Practice Free NSE7_SSE_AR-26 Exam Online Questions
(Single Choice – BGP Routing & Redundancy)
An organization uses a dual-Hub FortiSASE SPA topology. The administrator wants to ensure that returning traffic from the corporate data center to the FortiSASE clients primarily traverses Hub A. Hub B should only be used if Hub A fails.
Which BGP attribute modification is the most appropriate to achieve this inbound traffic engineering?
- A . Apply a route map on Hub B to modify the Local Preference attribute to a higher value for all prefixes received from the FortiSASE POPs.
- B . Apply a route map on Hub B to artificially lengthen the AS-Path attribute for all internal network prefixes advertised to FortiSASE.
- C . Apply a route map on Hub A to modify the Multi-Exit Discriminator (MED) attribute to a significantly higher metric than Hub B.
- D . Apply a route map on Hub A to tag all incoming FortiSASE prefixes with a specific BGP community string recognized by the internal core switches.
(Single Choice – DEM Synthetic Probes)
FortiSASE Digital Experience Monitoring (DEM) relies on deploying synthetic probes to monitor application health.
When configuring a custom DEM monitor for a highly secure internal web application hosted in the corporate datacenter via SPA, which probe configuration methodology provides the most accurate reflection of the end-user’s application experience?
- A . Configure a standard ICMP Echo Request probe targeting the public IP address of the primary enterprise FortiGate Hub connecting the SPA tunnel.
- B . Configure an explicit HTTP GET probe targeting the internal FQDN of the web application, ensuring the expected HTTP 200 OK response code is validated.
- C . Configure a UDP-based DNS resolution probe targeting the FortiSASE cloud DNS servers to ensure they can successfully resolve the internal domain name.
- D . Configure a raw TCP Connect probe targeting port 443 on the enterprise FortiGate Hub’s internal LAN interface to verify firewall policy execution.
(Single Choice – DEM Synthetic Probes)
FortiSASE Digital Experience Monitoring (DEM) relies on deploying synthetic probes to monitor application health.
When configuring a custom DEM monitor for a highly secure internal web application hosted in the corporate datacenter via SPA, which probe configuration methodology provides the most accurate reflection of the end-user’s application experience?
- A . Configure a standard ICMP Echo Request probe targeting the public IP address of the primary enterprise FortiGate Hub connecting the SPA tunnel.
- B . Configure an explicit HTTP GET probe targeting the internal FQDN of the web application, ensuring the expected HTTP 200 OK response code is validated.
- C . Configure a UDP-based DNS resolution probe targeting the FortiSASE cloud DNS servers to ensure they can successfully resolve the internal domain name.
- D . Configure a raw TCP Connect probe targeting port 443 on the enterprise FortiGate Hub’s internal LAN interface to verify firewall policy execution.
(Single Choice – DEM Synthetic Probes)
FortiSASE Digital Experience Monitoring (DEM) relies on deploying synthetic probes to monitor application health.
When configuring a custom DEM monitor for a highly secure internal web application hosted in the corporate datacenter via SPA, which probe configuration methodology provides the most accurate reflection of the end-user’s application experience?
- A . Configure a standard ICMP Echo Request probe targeting the public IP address of the primary enterprise FortiGate Hub connecting the SPA tunnel.
- B . Configure an explicit HTTP GET probe targeting the internal FQDN of the web application, ensuring the expected HTTP 200 OK response code is validated.
- C . Configure a UDP-based DNS resolution probe targeting the FortiSASE cloud DNS servers to ensure they can successfully resolve the internal domain name.
- D . Configure a raw TCP Connect probe targeting port 443 on the enterprise FortiGate Hub’s internal LAN interface to verify firewall policy execution.
(Single Choice – DEM Synthetic Probes)
FortiSASE Digital Experience Monitoring (DEM) relies on deploying synthetic probes to monitor application health.
When configuring a custom DEM monitor for a highly secure internal web application hosted in the corporate datacenter via SPA, which probe configuration methodology provides the most accurate reflection of the end-user’s application experience?
- A . Configure a standard ICMP Echo Request probe targeting the public IP address of the primary enterprise FortiGate Hub connecting the SPA tunnel.
- B . Configure an explicit HTTP GET probe targeting the internal FQDN of the web application, ensuring the expected HTTP 200 OK response code is validated.
- C . Configure a UDP-based DNS resolution probe targeting the FortiSASE cloud DNS servers to ensure they can successfully resolve the internal domain name.
- D . Configure a raw TCP Connect probe targeting port 443 on the enterprise FortiGate Hub’s internal LAN interface to verify firewall policy execution.
