, which configuration must also be defined on FortiNAC-F?

  • A A firewall policy
  • B A user/host profile
  • C A profiling method
  • D A compliance policy
Explanation

FortiNAC-F Security Rules combine a security-event trigger and an action with a User/Host Profile. The profile identifies the users or hosts to which the rule applies, allowing the response to be limited to the internal engineers instead of applying to every device that generates a matching FortiGate web-filter event.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
Concepts and initial configurationDeployment and provisioningIntegrationNetwork visibility and monitoring
Know a question that should be here? Contribute to this exam
Back home