A and D are correct. Fortinet ' s FortiSASE material identifies two fundamental prerequisites for agentless ZTNA/private application access: an SSO configuration for proxy users and an existing Secure Private Access (SPA) configuration. The Administrator Study Guide states explicitly that agentless support for private applications requires both an SPA configuration and a Secure Web Gateway SSO configuration.
Proxy user SSO (A) provides the identity-verification component. When an agentless user accesses the FortiSASE bookmark portal through a browser, the user must authenticate using SSO. The Enterprise Administrator workflow confirms that authentication occurs through FortiSASE proxy SSO user authentication before authorized application bookmarks are displayed.
SPA (D) provides connectivity from FortiSASE to the protected private applications. After authentication and policy evaluation, the application session is routed through FortiSASE SPA, which functions as the gateway for agentless ZTNA access.
B is incorrect because a FortiGate ZTNA access proxy is not itself a mandatory prerequisite for agentless ZTNA; SPA can be implemented through the supported private-access architecture. C is incorrect by definition: agentless ZTNA is designed for endpoints, including BYOD devices, that do not require FortiClient.
Study Guide Reference: SPA > Agentless ZTNA; Secure Private Access > Private Access for Agentless Users.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit