Official Bank 0/30

Fortinet NSE 7 – Secure Access 6.2 Exam (NSE7_SAC-6.2) - Fortinet Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
30 Total Questions
1
Question
Default VLANs are created on FortiGate when the FortiLink interface is created. By default, which VLAN is set as Allowed VLANs on all FortiSwitch ports?
Options
A Sniffer VLAN
B Quarantine VLAN
C Camera VLAN
D Voice VLAN
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Refer to the exhibit.

Exhibit

Examine the output of the debug command and port configuration shown in the exhibit. FortiGate learned the MAC address 78:2b:cb:d8:36:68 dynamically. What action does FortiSwitch take if there is an untagged frame coming to port1 will different MAC address?
Options
A The frame is accepted and assigned to the quarantine VLAN
B The frame is dropped.
C The frame is accepted and FortiSwitch will update its mac address table with the new MAC address.
D The frame is accepted and assigned to the user VLAN.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
Refer to the exhibit.

Exhibit

Examine the partial debug output shown in the exhibit. Which two statements about the debug output are true? (Choose two.)
Select 2
Options
A The LDAP server is configured to use regular bind.
B The connection to the LDAP server timed out.
C The user authenticated successfully.
D The debug output shows multiple user authentications.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Refer to the exhibit.

Exhibit

The exhibit shows two FortiGate devices in active-passive HA mode, including four FortiSwitch devices connected to a ring. Which two configurations are required to deploy this network topology'' (Choose two.)
Select 2
Options
A Enable f ortilink-split-interf ace on the FortiLink interfaces.
B Configure link aggregation interfaces on the FortiLink interfaces.
C Configure the trunk interfaces on the FortiSwitch devices as MCLAG-ISL.
D Enable STP on the FortiGate interfaces.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Refer to the exhibit.

Exhibit

The exhibit shows a network topology and SSID settings. FortiGate is configured to use an external captive portal. However, wireless users are not able to see the captive portal login page. Which configuration change should the administrator make to fix the problem?
Options
A Remove guest.portal user group in the firewall policy.
B Create a firewall policy to allow traffic from the Guest SSID to FortiAuthenticator and Windows AD devices.
C FortiAuthenticator and WindowsAD address objects should be added as exempt sources.
D Enable the captive-portal-exempt option in the firewall policy with the ID 10.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.