Pre-Summer Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

FCSS_LED_AR-7.6 Sample Questions Answers

Questions 4

Refer to the exhibits to analyze a network topology and SSID settings.

FortiGate is configured to use an external captive portal for authentication to grant access to a wireless network. Testing detected that users attempting to access the SSID are not able to access the captive portal login page. Which configuration change should fix this issue?

Options:

A.

Change the SSID security mode to WPA2-Enterprise for authentication.

B.

Firewall policy with the ID 13 must have NAT disabled.

C.

Address objects FortiAuthenticator and WindowsAD must be included as exempt destinations/services.

D.

A firewall policy with port4 as source is missing.

Buy Now
Questions 5

In addition to requiring a FortiAnalyzer device to configure the Security Fabric, which license must be added to FortiAnalyzer to use Indicators of Compromise (IOC) rules?

Options:

A.

loT Security Add-on license

B.

IOC Subscription license

C.

IOC detection is included on FAZ-Basic license

D.

Threat Detection Service license

Buy Now
Questions 6

Refer to the exhibit.

On FortiGate, a RADIUS server is configured to forward authentication requests to FortiAuthenticator, which acts as a RADIUS proxy. FortiAuthenticator then relays these authentication requests to a remote Windows AD server using LDAP.

While testing authentication using the CLI command diagnose test authserver. the administrator observed that authentication succeeded with PAP but failed when using MS-CHAFV2.

Which two solutions can the administrator implement to enable MS-CHAPv2 authentication? (Choose two.)

Options:

A.

Enable Windows Active Directory domain authentication on FortiAuthenticator.

B.

Configure FortiAuthenticator to use RADIUS instead of LDAP as the back-end authentication server.

C.

Enable RADIUS attribute filtering on FortiAuthenticator.

D.

Change the FortiGate authentication method to CHAP instead of MS-CHAPv2.

Buy Now
Questions 7

You are setting up a captive portal to provide Wi-Fi access for visitors. To simplify the process, your team wants visitors to authenticate using their existing social media accounts instead of creating new accounts or entering credentials manually.

Which two actions are required to enable this functionality? (Choose two.)

Options:

A.

Set up a remote open authorization (OAuth) server for each selected social media platform.

B.

Configure only the email login option because a social media login cannot be used with captive portals.

C.

Enable Account Login as the authentication type and configure a remote LDAP server.

D.

Set up the FortiAuthenticator internal database as the primary source for user credentials.

E.

Configure the social login profiles for the supported platforms.

Buy Now
Questions 8

Refer to the exhibit.

Review the exhibits to analyze the network topology, SSID settings, and firewall policies.

FortiGate is configured to use an external captive portal for authentication to grant access to a wireless network. During testing, it was found that users attempting to connect to the SSID cannot access the captive portal login page.

What configuration change should be made to resolve this issue to allow users to access the captive portal?

Options:

A.

Change the SSID security mode to WPA2-Enterprise for authentication.

B.

Disable HTTPS redirection for the captive portal authentication page.

C.

Exclude FortiAuthenticator and Windows AD address objects from filtering.

D.

A firewall policy allowing Guest SSID traffic to reach FortiAuthenticator and Windows AD.

Buy Now
Questions 9

How can FortiAIOps help optimize network performance in an SD-Branch deployment with FortiGate, FortiSwitch, and FortiAP?

Options:

A.

It disables low-performing APs and switches automatically.

B.

It uses Al-driven analytics to identify network issues and provide optimization recommendations.

C.

It removes the need for SD-WAN configuration by automating all routing decisions.

D.

It predicts and resolves all network issues without any human intervention.

Buy Now
Questions 10

Refer to the exhibits.

Which include debug output and SSL VPN configuration details.

An SSL VPN has been configured on FortiGate. To enhance security, the administrator enabled Required Client Certificate in the SSL VPN settings. However, when a user attempts to connect, authentication fails.

