Weekend Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Fortinet NSE7_SSE_AD-25 Dumps

Fortinet NSE 7 - FortiSASE 25 Enterprise Administrator Questions and Answers

Question 1

Refer to the exhibits.

as

Jumpbox and Windows-AD are endpoints from the same remote location. Jumpbox can access the internet through FortiSASE, while Windows-AD can no longer access the internet. Based on the information in the exhibits, which reason explains the outage on Windows-AD? (Choose one answer)

Options:

A.

The device security posture for Windows-AD has changed.

B.

The FortiClient version installed on Windows-AD does not match the expected version on FortiSASE.

C.

Windows-AD is excluded from FortiSASE management.

D.

The remote VPN user on Windows-AD no longer matches any VPN policy.

Question 2

Refer to the exhibits.

as

A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from

Which configuration on FortiSASE is allowing users to perform the download? (Choose one answer)

Options:

A.

Deep inspection is not enabled.

B.

Application control is exempting all the browser traffic.

C.

Web filter is allowing the URL.

D.

Intrusion prevention is disabled.

Question 3

What happens to the logs on FortiSASE that are older than the configured log retention period? (Choose one answer)

Options:

A.

The logs are deleted from FortiSASE.1

B.

The logs are compressed and archived.

C.

The logs are backed up on FortiCloud.

D.

The logs are indexed and can be stored in a SQL database.

Question 4

When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.)

Options:

A.

Endpoint management

B.

Points of presence

C.

SD-WAN hub

D.

Logging

E.

Authentication

Question 5

How does FortiSASE hide user information when viewing and analyzing logs? (Choose one answer)

Options:

A.

By compressing log data

B.

By hashing log data

C.

By tokenization in log data

D.

By deleting log data

Question 6

A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between the remote endpoints and the protected servers to be processed by FortiGate.

as

In this scenario, which two setups will achieve these requirements? (Choose two answers)

Options:

A.

Configure ZTNA tags on FortiGate.

B.

Configure FortiGate as a zero trust network access (ZTNA) access proxy.

C.

Configure ZTNA servers and ZTNA policies on FortiGate.

D.

Configure private access policies on FortiSASE with ZTNA.

Question 7

What are two benefits of deploying secure private access (SPA) with SD-WAN? (Choose two answers)

Options:

A.

ZTNA posture check performed by the hub FortiGate

B.

Support of both TCP and UDP applications

C.

A direct access proxy tunnel from FortiClient to the on-premises FortiGate

D.

Inline security inspection by FortiSASE

Question 8

Refer to the exhibits.

as

as

A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish

Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?

Options:

A.

NAT needs to be enabled in the Spoke-to-Hub firewall policy.

B.

The BGP router ID needs to match on the hub and FortiSASE.

C.

FortiSASE spoke devices do not support mode config.

D.

The hub needs IKEv2 enabled in the IPsec phase 1 settings.

Question 9

Refer to the exhibit.

as

Which two prerequisites must be met to use the feature shown in the exhibit? (Choose two.)

Options:

A.

FordClient must be installed on the users device to access the private application.

B.

The proxy and proxy user single sign-on (SSO) features must be configured in FortiSASE

C.

The secure private access (SPA) feature must be configured in FortiSASE.

D.

The relevant FortiGate ZTNA application gateway must be configured.

Question 10

Refer to the exhibit.

as

Which two statements about the onboarding process shown in the exhibit are true? (Choose two answers)

Options:

A.

The user must manually select which FortiSASE components to install during the FortiClient setup.

B.

Depending on the installer used, the invitation code step may be skipped.

C.

The invitation code must always be entered manually after installing FortiClient.

D.

This is an email from the FortiSASE platform to an end user.

Question 11

What is the purpose of security posture tagging in ZTNA? (Choose one answer)

Options:

A.

To assign usernames to different devices for security logs

B.

To ensure that all devices and users are monitored continuously

C.

To provide granular access control based on the compliance status of devices and users1

D.

To categorize devices and users based on their role in the organization

Question 12

Which secure internet access (SIA) use case minimizes individual workstation or device setup, because you do not need to install FortiClient on endpoints or configure explicit web proxy settings on web browser-based end points?

Options:

A.

SIA for inline-CASB users

B.

SIA for agentless remote users

C.

SIA for SSLVPN remote users

D.

SIA for site-based remote users

Question 13

Which service is included in a secure access service edge (SASE) solution, but not in a security service edge (SSE) solution? (Choose one answer)

Options:

A.

SWG

B.

SD-WAN1

C.

CASB

D.

ZTNA

Question 14

A customer wants to upgrade their legacy on-premises proxy to a could-based proxy for a hybrid network. Which FortiSASE features would help the customer to achieve this outcome?

Options:

A.

SD-WAN and NGFW

B.

SD-WAN and inline-CASB

C.

zero trust network access (ZTNA) and next generation firewall (NGFW)

D.

secure web gateway (SWG) and inline-CASB

Question 15

Which two deployment methods are used to connect a FortiExtender as a FortiSASE LAN extension? (Choose two.)

Options:

A.

Connect FortiExtender to FortiSASE using FortiZTP

B.

