Pre-Summer Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

FCSS_LED_AR-7.6 Fortinet NSE 6 - LAN Edge 7.6 Architect Questions and Answers

Questions 4

Refer to the exhibits.

A NAC policy has been configured to apply traffic that flows through FortiSwitch port 2. Traffic that meets the NAC policy criteria will be assigned to the Students VLAN. However, the NAC policy does not seem to be taking effect.

Which configuration is missing?

Options:

A.

Port2 Access mode should be set to NAC mode.

B.

The MAC address or OS might be misconfigured for the connected device.

C.

Port2 Access mode should be set to Port Policy mode.

D.

The Students VLAN should be set to Allowed VLANs instead of Native VLAN.

Buy Now
Questions 5

APs have been manually configured to connect to FortiGate over an IPsec network, and FortiGate successfully detects and authorizes them. However, the APs remain unmanaged because FortiGate is unable to establish a CAPWAP tunnel with them.

What configuration change can resolve this issue and enable FortiGate to establish the CAPWAP tunnel over the IPsec connection?

Options:

A.

Configure a static route on FortiGate to reach the APs over the IPsec tunnel.

B.

Assign a custom AP profile for the remote APs with the set mpls-connection option enabled.

C.

Decrease the CAPWAP tunnel MTU size for APs to prevent fragmentation.

D.

Upgrade the FortiAP firmware image to ensure compatibility with the FortiOS version.

Buy Now
Questions 6

Which VLAN is used by FortiGate to place devices that fail to match any configured NAC policies? CRSPAN

Options:

A.

NAC

B.

segment

C.

Quarantine

D.

Onboarding

Buy Now
Questions 7

Refer to the exhibits.

Which include debug output and SSL VPN configuration details.

An SSL VPN has been configured on FortiGate. To enhance security, the administrator enabled Required Client Certificate in the SSL VPN settings. However, when a user attempts to connect, authentication fails.

Which configuration change is needed to fix the issue and allow the user to connect?

Options:

A.

Enable Redirect HTTP to SSL-VPN on the SSL VPN configuration page.

B.

Import the CA that signed the SSL VPN Server Certificate to FortiGate.

C.

Set the user certificate as the Server Certificate on the SSL VPN configuration page.

D.

Import the CA that signed the user certificate to FortiGate.

Buy Now
Questions 8

Why is the suppression of rogue APs becoming more difficult with the introduction of new wireless security standards, such as 802.11w?

Options:

A.

802.11w increases the processing overhead on network devices, slowing down the detection of rogue APs.

B.

The 802.11w standard reduces the range of wireless signals, limiting the ability to detect rogue APs at a distance.

C.

802.11w encrypts all data traffic, making it difficult to identify rogue APs through packet inspection.

D.

802.11w requires that clients authenticate management frames as legitimate, which helps prevent spoofing attacks.

Buy Now
Questions 9

You are deploying a FortiSwitch device managed by FortiGate in a secure network environment. To ensure accurate communication, you must identify which protocols are required for communication and control between FortiGate and FortiSwitch.

Which three protocols are used by FortiGate to manage and control FortiSwitch devices? (Choose three.)

Options:

A.

SNMP can be used by FortiGate to manage FortiSwitch devices by monitoring their status.

B.

HTTPS is used by FortiGate to securely manage and configure FortiSwitch devices.

C.

FortiGate uses the FortiLink protocol to establish communication with FortiSwitch.

D.

CAPWAP is used to establish the control channel between FortiSwitch and FortiGate.

E.

IGMP is required for managing communication between FortiGate and FortiSwitch devices in multicast environments.

Buy Now
Questions 10

Refer to the exhibits.

Examine the FortiManager configuration and FortiGate CLI output shown in the exhibit.

The NAC feature is being tested with a device connected to port2 on managed FortiSwitch S224SPTF19005867. The NAC policy has been applied to port2, and traffic was generated from the test device. However, the traffic from the test device does not match the NAC policy and remains in the onboarding VLAN.

What are two possible reasons why the test device is not being correctly classified by the NAC policy? (Choose two.)

Options:

A.

Device detection is not enabled on VLAN 4089.

B.

The device operating system detected by FortiGate is not Linux.

C.

Management communication between FortiGate and FortiSwitch is down.

D.

The MAC address configured on the NAC policy is incorrect.

Buy Now
Questions 11

A conference center wireless network provides guest access through a captive portal, allowing unregistered users to self-register and connect to the network. The IT team has been tasked with updating the existing configuration to enforce captive portal authentication over a secure HTTPS connection. Which two steps should the administrator take to implement this change? (Choose two.)

Options:

A.

Enable HTTP redirect in the user authentication settings.

B.

Create a new SSID with the HTTPS captive portal URL.

C.

Disable HTTP administrative access on the guest SSID to enforce HTTPS connection.

D.

Update the captive portal URL to use HTTPS on FortiGate and FortiAuthenticator.

Buy Now
Questions 12

Refer to the exhibits.

A set of SSID profiles has been configured on FortiManager, and an AP profile has been assigned to a group of APs managed by FortiGate. However, none of the designated SSIDs are being broadcast by these APs.

Which configuration change is required to make the APs broadcast these SSIDs as intended?

Options:

A.

Change the AP profile to use a platform that supports the configured mix of SSIDs.

B.

Adjust the AP profile to ensure all SSIDs are configured in a supported mode, either bridge or tunnel, but not a mix of both.

C.

Set the Transmit Power Mode to Auto.

D.

Choose Manual in the SSIDs setting and select the SSIDs to broadcast.

Buy Now
Questions 13

Refer to the exhibits.

A FortiSwitch is successfully managed by a FortiGate. FortiAP is connected to port1 of the managed FortiSwitch. On FortiGate, the VLAN AP is configured to detect and manage FortiAP, along with a DHCP server for the VLAN AP. Additionally, the VLAN AP is assigned to port1 of FortiSwitch. However. FortiGate is unable to detect or manage FortiAP.

Which FortiGate misconfiguration is preventing the detection of FortiAP?

Options:

A.

Security Fabric is disabled in the administrative access options of the VLAN.

B.

The FortiAP firmware is incompatible with the FortiGate firmware version.

C.

The VLAN is not tagged correctly on the FortiSwitch uplink port.

D.

The CAPWAP ports (UDP 5246 and 5247) are not open on FortiGate.

Buy Now
Questions 14

Refer to the exhibits to analyze a network topology and SSID settings.

FortiGate is configured to use an external captive portal for authentication to grant access to a wireless network. Testing detected that users attempting to access the SSID are not able to access the captive portal login page. Which configuration change should fix this issue?

Options:

A.

Change the SSID security mode to WPA2-Enterprise for authentication.

B.

Firewall policy with the ID 13 must have NAT disabled.

C.

Address objects FortiAuthenticator and WindowsAD must be included as exempt destinations/services.

D.

A firewall policy with port4 as source is missing.

Buy Now
Exam Code: FCSS_LED_AR-7.6
Exam Name: Fortinet NSE 6 - LAN Edge 7.6 Architect
Last Update: Apr 29, 2026
Questions: 47
FCSS_LED_AR-7.6 pdf

FCSS_LED_AR-7.6 PDF

$25.5  $84.99
FCSS_LED_AR-7.6 Engine

FCSS_LED_AR-7.6 Testing Engine

$30  $99.99
FCSS_LED_AR-7.6 PDF + Engine

FCSS_LED_AR-7.6 PDF + Testing Engine

$40.5  $134.99