Free NSE6_FAC-6.1 Exam Braindumps (page: 3)

Page 2 of 8

Which option correctly describes an SP-initiated SSO SAML packet flow for a host without a SAML assertion?

  1. Service provider contacts identity provider, identity provider validates principal for service provider, service provider establishes communication with principal
  2. Principal contacts identity provider and is redirected to service provider, principal establishes connection with service provider, service provider validates authentication with identify provider
  3. Principal contacts service provider, service provider redirects principal to identity provider, after successful authentication identify provider redirects principal to service provider
  4. Principal contacts identity provider and authenticates, identity provider relays principal to service provider after valid authentication

Answer(s): C



A device or user identity cannot be established transparently, such as with non-domain BYOD devices, and allow users to create their own credentialism. In this case, which user identity discovery method can Fortiauthenticator use?

  1. Syslog messaging or SAML IDP
  2. Kerberos-base authentication
  3. Radius accounting
  4. Portal authentication

Answer(s): D



Which two SAML roles can Fortiauthenticator be configured as? (Choose two)

  1. Identity provider
  2. Principal
  3. Assertion server
  4. Service provider

Answer(s): A,D



What happens when a certificate is revoked? (Choose two)

  1. Revoked certificates cannot be reinstated for any reason
  2. All certificates signed by a revoked CA certificate are automatically revoked
  3. Revoked certificates are automatically added to the CRL
  4. External CAs will periodically query Fortiauthenticator and automatically download revoked certificates

Answer(s): C,D






Post your Comments and Discuss Fortinet NSE6_FAC-6.1 exam with other Community members:

NSE6_FAC-6.1 Discussions & Posts