nerdexam
Fortinet

FCSS_SASE_AD-25 · Question #4

Refer to the exhibits. Jumpbox and Windows-AD are endpoints from the same remote location. Jumpbox can access the internet through FortiSASE, while Windows-AD can no longer access the internet…

The correct answer is C. The device posture for Windows-AD has changed. The Windows-AD endpoint now has both "FortiSASE-Compliant" and "FortiSASE-Non- Compliant" tags due to failing the antivirus software check. As a result, the Secure Internet Access Policy matches the "Non-Compliant" rule, which is set to Deny, causing the device to lose internet…

FortiSASE Troubleshooting

Question

Refer to the exhibits. Jumpbox and Windows-AD are endpoints from the same remote location. Jumpbox can access the internet through FortiSASE, while Windows-AD can no longer access the internet. Based on the information in the exhibits, which reason explains the outage on Windows-AD?

Exhibits

FCSS_SASE_AD-25 question #4 exhibit 1
FCSS_SASE_AD-25 question #4 exhibit 2
FCSS_SASE_AD-25 question #4 exhibit 3

Options

  • AWindows-AD is excluded from FortiSASE management.
  • BThe FortiClient version installed on Windows AD does not match the expected version on
  • CThe device posture for Windows-AD has changed.
  • DThe remote VPN user on Windows-AD no longer matches any VPN policy.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    7% (2)
  • C
    76% (22)
  • D
    14% (4)

Explanation

The Windows-AD endpoint now has both "FortiSASE-Compliant" and "FortiSASE-Non- Compliant" tags due to failing the antivirus software check. As a result, the Secure Internet Access Policy matches the "Non-Compliant" rule, which is set to Deny, causing the device to lose internet access.

Topics

#device posture#ZTNA tags#endpoint compliance#troubleshooting

Community Discussion

No community discussion yet for this question.

Full FCSS_SASE_AD-25 Practice