Spring Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > Fortinet Network Security Expert > NSE5_SSE_AD-7.6

NSE5_SSE_AD-7.6 Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Question and Answers

Question # 4

A FortiGate device is in production. To optimize WAN link use and improve redundancy, you enable and configure SD-WAN.

What must you do as part of this configuration update process? (Choose one answer)

A.

Replace references to interfaces used as SD-WAN members in the firewall policies.

B.

Replace references to interfaces used as SD-WAN members in the routing configuration.

C.

Disable the interface that you want to use as an SD-WAN member.

D.

Purchase and install the SD-WAN license, and reboot the FortiGate device.

Full Access
Question # 5

How is the Geofencing feature used in FortiSASE? (Choose one answer)

A.

To allow or block remote user connections to FortiSASE POPs from specific countries.

B.

To restrict access to applications based on the time of day in specific countries.

C.

To encrypt data at rest on mobile devices in specific countries.

D.

To monitor user behavior on websites and block non-work-related content from specific countries

Full Access
Question # 6

The IT team is wondering whether they will need to continue using MDM tools for future FortiClient upgrades.

What options are available for handling future FortiClient upgrades?

A.

Enable the Endpoint Upgrade feature on the FortiSASE portal.

B.

FortiClient will need to be manually upgraded.

C.

Perform onboarding for managed endpoint users with a newer FortiClient version.

D.

A newer FortiClient version will be auto-upgraded on demand.

Full Access
Question # 7

An existing Fortinet SD-WAN customer who has recently deployed FortiSASE wants to have a comprehensive view of, and combined reports for, both SD-WAN branches and remote users. How can the customer achieve this?

A.

Forward the logs from FortiSASE to Fortinet SOCaaS.

B.

Forward the logs from FortiGate to FortiSASE.

C.

Forward the logs from FortiSASE to the external FortiAnalyzer.

D.

Forward the logs from the external SD-WAN FortiAnalyzer to FortiSASE.

Full Access
Question # 8

Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two answers)

A.

Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.

B.

Traffic does not match any of the entries in the policy route table.

C.

FortiGate flags the session with may_dirty and vwl_default.

D.

The traffic is distributed, regardless of weight, through all available static routes.

E.

The session information output displays no SD-WAN service id.

Full Access
Question # 9

What is the purpose of the on/off-net rule setting in FortiSASE?

A.

To enable or disable user authentication for external network access.

B.

To define different traffic routing rules for on-premises and cloud-based resources.

C.

To determine if an endpoint is connecting from a trusted network or untrusted location.

D.

To configure different access policies for users based on their geographical location.

Full Access
Question # 10

Which secure internet access (SIA) use case minimizes individual endpoint configuration? (Choose one answer)

A.

Agentless remote user internet access

B.

SIA for FortiClient agent remote users

C.

Site-based remote user internet access

D.

SIA using ZTNA

Full Access