NSE5_SSE_AD-7.6 Exam Questions
49 real NSE5_SSE_AD-7.6 exam questions with expert-verified answers and explanations. Page 1 of 1.
- Question #1Monitoring, Logging, and Reporting
What is the primary function of FortiView on FortiSASE?
FortiViewsecurity event monitoringconsolidated dashboardslog visualization - Question #2Endpoint Security and Remote Access
Which two statements about configuring a steering bypass destination in FortiSASE are correct? (Choose two.)
steering bypasssplit tunnelingdestination typesOn-net Off-net - Question #3Secure Web Gateway and CASB
Which statement about FortiSASE CASB capabilities is true?
CASBinline CASBAPI-based CASBcloud access security - Question #4FortiSASE Architecture and Deployment
Which three challenges in a work-from-anywhere environment does FortiSASE address? (Choose three.)
work-from-anywherevisibility and controlsecurity consistencySASE value proposition - Question #5Endpoint Security and Remote Access
Which two methods are available for provisioning FortiClient on endpoints using FortiSASE? (Choose two.)
FortiClient provisioninginvitation codeSCCM GPO deploymentendpoint onboarding - Question #6Monitoring, Logging, and Reporting
Which three reports are valid report types in FortiSASE? (Choose three.)
report typesShadow ITvulnerability assessmentweb usage summary - Question #7Monitoring, Logging, and Reporting
FortiSASE allows forwarding logs to an external server. Which two external server types are supported? (Choose two.)
log forwardingFortiAnalyzersyslogexternal log servers - Question #8FortiSASE Architecture and Deployment
Which statement is true about FortiSASE supported deployment?
deployment modesEndpoint modeSWG modeFortiSASE architecture - Question #9SD-WAN Configuration and Management
What are three key routing principles of SD-WAN? (Choose three.)
SD-WAN routing principlesrouting precedencepolicy routesSD-WAN rule evaluation - Question #10SD-WAN Configuration and Management
An SD-WAN member is no longer used to steer SD-WAN traffic. You want to update the SD- WAN configuration and delete the unused member. Which action should you take first?
SD-WAN member deletionSLA definitionsconfiguration sequencingmember management - Question #11Secure Web Gateway and CASB
What is a key use case for FortiSASE Secure Internet Access (SIA) in an agentless deployment?
SIA agentlessPAC fileexplicit web proxysecure web gateway - Question #12SD-WAN Configuration and Management
SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD- WAN to steer the traffic. Which three configuration elements must you configure before F...
SD-WAN prerequisitesfirewall policiesrouting configurationinterface setup - Question #13Endpoint Security and Remote Access
How does the FortiSASE security dashboard facilitate vulnerability management for FortiClient endpoints?
vulnerability managementsecurity dashboardFortiClient endpointsautomatic patching - Question #14SD-WAN Configuration and Management
Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two.)
implicit SD-WAN rulesession flagsvwl_defaultSD-WAN service ID - Question #15SD-WAN Configuration and Management
Refer to the exhibit. You configure SD-WAN on a standalone FortiGate device. You want to create an SD-WAN rule that steers traffic related to Facebook and LinkedIn through the less...
SD-WAN rule configurationinternet servicesapplication destinationstraffic steering - Question #16Policy Enforcement and Security Profiles
Refer to the exhibit. Which web filter category will be denied access and display a replacement message to the user?
web filteringURL categoriesreplacement messagesecurity profiles - Question #17FortiSASE Architecture and Deployment
Which secure internet access (SIA) use case minimizes individual endpoint configuration?
SIA use casesagentless deploymentendpoint configuration minimizationremote user access - Question #18SD-WAN Configuration and Management
Refer to the exhibit, which shows the SD-WAN rule status and configuration. Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred mem...
SD-WAN SLApacket loss thresholdpreferred member selectionperformance-based routing - Question #19SD-WAN Configuration and Management
A FortiGate device is in production. To optimize WAN link use and improve redundancy, you enable and configure SD-WAN. What must you do as part of this configuration update process...
SD-WAN deploymentfirewall policy referencesinterface migrationproduction configuration - Question #20SD-WAN Configuration and Management
Drag and Drop In which order does a FortiGate device consider the following elements shown in the left column during the route lookup process? Answer:
route lookup orderrouting precedencepolicy routesSD-WAN rule evaluation - Question #21SD-WAN Configuration and Management
Refer to the exhibit. How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0.125?
SD-WAN routingFIB lookuptraffic steeringroute matching - Question #22Endpoint Security and Remote Access
Which statement is true about scheduling a FortiClient upgrade using an endpoint upgrade rule?
FortiClient upgradeendpoint upgrade rulescheduled upgradetimezone behavior - Question #23SD-WAN Configuration and Management
Which three factors about SLA targets and SD-WAN rules should you consider when configuring SD-WAN rules? (Choose three.)
SLA targetsSD-WAN rulesmember metricsperformance SLA - Question #24FortiSASE Architecture and Deployment
Which authentication method overrides any other previously configured user authentication on FortiSASE?
