Algoraro
|
|
Título del Test:
![]() Algoraro Descripción: primer test |



| Comentarios |
|---|
NO HAY REGISTROS |
|
Refer to the exhibit. Users are unable to access https://login.live.com. To allow access, which web filter configuration must you change on FortiSASE?. FortiGuard category-based filter. content filter. inline-CASB headers. URL filter. You are designing a new network for Company X and one of the new cybersecurity policy requirements is that all remote user endpoints must always be connected and protected. Which FortiSASE component facilitates this alwayson security measure?. Osite-based deployment. thin-branch SASE extension. inline-CASB. unified FortiClient. When viewing the daily summary report generated by FortiSASE, the administrator notices that the report contains very little data. What is a possible explanation for this almost empty report?. The web filter security profile is not set to Monitor. There are no security profile group applied to all policies. Log allowed traffic is set to Security Events for all policies. Digital experience monitoring is not configured. A FortiSASE administrator is deploying FortiExtender as a FortiSASE LAN extension. While configuring the internet access policy with a source scope edge device, the option to add security posture (ZTNA) tags is not available. What is preventing the administrator from enabling this functionality?. No security posture (ZTNA) tags are configured on FortiSASE. FortiExtender needs to be added on FortiSASE as an access proxy. FortiExtender needs an additional license to support ZTNA. Edge device deployment does not support security posture (ZTNA) tags. Refer to the exhibits. Antivirus is installed on the endpoint, but the windows defender is stopping it from running. What will the endpoint security posture check be?. FortiClient will no longer be managed by FortiSASE. FortiClient will force the user to update the antivirus database. FortiClient will tag the endpoint as FortiSASE-Non-Compliant. FortiClient will block the endpoint from getting access to the network. How does FortiSASE hide user information when viewing and analyzing logs?. By hashing data using salt. By encrypting data using Secure Hash Algorithm 256-bit (SHA-256). By encrypting data using advanced encryption standard (AES). By hashing data using Blowfish. Which FortiSASE feature ensures least-privileged user access to all applications?. zero trust network access (ZTNA). secure web gateway (SWG). SD-WAN. thin branch SASE extension. In which three ways does FortiSASE help organizations ensure secure access for remote workers? (Choose three.). It enables biometric data to validate the identities of remote workers. It secures traffic from endpoints to cloud applications. It enforces multi-factor authentication (MFA) to validate remote users. It enforces granular access policies based on user identities. It offers zero trust network access (ZTNA) capabilities. Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGate hub. However, the administrator is not able to ping the webserver hosted behind the FortiGate hub. Based on the output, what is the reason for the ping failures?. The BGP route is not received. The Secure Private Access (SPA) policy needs to allow PING service. Quick mode selectors are restricting the subnet. Network address translation (NAT) is not enabled on the spoke-to-hub policy. When deploying FortiSASE agentless secure web gateway (SWG) clients, which three features can you use to scan client traffic? (Choose three.). zero trust network access (ZTNA) t. anti-ransomware protection. intrusion prevention system (IPS). inline-CASB HTTP header insertion. SSL inspection. Which technology is used with IPsec for spoke-to-spoke connectivity in a Secure Private Access (SPA) with SDWAN deployment?. EBGP. auto-discovery VPN (ADVPN). Virtual Extensible LAN (VXLAN). Generic Routing Encapsulation (GRE). Which authentication method overrides any other previously configured user authentication on FortiSASE?. SSO. RADIUS. Local. LDAP. Your organization is currently using FortiSASE for its cybersecurity. They have recently hired a contractor who will work from the HQ office and who needs temporary internet access in order to set up a point of sale (POS) system. What is the recommended way to provide internet access to the contractor?. Use FortiClient on the endpoint to manage internet access. Use zero trust network access (ZTNA) and tag the client as an unmanaged endpoint. Use a proxy