Pass Your Fortinet Network Security Expert NSE5_SSE_AD-7.6 Exam on Aug 04, 2026 with 52 Questions [Q28-Q51]

Share

Pass Your Fortinet Network Security Expert NSE5_SSE_AD-7.6 Exam on Aug 04, 2026 with 52 Questions

NSE5_SSE_AD-7.6 Free Exam Study Guide! (Updated 52 Questions)


Fortinet NSE5_SSE_AD-7.6 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Analytics: This domain covers analyzing SD-WAN and FortiSASE logs to monitor traffic behavior, identify security threats, and generate reports.
Topic 2
  • SASE Deployment: This domain covers FortiSASE administration settings, user onboarding methods, and integration with SD-WAN infrastructure.
Topic 3
  • Decentralized SD-WAN: This domain covers basic SD-WAN implementation including configuring members, zones, and performance SLAs to monitor network quality.
Topic 4
  • Rules and Routing: This section addresses configuring SD-WAN rules and routing policies to control and direct traffic flow across different links.
Topic 5
  • Secure Internet Access (SIA) and Secure SaaS Access (SSA): This section focuses on implementing security profiles for content inspection and deploying compliance rules to managed endpoints.

 

NEW QUESTION # 28
Which two statements about configuring a steering bypass destination in FortiSASE are correct? (Choose two.)

  • A. Apply condition can be set only to On-net or Off-net. but not both
  • B. You can select from four destination types: Infrastructure, FQDN, Local Application, or Subnet
  • C. Subnet is the only destination type that supports the Apply condition
  • D. Apply condition allows split tunneling destinations to ae applied to On-net. off-net. or both types of endpoints

Answer: B,D

Explanation:
According to theFortiSASE 7.6 Feature Administration Guide, steering bypass destinations (also known as split tunneling) allow administrators to optimize bandwidth by redirecting specific trusted traffic away from the SASE tunnel to the endpoint's local physical interface.
* Destination Types (Option C): When creating a bypass destination, administrators can select from four distinct types:Infrastructure(pre-defined apps like Zoom/O365),FQDN(specific domains),Local Application(identifying processes on the laptop), orSubnet(specific IP ranges).
* Apply Condition (Option B): The "Apply" condition is a flexible setting that allows the administrator to choose when the bypass is active. It can be applied to endpoints that areOn-net(inside the office),Off- net(remote), orBoth. This ensures that if a user is in the office, they don't use the SASE tunnel for local resources, but if they are home, they might still bypass high-bandwidth sites like YouTube to preserve tunnel capacity.
Why other options are incorrect:
* Option A: Subnet is one of four types and is not the only type supporting these conditions.
* Option D: The system explicitly supports "Both" to ensure consistency across network transitions.


NEW QUESTION # 29
FortiSASE allows forwarding logs to an external server.
Which two external server types are supported? (Choose two.)

  • A. SNMP
  • B. FortiAnalyzer
  • C. Syslog
  • D. API

Answer: B,C

Explanation:
FortiSASE supports forwarding logs to external servers using FortiAnalyzer and Syslog, enabling centralized log collection and analysis.


NEW QUESTION # 30
Which statement is true about scheduling a FortiClient upgrade using an endpoint upgrade rule?

  • A. If the scheduled time is already past in the local time zone of the endpoint, installation starts the next day at that time.
  • B. Scheduled upgrades automatically reboot macOS endpoints after installation.
  • C. An endpoint upgrade rule can be assigned to a user group.
  • D. When scheduled, the installation always starts immediately if the endpoint is online.

Answer: A

Explanation:
A scheduled FortiClient upgrade is executed according to the endpoint's local time. If the scheduled time has already passed in that time zone, the upgrade is deferred until the same time on the following day.


NEW QUESTION # 31
You want FortiGate to use SD-WAN rules to steer local-out traffic.
Which two constraints should you consider? (Choose two.)

  • A. You must configure each local-out feature individually to use SD-WAN.
  • B. By default, local-out traffic does not use SD-WAN.
  • C. By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to ping and traceroute.
  • D. You can steer local-out traffic only with SD-WAN rules that use the manual strategy.

