Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

FCSS_LED_AR-7.6 Fortinet NSE 6 - LAN Edge 7.6 Architect Questions and Answers

Questions 4

Refer to the exhibit.

FCSS_LED_AR-7.6 Question 4

Which shows the WTP profile configuration.

The AP profile is assigned to two FAP-231F APs that are installed in an open plan area.

The first AP has 32 clients associated with the 5 GHz radios and 22 clients associated with the 2.4 GHz radio. The second AP has 12 clients associated with the 5 GHz radios and 20 clients associated with the 2.4 GHz radio.

A dual-band-capable client enters the area near the first AP and the first AP measures the new client at - 3 3 dBm signal strength. The second AP measures the new client at -43 dBm signal strength.

If the new client attempts to conned to the student 01 wireless network, which AP radio will the client be associated with?

Options:

A.

The first AP 2.4 GHz interface provides a stronger signal, which clients often prioritize.

B.

The first AP 5 GHz interface because it has a stronger signal.

C.

The second AP 5 GHz interface has fewer clients, which ensures better performance despite the weaker signal.

D.

The second AP 2.4 GHz interface is preferred over 5 GHz for better speed and lower interference.

Buy Now
Questions 5

A FortiSwitch is not appearing in the FortiGate management interface after being connected via FortiLink. What could be a first troubleshooting step?

Options:

A.

Ensure that the FortiGate security policies allow traffic from the FortiSwitch.

B.

Manually assign a static IP to the FortiSwitch.

C.

Verify that FortiGate device DHCP server is assigning an IP to the FortiSwitch.

D.

Ensure the FortiSwitch has internet access.

Buy Now
Questions 6

A conference center wireless network provides guest access through a captive portal, allowing unregistered users to self-register and connect to the network. The IT team has been tasked with updating the existing configuration to enforce captive portal authentication over a secure HTTPS connection. Which two steps should the administrator take to implement this change? (Choose two.)

Options:

A.

Enable HTTP redirect in the user authentication settings.

B.

Create a new SSID with the HTTPS captive portal URL.

C.

Disable HTTP administrative access on the guest SSID to enforce HTTPS connection.

D.

Update the captive portal URL to use HTTPS on FortiGate and FortiAuthenticator.

Buy Now
Questions 7

A network administrator connects a new FortiGate to the network, allowing it to automatically discover andI register with FortiManager.

What occurs after FortiGate retrieves the FortiManager address?

Options:

A.

FortiGate establishes a secure tunnel to FortiManager over TCP port 541.

B.

The device needs to be manually authorized on FortiManager.

C.

FortiGate configures its interface settings based on a DHCP response from FortiManager.

D.

FortiGate sends a discovery request to all devices on the local network using UDP port 1068.

Buy Now
Questions 8

Refer to the exhibits.

FCSS_LED_AR-7.6 Question 8

FCSS_LED_AR-7.6 Question 8

Examine the FortiGate RSSO configuration shown in the exhibit.

FortiGate is set up to use RSSO for user authentication. It is currently receiving RADIUS accounting messages through port3. The incoming RADIUS accounting messages contain the username in the User-Name attribute and group membership in the Class attribute. You must ensure that the users are authenticated through these RADIUS accounting messages and accurately mapped to their respective RSSO user groups.

Which three critical configurations must you implement on the FortiGate device? (Choose three.)

Options:

A.

The RADIUS Attribute Value setting configured for an RSSO user group should match the class RADIUS attribute value in the RADIUS accounting message.

B.

RSSO user groups should be assigned to all firewall policies.

C.

Device detection and Security Fabric Connection should be enabled on port3

D.

The sso-attribute CLI setting in the RSSO agent configuration should be set to Class.

E.

The rsso-endpoint-attribute CLI setting in the RSSO agent configuration should be set to User-Name.

Buy Now
Questions 9

FCSS_LED_AR-7.6 Question 9

FortiGate has been added to FortiAIOps for management.

Which step must be performed on FortiAIOps to add a FortiSwitch device connected to the recently added FortiGate?

Options:

A.

Add the FortiSwitch device by submitting its serial number.

B.

FortiAIOps requires that the FortiSwitch IP address is submitted.

C.

FortiSwitch is added automatically.

D.

Configure the FortiSwitch IP address, user ID, and password

Buy Now
Questions 10

APs have been manually configured to connect to FortiGate over an IPsec network, and FortiGate successfully detects and authorizes them. However, the APs remain unmanaged because FortiGate is unable to establish a CAPWAP tunnel with them.

What configuration change can resolve this issue and enable FortiGate to establish the CAPWAP tunnel over the IPsec connection?

Options:

A.

Configure a static route on FortiGate to reach the APs over the IPsec tunnel.

B.

Assign a custom AP profile for the remote APs with the set mpls-connection option enabled.

C.

Decrease the CAPWAP tunnel MTU size for APs to prevent fragmentation.

D.

Upgrade the FortiAP firmware image to ensure compatibility with the FortiOS version.

Buy Now
Questions 11

Refer to the exhibits.

FCSS_LED_AR-7.6 Question 11

FCSS_LED_AR-7.6 Question 11

Examine the FortiGate configuration, FortiAnalyzer logs, and FortiGate widget shown in the exhibits.

Security Fabhc quarantine automation has been configured to isolate compromised devices automatically. FortiAnalyzer has been added to the Security Fabric, and an automation stitch has been configured to quarantine compromised devices.

To test the setup, a device with the IP address 10.0.2.1 that is connected through a managed FortiSwitch attempts to access a malicious website. The logs on FortiAnalyzer confirm that the event was recorded, but the device does not appear in the FortiGate quarantine widget.

Which two reasons could explain why FortiGate is not quarantining the device? (Choose two.)

Options:

A.

The IOC action should include only the FortiSwitch in the quarantine.

B.

The SSL inspection should be set to deep-Inspection

C.

The malicious website is not recognized as an indicator of compromise (IOC) by FortiAnalyzer.

D.

The threat detection services license is missing or invalid under FortiAnalyzer.

Buy Now
Questions 12

Refer to the exhibits.

FCSS_LED_AR-7.6 Question 12

FCSS_LED_AR-7.6 Question 12

A set of SSID profiles has been configured on FortiManager, and an AP profile has been assigned to a group of AP managed by FortiGate. However, none of the designated SSIDs are being broadcast by these APs.

Which configuration change is required to make the APs broadcast these SSIDs as intended?

Options:

A.

Adjust the AP profile to ensure all SSIDs are configured in a supported mode, either bridge or tunnel, but not a mix of both.

B.

Change the AP profile to use a platform that supports the configured mix of SSIDs.

C.

Choose Manual in the SSIDs setting and select the SSIDs to broadcast.

D.

Set the Transmit Power Mode to Auto.

Buy Now
Questions 13

Which statement about generating a certificate signing request (CSR) for a CER certificate is true?

Options:

A.

Inaccurate or missing fields in the CSR will prevent the CA from validating the request, leading to the rejection of the certificate and possible delays in the deployment process.

B.

If key fields like the common name (CN) and organization (O) are incorrect, the certification authority (CA) will still issue the certificate, but it may not be trusted by certain applications or systems that rely on accurate field information for validation.

C.

CSR fields are primarily used for internal recordkeeping by the requesting organization, and only the public key in the CSR must be accurate for successful certificate signing.

D.

The fields in the CSR are primarily for documentation purposes; any missing or incorrect information will be automatically corrected by the CA during the signing process.

Buy Now
Questions 14

Refer to the exhibit.

FCSS_LED_AR-7.6 Question 14

On FortiGate, a RADIUS server is configured to forward authentication requests to FortiAuthenticator, which acts as a RADIUS proxy. FortiAuthenticator then relays these authentication requests to a remote Windows AD server using LDAP.

While testing authentication using the CLI command diagnose test authserver. the administrator observed that authentication succeeded with PAP but failed when using MS-CHAFV2.

Which two solutions can the administrator implement to enable MS-CHAPv2 authentication? (Choose two.)

Options:

A.

Enable Windows Active Directory domain authentication on FortiAuthenticator.

B.

Configure FortiAuthenticator to use RADIUS instead of LDAP as the back-end authentication server.

C.

Enable RADIUS attribute filtering on FortiAuthenticator.

D.

Change the FortiGate authentication method to CHAP instead of MS-CHAPv2.

Buy Now
Exam Code: FCSS_LED_AR-7.6
Exam Name: Fortinet NSE 6 - LAN Edge 7.6 Architect
Last Update: Apr 11, 2026
Questions: 47

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99