Join the discussion
Question 16/27
An organization wants to add a FortiNAC-F Manager to simplify their large FortiNAC-F deployment.
Which two policy types can be managed globally? (Choose two.)
Which two policy types can be managed globally? (Choose two.)
Correct Answer: B,D
TheFortiNAC-F Manageris designed to centralize the management of multiple Control and Application (CA) appliances, ensuring consistent security posture across a distributed enterprise. To achieve this, the Manager allows administrators to define and distribute specific types of policies globally rather than configuring them on each individual CA.
According to theFortiNAC Manager Guide, the two primary policy types that are managed globally are:
Network Access Policies (D):These policies define the " If-Then " logic for network entry. By managing these at the global level, an administrator can ensure that a " Contractor " receives the same restricted access regardless of which branch office or campus they connect to.
Endpoint Compliance Policies (B):Global management of compliance policies-which consist of scans and configurations-allows for a unified security baseline. For example, a global policy can mandate that all Windows devices across the entire organization must have a specific antivirus version installed and active before gaining access to the production network.
While the Manager provides visibility into authentication events and can synchronize directory data, the specificAuthentication(A) configurations (like local RADIUS secrets or specific LDAP server links) are often localized to the CA to account for site-specific infrastructure.Supplicant EasyConnect(C) is a feature set for onboarding, but the structural " Global Policy " engine focuses primarily on the Access and Compliance frameworks.
" The FortiNAC Manager enablesGlobal Policy Management, allowing for the creation and distribution of policies across all managed CA appliances. This includesNetwork Access Policies, which control VLAN and ACL assignment, andEndpoint Compliance Policies, which define the security requirements for hosts.
Centralizing these policies ensures that security standards are enforced uniformly across the global network fabric. " -FortiNAC Manager Administration Guide: Global Policy Management Overview.
According to theFortiNAC Manager Guide, the two primary policy types that are managed globally are:
Network Access Policies (D):These policies define the " If-Then " logic for network entry. By managing these at the global level, an administrator can ensure that a " Contractor " receives the same restricted access regardless of which branch office or campus they connect to.
Endpoint Compliance Policies (B):Global management of compliance policies-which consist of scans and configurations-allows for a unified security baseline. For example, a global policy can mandate that all Windows devices across the entire organization must have a specific antivirus version installed and active before gaining access to the production network.
While the Manager provides visibility into authentication events and can synchronize directory data, the specificAuthentication(A) configurations (like local RADIUS secrets or specific LDAP server links) are often localized to the CA to account for site-specific infrastructure.Supplicant EasyConnect(C) is a feature set for onboarding, but the structural " Global Policy " engine focuses primarily on the Access and Compliance frameworks.
" The FortiNAC Manager enablesGlobal Policy Management, allowing for the creation and distribution of policies across all managed CA appliances. This includesNetwork Access Policies, which control VLAN and ACL assignment, andEndpoint Compliance Policies, which define the security requirements for hosts.
Centralizing these policies ensures that security standards are enforced uniformly across the global network fabric. " -FortiNAC Manager Administration Guide: Global Policy Management Overview.
Add Comments
- Other Question (27q)
- Q1. During an evaluation of state-based enforcement, an administrator discovers that ports tha...
- Q2. Refer to the exhibit. (Exhibit) After a successful layer 2 poll, two hosts were learned on...
- Q3. Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)...
- Q4. Which two actions must the administrator perform to allow FortiNAC-F to process incoming s...
- Q5. While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen...
- Q6. When creating a user or host profile, which three criteria can you apply? (Choose three.)...
- Q7. Refer to the exhibit. (Exhibit) If a host is connected to a port in the Building 1 First F...
- Q8. Refer to the exhibit. (Exhibit) An administrator wants to ensure that guest accounts creat...
- Q9. Refer to the exhibits. (Exhibit) What would happen if the highlighted port with connected ...
- Q10. While troubleshooting a network connectivity issue, an administrator determines that a dev...
- Q11. When configuring FortiNAC-F to manage FortiGate VPN users, an endpoint compliance policy m...
- Q12. An administrator wants to control user access to corporate resources by integrating FortiN...
- Q13. An administrator wants FortiNAC-F to pass firewall tags to FortiGate to leverage dynamic a...
- Q14. Two FortiNAC-F devices have been configured as a 1 + 1 HA pair. The primary server went of...
- Q15. Refer to the exhibit. (Exhibit) An administrator has configured the DHCP scope for a regis...
- Q16. An organization wants to add a FortiNAC-F Manager to simplify their large FortiNAC-F deplo...
- Q17. When working with a FortiNAC-F Manager and cluster management, what will occur when a clus...
- Q18. Refer to the exhibits. (Exhibit) An administrator is troubleshooting visibility issues on ...
- Q19. An administrator wants to create a conference manager administrator account but would like...
- Q20. Refer to the exhibit. (Exhibit) What would FortiNAC-F generate if only one of the security...
- Q21. Refer to the exhibit. (Exhibit) An administrator wants to use FortiNAC-F to automatically ...
- Q22. What must an administrator configure to allow FortiNAC-F to process incoming syslog messag...
- Q23. When preparing network infrastructure devices for visibility, what are the two main advant...
- Q24. A user was attempting to register their host through the registration captive portal. Afte...
- Q25. When managing multiple FortiNAC-F CAs with a FortiNAC-F Manager, how is endpoint informati...
- Q26. Refer to the exhibit. A FortiNAC-F N+1 HA configuration is shown. (Exhibit) What will occu...
- Q27. An administrator wants to build a security rule that will quarantine contractors who attem...
[×]
Download PDF File
Enter your email address to download Fortinet.NSE5_FNC_AD_7.6.v2026-07-18.q27.pdf
