Fortinet NSE6_FAC-6.1 Exam
Fortinet NSE 6 - FortiAuthenticator 6.1 (Page 2 )

Updated On: 12-Feb-2026

Which interface services must be enabled for the SCEP client to connect to Authenticator?

  1. OCSP
  2. REST API
  3. SSH
  4. HTTP/HTTPS

Answer(s): D



Which FSSO discovery method transparently detects logged off users without having to rely on external features such as WMI polling?

  1. Windows AD polling
  2. FortiClient SSO Mobility Agent
  3. Radius Accounting
  4. DC Polling

Answer(s): B



How can a SAML metada file be used?

  1. To defined a list of trusted user names
  2. To import the required IDP configuration
  3. To correlate the IDP address to its hostname
  4. To resolve the IDP realm for authentication

Answer(s): B



Which two are supported captive or guest portal authentication methods? (Choose two)

  1. LinkedIn
  2. Apple ID
  3. Instagram
  4. Email

Answer(s): A,D



Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?

  1. Service provider contacts identity provider, identity provider validates principal for service provider, service provider establishes communication with principal
  2. Principal contacts identity provider and is redirected to service provider, principal establishes connection with service provider, service provider validates authentication with identify provider
  3. Principal contacts service provider, service provider redirects principal to identity provider, after successful authentication identify provider redirects principal to service provider
  4. Principal contacts identity provider and authenticates, identity provider relays principal to service provider after valid authentication

Answer(s): C






Post your Comments and Discuss Fortinet NSE6_FAC-6.1 exam prep with other Community members:

Join the NSE6_FAC-6.1 Discussion