Answer: A,B

Explanation:
By default, local-out traffic does not use SD-WAN → FortiGate normally sends local-out traffic (e.g., DNS, NTP, FortiGuard updates) directly through its interfaces without applying SD-WAN rules.
You must configure each local-out feature individually to use SD-WAN → To steer local-out traffic via SD-WAN, you must explicitly configure the desired local-out features (e.g., DNS, FortiGuard, CAPWAP) to use SD-WAN rules.


NEW QUESTION # 32
An SD-WAN member is no longer used to steer SD-WAN traffic. You want to update the SD-WAN configuration and delete the unused member.
Which action should you take first? (Choose one answer)

  • A. Remove the member from the performance service-level agreement (SLA) definitions.
  • B. Delete static route definitions for that interface.
  • C. Move the SD-WAN member to the virtual-wan-link zone.
  • D. Disable the interface.

Answer: A

Explanation:
According to theSD-WAN 7.6 Core Administratorstudy guide and theFortinet Document Library, FortiOS maintains strict referential integrity for SD-WAN objects. An SD-WAN member interface cannot be deleted or removed from the configuration if it is still being "used" or referenced by other features.
* Reference Locking: In the FortiOS GUI, the "Delete" button for an SD-WAN member is typically grayed out or an error message appears if the interface is part of an active service or monitoring tool.
* Performance SLA Dependency: Performance SLAs (health checks) monitor specific member interfaces. If an interface is a participant in an SLA, it is considered "active" by the system. Therefore, a critical first step in the decommissioning process is toremove the member from all Performance SLA definitions. Once the health check is no longer polling that interface, one major reference lock is released.
* Other Dependencies: While firewall policies and SD-WAN rules (service rules) also create references, the question specifies the member is "no longer used to steer traffic," implying it may have already been removed from steering rules. However, Performance SLAs often remain active in the background, making their removal the essential next step to permit the deletion of the member itself.
Why other options are incorrect:
* Option A: Moving a member between zones doesn't help you delete it; it just changes its logical grouping. It still remains an active SD-WAN member.
* Option B: Disabling the physical interface does not remove the configuration references within the SD- WAN engine. The FortiGate will simply report the member as "Down," but it will still exist in the configuration as a member.
* Option D: In modern SD-WAN deployments, static routes usually point to theSD-WAN Zone(like virtual-wan-link) rather than individual physical interfaces. Therefore, you don't typically need to delete the static route to remove a single member from the zone.


NEW QUESTION # 33
Which secure internet access (SIA) use case minimizes individual endpoint configuration?

  • A. Agentless remote user internet access
  • B. SIA for FortiClient agent remote users
  • C. SIA using ZTNA
  • D. Site-based remote user internet access

Answer: A

Explanation:
Agentless remote user internet access uses an explicit proxy PAC file, which minimizes configuration on individual endpoints because no FortiClient agent installation or per-device setup is required.


NEW QUESTION # 34
Which FortiSASE feature monitors SaaS application performance and connectivity to points of presence (POPs)?

  • A. Digital experience monitoring
  • B. Event logs
  • C. Operations widgets
  • D. FortiView dashboards

Answer: A

Explanation:
According to theFortiSASE 7.6 Administration GuideandDigital Experience Monitoring (DEM) documentation, the feature specifically designed to monitor SaaS application performance and connectivity to PoPs isDigital Experience Monitoring (DEM).
* SaaS and Path Visibility: DEM assists administrators in troubleshooting remote user connectivity issues by providing enhanced health check visibility forSaaS applications, endpoint devices, and the network path. It provides real-time insights into application performance and latency issues.
* PoP Connectivity: It monitors the digital journey from the end-user device through theSecurity Points of Presence (POPs)to the final application, identifying hops where degraded service (packet loss, delay, or jitter) is detected.
* Proactive Management: By establishing thresholds and simulating user activities throughSynthetic Transaction Monitoring (STM), DEM allows IT teams to identify performance problems before they impact the business.
Why other options are incorrect:
* Option A: Operations widgets provide general status overviews but do not offer the granular per-hop path analysis or specific SaaS transaction monitoring found in DEM.
* Option B: FortiView dashboards provide traffic visibility and session data but are not dedicated performance monitoring tools for end-to-end digital experience.
* Option C: Event logs record system occurrences and security events but do not provide real-time performance metrics or health check probes for SaaS applications.


