Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Fortinet Network Security Expert NSE5_SSE_AD-7.6 Questions and answers with Dumpstech

Exam NSE5_SSE_AD-7.6 Premium Access

View all detail and faqs for the NSE5_SSE_AD-7.6 exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which configuration is a valid use case for FortiSASE features in supporting remote users?

Options:

A.

Enabling secure SaaS access through SD-WAN integration, protecting against web-based threats with data loss prevention, and monitoring user connectivity with shadow IT visibility.

B.

Monitoring SaaS application performance, isolating browser sessions for all websites, and integrating with SD-WAN for data loss prevention.

C.

Enabling secure web browsing to protect against threats, providing explicit application access with zero-trust or SD-WAN integration, and addressing shadow IT visibility with data loss prevention.

D.

Providing secure web browsing through remote browser isolation, addressing shadow IT with zero-trust access, and protecting data at rest only.

Questions # 12:

You have configured the performance SLA with the probe mode as Prefer Passive.

What are two observable impacts of this configuration? (Choose two.)

Options:

A.

FortiGate can offload the traffic that is subject to passive monitoring to hardware.

B.

FortiGate passively monitors the member if ICMP traffic is passing through the member.

C.

During passive monitoring, the SLA performance rule cannot detect dead members.

D.

After FortiGate switches to active mode, the SLA performance rule falls back to passive monitoring after 3 minutes.

E.

FortiGate passively monitors the member if TCP traffic is passing through the member.

Questions # 13:

SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.

Which three configuration elements must you configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)

Options:

A.

Firewall policies

B.

Security profiles

C.

Interfaces

D.

Routing

E.

Traffic shaping

Questions # 14:

In which order does a FortiGate device consider the following elements shown in the left column during the route lookup process?

Select the element in the left column, hold and drag it to a blank position in the column on the right. Place the four correct elements in order, placing the first element in the first position at the top of the column. Once you place an element, you can move it again if you want to change your answer before moving to the next question. You need to drop four elements in the work area.

Select and drag the screen divider to change the viewable area of the source and work areas.

Question # 14

Options:

Questions # 15:

Which two delivery methods are used for installing FortiClient on a user's laptop? (Choose two.)

Options:

A.

Use zero-touch installation through a third-party application store.

B.

Download the installer directly from the FortiSASE portal.

C.

Send an invitation email to selected users containing links to FortiClient installers.

D.

Configure automatic installation through an API to the user's laptop.

Questions # 16:

Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two answers)

Options:

A.

Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.

B.

Traffic does not match any of the entries in the policy route table.

C.

FortiGate flags the session with may_dirty and vwl_default.

D.

The traffic is distributed, regardless of weight, through all available static routes.

E.

The session information output displays no SD-WAN service id.

Questions # 17:

You are configuring SD-WAN to load balance network traffic. Which two facts should you consider when setting up SD-WAN? (Choose two.)

Options:

A.

When applicable, FortiGate load balances traffic through all members that meet the SLA target.

B.

SD-WAN load balancing is possible only when using the manual and the best quality strategies.

C.

Only the manual and lowest cost (SLA) strategies allow SD-WAN load balancing.

D.

You can select the outsessions hash mode with all strategies that allow load balancing.

Questions # 18:

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Question # 18

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member? (Choose one answer)

Options:

A.

When all three members have the same packet loss

B.

When HUB1-VPN1 has 4% packet loss

C.

When HUB1-VPN1 has 12% packet loss

D.

When HUB1-VPN3 has 4% packet loss

Questions # 19:

What is the purpose of the on/off-net rule setting in FortiSASE?

Options:

A.

To enable or disable user authentication for external network access.

B.

To define different traffic routing rules for on-premises and cloud-based resources.

C.

To determine if an endpoint is connecting from a trusted network or untrusted location.

D.

To configure different access policies for users based on their geographical location.

Questions # 20:

A FortiGate device is in production. To optimize WAN link use and improve redundancy, you enable and configure SD-WAN.

What must you do as part of this configuration update process? (Choose one answer)

Options:

A.

Replace references to interfaces used as SD-WAN members in the firewall policies.

B.

Replace references to interfaces used as SD-WAN members in the routing configuration.

C.

Disable the interface that you want to use as an SD-WAN member.

D.

Purchase and install the SD-WAN license, and reboot the FortiGate device.

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions