Fortinet NSE7_SAC-6.2 試験概要:
| 認定ベンダー: | Fortinet |
|---|---|
| 試験名: | Fortinet NSE 7 - Secure Access 6.2 |
| 試験番号: | NSE7_SAC-6.2 |
| 対応言語: | 韓国語, 英語, 簡体字中国語, 日本語 |
| 試験時間: | 60 分 |
| 試験形式: | 単一回答, 多肢選択式, 複数回答 |
| 認定の有効期間: | 2年間 |
| 受験料: | 400米ドル |
| 出題数: | 30 |
| 関連資格: | NSE 4 FortiGate NSE 8 ネットワークセキュリティエキスパート NSE 5 ネットワークセキュリティアナリスト |
| 合格点: | 変動制(約70%) |
| 推奨トレーニング: | NSE 7 Secure Access 6.2 公式トレーニング |
| 受験申し込み: | Fortinet トレーニング機関 Pearson VUE Fortinet 試験の登録 |
| サンプル問題: | Fortinet NSE7_SAC-6.2 サンプル問題 |
| 受験方法: | Pearson VUE の試験会場での受験、または OnVUE を利用したオンライン監督付き受験 |
| 前提条件: | 推奨要件:NSE 4 の資格保有に加え、FortiGate、FortiSwitch、FortiAP の実務経験を有すること。受験に必須の前提条件は設けられていません。 |
| 公式シラバスのURL: | https://training.fortinet.com/local/staticpage/view.php?page=nse_7 |
Fortinet NSE7_SAC-6.2 試験シラバストピック:
| セクション | 比重 | 目標 |
|---|---|---|
| 認証および権限付与 | 15% | - RADIUS、LDAP および FortiAuthenticator との連携 - 証明書による認証 - ゲストアクセスの設定・提供 |
| 有線ネットワークセキュリティおよび FortiSwitch | 25% | - ループ保護、ポートセキュリティおよび隔離処理 - FortiLink による管理 - 802.1X 認証および VLAN の割り当て |
| 無線セキュリティおよび FortiAP | 25% | - キャプティブポータルによる認証 - CAPWAP トンネルの導入およびトラブルシューティング - SSID、VAP およびセキュリティプロファイル - 無線クライアントの管理および負荷分散 |
| 監視、トラブルシューティングおよび隔離処理 | 10% | - Security Fabric による自動隔離機能 - 診断ツールおよびデバッグ用コマンド - FortiAnalyzer を活用したログ管理およびレポート作成 |
| セキュアアクセスアーキテクチャおよびSecurity Fabric | 25% | - Fortinet Security Fabric の統合 - FortiGate、FortiSwitch、FortiAP の相互運用性 - セキュアアクセスの設計原則 |
Fortinet NSE 7 - Secure Access 6.2 認定 NSE7_SAC-6.2 試験問題:
問題 #1
Which two statements about the use of digital certificates are true? (Choose two.)
A. The end entity's certificate can only be created by an intermediate CA.
B. An intermediate CA can sign server certificates.
C. An intermediate CA can validate the end entity certificate signed by another intermediate CA
D. An intermediate CA can sign another intermediate CA certificate.
問題 #2
An administrator is deploying APs that are connecting over an IPsec network. All APs have been configured to connect to FortiGate manually. FortiGate can discover the APs and authorize them. However, FortiGate is unable to establish CAPWAPtunnels to manage the APs.
Which configuration setting can the administrator perform to resolve the problem?
A. Decrease the CAPWAP tunnel MTU size for APs to prevent fragmentation.
B. Assign a custom AP profile for the remote APs with the set mpls-connection option enabled.
C. Enable CAPWAP administrative access on the IPsec interface.
D. Upgradethe FortiAP firmware image to ensure compatibility with the FortiOS version.
問題 #3
Examine the sections of the configuration shown in the following output;
What action will the FortiGate take when using OCSP certificate validation?
A. FortiGate will use the OCSP server 10.0.1.150 even when the OCSP URL field in the user certificate contains a different OCSP server IP address.
B. FortiGate will invalidate the certificate if the OSCP server is unavailable.
C. FortiGate will use the OCSP server 10.0.1.150 even when there is a different OCSP IP address in theocsp-override-server option under config user peer.
D. FortiGate will reject the certificate if the OCSP server replies that the certificate is unknown.
解説:
| 問題 #1 正解: C、D | 問題 #2 正解: C | 問題 #3 正解: B |














1310 お客様のコメント
品質保証JPexamはIT認定試験のシラバスに従って、試験問題の範囲を正確に絞って、的中率が99%の最新問題集を捧げます。
1年間の無料更新サービスJPexamは1年以内に問題集の無料更新サービスを提供し、お客様がいつでも最新版の問題集を持つことを保証いたします。もし試験の内容が変更されたら、弊社は直ちにお客様にお知らせします。それに、弊社の問題集が更新されたら、早速メールで最新バージョンを送付いたします。
全額返金JPexamの問題集を利用すると、短時間で勉強しても試験に合格できるのを保証いたします。試験に不合格になってしまった場合、弊社は全額返金いたします。(
ご購入前のお試しJPexamは問題集のサンプルを無料で提供いたします。ご購入前にサンプルを試用して製品の品質を確認することができます。ご遠慮なく利用してください。