NEW QUESTION # 35
What is a key use case for FortiSASE Secure Internet Access (SIA) in an agentless deployment?

  • A. It provides secure web browsing by isolating browser sessions and enforcing data loss prevention for temporary employees.
  • B. It acts as a secure web gateway (SWG) distributing a PAC file for explicit web proxy use, securing HTTP and HTTPS traffic with a full security stack, and is ideal for unmanaged endpoints like contractors.
  • C. It distributes a PAC file to secure non-web traffic protocols and applies antivirus protection only for managed endpoints.
  • D. It requires FortiClient endpoints and supports ZTNA tags to secure all network traffic for unmanaged endpoints.

Answer: B

Explanation:
In agentless deployments, FortiSASE SIA works as an explicit Secure Web Gateway using a PAC file to secure HTTP/HTTPS traffic with full security controls, making it ideal for unmanaged or contractor endpoints where no agent is installed.


NEW QUESTION # 36
Which statement about security posture tags in FortiSASE is correct?

  • A. Multiple tags can be assigned to an endpoint and used for evaluation.
  • B. Only one tag can be assigned to an endpoint.
  • C. Multiple tags can be assigned to an endpoint, but only one is used for evaluation.
  • D. Tags are static and do not change with endpoint status.

Answer: A

Explanation:
According to theFortiSASE 7.6 Administration GuideandFCP - FortiSASE 24/25 Administrator curriculum, security posture tags (often referred to as ZTNA tags) are the fundamental building blocks for identity-based and posture-based access control.
* Multiple Tag Assignment: A single endpoint can be assigned multiple tags at the same time. For example, an endpoint might simultaneously have the tags"OS-Windows-11","AV-Running", and
"Corporate-Domain-Joined".
* Evaluation Logic: During the policy evaluation process (for both SIA and SPA), FortiSASE or the FortiGate hub considers all tags assigned to the endpoint. Security policies can be configured to use these tags as source criteria. If an administrator defines a policy that requires both "AV-Running" and
"Corporate-Domain-Joined," the system evaluates both tags to decide whether to permit the traffic.
* Dynamic Nature: Contrary to Option C, these tags are highly dynamic. They are automatically applied or removed in real-time based on the telemetry data sent by theFortiClientto the SASE cloud. If a user disables their antivirus, the "AV-Running" tag is removed immediately, and the endpoint's access is revoked by the next policy evaluation.
* Scalability: While the system supports many tags, documentation recommends a baseline of custom tags for optimal performance, though it confirms that multiple tags are standard for reflecting a comprehensive security posture.
Why other options are incorrect:
* Option A: This is incorrect because the system does not pick just one tag; it evaluates the collection of tags against the policy's requirements (e.g., matching any or matching all).
* Option C: This is incorrect because tags are dynamic and change as soon as the endpoint's status (like vulnerability count or software presence) changes.
* Option D: This is incorrect because the architectural advantage of ZTNA is the ability to layer multiple security "checks" (tags) for a single user.


NEW QUESTION # 37
Which three factors about SLA targets and SD-WAN rules should you consider when configuring SD-WAN rules? (Choose three.)

  • A. Member metrics are measured only if a rule uses the SLA target.
  • B. SD-WAN rules can use SLA targets to check whether the preferred members meet the SLA requirements.
  • C. When configuring an SD-WAN rule, you can select multiple SLA targets from different performance SLAs.
  • D. When configuring an SD-WAN rule, you can select multiple SLA targets if they are from the same performance SLA.
  • E. SLA targets are used only by SD-WAN rules that are configured with a Lowest Cost (SLA) strategy.

