FCSS_SASE_AD-24 · Question #48
A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between the remote endpoints and the protected…
The correct answer is A. Configure ZTNA tags on FortiGate. B. Configure FortiGate as a zero trust network access (ZTNA) access proxy. C. Configure ZTNA servers and ZTNA policies on FortiGate. To meet the requirements of implementing device posture checks for remote endpoints and ensuring that TCP traffic between the endpoints and protected servers is processed by FortiGate, the following three setups are necessary: Configure ZTNA tags on FortiGate (Option A): ZTNA…
Question
A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between the remote endpoints and the protected servers to be processed by FortiGate. In this scenario, which three setups will achieve the above requirements? (Choose three.)
Options
- AConfigure ZTNA tags on FortiGate.
- BConfigure FortiGate as a zero trust network access (ZTNA) access proxy.
- CConfigure ZTNA servers and ZTNA policies on FortiGate.
- DConfigure private access policies on FortiSASE with ZTNA.
- ESync ZTNA tags from FortiSASE to FortiGate.
How the community answered
(32 responses)- A75% (24)
- D16% (5)
- E9% (3)
Explanation
To meet the requirements of implementing device posture checks for remote endpoints and ensuring that TCP traffic between the endpoints and protected servers is processed by FortiGate, the following three setups are necessary: Configure ZTNA tags on FortiGate (Option A): ZTNA (Zero Trust Network Access) tags are used to define access control policies based on the security posture of devices. By configuring ZTNA tags on FortiGate, administrators can enforce granular access controls, ensuring that only compliant devices can access protected resources. Configure FortiGate as a zero trust network access (ZTNA) access proxy (Option B): FortiGate can act as a ZTNA access proxy, which allows it to mediate and secure connections between remote endpoints and protected servers. This setup ensures that all TCP traffic passes through FortiGate, enabling inspection and enforcement of security policies. Configure ZTNA servers and ZTNA policies on FortiGate (Option C): To enable ZTNA functionality, administrators must define ZTNA servers (the protected resources) and create ZTNA policies on FortiGate. These policies determine how traffic is routed, inspected, and controlled based on device posture and user identity.
Topics
Community Discussion
No community discussion yet for this question.