Pass the Fortinet NSE 7 Network Security Architect NSE7_ZTA-7.2 Questions and answers with CertsForce

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which two statements are true regarding certificate-based authentication for ZTNA deployment? (Choose two.)

Options:

A.

FortiGate signs the client certificate submitted by FortiClient.


B.

The default action for empty certificates is block


C.

Certificate actions can be configured only on the FortiGate CLI


D.

Client certificate configuration is a mandatory component for ZTNA


Expert Solution
Questions # 2:

In which FortiNAC configuration stage do you define endpoint compliance?

Options:

A.

Device onboarding


B.

Management configuration


C.

Policy configuration


D.

Network modeling


Expert Solution
Questions # 3:

Exhibit.

Question # 3

Which statement is true about the configuration shown in the exhibit?

Options:

A.

The domain that FortiClient is connecting to should match the domain to which the certificate is issued.


B.

It the FortiClient EMS server certificate is invalid, FortiClient connects silently.


C.

The connection from FortiClient to FortiClient EMS uses TCP and TLS 1.2.


D.

default_ZTNARoot CA signs the FortiClient certificate for the SSL connectivity to FortiClient EMS


Expert Solution
Questions # 4:

Which two types of configuration can you associate with a user/host profile on FortiNAC? (Choose two.)

Options:

A.

Service Connectors


B.

Network Access


C.

Inventory


D.

Endpoint compliance


Expert Solution
Questions # 5:

Which three statements are true about a persistent agent? (Choose three.)

Options:

A.

Agent is downloaded and run from captive portal


B.

Supports advanced custom scans and software inventory.


C.

Can apply supplicant configuration to a host


D.

Deployed by a login/logout script and is not installed on the endpoint


E.

Can be used for automatic registration and authentication


Expert Solution
Questions # 6:

Exhibit.

Question # 6

Which statement is true about the FortiAnalyzer playbook configuration shown in the exhibit?

Options:

A.

The playbook is run on a configured schedule


B.

The playbook is run when an incident is created that matches the filters.


C.

The playbook is run when an event is created that matches the filters


D.

The playbook is manually started by an administrator


Expert Solution
Questions # 7:

An administrator is trying to create a separate web tittering profile for off-fabric and on-fabric clients and push it to managed FortiClient devices

Where can you enable this feature on FortiClient EMS?

Options:

A.

Endpoint policy


B.

ZTNA connection rules


C.

System settings


D.

On-fabric rule sets


Expert Solution
Questions # 8:

Exhibit.

Question # 8

Which two statements are true about the hr endpoint? (Choose two.)

Options:

A.

The endpoint application inventory could not be retrieved


B.

The endpoint is marked as a rogue device


C.

The endpoint has failed the compliance scan


D.

The endpoint will be moved to the remediation VLAN


Expert Solution
Questions # 9:

Which statement is true regarding a FortiClient quarantine using FortiAnalyzer playbooks?

Options:

A.

FortiGate sends a notification to FortiClient EMS to quarantine the endpoint


B.

FortiAnalyzer discovers malicious activity in the logs and notifies FortiGate


C.

FortiAnalyzer sends an API to FortiClient EMS to quarantine the endpoint


D.

FortiClient sends logs to FortiAnalyzer


Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions