Fortinet NSE7_SSE_AD-25 - Fortinet NSE 7 - FortiSASE 25 Enterprise Administrator Exam
Page: 3 / 13
Total 64 questions
Question #11 (Topic: Exam A)
Refer to the exhibit.

A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between the remote endpoints and the protected servers to be processed by FortiGate.
In this scenario, which two setups will achieve these requirements? (Choose two.)

A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between the remote endpoints and the protected servers to be processed by FortiGate.
In this scenario, which two setups will achieve these requirements? (Choose two.)
A. Configure ZTNA tags on FortiGate.
B. Configure FortiGate as a zero trust network accesss (ZTNA) access proxy.
C. Configure ZTNA servers and ZTNA policies on FortiGate.
D. Configure private access policies on FortiSASE with ZTNA.
Answer: BC
Question #12 (Topic: Exam A)
A AFortiSASE customer has been enforcing always-on VPN for their remote-users running FortiClient.
What option can be enabled under the customer’s Endpoint Profile o allow them access different resources located in the same L2 network?
What option can be enabled under the customer’s Endpoint Profile o allow them access different resources located in the same L2 network?
A. Allow local LAN Access into user Endpoint Profile before they get connected to the VPN
B. Endpoint Sandbox protection for VPN users
C. Endpoint Anti-Virus protection in the Endpoint Profile for VPN
D. Network Lockdown for endpoints with VPN enabled
Answer: A
Question #13 (Topic: Exam A)
Which three traffic flows are supported by FortiSASE Secure Private Access (SPA)? (Choose three.)
A. From private resources to FortiSASE agent-based users.
B. From private resources to the internet.
C. From agent-based users to private resources behind the Fortinet SD-WAN.
D. From private resources to other private resources (SPA to SPA).
E. From thin branches/branch on-ramp to private resources behind the Fortinet SD-WAN.
Answer: ACD
Question #14 (Topic: Exam A)
What are two benefits of deploying secure private access with SD-WAN? (Choose two.)
A. ZTNA posture check performed by the hub FortiGate
B. Support of both TCP and UDP applications
C. A direct access proxy tunnel from FortiClient to the on-premises FortiGate
D. Inline security inspection by FortiSASE
Answer: AB
Question #15 (Topic: Exam A)
How does FortiSASE address the market trends of multicloud and Software-as-a-Service (SaaS) adoption, hybrid workforce, and zero trust?
A. It focuses solely on securing on-premises networks, ignoring cloud and remote work challenges.
B. It prioritizes legacy VPN connections for hybrid workforces, bypassing modern cloud and zero-rust security measures.
C. It provides visibility and control for multicloud and SaaS environments, ensures secure and seamless access for hybrid workforces, and implements zero-trust principles.
D. It supports only zero-trust frameworks without addressing multicloud or hybrid workforce needs.
Answer: C