An SPA service connection is having connectivity issues. Which configuration setting should the administrator verify and correct first?
ARemote Gateway
BBGP Peer IP
CNetwork overlay ID
DAuthentication Method
What is the role of security posture tagging in ZTNA?
ATo assign usernames to different devices for security logs
BTo categorize devices and users based on their role in the organization
CTo provide granular access control based on the compliance status of devices and users
DTo ensure that all devices and users are monitored continuously
Refer to the exhibit.
A customer must implement device-posture checks for remote endpoints when they access the protected server. They also require TCP traffic between the remote endpoints and protected servers to be processed by FortiGate.
In this scenario, which two configurations meet these requirements?
Choose two
AConfigure ZTNA tags on FortiGate.
BConfigure FortiGate as a zero trust network accesss (ZTNA) access proxy.
CConfigure ZTNA servers and ZTNA policies on FortiGate.
DConfigure private access policies on FortiSASE with ZTNA.
Which authentication method supersedes any other user authentication that was previously configured on FortiSASE?
ALocal
BSSO
CRADIUS
DMFA
QuestionQ6
Troubleshooting
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
SPA
QuestionQ8
Advanced Deployment Features
QuestionQ9
Endpoint Management
QuestionQ10
Advanced Deployment Features
QuestionQ11
Advanced Deployment Features
QuestionQ12
Advanced Deployment Features
QuestionQ13
Troubleshooting
QuestionQ15
Central Management, Central Analytics, and Security Operations
QuestionQ16
Central Management, Central Analytics, and Security Operations
QuestionQ17
Endpoint Management
QuestionQ19
Central Management, Central Analytics, and Security Operations
QuestionQ20
Endpoint Management
QuestionQ21
Advanced Deployment Features
QuestionQ22
Central Management, Central Analytics, and Security Operations
QuestionQ23
Endpoint Management
QuestionQ24
SPA
QuestionQ25
Advanced Deployment Features
QuestionQ26
Central Management, Central Analytics, and Security Operations
QuestionQ27
Endpoint Management
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
A FortiSASE administrator is receiving reports that some users have traveled overseas and cannot establish their agent-based VPN tunnels, although they can authenticate with their SSO credentials to access 0365 and SFDC directly. The administrator reviewed the firewall policies and ZTNA tags for some users but found nothing unusual.
Which action can the administrator take to resolve this problem?
ACreate a dedicated firewall policy for the users.
BInstruct the users to restart their laptops and log in again.
CInstruct the users to install the updated version of the agent-based client.
DEnsure that the countries the users are visiting are not listed under the Deny list in the Geofencing settings.
You have configured a FortiSASE Secure Private Access (SPA) deployment.
Which statements about traffic flows are true?
Choose two
AWhen using SD-WAN private access, traffic goes from an endpoint directly to an SPA hub.
BWhen using zero trust network access, traffic goes from an endpoint to a FortiSASE POP, and then to a ZTNA access proxy.
CWhen using zero trust network access (ZTNA) traffic goes from an endpoint directly to a ZTNA access proxy.
DWhen using SD-WAN private access, traffic goes from an endpoint to a FortiSASE POP, and then to an SPA hub.
Which two statements about on-ramp tunnels in FortiSASE are correct?
Choose two
AOnly FortiExtender and FortiAP devices are supported for on-ramp tunnels.
BA branch device can connect to two or more on-ramp locations.
CSSL deep inspection for site-based users is fully functional without installing the FortiSASE certificate authority certificate.
DThe branch on-ramp and secure private access (SPA) features share the same BGP configuration.
A school has implemented an agent-based FortiSASE solution to block students’ internet access during class time while allowing internet access only for the lunch break.
What is the recommended way to enforce this policy?
ACreate a scheduled firewall policy with an appropriate security profile that is active only during the lunch break.
BEnable a PAC file on the existing FortiClient agent.
CAllowing the students to manually disconnect their VPN tunnel.
DConfigure the off-net/on-net network setting.
Which two advantages result from deploying FortiSASE with a FortiGate ZTNA access proxy?
Choose two
AIt supports both agentless ZTNA and agent-based ZTNA.
BIt offers data center redundancy.
CThe on-premises FortiGate performs a device posture check.
DIt is ideal for latency-sensitive applications.
An existing Fortinet SD-WAN customer is reviewing the FortiSASE ordering guide to determine which add-on is required so that future FortiSASE remote users can access private resources.
Which add-on should the customer consider to enable private access?
AFortiSASE SPA add-on
BFortiSASE Global add-on
CFortiSASE Dedicated Public IP Address add-on
DFortiSASE Branch On-Ramp add-on
Which two statements about FortiSASE Geofencing with regional compliance are correct?
Choose two
AYou can configure regional compliance on the security POP or the on-premises device, not both.
BIf no regional compliance rule is configured, the connection is made to the closest security POP.
CA regional compliance rule can connect only to an on-premises device or only to a security POP.
DThe connection order for a regional compliance rule is always the security POP first, followed by the on-premises device.
One user has reported connectivity issues; no other users have reported problems.
Which tool can the administrator use to identify the issue?
ADigital experience monitoring (DEM) to the performance metrics of the remote computer.
BForensics service to obtain detailed information about the user’s remote computer performance.
