Fortinet NSE 6 - Secure Wireless LAN 6.4 NSE6_FWF-6.4 Exam Practice Test

Page: 1 / 14
Total 35 questions
Question 1

Which two statements about distributed automatic radio resource provisioning (DARRP) are correct? (Choose two.)



Answer : B, C

According to Fortinet training: 'When using DARRP, the AP selects the best channel available to use based on the scan results of BSSID/receive signal strength (RSSI) to AC' and 'To set the running time for DARRP optimization, use the following CLI command within the wireless controller setting: set darrp-optimize {integer}. Note that DARRP doesn't do continuous spectrum analysis...'


Question 2

Refer to the exhibits.

Exhibit A

Exhibit B

A wireless network has been created to support a group of users in a specific area of a building. The wireless network is configured but users are unable to connect to it. The exhibits show the relevant controller configuration for the APs and the wireless network.

Which two configuration changes will resolve the issue? (Choose two.)



Question 3
Question 4

Which statement is correct about security profiles on FortiAP devices?



Answer : D

Security profiles are a feature that allows FortiAP devices to apply various security functions to the wireless traffic, such as antivirus, web filter, application control, intrusion prevention, and botnet scanning. Security profiles can be enabled on both tunnel-mode and bridge-mode SSIDs, and can be applied either through the wireless controller configuration or through firewall policies on the FortiGate device. Security profiles can also inspect encrypted wireless traffic, as long as the FortiAP device has access to the encryption keys.

Security profiles on FortiAP devices can use FortiGate subscription services to inspect the traffic, such as FortiGuard Antivirus, FortiGuard Web Filter, FortiGuard Application Control, and FortiGuard IPS. This means that the FortiAP device can leverage the latest threat intelligence and updates from Fortinet to protect the wireless network from malicious or unwanted content.

Therefore, the correct answer is D. Security profiles on FortiAP devices can use FortiGate subscription to inspect the traffic.


FortiAP-S and FortiAP-U bridge mode security profiles

Configuring security | FortiAP / FortiWiFi 6.4.2

Security profiles - Fortinet Document Library

Question 5

Refer to the exhibit.

If the signal is set to -68 dB on the FortiPlanner site survey reading, which statement is correct regarding the coverage area?

A. Areas with the signal strength weaker than -68 dB are shown with black background.

B. Areas with the signal strength equal to -68 dB are zoomed in to provide better visibility.

C. Areas with the signal strength weaker than -68 dB are highlighted in orange and red to indicate that no signal was propagated by the APS.



Answer : D

The FortiPlanner site survey reading is a tool that shows the predicted signal strength of the wireless network based on the floor plan, the placement of the APs, and the propagation model. The signal strength is measured in decibels (dB), which is a logarithmic scale that indicates how much power the signal has. The higher the dB value, the stronger the signal.

The site survey reading allows the user to set a threshold value for the signal strength, which is -68 dB by default. This means that any area with a signal strength equal or stronger than -68 dB is considered to have adequate coverage for most wireless applications. These areas are highlighted in green circles on the floor plan. Any area with a signal strength weaker than -68 dB is considered to have poor coverage or no coverage at all. These areas are shown with different colors, such as yellow, orange, red, or black, depending on how weak the signal is.

Therefore, the correct answer is D. Areas with the signal strength equal or stronger than -68 dB are highlighted in green circles.


FortiPlanner 2.0 User Guide, page 28

FortiPlanner Data Sheet, page 2

FortiPlanner 2.2 User Guide, page 19

Question 6

Where in the controller interface can you find a wireless client's upstream and downstream link rates?



Answer : A


Question 7

A tunnel mode wireless network is configured on a FortiGate wireless controller.

Which task must be completed before the wireless network can be used?



Answer : C

A FortiGate unit is an industry leading enterprise firewall. In addition to consolidating all the functions of a network firewall, IPS, anti-malware, VPN, WAN optimization, Web filtering, and application control in a single platform, FortiGate also has an integrated Wi-Fi controller.


Page:    1 / 14   
Total 35 questions