NSE6 Sample Questions

NSE6 Sample Questions & Answers

RADIUS, remote authentication services, and 802.1X take the biggest share, next to FortiAuthenticator deployment and admin roles, PKI and digital-certificate handling, and single sign-on across FSSO, RADIUS SSO, and SAML.

Launch the full NSE6 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Active Authentication (RADIUS, LDAP, 802.1X, Portal Services) · RADIUS Authentication

    A company is using FortiAuthenticator to provide RADIUS authentication for VPN users. The security team wants to enforce a policy where users connecting from the corporate office network bypass two-factor authentication (2FA), but users connecting from any other network must provide a FortiToken code. How can this be configured within a single RADIUS policy?

    Show answer & explanation

    Correct answer: C

    FortiAuthenticator's RADIUS policies support adaptive authentication. By enabling 'Authentication factors' and specifying the corporate office subnet in the 'Trusted source addresses' list, you can create a rule that exempts users from 2FA when their connection originates from that trusted network. All other connections will be prompted for the second factor as per the policy.

  2. Question 2Intermediate

    Certificate Management · Certificate Revocation

    An administrator revokes a user's certificate that was issued by the FortiAuthenticator's local CA. However, the user is still able to authenticate to the network using EAP-TLS. What is the most likely reason for this failure in security enforcement?

    Show answer & explanation

    Correct answer: B

    Simply revoking a certificate marks it for inclusion in the next Certificate Revocation List (CRL). The CRL must then be generated and published. Furthermore, the EAP-TLS authentication policy on the RADIUS server (FortiAuthenticator) must be explicitly configured to perform a CRL check during the authentication process. If either of these steps is missed, the server will not know the certificate has been revoked and will continue to accept it.

  3. Question 3Beginner

    Active Authentication (RADIUS, LDAP, 802.1X, Portal Services) · Portal Services

    A hospital is setting up a guest wireless network. They require a self-registration process where guests can create their own temporary accounts, but each account must be approved by a receptionist before network access is granted. Which FortiAuthenticator feature should be used to meet this requirement?

    Show answer & explanation

    Correct answer: C

    The guest portal feature with sponsor-based approval is designed specifically for this scenario. Guests can self-register on the portal, and the system will then notify a designated sponsor (or a group of sponsors, like the receptionists) to approve or deny the request. The guest account is only activated after the sponsor grants approval.

  4. Question 4Intermediate

    SSO (Single Sign-On) · RADIUS Single Sign-On (RSSO)

    An administrator is configuring RADIUS Single Sign-On (RSSO) on FortiAuthenticator. The goal is to create FSSO logon events based on RADIUS authentication from a third-party wireless controller. Which RADIUS message type is essential for FortiAuthenticator to receive to successfully create and terminate user sessions for RSSO?

    Show answer & explanation

    Correct answer: C

    RSSO relies on RADIUS Accounting messages to track user sessions. The third-party RADIUS client (wireless controller) must be configured to send Accounting-Request messages with a status type of 'Start' when a user connects and 'Stop' when they disconnect. FortiAuthenticator listens for these accounting packets to create and terminate the corresponding FSSO sessions.

  5. Question 5Intermediate

    Active Authentication (RADIUS, LDAP, 802.1X, Portal Services) · RADIUS Authentication

    A retail company is deploying a new wireless network and wants to use FortiAuthenticator for authentication. They have two main requirements:

    1. Corporate employees must authenticate using their Active Directory credentials.
    2. In-store customers should connect to a separate guest SSID and authenticate using their social media accounts (Facebook or Google).

    How should the administrator configure realms on FortiAuthenticator to support this?

    Show answer & explanation

    Correct answer: B

    Realms are used to direct authentication requests to the correct user source based on the source of the request (like the SSID). The correct approach is to create two distinct realms. The employee realm would be associated with the corporate SSID and configured to use the remote AD server for authentication. The guest realm would be associated with the guest SSID and configured to use a captive portal with social media authenticators enabled.

