Fortinet FCP_FAC_AD-6.5 Exam (page: 1)
Fortinet FCP - FortiAuthenticator 6.5 Administrator
Updated on: 31-Mar-2026

Viewing Page 1 of 5

Which three of the following can be used as SSO sources? (Choose three.)

  1. RADIUS accounting
  2. FortiClient SSO Mobility Agent
  3. SSH sessions
  4. FortiGate
  5. FortiAuthenticator in SAML SP role

Answer(s): A,B,D

Explanation:

RADIUS accounting can be used by FortiAuthenticator to obtain user identity and session details for SSO.

FortiClient SSO Mobility Agent reports user login events to FortiAuthenticator for SSO.

FortiGate can act as an SSO source by sending user authentication information to FortiAuthenticator.



You have implemented two-factor authentication to enhance security to sensitive enterprise systems.

How could you bypass the need for two-factor authentication for users accessing form specific secured networks?

  1. Enable Adaptive Authentication in the portal policy.
  2. Specify the appropriate RADIUS clients in the authentication policy.
  3. Create an admin realm in the authentication policy.
  4. Enable the Resolve user geolocation from their IP address option in the authentication policy

Answer(s): A

Explanation:

Enabling Adaptive Authentication in the portal policy allows FortiAuthenticator to apply contextual rules, such as bypassing two-factor authentication when users connect from specific secured networks.



When configuring an active-passive HA deployment, what is the recommended data synchronization path?

  1. Dedicated fiber channel
  2. Same VLAN
  3. Dedicated point-to-point VPN connection
  4. Direct cable connection

Answer(s): D

Explanation:

A direct cable connection is the recommended data synchronization path in an active-passive HA deployment because it provides the fastest, most reliable, and secure method for synchronizing data between FortiAuthenticator units without depending on external network infrastructure.



Which FSSO discovery method transparently detects logged off users without having to rely on external features such as WMI polling?

  1. RADIUS accounting
  2. FortiClient SSO mobility agent
  3. DC polling
  4. Windows AD polling

Answer(s): B

Explanation:

The FortiClient SSO Mobility Agent runs on the endpoint and communicates login and logoff events directly to FortiAuthenticator, allowing transparent detection of logged-off users without relying on external mechanisms like WMI polling.



When performing a remote LDAP server integration with FortiAuthenticator, how do server type templates assist with the integration?

  1. They autopopulate the simple and regular bind settings.
  2. They automatically set the LDAP user auto provisioning settings.
  3. They populate the query element fields with defined attribute and class values.
  4. They define the connection security and domain authentication settings for each LDAP server you integrate with.

Answer(s): C

Explanation:

Server type templates in FortiAuthenticator assist LDAP integration by prepopulating the query element fields with the correct attribute and class values for the selected LDAP server type, simplifying configuration and ensuring accurate directory queries.



Which two data items are not synchronized in an active-active HA deployment? (Choose two.)

  1. Group mappings
  2. User certificates
  3. FSSO events
  4. Seeds

Answer(s): C,D

Explanation:

In an active-active HA deployment, FSSO events and seeds are not synchronized between FortiAuthenticator units, as these are instance-specific and typically handled locally on each node.



Refer to the exhibit.



Which functionality does the Enable NTLM option provide?

  1. It allows FortiAuthenticator to message end users using the FortiClient for SSO.
  2. It forces FortiClient users to use two-factor authentication when using FortiClient for SSO.
  3. It prevents users from authenticating to an unauthorized AD server.
  4. It enables tracking and recording all authentications performed through FortiClient.

Answer(s): C

Explanation:

Enabling NTLM authentication in this FortiAuthenticator SSO configuration ensures that user authentication requests are validated against the specified domain, preventing users from authenticating to an unauthorized Active Directory server.



You are a FortiAuthenticator administrator for a large organization. Users who are configured to use FortiToken 200 for two-factor authentication can no longer authenticate. You have verified that only the users with two-factor authentication are experiencing the issue.

What can cause this issue?