Which configuration change is needed to fix the issue and allow the user to connect?

Options:

A.

Enable Redirect HTTP to SSL-VPN on the SSL VPN configuration page.

B.

Import the CA that signed the SSL VPN Server Certificate to FortiGate.

C.

Set the user certificate as the Server Certificate on the SSL VPN configuration page.

D.

Import the CA that signed the user certificate to FortiGate.

Buy Now
Questions 11

Refer to the exhibits.

A company has multiple FortiGate devices deployed and wants to centralize user authentication and authorization. The administrator decides to use FortiAuthenticator to convert RSSO messages to FSSO, allowing all FortiGate devices to receive user authentication updates.

After configuring FortiAuthenticator to receive RADIUS accounting messages, users can authenticate, but FortiGate does not enforce the correct policies based on user groups. Upon investigation, the administrator discovers that FortiAuthenticator is receiving RADIUS accounting messages from the RADIUS server and successfully queries LDAP for user group information. But, FSSO updates are not being sent to FortiGate devices and FortiGate firewall policies based on FSSO user groups are not being applied.

What is the most likely reason FortiGate is not receiving FSSO updates?

Options:

A.

The RADIUS Username and Client IPv4 attributes are not defined on FortiAuthenticator.

B.

The LDAP server is not configured to retrieve group memberships for RSSO users.

C.

FortiAuthenticator is missing the FSSO user group attribute in the configuration.

D.

The FortiAuthenticator interface is not enabled to receive RADIUS accounting messages.

Buy Now
Questions 12

Refer to the exhibits.

An LDAP server has been successfully configured on FortiGate. which forwards LDAP authentication requests to a Windows Active Directory (AD) server. Wireless users report that they are unable to authenticate. Upon troubleshooting, you find that authentication fails when using MSCHAPv2.

What is the most likely reason for this issue?

Options:

A.

A firewall policy is missing an LDAP authentication rule.

B.

The Windows AD server requires LDAPS (LDAP over SSL) for authentication.

C.

The FortiGate LDAP configuration is missing the correct Bind DN.

D.

FortiGate does not support MSCHAPv2 for LDAP authentication.

Buy Now
Questions 13

Refer to the exhibit.

A RADIUS server has been successfully configured on FortiGate, which sends RADIUS authentication requests to FortiAuthenticator. FortiAuthenticator, in turn, relays the authentication using LDAP to a Windows Active Directory server.

It was reported that wireless users are unable to authenticate successfully.

The FortiGate configuration confirms that it can connect to the RADIUS server without issues.

While testing authentication on FortiGate using the command diagnose test authserver radius, it was observed that authentication succeeds with PAP but fails with MSCHAPv2.

Additionally, the Remote LDAP Server configuration on FortiAuthenticator was reviewed.

Which configuration change might resolve this issue?

Options:

A.

Change the RADIUS authentication protocol to CHAP

B.

Enable Windows Active Directory Domain Authentication.

C.

Manually add user credentials to the FortiAuthenticator local database

D.

Use RADIUS attributes under the FortiGate configuration.

Buy Now
Questions 14

You ' ve configured the FortiLink interface, and the DHCP server is enabled by default. The resulting DHCP server settings are shown in the exhibit. What is the role of the vci-string setting in this configuration?

Options:

A.

To ignore DHCP requests coming from FortiSwitch and FortiExtender devices.

B.

To restrict the IP address assignment to devices that have FortiSwitch or FortiExtender as their hostname.

C.

To connect, devices must match the VCI string; otherwise, they will not receive an IP address.

D.

To reserve IP addresses for FortiSwitch and FortiExtender devices.

Buy Now
Exam Code: FCSS_LED_AR-7.6
Exam Name: Fortinet NSE 6 - LAN Edge 7.6 Architect
Last Update: May 20, 2026
Questions: 47
$64.4  $183.99
$49.35  $140.99
$44.8  $127.99
buy now FCSS_LED_AR-7.6