auto-configuration (PAC) file and provide secure web gateway (SWG) service as an explicit web proxy. Use SSL VPN to provide SWG access to the client. What are two advantages of using zero-trust tags? (Choose two.). Zero-trust tags can be used to allow or deny access to network resources. Zero-trust tags can be used to create multiple endpoint profiles which can be applied to different endpoints. Zero-trust tags can be used to allow secure web gateway (SWG) access. Zero-trust tags can determine the security posture of an endpoint. In the Secure Private Access (SPA) use case, which two FortiSASE features facilitate access to corporate applications? (Choose two.). SD-WAN secure. web gateway (SWG). zero trust network access (ZTNA). Firewall-as-a-Service (FWaaS). cloud access security broker (CASB). Which FortiSASE component secures internet access for remote users who have configured FortiSASE as an explicit web proxy?. Firewall-as-a-Service (FWaaS). secure web gateway (SWG). zero trust network access (ZTNA). SD-WAN. During FortiSASE provisioning, how many security points of presence (POPs) need to be configured by the FortiSASE administrator?. 3. 4. 2. 1. Which policy type is used to control traffic between the agent-based remote users to applications hosted behind the FortiGate hub?. OSWG Policy. Private Access Policy. Thin-Edge Policy. OVPN Policy. A customer wants to ensure secure access for private applications for their users by replacing their VPN. Which two SASE technologies can you use to accomplish this task? (Choose two.). next-generation firewall (NGFW). secure web gateway (SWG) and cloud access security broker (CASB). zero trust network access (ZTNA). secure SD-WAN. Which two additional components does FortiSASE use for application control to act as an inline-CASB? (Choose two.). DNS filter. Web filter with inline-CASB. SSL deep inspection. intrusion prevention system (IPS). Which two settings are automatically pushed from FortiSASE to FortiClient in a new FortiSASE deployment with default settings? (Choose two.). SSL VPN profile. ZTNA tags. FortiSASE CA certificate. Real-time protection. When deploying FortiSASE agent-based clients, which three features are available compared to an agentless solution? (Choose three.). SSL inspection. Anti-ransomware protection. Web filter. Vulnerability scan. ZTNA tags. Refer to the exhibits Win10-Pro and Win7-Pro are endpoints from the same remote location. Win10-Pro can access the internet though FortiSASE, while Win7-Pro can no longer access the internet. Given the exhibits, which reason explains the outage on Win7-Pro?. Win7-Pro cannot reach the FortiSASE SSL VPN gateway. Win-7 Pro has exceeded the total vulnerability detected threshold. The Win7-Pro FortiClient version does not match the FortiSASE endpoint reçirement. The Win7-Pro device posture has changed. An organization must block user attempts to log in to non-company resources while using Microsoft Office 365 to prevent users from accessing unapproved cloud resources. Which FortiSASE feature can you implement to achieve this requirement?. DNS filter. Application Control with Inline-CASB. SSL deep inspection. Web Filter with Inline-CASB. Refer to the exhibit. Daily report for application usage The daily report for application usage shows an unusually high number of unknown applications by category. What are two possible explanations for this? (Choose two.). Zero trust network access (ZTNA) tags are not being used to tag the correct users. The inline-CASB application control profile does not have application categories set to Monitor. Deep inspection is not being used to scan traffic. Certificate inspection is not being used to scan application traffic. Refer to the exhibit. Based on the configuration shown, in which two ways will FortiSASE process sessions that require FortiSandbox inspection? (Choose two.). Only files that are found on off-net endpoints will be scanned. All infected files that FortiSandbox detects as malicious will be quarantined. All files detected on a USB drive will be sent to FortiSandbox for analysis. Only endpoints assigned with profile for Sandbox Detection will be processed by the sandbox feature. When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.). SD-WAN hub. Points of presence. Logging. Endpoint management. Authentication. In a FortiSASE secure web gateway (SWG) deployment, which three features protect against web-based threats? (Choose three.). network access control (NAC) for