CMobile device management (MDM) service to troubleshoot the connectivity issue.
DSOC-as-a-Service (SOCaaS) to get information about the user’s remote computer.
How does FortiSASE respond to market trends in multicloud and Software-as-a-Service (SaaS) adoption, hybrid workforces, and zero trust?
AIt focuses solely on securing on-premises networks, ignoring cloud and remote work challenges.
BIt prioritizes legacy VPN connections for hybrid workforces, bypassing modern cloud and zero-rust security measures.
CIt provides visibility and control for multicloud and SaaS environments, ensures secure and seamless access for hybrid workforces, and implements zero-trust principles.
DIt supports only zero-trust frameworks without addressing multicloud or hybrid workforce needs.
Which two primary features and benefits does Fortinet SOCaaS provide when integrated with FortiSASE?
Choose two
AFortinet SOCaaS is a standalone service that monitors only FortiGate environments, provides automated patching without human analysis, and does not integrate with FortiSASE.
BFortinet SOCaaS monitors only remote users, does not support log forwarding, and provides threat notifications without response guidance or expert meetings.
CFortinet SOCaaS allows for consistent security monitoring through log forwarding, offers rapid threat notifications and response guidance, and includes intuitive dashboards.
DFortinet SOCaaS offers monitoring only during standard business hours, uses AI without human analysis, and provides annual reports without dashboards or FortiSASE integration.
EFortinet SOCaaS provides 24x7x365 cloud-based monitoring by Fortinet experts using AI, machine learning, and human analysis.
Refer to the exhibit.
Based on the displayed configuration, in which two ways will FortiSASE process sessions requiring FortiSandbox inspection?
Choose two
AAll files will be sent to an on-premises FortiSandbox for inspection.
BFortiClient quarantines only infected files that FortiSandbox detects as medium level.
CAll files executed on a USB drive will be sent to FortSandbox for analysis.
DOnly endpoints assigned a profile for sandbox detection will be processed by the sandbox feature.
When configuring a DLP rule in FortiSASE in Regex format, arrange the correct configuration steps in order.
Drag & Drop
DLP Rule
DLP Dictionary
DLP Data Pattern
DLP Sensor
DLP Profile
Refer to the exhibit.
What type of information or actions can a FortiSASE administrator access from the following output?
AAdministrators can view and configure endpoint profiles and ZTNA tags.
BAdministrators can view and configure automatic patching of endpoints, and first detected date for applications.
CAdministrators can view latest application version available and push updates to managed endpoints.
DAdministrators can view application details, such as vendor, version, and installation dates to identify unwanted or outdated software.
A FortiSASE customer has a small branch office where ten users will use personal laptops and mobile devices to access the internet.
Which deployment should be used to secure their internet access with minimal configuration?
AFortiClient endpoint agent to secure internet access
BFortiAP to secure internet access
CSD-WAN on-ramp to secure internet access
DFortiGate as a LAN extension to secure internet access
A Fortinet customer is evaluating an integration of FortiManager with FortiSASE.
What two prerequisites should they consider?
Choose two
AAdding a FortiManager connection add-on license to FortiSASE.
BPlacing ForfiManager in the same FortiCloud account as FortiSASE.
CReducing the number of FortiSASE PoPs that support FortiManager.
DRunning a FortiManager version that is supported by FortiSASE.
A FortiSASE customer enforces always-on VPN for remote users running FortiClient.
Which option can be enabled in the customer’s Endpoint Profile to allow access to different resources located on the same L2 network?
AAllow local LAN Access into user Endpoint Profile before they get connected to the VPN
BEndpoint Sandbox protection for VPN users
CEndpoint Anti-Virus protection in the Endpoint Profile for VPN
DNetwork Lockdown for endpoints with VPN enabled
Which three traffic flows does FortiSASE Secure Private Access (SPA) support?
Choose three
AFrom private resources to FortiSASE agent-based users.
BFrom private resources to the internet.
CFrom agent-based users to private resources behind the Fortinet SD-WAN.
DFrom private resources to other private resources (SPA to SPA).
EFrom thin branches/branch on-ramp to private resources behind the Fortinet SD-WAN.
Which two advantages result from integrating SoCaaS with FortiSASE?
Choose two
AProvides bandwidth usage analytics
BEliminates the need of endpoint projection software
CCentralized visibility of all threat events
DContinuous threat monitoring of all connected endpoints
Which statement most accurately describes the Digital Experience Monitor (DEM) feature in FortiSASE?
AIt monitors the FortiSASE POP health based on ping probes.
BIt is used for performing device compliance checks on endpoints.
CIt provides end-to-end network visibility from all the FortiSASE security PoPs to a specific SaaS application.
DIt gathers all the vulnerability information from all the FortiClient endpoints.
Refer to the exhibit.
A customer’s configured endpoint profile is displayed.
A workstation user reports that, after installing and connecting the FortiSASE client, they can no longer access printers on their local home network. The customer’s On-net rule set is mapped to the office public IP address.
What must the customer enable so the user can use the local network printer at home?
AThe customer should disable Lockdown endpoint when off-net.
BThe customer should enable Allow local LAN access when endpoint is off-net.
CThe customer must create a new firewall policy to give the user access to the local subnet.
DThe customer should increase the Grace period to allow the user to print immediately after booting the computer.
Community Discussion