Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet NSE5_SSE_AD-7.6 Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Exam Practice Test

Demo: 10 questions
Total 36 questions

Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Questions and Answers

Question 1

How is the Geofencing feature used in FortiSASE? (Choose one answer)

Options:

A.

To allow or block remote user connections to FortiSASE POPs from specific countries.

B.

To restrict access to applications based on the time of day in specific countries.

C.

To encrypt data at rest on mobile devices in specific countries.

D.

To monitor user behavior on websites and block non-work-related content from specific countries

Question 2

Which three authentication sources support secure identity verification and access control for FortiSASE remote users? (Choose three.)

Options:

A.

Security Assertion Markup Language (SAML)

B.

OpenID Conned (OIDC)

C.

Lightweight Directory Access Protocol (LDAP)

D.

Terminal Access Controller Access-Control System Plus (TACACS+)

E.

Remote Authentication Dial-in User Service (RADIUS)

Question 3

You have configured the performance SLA with the probe mode as Prefer Passive.

What are two observable impacts of this configuration? (Choose two.)

Options:

A.

FortiGate can offload the traffic that is subject to passive monitoring to hardware.

B.

FortiGate passively monitors the member if ICMP traffic is passing through the member.

C.

During passive monitoring, the SLA performance rule cannot detect dead members.

D.

After FortiGate switches to active mode, the SLA performance rule falls back to passive monitoring after 3 minutes.

E.

FortiGate passively monitors the member if TCP traffic is passing through the member.

Question 4

An SD-WAN member is no longer used to steer SD-WAN traffic. You want to update the SD-WAN configuration and delete the unused member.

Which action should you take first? (Choose one answer)

Options:

A.

Move the SD-WAN member to the virtual-wan-link zone.

B.

Disable the interface.

C.

Remove the member from the performance service-level agreement (SLA) definitions.

D.

Delete static route definitions for that interface.

Question 5

You want FortiGate to use SD-WAN rules to steer ping local-out traffic. Which two constraints should you consider? (Choose two.)

Options:

A.

You must configure each local-out feature individually to use SD-WAN.

B.

By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to ping and traceroute.

C.

You can steer local-out traffic only with SD-WAN rules that use the manual strategy.

D.

By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to ping and traceroute.

Question 6

Which secure internet access (SIA) use case minimizes individual endpoint configuration? (Choose one answer)

Options:

A.

Agentless remote user internet access

B.

SIA for FortiClient agent remote users

C.

Site-based remote user internet access

D.

SIA using ZTNA

Question 7

Refer to the exhibit.

Which two statements about the Vulnerability summary dashboard in FortiSASE are correct? (Choose two.)

Options:

A.

The dashboard shows the vulnerability score for unknown applications.

B.

Vulnerability scan is disabled in the endpoint profile.

C.

The dashboard allows the administrator to drill down and view CVE data and severity classifications.

D.

Automatic vulnerability patching can be enabled for supported applications.

Question 8

For a small site, an administrator plans to implement SD-WAN and ensure high network availability for business-critical applications while limiting the overall cost and the cost of pay-per-use backup connections.

Which action must the administrator take to accomplish this plan?

Options:

A.

Use a mid-range FortiGate device to implement standalone SD-WAN.

B.

Implement dynamic routing.

C.

Set up a high availability (HA) cluster to implement standalone SD-WAN.

D.

Configure at least two WAN links.

Question 9

The IT team is wondering whether they will need to continue using MDM tools for future FortiClient upgrades.

What options are available for handling future FortiClient upgrades?

Options:

A.

Enable the Endpoint Upgrade feature on the FortiSASE portal.

B.

FortiClient will need to be manually upgraded.

C.

Perform onboarding for managed endpoint users with a newer FortiClient version.

D.

A newer FortiClient version will be auto-upgraded on demand.

Question 10

Which two statements about configuring a steering bypass destination in FortiSASE are correct? (Choose two.)

Options:

A.

Subnet is the only destination type that supports the Apply condition

B.

Apply condition allows split tunneling destinations to ae applied to On-net. off-net. or both types of endpoints

C.

You can select from four destination types: Infrastructure, FQDN, Local Application, or Subnet

D.

Apply condition can be set only to On-net or Off-net. but not both

Demo: 10 questions
Total 36 questions