QuestionQ8

Network Security

Refer to the exhibit.

Question Image

A customer must implement device-posture checks for remote endpoints accessing the protected server. They also require TCP traffic between the remote endpoints and the protected servers to be processed by FortiGate.

In this scenario, which two configurations will meet these requirements?

Choose two
  • A Configure ZTNA servers and ZTNA policies on FortiGate.
  • B Configure FortiGate as a zero trust network access (ZTNA) access proxy.
  • C Configure ZTNA tags on FortiGate.
  • D Configure private access policies on FortiSASE with ZTNA.
Explanation

For FortiSASE ZTNA access to TCP-based private applications, FortiGate operates as the ZTNA access proxy in front of the protected resources. The FortiGate access proxy uses the identity and posture-derived ZTNA tags supplied through FortiSASE to allow or deny sessions. ZTNA servers define the protected applications, and ZTNA policies enforce user-group and ZTNA-tag access control on FortiGate.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!