Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A network administrator is deploying FortiNAC-F for the first time and wants to gain visibility into all connected infrastructure devices before configuring enforcement. The administrator runs an L2/L3 poll against the core switches and routers to populate the topology.
Which statement best describes the primary purpose of this initial device discovery and modeling process?
Modeling infrastructure devices through L2/L3 polling allows FortiNAC-F to build an accurate topology of switches, routers, and their interconnections. This model is essential because enforcement (VLAN switching, port control) depends on knowing exactly where a host is physically connected. It does not automatically create firewall tags (that is part of Security Fabric integration), does not isolate hosts by itself, and still requires proper SNMP/CLI credentials to poll devices.
A security team wants FortiNAC-F to automatically quarantine any host that generates a high-severity IPS alert on a connected FortiGate. They configure a security event integration and create a rule that triggers a network access policy change when the specific event is received.
Which two components must be correctly configured together for this automated threat response to function as intended? (Choose the most complete answer.)
Security automation in FortiNAC-F requires two pieces working together: a security device integration (which defines how events are received from the third-party or Fortinet device, such as a FortiGate) and a security rule (which defines the trigger conditions parsed from the event and the resulting action, such as changing network access or triggering isolation). Portal pages and guest registration are unrelated to automated threat response, HA/N+ relate to redundancy, and MDM/OUI tables relate to device profiling, not security event automation.
An organization deploys FortiNAC-F in hot standby HA mode across two appliances located in the same data center. During a maintenance window, the primary appliance is powered off to test failover.
Which statement is true regarding FortiNAC-F hot standby HA behavior during this failover?
In FortiNAC-F hot standby HA, only one node is active at a time. The secondary node continuously synchronizes the database and configuration from the primary, and upon failover it assumes the shared virtual IP address and takes over all NAC processing without manual IP reconfiguration. This is different from N+ mode, which supports multiple active appliances for load balancing. Hot standby protects both the database and the NAC engine services, not just the database.
A company wants FortiNAC-F to dynamically assign contractors' laptops to a restricted logical network on the connected FortiGate firewalls based on their host profile, without manually configuring VLANs on every switch port.
Which FortiNAC-F feature enables this by passing group and access information to FortiGate as part of Security Fabric integration?
When FortiNAC-F is integrated into the Security Fabric as a Fabric Connector, it can pass group and tag information to FortiGate using firewall tags, which are derived from logical network configurations. FortiGate then uses these tags in firewall policies to control access dynamically, such as placing contractors into a restricted logical network, without needing to hardcode VLANs at the switch port level. Endpoint fingerprinting is used for device classification, manual registration is unrelated to dynamic tag-based access, and SNMP traps are used for third-party alarm notification, not Fabric tag propagation.
An administrator is troubleshooting why a newly connected laptop is not appearing as a registered host in FortiNAC-F, even though the switch port shows link up and the device has an IP address. The administrator checks the Host View and applies filters to narrow down the search.
Which action would most directly help the administrator determine whether the device is currently classified as a rogue host in the FortiNAC-F database?
To determine whether a device is a rogue (an unregistered, unclassified host seen on the network), the administrator should use the Hosts page filters (online/offline, registration status) along with the Rogue Hosts view to search by MAC address and confirm the device's current classification state. FortiNAC-F Manager and HA N+ status pages relate to distributed deployment and redundancy, not individual host classification. Adding an OUI entry may assist with future profiling but does not directly reveal the current rogue status of an existing device.
60 questions covering all exam domains, starting from $20
Exam domains verified against: Official Fortinet NSE6_FNC_AD-7.6 exam guide, last checked September 2026.
Model and organize infrastructure devices to establish baseline network visibility. Learn key features of FortiNAC-F architecture, information gathering capabilities, and how to use groups for logical organization of network elements.
Sample question from this domain above: Q1
Configure security automation and access control using modeled devices, portal pages, and host inventory management. Set up FortiNAC-F security policies for user and host profiles, integrate into the Fortinet Security Fabric, and configure high availability in hot standby or N+ mode.
Integrate with third-party devices through syslog and SNMP trap input for automated response. Deploy FortiNAC-F Manager in distributed environments and configure FortiGate VPN session management and MDM integration.
Sample question from this domain above: Q3
Configure guest and contractor administration, explain device profiling concepts including classified devices and rogue detection. Troubleshoot network devices using administrative visibility views, logs, and database information to determine host status and connectivity issues.
Sample question from this domain above: Q5
Common questions about the exam itself