Answer: B,D,E

Explanation:
The use of SLA targets is specific to certain SD-WAN strategies. The "Lowest Cost (SLA)" and
"Maximize Bandwidth (SLA)" strategies are explicitly designed to use the configured SLA targets to make routing decisions. The "Best Quality" strategy uses performance metrics but does not necessarily require or reference SLA targets in the same way, while "Manual" does not use metrics at all for path selection.
This is a core function of SD-WAN rules with SLA targets. The purpose of configuring an SLA target with specific thresholds for latency, jitter, and packet loss is to define what is considered
"acceptable" performance for an application. SD-WAN rules then use these targets to check if the members (interfaces) meet these requirements before a flow is steered over them, ensuring that a preferred path still offers a good user experience.
FortiGate allows for a single SD-WAN rule to reference multiple, different performance SLAs. This is crucial for complex deployments where a single SD-WAN rule needs to handle traffic for multiple applications that have distinct performance requirements. For example, a single rule might direct VoIP traffic based on one performance SLA with strict latency/jitter targets, while simultaneously handling general web traffic using another performance SLA with more lenient requirements.


NEW QUESTION # 38
Which statement about security posture tags in FortiSASE is correct?

  • A. Multiple tags can be assigned to an endpoint and used for evaluation.
  • B. Only one tag can be assigned to an endpoint.
  • C. Multiple tags can be assigned to an endpoint, but only one is used for evaluation.
  • D. Tags are static and do not change with endpoint status.

Answer: A

Explanation:
Security posture tags in FortiSASE dynamically assess endpoint compliance based on rules like OS version, antivirus status, and FortiClient connectivity. Endpoints receive multiple tags simultaneously (e.g., for Windows 11, active AV, and SASE connection), which firewalls then evaluate in policies for ZTNA access control.


NEW QUESTION # 39
Which three reports are valid report types in FortiSASE? (Choose three.)

  • A. Shadow IT Report
  • B. Vulnerability Assessment Report
  • C. Web Usage Summary Report
  • D. Cyber Threat Assessment
  • E. Endpoint Compliance Deviation Report

Answer: A,B,C


NEW QUESTION # 40
Which three reports are valid report types in FortiSASE? (Choose three.)

  • A. Shadow IT Report
  • B. Vulnerability Assessment Report
  • C. Web Usage Summary Report
  • D. Cyber Threat Assessment
  • E. Endpoint Compliance Deviation Report

Answer: A,B,C

Explanation:
According to theFortiSASE 7.6 Administration Guideand theFCP - FortiSASE 24/25training materials, FortiSASE leverages a cloud-native FortiAnalyzer instance to provide specialized reports. These reports are designed to give administrators visibility into remote user behavior, endpoint health, and cloud application usage.
The three valid and standard report types available directly within the FortiSASE portal are:
* Web Usage Summary Report (Option A):This report provides a high-level overview of web activity across the SASE deployment. It categorizes traffic by website categories (e.g., Social Media, Streaming, Malicious Sites), top users by bandwidth, and blocked requests, helping IT teams understand how internet resources are being consumed by remote workers.
* Vulnerability Assessment Report (Option C):Since FortiSASE integrates with FortiClient and an embedded EMS, it can aggregate vulnerability scan data from managed endpoints. This report lists software vulnerabilities found on user devices (OS-level and application-level), providing a "Security Rating" or posture assessment that is critical for Zero Trust Network Access (ZTNA) enforcement.
* Shadow IT Report (Option D):Leveraging the built-inCASB (Cloud Access Security Broker) capabilities, this report identifies "unsanctioned" or "risky" SaaS applications being used by employees.
It helps organizations discover hidden security risks by cataloging cloud applications that have not been explicitly approved by the IT department.
Why other options are incorrect:
* Endpoint Compliance Deviation Report (Option B):While FortiSASE performs compliance checks via ZTNA tags, this specific name is not a standard "Report Type" template in the portal; compliance is typically monitored via theEndpoint ManagementorZTNA Dashboards.
* Cyber Threat Assessment (Option E):TheCyber Threat Assessment Program (CTAP)is a specific Fortinet sales and auditing tool used to generate a one-time report on a network's security posture (often used for FortiGate evaluations). It is not a native, recurring report type within the day-to-day FortiSASE administration interface.