SSO authenticationauthentication overrideFortiSASE identityuser authentication - Question #25Zero Trust Network Access (ZTNA)
Which two configurations are required for Agentless ZTNA to work? (Choose two.)
agentless ZTNAZTNA proxyproxy SSOZTNA requirements - Question #26FortiSASE Architecture and Deployment
What is the purpose of the priority/failover connection feature in FortiSASE Geofencing for managing VPN connections?
geofencingVPN priority failoversecurity POPon-premises FortiGate - Question #27FortiSASE Architecture and Deployment
What is the primary purpose of implementing a dedicated IP in security POPs?
dedicated IPsecurity POPsource IP anchoringgeolocation rules - Question #28Monitoring, Logging, and Reporting
Refer to the exhibit. Which two statements about the Vulnerability summary dashboard in FortiSASE are correct? (Choose two.)
vulnerability dashboardCVE dataautomatic patchingendpoint profile - Question #29SD-WAN Configuration and Management
Refer to the exhibit. Which conclusion can you draw from the exhibit?
performance SLAhealth checkmember latencySLA criteria - Question #30SD-WAN Configuration and Management
Refer to the exhibit. An SD-WAN zone configuration on the FortiGate GUI is shown. What can you conclude about the zone and member configuration on this device?
SD-WAN zoneszone membersoverlay-factoriesvirtual-wan-link - Question #31Endpoint Security and Remote Access
The IT team is wondering whether they will need to continue using MDM tools for future FortiClient upgrades. What options are available for handling future FortiClient upgrades?
FortiClient upgradeendpoint upgrade featureFortiSASE portalMDM replacement - Question #32SD-WAN Configuration and Management
Refer to the exhibit. The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device. The administrator wants to know through which interface Fo...
SD-WAN service ruleapplication steeringload balancingtraffic classification - Question #33SD-WAN Configuration and Management
You have configured the performance SLA with the probe mode as Prefer Passive. What are two observable impacts of this configuration? (Choose two.)
performance SLAprefer passive probe modepassive monitoringdead member detection - Question #34SD-WAN Configuration and Management
Refer to the exhibit. You want the performance service-level agreement (SLA) to measure the jitter of each member. Which configuration change must you make to achieve this result?
performance SLAjitter measurementSLA configurationmember metrics - Question #35SD-WAN Configuration and Management
You have a FortiGate configuration with three user-defined SD-WAN zones and one or two members in each of these zones. One SD-WAN member is no longer used in health-check and SD-WA...
SD-WAN member deletionsingle-member zonestatic routeszone constraints - Question #36Endpoint Security and Remote Access
Which statement about security posture tags in FortiSASE is correct?
security posture tagsendpoint evaluationtag assignmentFortiSASE - Question #37Policy Enforcement and Security Profiles
What is the purpose of the on/off-net rule setting in FortiSASE?
on-net off-net ruletrusted network detectionendpoint locationaccess policy - Question #38Monitoring, Logging, and Reporting
Which FortiSASE feature monitors SaaS application performance and connectivity to points of presence (POPs)?
digital experience monitoringSaaS performancePOP connectivityFortiSASE monitoring - Question #39SD-WAN Configuration and Management
For a small site, an administrator plans to implement SD-WAN and ensure high network availability for business-critical applications while limiting the overall cost and the cost of...
SD-WAN designWAN link redundancyhigh availabilitycost optimization - Question #40Troubleshooting
Refer to the exhibit. An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects th...
SD-WAN rule mismatchroute prioritypolicy routeVPN interface selection - Question #41FortiSASE Architecture and Deployment
Which configuration is a valid use case for FortiSASE features in supporting remote users?
FortiSASE use casesremote usersSaaS accesssecure web browsing - Question #42Endpoint Security and Remote Access
Which two delivery methods are used for installing FortiClient on a user's laptop? (Choose two.)
FortiClient installationFortiSASE portalinvitation emailendpoint deployment - Question #43Monitoring, Logging, and Reporting
An existing Fortinet SD-WAN customer who has recently deployed FortiSASE wants to have a comprehensive view of, and combined reports for, both SD-WAN branches and remote users. How...
FortiAnalyzer integrationlog forwardingSD-WAN reportingFortiSASE logging - Question #44SD-WAN Configuration and Management
You want FortiGate to use SD-WAN rules to steer local-out traffic. Which two constraints should you consider? (Choose two.)
local-out trafficSD-WAN rulestraffic steeringFortiGate configuration - Question #45SD-WAN Configuration and Management
Refer to the exhibit, which shows the SD-WAN rule status and configuration. Based on the exhibit, which change in the measured latency will first make HUB1-VPN3 the new preferred m...
SD-WAN member selectionlatency thresholdsSLA quality strategypreferred member - Question #46SD-WAN Configuration and Management
An administrator is configuring SD-WAN to load balance their network traffic. Which two things should they consider when setting up SD-WAN? (Choose two.)
SD-WAN load balancingSLA targetsoutbandwidth hashload balancing strategies - Question #47FortiSASE Architecture and Deployment
Which three FortiSASE use cases are possible? (Choose three answers)
SIASSASPAFortiSASE use cases - Question #48Policy Enforcement and Security Profiles
How is the Geofencing feature used in FortiSASE? (Choose one answer)
geofencingcountry-based restrictionsPOP access controlFortiSASE policy - Question #49Troubleshooting
Refer to the exhibits. Two SD-WAN event logs, the member status, the SD-WAN rule configuration, and the health-check configuration for a FortiGate device are shown. Immediately aft...
SD-WAN event logshealth-checkmember statustraffic steering analysis