nerdexam
Fortinet

FCSS_SASE_AD-23 · Question #49

Refer to the exhibit. Users are unable to access https://login.live.com. To allow access, which web filter configuration must you change on FortiSASE?

The correct answer is D. inline-CASB headers. The log entry shows that the event type is http_header_change, and it references the authentication server FORTISASE_SAML_SERVER, along with the added header: sec-Restrict-Tenant-Access-Policy: restrict-msa This indicates that FortiSASE's inline-CASB is modifying HTTP headers…

Access Policies

Question

Refer to the exhibit. Users are unable to access https://login.live.com. To allow access, which web filter configuration must you change on FortiSASE?

Exhibit

FCSS_SASE_AD-23 question #49 exhibit

Options

  • AFortiGuard category-based filter
  • Bcontent filter
  • CURL filter
  • Dinline-CASB headers

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    9% (4)
  • C
    6% (3)
  • D
    83% (39)

Explanation

The log entry shows that the event type is http_header_change, and it references the authentication server FORTISASE_SAML_SERVER, along with the added header: sec-Restrict-Tenant-Access-Policy: restrict-msa This indicates that FortiSASE's inline-CASB is modifying HTTP headers to restrict access based on a CASB policy, which is likely blocking access to Microsoft login services.

Topics

#web filter#inline-CASB#HTTP headers#tenant restriction

Community Discussion

No community discussion yet for this question.

Full FCSS_SASE_AD-23 Practice