web applications. SSL inspection for encrypted web traffic. data loss prevention (DLP) for web traffic. intrusion prevention system (IPS) for web traffic. malware protection with sandboxing capabilities. Refer to the exhibits. Web Filtering logs A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy. Which configuration on FortiSASE is allowing users to perform the download?. The HTTPS protocol is not enabled in the antivirus profile. Web filter is allowing the traffic. Force certificate inspection is enabled in the policy. Which configuration on FortiSASE is allowing users to perform the download?. Refer to the exhibits. A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between the remote endpoints and protected server to be in house. In this scenario, which three setups will achieve the above requirements? (Choose three.). Configure ZTNA servers and ZTNA policies on FortiGate. Sync ZTNA tags from FortiSASE to FortiGate. Configure ZTNA tags on FortiGate. Configure FortiGate as a zero trust network access (ZTNA) access proxy. Configure private access policies on FortiSASE with ZTNA. Refer to the exhibit. A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redirect it to the endpoint physical interface. Which configuration must you apply to achieve this requirement?. Exempt the Google Maps FQDN from the endpoint system proxy settings. Configure a static route with the Google Maps FQDN on the endpoint to redirect traffic. Configure the Google Maps FQDN as a split tunneling destination on the FortiSASE endpoint profile. Change the default DNS server configuration on FortiSASE to use the endpoint system DNS. Refer to the exhibit. To allow access, which web filter configuration must you change on FortiSASE?. inline cloud access security broker (CASB) headers. content filter. FortiGuard category-based filter. URL Filter. Which statement applies to a single sign-on (SSO) deployment on FortiSASE?. SSO users can be imported into FortiSASE and added to user groups. SSO overrides any other previously configured user authentication. SSO is recommended only for agent-based deployments. SSO identity providers can be integrated using public and private access types. Which two statements describe a zero trust network access (ZTNA) private access use case? (Choose two.). The security posture of the device is secure. Data center redundancy is offered. All FortiSASE user-based deployments are supported. All TCP-based applications are supported. Which of the following describes the FortiSASE inline-CASB component?. lt uses API to connect to the cloud applications. lt detects data at rest. lt provides visibility for unmanaged locations and devices. lt is placed directly in the traffic path between the endpoint and cloud applications. Which statement describes the FortiGuard forensics analysis feature on FortiSASE?. lt is a 24x7x365 monitoring service of your FortiSASE environment. lt can monitor endpoint resources in real-time. lt can help customers identify and mitigate potential risks to their network. lt can help troubleshoot user-to-application performance issues. What access point communication protocol does FortiAP use to communicate with FortiSASE in a micro branch deployment?. Wireless Application Protocol (WAP). Inter-Access Point Protocol (IAPP). Lightweight Access Point Protocol (LWAPP). Control and Provisioning of Wireless Access Points (CAPWAP). What are two requirements to enable the MSSP feature on FortiSASE? (Choose two.). Enable multi-tenancy on the FortiSASE portal. Assign role-based access control (RBAC) to IAM users using FortiCloud IAM portal. Configure MSSP user accounts and permissions on the FortiSASE portal. Add FortiCloud premium subscription on the root FortiCloud account. Which statement describes the FortiGuard forensics analysis feature on FortiSASE?. It is a 24x7x365 monitoring service of your FortiSASE environment. It can monitor endpoint resources in real-time. It can help customers identify and mitigate potential risks to their network. It can help troubleshoot user-to-application performance issues. Which three configurations must you perform to set up ForliGale as a FortiSASE LAN extension? (Choose three.). Configure VXLAN-over-IPsec on the FortiSASE portal. Enter the FortiSASE domain name in the FortiGate GUI as the access controller address. Authorize the edge FortiGate device on FortiSASE portal. Create a LAN extension VDOM on the edge FortiGate. Connect FortiGate to FortiSASE using FortiZTP. |