  1. Time drift between FortiAuthenticator and hardware tokens
  2. The seed value on the tokens was incorrectly updated
  3. Token certificate was added to a CRL
  4. FortiAuthenticator has lost contact with the FortiCloud token provisioning servers

Answer(s): A

Explanation:

If there is time drift between FortiAuthenticator and FortiToken 200 hardware tokens, the one-time passwords generated will no longer match the expected values, causing all two-factor authentication attempts to fail for affected users.



Viewing Page 1 of 5



Share your comments for Fortinet FCP_FAC_AD-6.5 exam with other users:

Freddie 12/12/2023 12:37:00 PM

helpful dump questions
SOUTH AFRICA


Da Costa 8/25/2023 7:30:00 AM

question 423 eigrp uses metric
Anonymous


Bsmaind 8/20/2023 9:22:00 AM

hello nice dumps
Anonymous


beau 1/12/2024 4:53:00 PM

good resource for learning
UNITED STATES


Sandeep 12/29/2023 4:07:00 AM

very useful
Anonymous


kevin 9/29/2023 8:04:00 AM

physical tempering techniques
Anonymous


Blessious Phiri 8/15/2023 4:08:00 PM

its giving best technical knowledge
Anonymous


Testbear 6/13/2023 11:15:00 AM

please upload
ITALY


shime 10/24/2023 4:23:00 AM

great question with explanation thanks!!
ETHIOPIA


Thembelani 5/30/2023 2:40:00 AM

does this exam have lab sections?
Anonymous


Shin 9/8/2023 5:31:00 AM

please upload
PHILIPPINES


priti kagwade 7/22/2023 5:17:00 AM

please upload the braindump for .net
UNITED STATES


Robe 9/27/2023 8:15:00 PM

i need this exam 1z0-1107-2. please.
Anonymous


Chiranthaka 9/20/2023 11:22:00 AM

very useful!
Anonymous


Not Miguel 11/26/2023 9:43:00 PM

for this question - "which three type of basic patient or member information is displayed on the patient info component? (choose three.)", list of conditions is not displayed (it is displayed in patient card, not patient info). so should be thumbnail of chatter photo
Anonymous


Andrus 12/17/2023 12:09:00 PM

q52 should be d. vm storage controller bandwidth represents the amount of data (in terms of bandwidth) that a vms storage controller is using to read and write data to the storage fabric.
Anonymous


Raj 5/25/2023 8:43:00 AM

nice questions
UNITED STATES


max 12/22/2023 3:45:00 PM

very useful
Anonymous


Muhammad Rawish Siddiqui 12/8/2023 6:12:00 PM

question # 208: failure logs is not an example of operational metadata.
SAUDI ARABIA


Sachin Bedi 1/5/2024 4:47:00 AM

good questions
Anonymous


Kenneth 12/8/2023 7:34:00 AM

thank you for the test materials!
KOREA REPUBLIC OF


Harjinder Singh 8/9/2023 4:16:00 AM

its very helpful
HONG KONG


SD 7/13/2023 12:56:00 AM

good questions
UNITED STATES


kanjoe 7/2/2023 11:40:00 AM

good questons
UNITED STATES


Mahmoud 7/6/2023 4:24:00 AM

i need the dumb of the hcip security v4.0 exam
EGYPT


Wei 8/3/2023 4:18:00 AM

upload the dump please
HONG KONG


Stephen 10/3/2023 6:24:00 PM

yes, iam looking this
AUSTRALIA


Stephen 8/4/2023 9:08:00 PM

please upload cima e2 managing performance dumps
Anonymous


hp 6/16/2023 12:44:00 AM

wonderful questions
Anonymous


Priyo 11/14/2023 2:23:00 AM

i used this site since 2000, still great to support my career
INDONESIA


Jude 8/29/2023 1:56:00 PM

why is the answer to "which of the following is required by scrum?" all of the following stated below since most of them are not mandatory? sprint retrospective. members must be stand up at the daily scrum. sprint burndown chart. release planning.
UNITED STATES


Marc blue 9/15/2023 4:11:00 AM

great job. hope this helps out.
UNITED STATES


Anne 9/13/2023 2:33:00 AM

upload please. many thanks!
Anonymous


pepe el toro 9/12/2023 7:55:00 PM

this is so interesting
Anonymous