Enable Control and Provisioning Wireless Access Points (CAPWAP) access on the FortiSASE portal.

C.

Enter the FortiSASE domain name in the FortiExtender GUI as a static discovery server

D.

Configure an IPsec tunnel on FortiSASE to connect to FortiExtender.

Question 16

What are two benefits of deploying FortiSASE with FortiGate ZTNA access proxy? (Choose two answers)

Options:

A.

The on-premises FortiGate performs a device posture check.

B.

It is ideal for latency-sensitive applications.

C.

It supports both agentless ZTNA and agent-based ZTNA.

D.

It offers data center redundancy.

Question 17

A customer configured the On/off-net detection rule to disable FortiSASE VPN auto-connect when users are inside the corporate network. The rule is set to Connects with a known public IP using the company’s public IP address. However, when the users are on the corporate network, the FortiSASE VPN still auto-connects. The customer has confirmed that traffic is going to the internet with the correct IP address.

as

Which configuration is causing the issue? (Choose one answer)

Options:

A.

The On-net rule set configuration is incorrect.

B.

Allow local LAN access when endpoint is on-net is disabled when it should be enabled.

C.

Exempt endpoint from FortiSASE auto-connect is disabled when it should be enabled.

D.

Is connected to a known DNS server should be enabled and configured.

Question 18

What is the purpose of the grace period for off-net endpoints in the FortiSASE Network Lockdown feature? (Choose one answer)

Options:

A.

To allow users to attempt VPN reconnection before restrictions are applied1

B.

To bypass security policies for specific applications

C.

To permanently block network access for non-compliant endpoints

D.

To automatically reset the FortiClient configuration

Question 19

Your FortiSASE customer has a small branch office in which ten users will be using their personal laptops and mobile devices to access the internet. Which deployment should they use to secure their internet access with minimal configuration? (Choose one answer)

Options:

A.

FortiClient endpoint agent to secure internet access

B.

FortiAP to secure internet access

C.

SD-WAN on-ramp to secure internet access

D.

FortiGate as a LAN extension to secure internet access

Question 20

For monitoring potentially unwanted applications on endpoints, which information is available on the FortiSASE software installations page? (Choose two answers)

Options:

A.

The endpoint the software is installed on1

B.

The license status of the software2

C.

The vendor of the software3

D.

The usage frequency of the software

Question 21

Refer to the exhibit.

as

A customer wants to fine-tune network assignments on FortiSASE, so they modified the IPAM configuration as shown in the exhibit. After this configuration, the customer started having connectivity problems and noticed that devices are using excluded ranges. What could be causing the unexpected behavior and connectivity problems? (Choose two answers)

Options:

A.

The pool must include at least one /20 per security POP for the IPAM to work correctly.

B.

The pool must include at least one /16 per Instance for the IPAM to work correctly.

C.

The pool must include at least one /20 per Instance for the IPAM to work correctly.

D.

The customer excluded too many networks from the pool.

Question 22

Refer to the exhibits.

as

as

When remote users connected to FortiSASE require access to internal resources on Branch-2. how will traffic be routed?

Options:

A.

FortiSASE will use the SD-WAN capability and determine that traffic will be directed to HUB-2. which will then route traffic to Branch-2.

B.

FortiSASE will use the AD VPN protocol and determine that traffic will be directed to Branch-2 directly, using a static route

C.

FortiSASE will use the SD-WAN capability and determine that traffic will be directed to HUB-1, which will then route traffic to Branch-2.

D.

FortiSASE will use the AD VPN protocol and determine that traffic will be directed to Branch-2 directly, using a dynamic route

Question 23

An organization must block user attempts to log in to non-company resources while using Microsoft Office 365 to prevent users from accessing unapproved cloud resources. Which FortiSASE feature can you implement to meet this requirement? (Choose one answer)

Options:

A.

Data loss prevention (DLP) with Microsoft Purview Information Protection (MPIP)

B.

DNS filter with domain filter

C.

Application control with inline-CASB

D.

Web filter with inline-CASB

Question 24

How does FortiSASE address the market trends of multicloud and Software-as-a-Service (SaaS) adoption, hybrid workforce, and zero trust? (Choose one answer)

Options:

A.

It focuses solely on securing on-premises networks, ignoring cloud and remote work challenges.

B.

It prioritizes legacy VPN connections for hybrid workforces, bypassing modern cloud and zero-trust security measures.

C.

It provides visibility and control for multicloud and SaaS environments, ensures secure and seamless access for hybrid workforces, and implements zero-trust principles.1

D.

It supports only zero-trust frameworks without addressing multicloud or hybrid workforce needs.

Question 25

What is the maximum number of Secure Private Access (SPA) service connections (SPA hubs) supported in the SPA use case? (Choose one answer)

Options:

A.

8

B.

12

C.

4

D.

16

Question 26

When deploying FortiSASE agent-based clients, which three features are available compared to an agentless solution? (Choose three.)

Options:

A.

Vulnerability scan

B.

SSL inspection

C.

Anti-ransomware protection

D.

Web filter

E.

ZTNA tags

Page: 1 / 9
Total 88 questions