Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE5_SSE_AD-7.6 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which three challenges in a work-from-anywhere environment does FortiSASE address? (Choose three.)

Options:

A.

Inconsistent security levels


B.

Lack of bandwidth


C.

Lack of visibility and control


D.

Poor performance


E.

Remote internet connectivity


Expert Solution
Questions # 2:

Refer to the exhibit.

Question # 2

You want the performance service-level agreement (SLA) to measure the jitter of each member. Which configuration change must you make to achieve this result?

Options:

A.

No change is required.


B.

Add an SLA target and define a jitter threshold.


C.

Specify the participant members.


D.

Set the protocol to HTTP.


Expert Solution
Questions # 3:

What is the primary function of FortiView on FortiSASE?

Options:

A.

Presents raw log data in graphical format only, without sorting criteria or aggregated views.


B.

Generates real-time alerts for security events and presents them in a single text-based console without metadata.


C.

Displays individual logs on the GUI without aggregation, allowing administrators to sort events by time only.


D.

Provides consolidated consoles to analyze security events over time using graphical or text-based log views.


Expert Solution
Questions # 4:

Which statement is true about scheduling a FortiClient upgrade using an endpoint upgrade rule?

Options:

A.

If the scheduled time is already past in the local time zone of the endpoint, installation starts the next day at that time.


B.

An endpoint upgrade rule can be assigned to a user group.


C.

When scheduled, the installation always starts immediately if the endpoint is online.


D.

Scheduled upgrades automatically reboot macOS endpoints after installation.


Expert Solution
Questions # 5:

Which three authentication sources support secure identity verification and access control for FortiSASE remote users? (Choose three.)

Options:

A.

Security Assertion Markup Language (SAML)


B.

OpenID Connect (OIDC)


C.

Lightweight Directory Access Protocol (LDAP)


D.

Terminal Access Controller Access-Control System Plus (TACACS+)


E.

Remote Authentication Dial-In User Service (RADIUS)


Expert Solution
Questions # 6:

Question # 6

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3.

Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)

Options:

A.

HUB1-VPN1 does not have a valid route to the destination.


B.

HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.


C.

HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.


D.

The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device.


Expert Solution
Questions # 7:

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Question # 7

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member? (Choose one answer)

Options:

A.

When all three members have the same packet loss


B.

When HUB1-VPN1 has 4% packet loss


C.

When HUB1-VPN1 has 12% packet loss


D.

When HUB1-VPN3 has 4% packet loss


Expert Solution
Questions # 8:

Refer to the exhibit.

Question # 8

Which two statements about the Vulnerability summary dashboard in FortiSASE are correct? (Choose two.)

Options:

A.

The dashboard shows the vulnerability score for unknown applications.


B.

Vulnerability scan is disabled in the endpoint profile.


C.

The dashboard allows the administrator to drill down and view CVE data and severity classifications.


D.

Automatic vulnerability patching can be enabled for supported applications.


Expert Solution
Questions # 9:

In which order does a FortiGate device consider the following elements shown in the left column during the route lookup process?

Select the element in the left column, hold and drag it to a blank position in the column on the right. Place the four correct elements in order, placing the first element in the first position at the top of the column. Once you place an element, you can move it again if you want to change your answer before moving to the next question. You need to drop four elements in the work area.

Select and drag the screen divider to change the viewable area of the source and work areas.

Question # 9


Expert Solution
Questions # 10:

Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two answers)

Options:

A.

Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.


B.

Traffic does not match any of the entries in the policy route table.


C.

FortiGate flags the session with may_dirty and vwl_default.


D.

The traffic is distributed, regardless of weight, through all available static routes.


E.

The session information output displays no SD-WAN service id.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions