Fortinet FCP_FAC_AD-6.5 Exam
FCP - FortiAuthenticator 6.5 Administrator (Page 3 )

Updated On: 7-Feb-2026

Which three of the following can be used as SSO sources? (Choose three.)

  1. RADIUS accounting
  2. FortiClient SSO Mobility Agent
  3. SSH sessions
  4. FortiGate
  5. FortiAuthenticator in SAML SP role

Answer(s): A,B,D

Explanation:

RADIUS accounting can be used by FortiAuthenticator to obtain user identity and session details for SSO.

FortiClient SSO Mobility Agent reports user login events to FortiAuthenticator for SSO.

FortiGate can act as an SSO source by sending user authentication information to FortiAuthenticator.



You have implemented two-factor authentication to enhance security to sensitive enterprise systems.

How could you bypass the need for two-factor authentication for users accessing form specific secured networks?

  1. Enable Adaptive Authentication in the portal policy.
  2. Specify the appropriate RADIUS clients in the authentication policy.
  3. Create an admin realm in the authentication policy.
  4. Enable the Resolve user geolocation from their IP address option in the authentication policy

Answer(s): A

Explanation:

Enabling Adaptive Authentication in the portal policy allows FortiAuthenticator to apply contextual rules, such as bypassing two-factor authentication when users connect from specific secured networks.



When configuring an active-passive HA deployment, what is the recommended data synchronization path?

  1. Dedicated fiber channel
  2. Same VLAN
  3. Dedicated point-to-point VPN connection
  4. Direct cable connection

Answer(s): D

Explanation:

A direct cable connection is the recommended data synchronization path in an active-passive HA deployment because it provides the fastest, most reliable, and secure method for synchronizing data between FortiAuthenticator units without depending on external network infrastructure.



Which FSSO discovery method transparently detects logged off users without having to rely on external features such as WMI polling?

  1. RADIUS accounting
  2. FortiClient SSO mobility agent
  3. DC polling
  4. Windows AD polling

Answer(s): B

Explanation:

The FortiClient SSO Mobility Agent runs on the endpoint and communicates login and logoff events directly to FortiAuthenticator, allowing transparent detection of logged-off users without relying on external mechanisms like WMI polling.



When performing a remote LDAP server integration with FortiAuthenticator, how do server type templates assist with the integration?

  1. They autopopulate the simple and regular bind settings.
  2. They automatically set the LDAP user auto provisioning settings.
  3. They populate the query element fields with defined attribute and class values.
  4. They define the connection security and domain authentication settings for each LDAP server you integrate with.

Answer(s): C

Explanation:

Server type templates in FortiAuthenticator assist LDAP integration by prepopulating the query element fields with the correct attribute and class values for the selected LDAP server type, simplifying configuration and ensuring accurate directory queries.






Post your Comments and Discuss Fortinet FCP_FAC_AD-6.5 exam prep with other Community members:

Join the FCP_FAC_AD-6.5 Discussion