NEW QUESTION # 41
Which two delivery methods are used for installing FortiClient on a user's laptop? (Choose two.)

  • A. Send an invitation email to selected users containing links to FortiClient installers.
  • B. Use zero-touch installation through a third-party application store.
  • C. Download the installer directly from the FortiSASE portal.
  • D. Configure automatic installation through an API to the user's laptop.

Answer: A,C

Explanation:
Download from the FortiSASE portal: Administrators can provide users with access to the FortiSASE portal where they can directly download a pre-configured installer. This installer is uniquely tied to the organization's SASE instance, ensuring the client automatically registers to the correct cloud EMS upon installation.
Invitation Email: This is the most common administrative method. The FortiSASE portal (via its integrated EMS) allows administrators to send an invitation email to specific users or groups. This email contains direct download links for various operating systems (Windows, macOS, Linux) and the necessary invitation code for zero-touch registration.


NEW QUESTION # 42
How does the FortiSASE security dashboard facilitate vulnerability management for FortiClient endpoints?

  • A. It shows vulnerabilities only for applications and requires endpoint users to manually check for affected endpoints.
  • B. It automatically patches all vulnerabilities without user intervention and does not categorize vulnerabilities by severity.
  • C. It displays only critical vulnerabilities, requires manual patching for all endpoints, and does not allow viewing of affected endpoints.
  • D. It provides a vulnerability summary, identifies affected endpoints, and supports automatic patching for eligible vulnerabilities.

Answer: D

Explanation:
The FortiSASE security dashboard presents a full vulnerability summary, shows which endpoints are affected, and supports automatic patching for vulnerabilities that are eligible for automated remediation.


NEW QUESTION # 43
How is the Geofencing feature used in FortiSASE? (Choose one answer)

  • A. To monitor user behavior on websites and block non-work-related content from specific countries
  • B. To restrict access to applications based on the time of day in specific countries.
  • C. To allow or block remote user connections to FortiSASE POPs from specific countries.
  • D. To encrypt data at rest on mobile devices in specific countries.

Answer: C

Explanation:
According to theFortiSASE 7.6 Administration Guideand theFCP - FortiSASE 24/25 Administratorstudy materials, theGeofencingfeature is a security measure implemented at the edge of the FortiSASE cloud to control ingress connectivity based on the physical location of the user.
* Access Control by Location (Option A): Geofencing allows administrators toallow or block remote user connectionsto the FortiSASE Points of Presence (PoPs) based on the source country, region, or specific network infrastructure (e.g., AWS, Azure, GCP).
* Scope of Application: This feature is universal across all SASE connectivity methods. It applies to Agent-based users(FortiClient),Agentless users(SWG/PAC file), andEdge devices(FortiExtender
/FortiAP). If a user attempts to connect from a blacklisted country, the connection is dropped at the PoP level before the user can even attempt to authenticate.
* Use Case Example: An organization operating exclusively in North America might configure geofencing toblock all connections originating from outside the US and Canada. This significantly reduces the attack surface by preventing brute-force or unauthorized access attempts from high-risk regions or countries where the organization has no legitimate employees.
* Configuration Path: In the FortiSASE portal, this is managed underConfiguration > Geofencing.
From there, administrators can create an "Allow" or "Deny" list and select the relevant countries from a standardized global database.
Why other options are incorrect:
* Option B: While FortiSASE supportsTime-based schedulesfor firewall policies, geofencing is specifically an IP-to-Geography mapping tool for connection admission, not a time-of-day restriction tool.
* Option C: Encryption of data at rest on mobile devices is a function of anMDM (Mobile Device Management)solution or local OS features (like FileVault or BitLocker), not a SASE network geofencing feature.
* Option D: Monitoring web behavior and blocking non-work content is the role of theWeb Filterand Application Controlprofiles, which operate on the trafficafterthe connection is allowed by geofencing.


NEW QUESTION # 44
A FortiGate device is in production. To optimize WAN link use and improve redundancy, you enable and configure SD-WAN.
What must you do as part of this configuration update process?

  • A. Disable the interface that you want to use as an SD-WAN member.
  • B. Replace references to interfaces used as SD-WAN members in the routing configuration.
  • C. Purchase and install the SD-WAN license, and reboot the FortiGate device.
  • D. Replace references to interfaces used as SD-WAN members in the firewall policies.

Answer: D

Explanation:
When you enable SD-WAN on a FortiGate, the individual WAN interfaces that you add into the SD-WAN zone are no longer referenced directly in firewall policies.
Instead, you must update those firewall policies to use the SD-WAN zone as the interface reference.


NEW QUESTION # 45
Which statement is true about FortiSASE supported deployment?

  • A. FortiSASE relies on ZTNA-only mode, which replaces SWG and endpoint functions.
  • B. FortiSASE supports VPN mode and Agentless mode, based on user requirements.
  • C. FortiSASE supports both Endpoint mode and SWG mode, depending on deployment.
  • D. FortiSASE operates only in SWG mode, where all traffic is forced through FortiSASE POPs.

Answer: C

Explanation:
According to theFortiSASE 7.6 Administration Guideand theFCP - FortiSASE 24/25 Administrator curriculum, FortiSASE is designed with a hybrid deployment architecture to support various user and device requirements. It primarily operates in two modes:
* Endpoint Mode (Agent-based): This mode requires the installation ofFortiClienton the user's laptop or device. The agent establishes an "always-up" secure VPN tunnel to the nearest FortiSASE Point of Presence (PoP), providing full Secure Internet Access (SIA), Secure Private Access (SPA), and endpoint posture checks (ZTNA).
* Secure Web Gateway (SWG) Mode (Agentless): This mode is used for users or devices where installing an agent is not feasible (e.g., unmanaged devices or Chromebooks). It relies on explicit web proxy settings or a PAC (Proxy Auto-Configuration) file to redirect web traffic (HTTP/HTTPS) to the SASE PoP for inspection.
Why other options are incorrect:
* Option A: While it supports VPN, "VPN mode" is not the formal name of the deployment type; it is
"Endpoint mode".
* Option C: FortiSASE is not limited to SWG; it is a full SSE (Security Service Edge) solution including FWaaS and ZTNA.
* Option D: ZTNA is a capability within the platform, not a replacement for the overall endpoint or SWG functions.


NEW QUESTION # 46
Which FortiSASE feature monitors SaaS application performance and connectivity to points of presence (POPs)?

  • A. Digital experience monitoring
  • B. Event logs
  • C. Operations widgets
  • D. FortiView dashboards

Answer: A

Explanation:
The Digital Experience Monitor (DEM) feature on FortiSASE provides end-to-end network visibility by monitoring the performance and health of connections between FortiSASE security Points of Presence (PoPs) and specific SaaS applications, allowing IT teams to troubleshoot connectivity issues and ensure smooth user experience.


NEW QUESTION # 47
What is a key use case for FortiSASE Secure Internet Access (SIA) in an agentless deployment? (Choose one answer)

  • A. It provides secure web browsing by isolating browser sessions and enforcing data loss prevention for temporary employees.
  • B. It acts as a secure web gateway (SWG) distributing a PAC file for explicit web proxy use, securing HTTP and HTTPS traffic with a full security stack, and is ideal for unmanaged endpoints like contractors.
  • C. It distributes a PAC file to secure non-web traffic protocols and applies antivirus protection only for managed endpoints.
  • D. It requires FortiClient endpoints and supports ZTNA tags to secure all network traffic for unmanaged endpoints.