  6. Question 6Beginner

    Active Authentication (RADIUS, LDAP, 802.1X, Portal Services) · 802.1X Authentication

    What is the primary security advantage of using EAP-TLS over PEAP (MSCHAPv2) for 802.1X wireless authentication?

    Show answer & explanation

    Correct answer: B

    The key advantage of EAP-TLS is its use of digital certificates for mutual authentication. The client validates the server's identity by checking its certificate, and the server validates the client's identity by checking its certificate. This is stronger than PEAP (MSCHAPv2), which relies on user credentials (username/password) for client authentication and is susceptible to password-based attacks if weak passwords are used.

  7. Question 7Beginner

    FortiAuthenticator Management · Troubleshooting

    The command diagnose debug authd ______ 255 is used on the FortiAuthenticator CLI to enable real-time debugging for authentication processes. Which keyword fills in the blank to specifically enable the debug output?

    Show answer & explanation

    Correct answer: B

    The correct command syntax to start the authentication daemon debug is diagnose debug authd enable 255. The enable keyword starts the debug output, and 255 sets the debug level to the most verbose.

  8. Question 8AdvancedSelect 3

    Active Authentication (RADIUS, LDAP, 802.1X, Portal Services) · Two-Factor Authentication and Tokens

    An administrator needs to import several third-party OATH tokens into FortiAuthenticator. The token vendor has provided a PSKC (Portable Symmetric Key Container) file. Which three pieces of information are typically contained within this file for each token? (Select THREE)

    Show answer & explanation

    Correct answers: A, B, D

  9. Question 9Intermediate

    SSO (Single Sign-On) · SAML SP Configuration

    A company has configured FortiAuthenticator as a SAML Service Provider (SP) to integrate with a cloud-based Identity Provider (IdP). The IdP requires all communications to be encrypted. What must be configured on the FortiAuthenticator SP to meet this requirement?

    Show answer & explanation

    Correct answer: B

    For an IdP to encrypt SAML assertions for a specific SP, the IdP needs the SP's public encryption key. The administrator must generate a certificate on the FortiAuthenticator (acting as the SP) for this purpose. The public key of this certificate is then exported and provided to the IdP. The IdP will use this public key to encrypt the assertion, and only the FortiAuthenticator, with its corresponding private key, can decrypt it.

  10. Question 10Advanced

    FortiAuthenticator Management · Backup and Restore

    Case Study

    A multinational corporation, GlobalCorp, is centralizing its identity and access management using FortiAuthenticator. They have a primary data center in New York and a disaster recovery (DR) site in London. The New York data center houses a two-node FortiAuthenticator HA cluster (FAC-NYC-1 and FAC-NYC-2) serving all North American users. The London site has a standalone FortiAuthenticator (FAC-LON-1) for European users.

    Current Situation:
    GlobalCorp wants to ensure that in the event of a total failure of the New York data center, user authentication services can be restored in London with minimal data loss. The security team has established that a Recovery Point Objective (RPO) of 15 minutes is acceptable. Configuration changes are infrequent, but user data and token seeds are updated constantly.

    Requirements:

    1. A mechanism must be in place to replicate FortiAuthenticator data from the New York cluster to the London unit.
    2. The solution must be automated and meet the 15-minute RPO.
    3. The London unit must remain active for local European user authentication during normal operations.

    Which solution should the GlobalCorp administrator implement to meet these requirements?

    Show answer & explanation

    Correct answer: C

    This is the most direct and supported method. FortiAuthenticator's scheduled backup feature allows an administrator to configure automated backups to be pushed to a remote server, which can be another FortiAuthenticator unit, using SCP or SFTP. Setting the schedule to every 15 minutes meets the RPO. This solution allows FAC-LON-1 to remain an active, standalone unit for its own users while receiving backups from the NYC cluster for DR purposes. Restoring in a DR scenario would be a manual process, but the data would be readily available.

Ready for the real thing?

The full NSE6 simulator has every exam-style question, timed mode, and instant scoring.

Go to the NSE6 simulator →