Weekend Sale - Special 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 75onlydt

NSE7_SSE_AD-25 Questions and Answers

Question # 6

Which FortiSASE feature ensures least-privileged user access to all applications?

A.

secure web gateway (SWG)

B.

SD-WAN

C.

zero trust network access (ZTNA)

D.

thin branch SASE extension

Full Access
Question # 7

Which policy type is used to control traffic between the FortiClient endpoint to FortiSASE for secure internet access?

A.

VPN policy

B.

thin edge policy

C.

private access policy

D.

secure web gateway (SWG) policy

Full Access
Question # 8

Which two components are part of onboarding a secure web gateway (SWG) endpoint? (Choose two)

A.

FortiSASE CA certificate

B.

proxy auto-configuration (PAC) file

C.

FortiSASE invitation code

D.

FortiClient installer

Full Access
Question # 9

Your organization is currently using FortiSASE for its cybersecurity. They have recently hired a contractor who will work from the HQ office and who needs temporary internet access in order to set up a web-based point of sale (POS) system. How can you provide secure internet access to the contractor using FortiSASE? (Choose one answer)

A.

Use a proxy auto-configuration (PAC) file and provide secure web gateway (SWG) service as an explicit web proxy.

B.

Use a tunnel policy with a contractors user group as the source on FortiSASE to provide internet access.

C.

Use zero trust network access (ZTNA) and tag the client as an unmanaged endpoint.

D.

Use the self-registration portal on FortiSASE to grant internet access.

Full Access
Question # 10

A company must provide access to a web server through FortiSASE secure private access for contractors. What is the recommended method to provide access? (Choose one answer)

A.

Configure a TCP access proxy forwarding rule and push it to the contractor FortiClient endpoint.

B.

Publish the web server URL on a bookmark portal and share it with contractors.

C.

Update the PAC file with the web server URL and share it with contractors.

D.

Update the DNS records on the endpoint to access private applications.

Full Access
Question # 11

Refer to the exhibit.

Question # 11

An SPA service connection is experiencing connectivity problems. Which configuration setting should the administrator verify and correct first? (Choose one answer)

A.

Remote Gateway

B.

BGP Peer IP

C.

Network overlay ID

D.

Authentication Method

Full Access
Question # 12

Which two settings are automatically pushed from FortiSASE to FortiClient in a new FortiSASE deployment with default settings? (Choose two answers)

A.

FortiSASE certificate authority (CA) certificate

B.

Tunnel profile

C.

Real-time protection

D.

Zero trust network access (ZTNA) tags1

Full Access
Question # 13

Which two additional components does FortiSASE use for application control to act as an inline-CASB? (Choose two.)

A.

intrusion prevention system (IPS)

B.

SSL deep inspection

C.

DNS filter

D.

Web filter with inline-CASB

Full Access
Question # 14

Which three traffic flows are supported by FortiSASE Secure Private Access (SPA)? (Choose three answers)

A.

From private resources to FortiSASE agent-based users.

B.

From private resources to the internet.

C.

From agent-based users to private resources behind the Fortinet SD-WAN.

D.

From private resources to other private resources (SPA to SPA).

E.

From thin branches/branch on-ramp to private resources behind the Fortinet SD-WAN.

Full Access
Question # 15

For monitoring potentially unwanted applications on endpoints, which information is available on the FortiSASE software installations page? (Choose two answers)

A.

The endpoint the software is installed on1

B.

The license status of the software2

C.

The vendor of the software3

D.

The usage frequency of the software

Full Access
Question # 16

You are designing a new network, and the cybersecurity policy mandates that all remote users working from home must always be connected and protected. Which FortiSASE component facilitates this always-on security measure? (Choose one answer)

A.

Unified FortiClient

B.

SDWAN on-ramp2

C.

Secure web gateway

D.

Thin-branch SASE extension

Full Access
Question # 17

Refer to the exhibit.

In the user connection monitor, the FortiSASE administrator notices the user name is showing random characters. Which configuration change must the administrator make to get proper user information?

A.

Turn off log anonymization on FortiSASE.

B.

Add more endpoint licenses on FortiSASE.

C.

Configure the username using FortiSASE naming convention.

D.

Change the deployment type from SWG to VPN.

