Official Bank 0/30

Fortinet NSE 7 – Secure Access 6.2 Exam (NSE7_SAC-6.2) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
30 Total Questions
1
Question
Refer to the exhibit.

Exhibit

Given the network topology shown in the exhibit, which two ports should be configured as untrusted DHCP ports? (Choose two.)
Select 2
Options
A FortiSwitch B, port1
B FortiSwitch B, port2
C FortiSwitch A, port1
D FortiSwitch A, port2
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Default VLANs are created on FortiGate when the FortiLink interface is created. By default, which VLAN is set as Allowed VLANs on all FortiSwitch ports?
Options
A Sniffer VLAN
B Quarantine VLAN
C Camera VLAN
D Voice VLAN
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Which two statements about the use of digital certificates are true? (Choose two.)
Select 2
Options
A The end entity's certificate can only be created by an intermediate CA.
B An intermediate CA can sign server certificates.
C An intermediate CA can validate the end entity certificate signed by another intermediate CA
D An intermediate CA can sign another intermediate CA certificate.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Refer to the exhibit.

Exhibit

The exhibit shows a network topology and SSID settings. FortiGate is configured to use an external captive portal. However, wireless users are not able to see the captive portal login page. Which configuration change should the administrator make to fix the problem?
Options
A Remove guest.portal user group in the firewall policy.
B Create a firewall policy to allow traffic from the Guest SSID to FortiAuthenticator and Windows AD devices.
C FortiAuthenticator and WindowsAD address objects should be added as exempt sources.
D Enable the captive-portal-exempt option in the firewall policy with the ID 10.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Refer to the exhibit.

Exhibit

The exhibit shows two FortiGate devices in active-passive HA mode, including four FortiSwitch devices connected to a ring. Which two configurations are required to deploy this network topology'' (Choose two.)
Select 2
Options
A Enable f ortilink-split-interf ace on the FortiLink interfaces.
B Configure link aggregation interfaces on the FortiLink interfaces.
C Configure the trunk interfaces on the FortiSwitch devices as MCLAG-ISL.
D Enable STP on the FortiGate interfaces.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.