Month end Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet NSE5_SSE_AD-7.6 Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Exam Practice Test

Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

You have a FortiGate configuration with three user-defined SD-WAN zones and one or two members in each of these zones. One SD-WAN member is no longer used in health-check and SD-WAN rules. This member is the only member of its zone. You want to delete it.

What happens if you delete the SD-WAN member from the FortiGate GUI?

Options:

A.

FortiGate displays an error message. SD-WAN zones must contain at least one member.

B.

FortiGate accepts the deletion and removes static routes as required.

C.

FortiGate accepts the deletion with no further action.

D.

FortiGate accepts the deletion and places the member in the default SD-WAN zone.

Question 2

Which statement about security posture tags in FortiSASE is correct?

Options:

A.

Multiple tags can be assigned to an endpoint, but only one is used for evaluation.

B.

Multiple tags can be assigned to an endpoint and used for evaluation.

C.

Tags are static and do not change with endpoint status.

D.

Only one tag can be assigned to an endpoint.

Question 3

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3.

Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)

Options:

A.

HUB1-VPN1 does not have a valid route to the destination.

B.

HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.

C.

HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.

D.

The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device.

Question 4

Which two delivery methods are used for installing FortiClient on a user's laptop? (Choose two.)

Options:

A.

Use zero-touch installation through a third-party application store.

B.

Download the installer directly from the FortiSASE portal.

C.

Send an invitation email to selected users containing links to FortiClient installers.

D.

Configure automatic installation through an API to the user's laptop.

Question 5

An existing Fortinet SD-WAN customer who has recently deployed FortiSASE wants to have a comprehensive view of, and combined reports for, both SD-WAN branches and remote users. How can the customer achieve this?

Options:

A.

Forward the logs from FortiSASE to Fortinet SOCaaS.

B.

Forward the logs from FortiGate to FortiSASE.

C.

Forward the logs from FortiSASE to the external FortiAnalyzer.

D.

Forward the logs from the external SD-WAN FortiAnalyzer to FortiSASE.

Question 6

Refer to the exhibits.

The administrator increases the member priority on port2 to 20. Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)

Options:

A.

FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.

B.

FortiGate flags the SNAT session as dirty only if the administrator has assigned an IP pool to the firewall policies with NAT.

C.

FortiGate routes only new sessions over port1.

D.

FortiGate continues routing all existing sessions over port2.

E.

FortiGate flags the sessions as dirty.

Question 7

Refer to the exhibit.

You want the performance service-level agreement (SLA) to measure the jitter of each member. Which configuration change must you make to achieve this result?

Options:

A.

No change is required.

B.

Add an SLA target and define a jitter threshold.

C.

Specify the participant members.

D.

Set the protocol to HTTP.

Question 8

Which two statements about configuring a steering bypass destination in FortiSASE are correct? (Choose two.)

Options:

A.

Subnet is the only destination type that supports the Apply condition

B.

Apply condition allows split tunneling destinations to ae applied to On-net. off-net. or both types of endpoints

C.

You can select from four destination types: Infrastructure, FQDN, Local Application, or Subnet

D.

Apply condition can be set only to On-net or Off-net. but not both

Question 9

Which configuration is a valid use case for FortiSASE features in supporting remote users?

Options:

A.

Enabling secure SaaS access through SD-WAN integration, protecting against web-based threats with data loss prevention, and monitoring user connectivity with shadow IT visibility.

B.

Monitoring SaaS application performance, isolating browser sessions for all websites, and integrating with SD-WAN for data loss prevention.

C.

Enabling secure web browsing to protect against threats, providing explicit application access with zero-trust or SD-WAN integration, and addressing shadow IT visibility with data loss prevention.

D.

Providing secure web browsing through remote browser isolation, addressing shadow IT with zero-trust access, and protecting data at rest only.

Question 10

You have configured the performance SLA with the probe mode as Prefer Passive.

What are two observable impacts of this configuration? (Choose two.)

Options:

A.

FortiGate can offload the traffic that is subject to passive monitoring to hardware.

B.

FortiGate passively monitors the member if ICMP traffic is passing through the member.

C.

During passive monitoring, the SLA performance rule cannot detect dead members.

D.

After FortiGate switches to active mode, the SLA performance rule falls back to passive monitoring after 3 minutes.

E.

FortiGate passively monitors the member if TCP traffic is passing through the member.