NSE7_SAC-6.2 Sample Questions & Answers
Advanced LDAP and RADIUS authentication ties with Security Fabric integration and compromised-host quarantine for the top weighting, alongside NAC architecture, 802.1X on FortiSwitch, FortiAP wireless policies, FortiManager administration, and troubleshooting.
Launch the full NSE7_SAC-6.2 simulator →Showing 2 of 4 free samples.
- Question 1
Refer to the exhibit.
In the WTP profile configuration shown in the exhibit, the AP profile is assigned to two FAP-320 APs that are installed in an open plan office.
The first AP has 32 clients associated to the 5GHz radios and 22 clients associated to the 2.4GHz radio.
The second AP has 12 clients associated to the 5GHz radios and 20 clients associated to the 2.4GHz radio.
A dual band-capable client enters the office near the first AP and the first AP measures the new client at 33 dBm signal strength. The second AP measures the new client at 43 dBm signal strength.
In the new client attempts to connect to the corporate wireless network, to which AP radio will the client be associated?

Show answer & explanation
Correct answer: A
Based on the WTP profile configuration shown in the image, with both APs having high client counts (32 on 5GHz, 22 on 2.4GHz for the first AP), the load balancing mechanism will direct new clients to the second AP 5GHz interface. The configuration shows channel bonding set to 40MHz and channel utilization enabled, which automatically distributes clients across available APs and radios based on current load. Since the first AP already has high utilization on both radios, new clients will be steered to the less loaded second AP, specifically the 5GHz interface which typically has better performance characteristics.
- Question 2Select 2
Which two EAP methods can use MSCHAPV2 for client authentication? (Choose two.)
Show answer & explanation
Correct answers: A, C
PEAP (Protected EAP) and EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) are the two EAP methods that can use MSCHAPV2 for client authentication. PEAP creates a secure TLS tunnel and then uses MSCHAPV2 as the inner authentication method, providing password-based authentication with additional protection. EAP-TLS supports MSCHAPV2 as an optional inner method when configured for tunneled authentication scenarios. EAP-TTLS (Tunneled TLS) typically uses other inner methods like PAP or CHAP rather than MSCHAPV2. EAP-GTC (Generic Token Card) is designed for token-based authentication, not password-based MSCHAPV2.
PEAP (Protected EAP) and EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) are the two EAP methods that can use MSCHAPV2 for client authentication. PEAP creates a secure TLS tunnel and then uses MSCHAPV2 as the inner authentication method, providing password-based authentication with additional protection. EAP-TLS supports MSCHAPV2 as an optional inner method when configured for tunneled authentication scenarios. EAP-TTLS (Tunneled TLS) typically uses other inner methods like PAP or CHAP rather than MSCHAPV2. EAP-GTC (Generic Token Card) is designed for token-based authentication, not password-based MSCHAPV2.
Ready for the real thing?
The full NSE7_SAC-6.2 simulator has every exam-style question, timed mode, and instant scoring.