Full Access
Question # 18

Refer to the exhibits.

Question # 18

A FortiSASE administrator has configured FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGate hub. However, the remote FortiClient is not able to access the web server hosted behind the FortiGate hub. What is the reason for the access failure? (Choose one answer)

A.

The hub is not advertising the required routes.

B.

A private access policy has denied the traffic because of failed compliance.

C.

The hub firewall policy does not include the FortiClient address range.

D.

The server subnet BGP route was not received on FortiSASE.

Full Access
Question # 19

Which statement about FortiSASE and SAML is true? (Choose one answer)

A.

FortiSASE acts as the SP, relies on an external IdP, and can use SAML group matching.

B.

FortiSASE supports SAML login but cannot use SAML group matching.

C.

FortiSASE acts as the IdP and can perform SAML group matching internally.

D.

FortiSASE includes IdP functionality and uses it for SAML group matching.

Full Access
Question # 20

Refer to the exhibits.

Question # 20

Question # 20

A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy.

Which configuration on FortiSASE is allowing users to perform the download?

A.

Web filter is allowing the traffic.

B.

IPS is disabled in the security profile group.

C.

The HTTPS protocol is not enabled in the antivirus profile.

D.

Force certificate inspection is enabled in the policy.

Full Access
Question # 21

Refer to the exhibits.

Question # 21

Question # 21

A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish

Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?

A.

NAT needs to be enabled in the Spoke-to-Hub firewall policy.

B.

The BGP router ID needs to match on the hub and FortiSASE.

C.

FortiSASE spoke devices do not support mode config.

D.

The hub needs IKEv2 enabled in the IPsec phase 1 settings.

Full Access
Question # 22

You are configuring FortiSASE SSL deep inspection. What is required for FortiSASE to inspect encrypted traffic? (Choose one answer)

A.

FortiSASE uses a third-party CA certificate without importing it to client machines, and SSL deep inspection supports only web filtering and application control.

B.

FortiSASE acts as a root CA without needing a certificate, and SSL deep inspection is used only for split DNS and video filtering.

C.

FortiSASE requires an external CA to issue certificates to client machines, and SSL deep inspection supports only antivirus and file filter.

D.

FortiSASE acts as a certificate authority (CA) with a self-signed or internal CA certificate, requiring the root CA certificate to be imported into client machines.

Full Access
Question # 23

When deploying FortiSASE agent-based clients, which three features are available compared to an agentless solution? (Choose three.)

A.

Vulnerability scan

B.

SSL inspection

C.

Anti-ransomware protection

D.

Web filter

E.

ZTNA tags

Full Access
Question # 24

Refer to the exhibits.

WiMO-Pro and Win7-Pro are endpoints from the same remote location. WiMO-Pro can access the internet though FortiSASE, while Wm7-Pro can no longer access the internet

Given the exhibits, which reason explains the outage on Wm7-Pro?

A.

The Win7-Pro device posture has changed.

B.

Win7-Pro cannot reach the FortiSASE SSL VPN gateway

C.

The Win7-Pro FortiClient version does not match the FortiSASE endpoint requirement.

D.

Win-7 Pro has exceeded the total vulnerability detected threshold.

Full Access
Question # 25

Refer to the exhibits.

Question # 25

An endpoint is assigned an IP address of 192.168.13.101/24. Which action will be run on the endpoint? (Choose one answer)

A.

The endpoint will be able to bypass the on-net rule because it is connecting from a known subnet.

B.

The endpoint will be detected as off-net.

C.

The endpoint will be exempted from auto-connect to the FortiSASE tunnel.

D.

The endpoint will automatically connect to the FortiSASE tunnel.

Full Access
Question # 26

Refer to the exhibits.

Question # 26

Jumpbox and Windows-AD are endpoints from the same remote location. Jumpbox can access the internet through FortiSASE, while Windows-AD can no longer access the internet. Based on the information in the exhibits, which reason explains the outage on Windows-AD? (Choose one answer)

A.

The device security posture for Windows-AD has changed.

B.

The FortiClient version installed on Windows-AD does not match the expected version on FortiSASE.

C.

Windows-AD is excluded from FortiSASE management.

D.

The remote VPN user on Windows-AD no longer matches any VPN policy.

Full Access