Where should you configure MAC notification traps on a supported switch?
Answer : C
In general, for network switches supporting MAC notification traps, it's advisable to configure these traps on all ports except uplink ports. Uplink ports are used for connecting to other switches or network infrastructure devices and typically don't need MAC notification traps, which are more relevant for end-device connectivity monitoring.
The study guide specifies that MAC notification traps should not be configured on interfaces that are uplinks. They are the preferred method for learning and updating Layer 2 information and should be used whenever available, but not on uplink interfaces.
Which group type can have members added directly from the FortiNAC Control Manager?
Answer : B
The study guide explains that there are six different types of groups in FortiNAC, including device, host, IP phone, port, user, and administrator groups. Groups created by administrative users or imported as a result of an LDAP integration can be used to organize elements but do not enforce any type of control or functionality directly
Which system group will force at-risk hosts into the quarantine network, based on point of connection?
Answer : D
Forced Quarantine, study guide 7.2 pag 245 and 248
When FortiNAC is managing FortiGate VPN users, why is an endpoint compliance policy necessary?
Answer : A
Refer to the exhibit.

What would happen if the highlighted port with connected hosts was placed in both the Forced Registration and Forced Remediation port groups?
Answer : B
In systems like FortiNAC, when a port is designated to be in multiple enforcement groups, it is common for only the higher-priority or higher-ranked group's policies to be applied. This is to prevent conflicting enforcement actions from being attempted on the same port. Although the specific details of the priority or ranking system are not provided in the extracted references, the principle of hierarchical policy enforcement suggests that only the policies of the higher-ranked group would be applied to the port.
Reference
FortiNAC documentation would typically outline this behavior in sections discussing port group enforcement or policy application.
Which agent is used only as part of a login script?
Answer : B
In the context of network access control systems like FortiNAC, a dissolvable agent is typically a piece of software that is executed on the endpoint as part of a login script or when a user accesses a captive portal. It runs once to gather information or enforce policies and then removes itself from the system, hence the term 'dissolvable.'
Reference
FortiNAC documentation on agent deployment and types of agents.
Which two things must be done to allow FortiNAC to process incoming syslog messages from an unknown vendor? (Choose two.)
Answer : A, B
To allow FortiNAC to process incoming syslog messages from an unknown vendor, two steps must be taken:
Creation of a customized event parser: This enables FortiNAC to parse and integrate syslog messages from any vendor or device, as long as the messages are in CSV, CEF, or Tag/Value format.
Modeling the device in the Topology view: Any device that sends syslog messages to FortiNAC must be modeled in this view. FortiNAC will not process syslog or trap messages unless the source address belongs to a device modeled in the topology.
Reference
FortiNAC 7.2 Study Guide, pages 428 and 399