Fortinet NSE7_SSE_AR-26 - Fortinet NSE 7 - FortiSASE 26 Architect Exam

Question #11 (Topic: Exam A)
What are three characteristics of the provisioning templates available on FortiManager? (Choose three.)
A. A CLI template can be of type CLI script or Perl script. B. Each template group can contain up to three IPsec tunnel templates. C. A template group can include a system template and an SD-WAN template. D. A CLI template group can contain CLI templates of different types. E. CLI templates are applied in order, from top to bottom.
Answer: CDE
Question #12 (Topic: Exam A)
An existing FortiSASE customer has a third-party router in a remote office and wants to secure internet access for users at that location.
Which add-on license is required to enable this setup?
A. FortiSASE global add-on B. FortiSASE branch on-ramp add-on C. FortiSASE Secure Private Access (SPA) add-on D. FortiSASE secure web gateway (SWG) add-on
Answer: B
Question #13 (Topic: Exam A)
In the context of SD-WAN, the terms underlay and overlay are commonly used to categorize links.
Which two statements about underlay and overlay links are correct? (Choose two.)
A. Wireless connections can be used to build overlay links. B. Only wired connections can be used as underlay links. C. A VLAN is a type of overlay link. D. FortiLink interface is considered a underlay link. E. Overlay links provide routing flexibility.
Answer: AE
Question #14 (Topic: Exam A)
When configuring FortiSASE BGP for SD-WAN private access with FortiSASE acting as the SD-WAN spoke, administrators must define specific settings.
What are some of the available configuration options?
A. FortiSASE supports BGP per overlay, but not BGP on loopback with IBGP or EBGP peering. B. FortiSASE supports dynamic BGP, BGP per overlay, or BGP on loopback with IBGP or EBGP peering. C. FortiSASE supports BGP per overlay or BGP on loopback with IBGP or EBGP peering. D. FortiSASE supports BGP per overlay or BGP on loopback with IBGP peering only.
Answer: C
Question #15 (Topic: Exam A)
Which component, typically categorized under network edge connectivity rather than cloud-delivered security controls, is incorporated as a foundational element within a secure access service edge (SASE) architecture but is not considered part of a security service edge (SSE) framework?
A. Zero trust network access (ZTNA) B. Software-Defined WAN (SD-WAN) C. Cloud access security broker (CASB) D. Secure web gateway (SWG)
Answer: B
Download Exam
Page: 3 / 7
Total 35 questions