Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE7_SSE_AD-25 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which two deployment methods are used to connect a FortiExtender as a FortiSASE LAN extension? (Choose two.)

Options:

A.

Connect FortiExtender to FortiSASE using FortiZTP


B.

Enable Control and Provisioning Wireless Access Points (CAPWAP) access on the FortiSASE portal.


C.

Enter the FortiSASE domain name in the FortiExtender GUI as a static discovery server


D.

Configure an IPsec tunnel on FortiSASE to connect to FortiExtender.


Expert Solution
Questions # 2:

Refer to the exhibit.

Question # 2

The daily report for application usage shows an unusually high number of unknown applications by category.

What are two possible explanations for this? (Choose two.)

Options:

A.

Certificate inspection is not being used to scan application traffic.


B.

The inline-CASB application control profile does not have application categories set to Monitor


C.

Zero trust network access (ZTNA) tags are not being used to tag the correct users.


D.

Deep inspection is not being used to scan traffic.


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

An SPA service connection is experiencing connectivity problems. Which configuration setting should the administrator verify and correct first? (Choose one answer)

Options:

A.

Remote Gateway


B.

BGP Peer IP


C.

Network overlay ID


D.

Authentication Method


Expert Solution
Questions # 4:

Refer to the exhibit.

Question # 4

An organization must inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE tunnel and redirect it to the endpoint physical interface.

Which configuration must you apply to achieve this requirement? (Choose one answer)

Options:

A.

Add the Google Maps URL in the zero trust network access (ZTNA) TCP access proxy forwarding rule.


B.

Configure a steering bypass tunnel firewall policy using Google Maps FQDN to exclude and redirect the traffic.


C.

Exempt Google Maps in URL filtering in the web filter profile.


D.

Add the Google Maps URL as a steering bypass destination in the endpoint profile.


Expert Solution
Questions # 5:

Which policy type is used to control traffic between the FortiClient endpoint to FortiSASE for secure internet access?

Options:

A.

VPN policy


B.

thin edge policy


C.

private access policy


D.

secure web gateway (SWG) policy


Expert Solution
Questions # 6:

How does FortiSASE Secure Private Access (SPA) facilitate connectivity to private resources in a hub-and-spoke network? (Choose one answer)

Options:

A.

SPA applies source network address translation (SNAT) for remote user traffic and uses IKEv1 for IPsec tunnels to connect to standalone hubs without BGP support.


B.

SPA connects to private resources using HTTP and HTTPS protocols and relies on FortiClient for agentless access to SD-WAN deployments.


C.

SPA establishes direct links to spokes without IPsec or BGP and uses an easy configuration key to secure web traffic for remote users.


D.

SPA connects a FortiSASE POP to a FortiGate hub or SD-WAN deployment using IPsec and BGP for dynamic route exchange, with an easy configuration key for simplified setup on FortiOS.


Expert Solution
Questions # 7:

What is the purpose of the grace period for off-net endpoints in the FortiSASE Network Lockdown feature? (Choose one answer)

Options:

A.

To allow users to attempt VPN reconnection before restrictions are applied1


B.

To bypass security policies for specific applications


C.

To permanently block network access for non-compliant endpoints


D.

To automatically reset the FortiClient configuration


Expert Solution
Questions # 8:

A Fortinet customer is considering integrating FortiManager with FortiSASE. What are two prerequisites they should consider? (Choose two answers)

Options:

A.

Adding a FortiManager connection add-on license to FortiSASE.


B.

Placing FortiManager in the same FortiCloud account as FortiSASE.


C.

Reducing the number of FortiSASE PoPs that support FortiManager.


D.

Running a FortiManager version that is supported by FortiSASE.


Expert Solution
Questions # 9:

Which two additional components does FortiSASE use for application control to act as an inline-CASB? (Choose two.)

Options:

A.

intrusion prevention system (IPS)


B.

SSL deep inspection


C.

DNS filter


D.

Web filter with inline-CASB


Expert Solution
Questions # 10:

Refer to the exhibit.

Question # 10

A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redirect it to the endpoint physical Interface.

Which configuration must you apply to achieve this requirement?

Options:

A.

Exempt the Google Maps FQDN from the endpoint system proxy settings.


B.

Configure a static route with the Google Maps FQDN on the endpoint to redirect traffic


C.

Configure the Google Maps FQDN as a split tunneling destination on the FortiSASE endpoint profile.


D.

Change the default DNS server configuration on FortiSASE to use the endpoint system DNS.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions