Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: big75certs

Free and Premium Fortinet NSE5_SSE_AD-7.6 Dumps Questions Answers

Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Questions and Answers

Question 1

Which three challenges in a work-from-anywhere environment does FortiSASE address? (Choose three.)

Options:

A.

Inconsistent security levels

B.

Lack of bandwidth

C.

Lack of visibility and control

D.

Poor performance

E.

Remote internet connectivity

Buy Now
Question 2

Refer to the exhibit.

Which web filter category will be denied access and display a replacement message to the user?

Options:

A.

Drug Abuse

B.

Discrimination

C.

Hacking

D.

Illegal or Unethical

Question 3

Refer to the exhibits.

Two SD-WAN event logs, the member status, the SD-WAN rule configuration, and the health-check configuration for a FortiGate device are shown. Immediately after the log messages are displayed, how will the FortiGate steer the traffic based on the information shown in the exhibits? (Choose one answer)

Options:

A.

FortiGate uses port1 or port2 to steer the traffic for SD-WAN rule ID 1.

B.

FortiGate uses port1 to steer the traffic for SD-WAN rule ID 1.

C.

FortiGate uses port2 to steer the traffic for SD-WAN rule ID 1.

D.

FortiGate skips SD-WAN rule ID 1.

Question 4

Which authentication method overrides any other previously configured user authentication on FortiSASE?

Options:

A.

Local

B.

SSO

C.

RADIUS

D.

MFA

Question 5

Which two methods are available for provisioning FortiClient on endpoints using FortiSASE? (Choose two.)

Options:

A.

FortiClient can be provisioned using SCCM or GPO, but only through an external portal and not through the FortiSASE portal.

B.

FortiClient can be provisioned using installers with an invitation code from the FortiSASE portal and deployed through SCCM or GPO, or mobile device management (MDM) software.

C.

FortiClient can be provisioned by distributing the installer to end users for manual installation.

D.

FortiClient provisioning is limited to using mobile device management (MDM) software or manual installation without requiring an invitation code.

E.

FortiClient can be provisioned only by distributing installers to end users through the FortiSASE portal without an invitation code.

Question 6

Refer to the exhibit.

The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.

The administrator wants to know through which interface FortiGate will steer traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the social media application Facebook.

Based on the exhibits, which two statements are correct? (Choose two.)

Options:

A.

FortiGate steers traffic for social media applications according to the service rule 2 and steers traffic through port2.

B.

There is no service defined for the Facebook application, so FortiGate applies service rule 3 and directs the traffic to headquarters.

C.

When FortiGate cannot recognize the application of the flow, it load balances the traffic through the tunnels HQ_T1, HQ_T2, HQ_T3.

D.

When FortiGate cannot recognize the application of the flow, it steers the traffic through the preferred member of rule 3, HQ_T1.

Question 7

Refer to the exhibit.

You want the performance service-level agreement (SLA) to measure the jitter of each member. Which configuration change must you make to achieve this result?

Options:

A.

No change is required.

B.

Add an SLA target and define a jitter threshold.

C.

Specify the participant members.

D.

Set the protocol to HTTP.

Question 8

You have a FortiGate configuration with three user-defined SD-WAN zones and one or two members in each of these zones. One SD-WAN member is no longer used in health-check and SD-WAN rules. This member is the only member of its zone. You want to delete it.

What happens if you delete the SD-WAN member from the FortiGate GUI?

Options:

A.

FortiGate displays an error message. SD-WAN zones must contain at least one member.

B.

FortiGate accepts the deletion and removes static routes as required.

C.

FortiGate accepts the deletion with no further action.

D.

FortiGate accepts the deletion and places the member in the default SD-WAN zone.

Question 9

What is the purpose of the on/off-net rule setting in FortiSASE?

Options:

A.

To enable or disable user authentication for external network access.

B.

To define different traffic routing rules for on-premises and cloud-based resources.

C.

To determine if an endpoint is connecting from a trusted network or untrusted location.

D.

To configure different access policies for users based on their geographical location.

Question 10

Refer to the exhibit.

The SD-WAN rule status and configuration is shown. Based on the exhibit, which change in the measured latency will first make HUB1-VPN3 the new preferred member?

Options:

A.

When HUB1-VPN3 has a latency of 80 ms

B.

When HUB1-VPN3 has a lower latency than HUB1-VPN1 and HUB1-VPN2

C.

When HUB1-VPN1 has a latency of 200 ms

D.

When HUB1-VPN3 has a latency of 90 ms

Question 11

The IT team is wondering whether they will need to continue using MDM tools for future FortiClient upgrades.

What options are available for handling future FortiClient upgrades?

Options:

A.

Enable the Endpoint Upgrade feature on the FortiSASE portal.

B.

FortiClient will need to be manually upgraded.

C.

Perform onboarding for managed endpoint users with a newer FortiClient version.

D.

A newer FortiClient version will be auto-upgraded on demand.

Question 12

Which three reports are valid report types in FortiSASE? (Choose three.)

Options:

A.

Web Usage Summary Report

B.

Endpoint Compliance Deviation Report

C.

Vulnerability Assessment Report

D.

Shadow IT Report

E.

Cyber Threat Assessment

Question 13

Refer to the exhibit.

Which two statements about the Vulnerability summary dashboard in FortiSASE are correct? (Choose two.)

Options:

A.

The dashboard shows the vulnerability score for unknown applications.

B.

Vulnerability scan is disabled in the endpoint profile.

C.

The dashboard allows the administrator to drill down and view CVE data and severity classifications.

D.

Automatic vulnerability patching can be enabled for supported applications.

Question 14

Refer to the exhibits.

The administrator increases the member priority on port2 to 20. Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)

Options:

A.

FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.

B.

FortiGate flags the SNAT session as dirty only if the administrator has assigned an IP pool to the firewall policies with NAT.

C.

FortiGate routes only new sessions over port1.

D.

FortiGate continues routing all existing sessions over port2.

E.

FortiGate flags the sessions as dirty.

Question 15

SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.

Which three configuration elements must you configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)

Options:

A.

Firewall policies

B.

Security profiles

C.

Interfaces

D.

Routing

E.

Traffic shaping