Pre-Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Fortinet NSE5_SSE_AD-7.6 Dumps

Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Questions and Answers

Question 1

You have configured the performance SLA with the probe mode as Prefer Passive.

What are two observable impacts of this configuration? (Choose two.)

Options:

A.

FortiGate can offload the traffic that is subject to passive monitoring to hardware.

B.

FortiGate passively monitors the member if ICMP traffic is passing through the member.

C.

During passive monitoring, the SLA performance rule cannot detect dead members.

D.

After FortiGate switches to active mode, the SLA performance rule falls back to passive monitoring after 3 minutes.

E.

FortiGate passively monitors the member if TCP traffic is passing through the member.

Question 2

The IT team is wondering whether they will need to continue using MDM tools for future FortiClient upgrades.

What options are available for handling future FortiClient upgrades?

Options:

A.

Enable the Endpoint Upgrade feature on the FortiSASE portal.

B.

FortiClient will need to be manually upgraded.

C.

Perform onboarding for managed endpoint users with a newer FortiClient version.

D.

A newer FortiClient version will be auto-upgraded on demand.

Question 3

Which three FortiSASE use cases are possible? (Choose three answers)

Options:

A.

Secure Internet Access (SIA)

B.

Secure SaaS Access (SSA)

C.

Secure Private Access (SPA)

D.

Secure VPN Access (SVA)

E.

Secure Browser Access (SBA)

Question 4

Which two statements about configuring a steering bypass destination in FortiSASE are correct? (Choose two.)

Options:

A.

Subnet is the only destination type that supports the Apply condition

B.

Apply condition allows split tunneling destinations to ae applied to On-net. off-net. or both types of endpoints

C.

You can select from four destination types: Infrastructure, FQDN, Local Application, or Subnet

D.

Apply condition can be set only to On-net or Off-net. but not both

Question 5

Which three factors about SLA targets and SD-WAN rules should you consider when configuring SD-WAN rules? (Choose three answers)

Options:

A.

When configuring an SD-WAN rule, you can select multiple SLA targets from different performance SLAs.

B.

SLA targets are used only by SD-WAN rules that are configured with a Lowest Cost (SLA) strategy.

C.

Member metrics are measured only if a rule uses the SLA target.

D.

SD-WAN rules can use SLA targets to check whether the preferred members meet the SLA requirements.

E.

When configuring an SD-WAN rule, you can select multiple SLA targets if they are from the same performance SLA.

Question 6

Refer to the exhibits.

as

The administrator increases the member priority on port2 to 20. Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)

Options:

A.

FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.

B.

FortiGate flags the SNAT session as dirty only if the administrator has assigned an IP pool to the firewall policies with NAT.

C.

FortiGate routes only new sessions over port1.

D.

FortiGate continues routing all existing sessions over port2.

E.

FortiGate flags the sessions as dirty.

Question 7

In which order does a FortiGate device consider the following elements shown in the left column during the route lookup process?

Select the element in the left column, hold and drag it to a blank position in the column on the right. Place the four correct elements in order, placing the first element in the first position at the top of the column. Once you place an element, you can move it again if you want to change your answer before moving to the next question. You need to drop four elements in the work area.

Select and drag the screen divider to change the viewable area of the source and work areas.

as

Options:

Question 8

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

as

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member? (Choose one answer)

Options:

A.

When all three members have the same packet loss

B.

When HUB1-VPN1 has 4% packet loss

C.

When HUB1-VPN1 has 12% packet loss

D.

When HUB1-VPN3 has 4% packet loss

Question 9

What is a key use case for FortiSASE Secure Internet Access (SIA) in an agentless deployment? (Choose one answer)

Options:

A.

It provides secure web browsing by isolating browser sessions and enforcing data loss prevention for temporary employees.

B.

It acts as a secure web gateway (SWG) distributing a PAC file for explicit web proxy use, securing HTTP and HTTPS traffic with a full security stack, and is ideal for unmanaged endpoints like contractors.

C.

It distributes a PAC file to secure non-web traffic protocols and applies antivirus protection only for managed endpoints.

D.

It requires FortiClient endpoints and supports ZTNA tags to secure all network traffic for unmanaged endpoints.

Question 10

You have a FortiGate configuration with three user-defined SD-WAN zones and one or two members in each of these zones. One SD-WAN member is no longer used in health-check and SD-WAN rules. This member is the only member of its zone. You want to delete it.

What happens if you delete the SD-WAN member from the FortiGate GUI?

Options:

A.

FortiGate displays an error message. SD-WAN zones must contain at least one member.

B.

FortiGate accepts the deletion and removes static routes as required.

C.

FortiGate accepts the deletion with no further action.

D.

FortiGate accepts the deletion and places the member in the default SD-WAN zone.

Page: 1 / 4
Total 36 questions