Pre-Winter Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Fortinet NSE5_SSE_AD-7.6 Dumps

Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Questions and Answers

Question 1

A FortiGate device is in production. To optimize WAN link use and improve redundancy, you enable and configure SD-WAN.

What must you do as part of this configuration update process? (Choose one answer)

Options:

A.

Replace references to interfaces used as SD-WAN members in the firewall policies.

B.

Replace references to interfaces used as SD-WAN members in the routing configuration.

C.

Disable the interface that you want to use as an SD-WAN member.

D.

Purchase and install the SD-WAN license, and reboot the FortiGate device.

Question 2

What is the purpose of the priority/failover connection feature in FortiSASE Geofencing for managing VPN connections?

Options:

A.

It automatically balances VPN traffic across all available security POPs without prioritizing on-premises devices.

B.

It allows administrators to define rules to prioritize on-premises FortiGate connections for users in specific countries, with failover to a security POP if the FortiGate device is unavailable.

C.

It forces all remote users to connect only to the nearest security POP regardless of location.

D.

It restricts VPN access to users based on their geolocation without allowing failover options.

Question 3

Refer to the exhibit.

as

How does FortiGate handle the traffic with the source IP 10.0.1 130 and the destination IP 128 66.0 125?

Options:

A.

FortiGate steers the traffic flow through port2

B.

FortiGate drops the traffic flow

C.

FortiGate routes the traffic flow according to the FIB.

D.

FortiGate load balances the traffic flow through port1 and port2

Question 4

How does the FortiSASE security dashboard facilitate vulnerability management for FortiClient endpoints? (Choose one answer)

Options:

A.

It automatically patches all vulnerabilities without user intervention and does not categorize vulnerabilities by severity.

B.

It shows vulnerabilities only for applications and requires endpoint users to manually check for affected endpoints.

C.

It displays only critical vulnerabilities, requires manual patching for all endpoints, and does not allow viewing of affected endpoints.

D.

It provides a vulnerability summary, identifies affected endpoints, and supports automatic patching for eligible vulnerabilities.

Question 5

Refer to the exhibit.

as

The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.

The administrator wants to know through which interface FortiGate will steer traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the social media application Facebook.

Based on the exhibits, which two statements are correct? (Choose two.)

Options:

A.

FortiGate steers traffic for social media applications according to the service rule 2 and steers traffic through port2.

B.

There is no service defined for the Facebook application, so FortiGate applies service rule 3 and directs the traffic to headquarters.

C.

When FortiGate cannot recognize the application of the flow, it load balances the traffic through the tunnels HQ_T1, HQ_T2, HQ_T3.

D.

When FortiGate cannot recognize the application of the flow, it steers the traffic through the preferred member of rule 3, HQ_T1.

Question 6

SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.

Which three configuration elements must you configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)

Options:

A.

Firewall policies

B.

Security profiles

C.

Interfaces

D.

Routing

E.

Traffic shaping

Question 7

Which secure internet access (SIA) use case minimizes individual endpoint configuration? (Choose one answer)

Options:

A.

Agentless remote user internet access

B.

SIA for FortiClient agent remote users

C.

Site-based remote user internet access

D.

SIA using ZTNA

Question 8

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

as

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member? (Choose one answer)

Options:

A.

When all three members have the same packet loss

B.

When HUB1-VPN1 has 4% packet loss

C.

When HUB1-VPN1 has 12% packet loss

D.

When HUB1-VPN3 has 4% packet loss

Question 9

Which statement about security posture tags in FortiSASE is correct?

Options:

A.

Multiple tags can be assigned to an endpoint, but only one is used for evaluation.

B.

Multiple tags can be assigned to an endpoint and used for evaluation.

C.

Tags are static and do not change with endpoint status.

D.

Only one tag can be assigned to an endpoint.

Question 10

Refer to the exhibit.

as

The SD-WAN rule status and configuration is shown. Based on the exhibit, which change in the measured latency will first make HUB1-VPN3 the new preferred member?

Options:

A.

When HUB1-VPN3 has a latency of 80 ms

B.

When HUB1-VPN3 has a lower latency than HUB1-VPN1 and HUB1-VPN2

C.

When HUB1-VPN1 has a latency of 200 ms

D.

When HUB1-VPN3 has a latency of 90 ms

Question 11

Refer to the exhibit.

as

An SD-WAN zone configuration on the FortiGate GUI is shown.

What can you conclude about the zone and member configuration on this device?

Options:

A.

You can delete the overlay-factories zone.

B.

You can delete the virtual-wan-link zone.

C.

The overlay-factories zone contains no member.

D.

You can move HUB1-VPN3 from the HUB1 zone to the virtual-wan-link zone.

Question 12

Which statement is true about scheduling a FortiClient upgrade using an endpoint upgrade rule?

Options:

A.

If the scheduled time is already past in the local time zone of the endpoint, installation starts the next day at that time.

B.

An endpoint upgrade rule can be assigned to a user group.

C.

When scheduled, the installation always starts immediately if the endpoint is online.

D.

Scheduled upgrades automatically reboot macOS endpoints after installation.

Question 13

In which order does a FortiGate device consider the following elements shown in the left column during the route lookup process?

Select the element in the left column, hold and drag it to a blank position in the column on the right. Place the four correct elements in order, placing the first element in the first position at the top of the column. Once you place an element, you can move it again if you want to change your answer before moving to the next question. You need to drop four elements in the work area.

Select and drag the screen divider to change the viewable area of the source and work areas.

as

Options:

Question 14

An existing Fortinet SD-WAN customer who has recently deployed FortiSASE wants to have a comprehensive view of, and combined reports for, both SD-WAN branches and remote users. How can the customer achieve this?

Options:

A.

Forward the logs from FortiSASE to Fortinet SOCaaS.

B.

Forward the logs from FortiGate to FortiSASE.

C.

Forward the logs from FortiSASE to the external FortiAnalyzer.

D.

Forward the logs from the external SD-WAN FortiAnalyzer to FortiSASE.

Question 15

Refer to the exhibit.

as

Which two statements about the Vulnerability summary dashboard in FortiSASE are correct? (Choose two.)

Options:

A.

The dashboard shows the vulnerability score for unknown applications.

B.

Vulnerability scan is disabled in the endpoint profile.

C.

The dashboard allows the administrator to drill down and view CVE data and severity classifications.

D.

Automatic vulnerability patching can be enabled for supported applications.

Page: 1 / 5
Total 50 questions