Fortinet NSE6_FWF-6.4 Fortinet NSE 6 - Secure Wireless LAN 6.4 Exam Practice Test

Page: 1 / 14
Total 35 questions
Question 1

Which statement is correct about security profiles on FortiAP devices?



Answer : D

Security profiles are a feature that allows FortiAP devices to apply various security functions to the wireless traffic, such as antivirus, web filter, application control, intrusion prevention, and botnet scanning. Security profiles can be enabled on both tunnel-mode and bridge-mode SSIDs, and can be applied either through the wireless controller configuration or through firewall policies on the FortiGate device. Security profiles can also inspect encrypted wireless traffic, as long as the FortiAP device has access to the encryption keys.

Security profiles on FortiAP devices can use FortiGate subscription services to inspect the traffic, such as FortiGuard Antivirus, FortiGuard Web Filter, FortiGuard Application Control, and FortiGuard IPS. This means that the FortiAP device can leverage the latest threat intelligence and updates from Fortinet to protect the wireless network from malicious or unwanted content.

Therefore, the correct answer is D. Security profiles on FortiAP devices can use FortiGate subscription to inspect the traffic.


FortiAP-S and FortiAP-U bridge mode security profiles

Configuring security | FortiAP / FortiWiFi 6.4.2

Security profiles - Fortinet Document Library

Question 2

Refer to the exhibit.

If the signal is set to -68 dB on the FortiPlanner site survey reading, which statement is correct regarding the coverage area?

A. Areas with the signal strength weaker than -68 dB are shown with black background.

B. Areas with the signal strength equal to -68 dB are zoomed in to provide better visibility.

C. Areas with the signal strength weaker than -68 dB are highlighted in orange and red to indicate that no signal was propagated by the APS.



Answer : D

The FortiPlanner site survey reading is a tool that shows the predicted signal strength of the wireless network based on the floor plan, the placement of the APs, and the propagation model. The signal strength is measured in decibels (dB), which is a logarithmic scale that indicates how much power the signal has. The higher the dB value, the stronger the signal.

The site survey reading allows the user to set a threshold value for the signal strength, which is -68 dB by default. This means that any area with a signal strength equal or stronger than -68 dB is considered to have adequate coverage for most wireless applications. These areas are highlighted in green circles on the floor plan. Any area with a signal strength weaker than -68 dB is considered to have poor coverage or no coverage at all. These areas are shown with different colors, such as yellow, orange, red, or black, depending on how weak the signal is.

Therefore, the correct answer is D. Areas with the signal strength equal or stronger than -68 dB are highlighted in green circles.


FortiPlanner 2.0 User Guide, page 28

FortiPlanner Data Sheet, page 2

FortiPlanner 2.2 User Guide, page 19

Question 3

Which statement is correct about security profiles on FortiAP devices?



Question 4

How can you find upstream and downstream link rates of a wireless client using FortiGate?



Question 5

A tunnel mode SSID is configured on a FortiGate wireless controller.

Which task must be completed before the SSID can be used?



Question 6

How are wireless clients assigned to a dynamic VLAN configured for hash mode?



Answer : C

VLAN from the VLAN pool based on a hash of the current number of SSID clients and the number of entries in the VLAN pool.


Question 7

Which statement is correct about security profiles on FortiAP devices?



Answer : B


If a bridge mode SSID is configured for a managed FortiAP, you can add a security profile group to the wireless controller, if the FortiAP model supports the security profile. This is supported only in bridge mode.

Page:    1 / 14   
Total 35 questions