Answer: B

Explanation:
According to theFortiSASE 7.6 Administration Guideand theFCP - FortiSASE 24/25 Administrator curriculum, the Agentless deployment mode-commonly referred to asSecure Web Gateway (SWG)mode- is a vital component of the Secure Internet Access (SIA) framework.
* Deployment Mechanism: In an agentless deployment, FortiSASE functions as an explicit web proxy.
This is achieved by distributing aPAC (Proxy Auto-Configuration) fileto the user's browser, which instructs the device to send its web traffic to the nearest FortiSASE Point of Presence (PoP).
* Target Use Case: This mode is specifically designed forunmanaged endpoints, such as those used by contractors, partners, or temporary workers, where the organization does not have the authority or capability to install the FortiClient agent.
* Security Capabilities: Even without an agent, FortiSASE applies afull security stackto the redirected traffic. This includesWeb Filtering,Anti-Malware,SSL Inspection, andInline-CASBto secure HTTP and HTTPS sessions.
* Protocol Limitations: Because it relies on proxy settings, this mode is limited to web protocols (HTTP
/HTTPS) and does not inherently secure non-web traffic like ICMP, DNS, or custom TCP/UDP applications unless they are specifically proxied.
Why other options are incorrect:
* Option A: While it provides secure browsing, session isolation (RBI) is a specific feature that can be used in either mode; the defining characteristic of the agentless use case is the proxy-based redirection for unmanaged devices.
* Option C: A PAC file can only secure web traffic (protocols that support proxying), not non-web traffic protocols.
* Option D: Agentless mode is the opposite of requiring FortiClient; ZTNA tags generally require the FortiClient agent to provide the necessary telemetry for tag evaluation.


NEW QUESTION # 48
How is the Geofencing feature used in FortiSASE? (Choose one answer)

  • A. To monitor user behavior on websites and block non-work-related content from specific countries
  • B. To restrict access to applications based on the time of day in specific countries.
  • C. To allow or block remote user connections to FortiSASE POPs from specific countries.
  • D. To encrypt data at rest on mobile devices in specific countries.

Answer: C


NEW QUESTION # 49
Refer to the exhibit.

The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.
The administrator wants to know through which interface FortiGate will steer traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the social media application Facebook.
Based on the exhibits, which two statements are correct? (Choose two.)

  • A. When FortiGate cannot recognize the application of the flow, it load balances the traffic through the tunnels HQ_T1, HQ_T2, HQ_T3.
  • B. When FortiGate cannot recognize the application of the flow, it steers the traffic through the preferred member of rule 3, HQ_T1.
  • C. FortiGate steers traffic for social media applications according to the service rule 2 and steers traffic through port2.
  • D. There is no service defined for the Facebook application, so FortiGate applies service rule 3 and directs the traffic to headquarters.

Answer: A,C

Explanation:
"If a flow is identified as belonging to a defined application category (such as social media), FortiGate will match it to the corresponding service rule (rule 2) and route it through the specified interface, such as port2.
However, if the application is not recognized during the session setup, the system defaults to load balancing the traffic using the available tunnels according to the policy for unclassified traffic, ensuring continuous connectivity while waiting for application classification." This guarantees both performance and resilience.


NEW QUESTION # 50
Which three authentication sources support secure identity verification and access control for FortiSASE remote users? (Choose three.)

  • A. Remote Authentication Dial-in User Service (RADIUS)
  • B. Lightweight Directory Access Protocol (LDAP)
  • C. Terminal Access Controller Access-Control System Plus (TACACS+)
  • D. Security Assertion Markup Language (SAML)
  • E. OpenID Conned (OIDC)

Answer: A,B,D


NEW QUESTION # 51
......

NSE5_SSE_AD-7.6 Dumps for Fortinet Network Security Expert Certified Exam Questions and Answer: https://www.dumpstests.com/NSE5_SSE_AD-7.6-latest-test-dumps.html

Realistic Verified NSE5_SSE_AD-7.6 exam dumps Q&As - NSE5_SSE_AD-7.6 Free Update: https://drive.google.com/open?id=1cdBK6CVLjF4YKsCCldgWlhLXGJwlkJnw