(Single Choice – DEM Synthetic Probes)
FortiSASE Digital Experience Monitoring (DEM) relies on deploying synthetic probes to monitor application health.
When configuring a custom DEM monitor for a highly secure internal web application hosted in the corporate datacenter via SPA, which probe configuration methodology provides the most accurate reflection of the end-user’s application experience?
- A . Configure a standard ICMP Echo Request probe targeting the public IP address of the primary enterprise FortiGate Hub connecting the SPA tunnel.
- B . Configure an explicit HTTP GET probe targeting the internal FQDN of the web application, ensuring the expected HTTP 200 OK response code is validated.
- C . Configure a UDP-based DNS resolution probe targeting the FortiSASE cloud DNS servers to ensure they can successfully resolve the internal domain name.
- D . Configure a raw TCP Connect probe targeting port 443 on the enterprise FortiGate Hub’s internal LAN interface to verify firewall policy execution.
(Single Choice – Comprehensive SASE Blueprint Final Check)
A security architect must present a final SASE design to the CIO. The design requires zero-trust posture checks for managed corporate laptops, agentless web filtering for unmanaged contractor BYOD devices, and centralized site-to-site connectivity for headless IoT warehouse scanners.
Which combination of FortiSASE deployment methodologies completely satisfies this complex requirement?
- A . Agent-based mode for managed laptops, Agentless (PAC) mode for unmanaged BYOD devices, and Microbranch (FortiExtender) mode for the IoT warehouse scanners.
- B . Dedicated SPA Hubs for managed laptops, Agent-based mode for unmanaged BYOD devices, and ZTNA Access Proxy mode for the IoT warehouse scanners.
- C . Microbranch mode for all locations, overriding individual endpoint configurations via a centralized FortiManager global policy package.
- D . Agentless (PAC) mode for managed laptops, ZTNA Access Proxy for unmanaged BYOD devices, and Agent-based mode for the IoT warehouse scanners.
(Single Choice – SPA Hub-and-Spoke Routing)
An enterprise utilizes a FortiSASE SPA topology with a single FortiGate Hub in their main datacenter. A remote FortiSASE user (User A) needs to initiate an RDP session to another remote FortiSASE user (User B) for IT support purposes.
Assuming all firewall policies are correctly configured to allow this, how will the underlying network routing handle this specific connection?
- A . The FortiSASE cloud infrastructure will dynamically establish a direct, peer-to-peer ADVPN shortcut tunnel between the two endpoints to optimize latency.
- B . The traffic will be routed from User A to the FortiSASE POP, forwarded down the SPA tunnel to the enterprise Hub, and then routed back up the SPA tunnel to User B.
- C . The FortiSASE POP will recognize both endpoints are connected to the same cloud tenant and route the traffic directly within the POP’s internal switching fabric.
- D . The FortiClient software on User A’s machine will bypass the SASE tunnel entirely and attempt a direct public internet connection to User B’s current public IP address.
(Single Choice – Traffic Shaping in SASE)
An organization has noticed that a small number of FortiSASE remote users are consuming excessive bandwidth by downloading large ISO files from public repositories, severely impacting the performance of critical SaaS applications like Microsoft 365 for other users.
What is the most effective administrative action to remediate this within the FortiSASE architecture?
- A . Implement a strict BGP route map on the enterprise Hub to artificially deprioritize routes associated with known large file repositories.
- B . Configure a FortiSASE Security Profile with a Traffic Shaping policy, defining a maximum bandwidth guarantee for Microsoft 365 and a restrictive limit for generic web downloads.
- C . Deploy FortiClient endpoint configuration profiles via EMS to completely disable the background intelligent transfer service (BITS) on all remote machines.
- D . Adjust the SD-WAN SLA threshold on the FortiSASE POP to automatically drop user connections whenever the aggregated latency exceeds 150 milliseconds.
(Single Choice – ZTNA TCP Access Proxy Execution)
A remote user initiates a connection to an internal RDP server (rdp.corp.local) protected by a FortiSASE ZTNA TCP Access Proxy rule.
How does the local FortiClient agent handle this non-HTTP application connection?
- A . FortiClient intercepts the local RDP connection, verifies device posture, and encapsulates the TCP session in a secure TLS tunnel to the ZTNA proxy.
- B . FortiClient converts the raw RDP stream into an HTML5 web session and opens it automatically inside the endpoint’s default browser.
- C . FortiClient passes the RDP session unencrypted to the enterprise Hub over a raw GRE tunnel to eliminate processing overhead.
- D . FortiClient instructs the local operating system to build a direct point-to-point IPsec VPN connection targeting the RDP server IP.
