nerdexam
Fortinet

FCSS_SASE_AD-23 · Question #60

Refer to the exhibits. Win10-Pro and Win7-Pro are endpoints from the same remote location. Win10-Pro can access the internet though FortiSASE, while Win7-Pro can no longer access the internet. Given…

The correct answer is A. The Win7-Pro device posture has changed. From the Managed Endpoints table, Win7-Pro has both FortiSASE-Non-Compliant and FortiSASE-Compliant ZTNA tags. The presence of the Non-Compliant tag suggests the device no longer meets compliance posture checks (e.g., outdated AV, many vulnerabilities). In the Secure Internet…

FortiClient for SASE

Question

Refer to the exhibits. Win10-Pro and Win7-Pro are endpoints from the same remote location. Win10-Pro can access the internet though FortiSASE, while Win7-Pro can no longer access the internet. Given the exhibits, which reason explains the outage on Win7-Pro?

Exhibits

FCSS_SASE_AD-23 question #60 exhibit 1
FCSS_SASE_AD-23 question #60 exhibit 2

Options

  • AThe Win7-Pro device posture has changed.
  • BWin7-Pro is disconnected from FortiClient telemetry.
  • CThe Win7-Pro FortiClient version does not match the FortiSASE endpoint requirement.
  • DWin-7 Pro has exceeded the total vulnerability detected threshold.

How the community answered

(23 responses)
  • A
    74% (17)
  • B
    9% (2)
  • C
    13% (3)
  • D
    4% (1)

Explanation

From the Managed Endpoints table, Win7-Pro has both FortiSASE-Non-Compliant and FortiSASE-Compliant ZTNA tags. The presence of the Non-Compliant tag suggests the device no longer meets compliance posture checks (e.g., outdated AV, many vulnerabilities). In the Secure Internet Access Policy, there is a rule for FortiSASE-Non-Compliant devices to deny internet access. Therefore, Win7-Pro is being blocked by the "Non-Compliant" policy rule.

Topics

#device posture#endpoint compliance#FortiClient#troubleshooting

Community Discussion

No community discussion yet for this question.

Full FCSS_SASE_AD-23 Practice