Practice Free NSE7_SSE_AR-26 Exam Online Questions
Manual Priority
Business Requirements:
- A . Ensure mission-critical voice traffic (VoIP) always dynamically selects the single link with the lowest real-time latency across all available overlays.
- B . Aggregates capacity by load-balancing file transfers across all healthy links that currently meet the baseline performance SLA.
- C . Route general traffic through the primary low-cost ISP link as long as it satisfies basic SLA criteria, avoiding unnecessary link flapping.
- D . Strictly force administrative backup traffic through a dedicated secondary link regardless of real-time latency or packet loss metrics.
(Multiple Choice – SSL Deep Inspection Exemptions)
An administrator enables SSL Deep Inspection on all outbound FortiSASE Secure Internet Access (SIA) policies. Shortly after, users report that both the Zoom desktop client and mobile banking applications fail to connect.
Which TWO actions should the architect implement to resolve these application failures securely? (Choose two)
- A . Disable SSL Deep Inspection globally across the entire FortiSASE tenant and fall back exclusively to basic URL filtering.
- B . Create explicit SSL inspection exemption rules targeting the specific application categories or FQDNs for Zoom and banking services.
- C . Add the root CA certificate of the Zoom application servers into the local trusted root certificate store of all FortiClient endpoints.
- D . Ensure that the default FortiGuard Certificate Inspection profile is applied to traffic matching certificate-pinned applications.
(Multiple Choice – SSL Deep Inspection Exemptions)
An administrator enables SSL Deep Inspection on all outbound FortiSASE Secure Internet Access (SIA) policies. Shortly after, users report that both the Zoom desktop client and mobile banking applications fail to connect.
Which TWO actions should the architect implement to resolve these application failures securely? (Choose two)
- A . Disable SSL Deep Inspection globally across the entire FortiSASE tenant and fall back exclusively to basic URL filtering.
- B . Create explicit SSL inspection exemption rules targeting the specific application categories or FQDNs for Zoom and banking services.
- C . Add the root CA certificate of the Zoom application servers into the local trusted root certificate store of all FortiClient endpoints.
- D . Ensure that the default FortiGuard Certificate Inspection profile is applied to traffic matching certificate-pinned applications.
(Single Choice – DEM Metrics Isolation)
An administrator is using FortiSASE Digital Experience Monitoring (DEM) to investigate complaints of slow SaaS application access. The DEM portal shows high total transaction times. The network latency metric is 15ms, the DNS resolution time is 8ms, but the HTTP Response Time metric is 850ms.
What does this telemetry indicate regarding the root cause of the performance bottleneck?
- A . The physical SPA IPsec tunnel between the FortiSASE POP and the corporate datacenter is suffering from severe packet corruption.
- B . The local internet service provider connected to the remote user’s home network is heavily throttling outbound DNS traffic.
- C . The performance issue is located entirely on the SaaS application server side or its backend database processing logic.
- D . The FortiClient endpoint operating system is experiencing severe CPU exhaustion caused by the local FortiClient agent.
(Single Choice – DEM Metrics Isolation)
An administrator is using FortiSASE Digital Experience Monitoring (DEM) to investigate complaints of slow SaaS application access. The DEM portal shows high total transaction times. The network latency metric is 15ms, the DNS resolution time is 8ms, but the HTTP Response Time metric is 850ms.
What does this telemetry indicate regarding the root cause of the performance bottleneck?
- A . The physical SPA IPsec tunnel between the FortiSASE POP and the corporate datacenter is suffering from severe packet corruption.
- B . The local internet service provider connected to the remote user’s home network is heavily throttling outbound DNS traffic.
- C . The performance issue is located entirely on the SaaS application server side or its backend database processing logic.
- D . The FortiClient endpoint operating system is experiencing severe CPU exhaustion caused by the local FortiClient agent.
(Single Choice – ZTNA Access Proxy vs IPsec Overlay)
An organization needs to secure access to a legacy client-server application that uses a proprietary TCP protocol. The architect must decide between deploying a ZTNA TCP Access Proxy or routing the application traffic over an SPA IPsec tunnel.
Which technical factor strictly mandates using the SPA IPsec overlay instead of the ZTNA Access Proxy?
- A . The proprietary application requires the remote FortiClient endpoint to perform deep SSL inspection on all outbound server responses.
- B . The application relies on server-initiated incoming connections (back-connects) directly from the datacenter back to the remote endpoint client.
- C . The remote user endpoints are unmanaged contractor laptops that do not have the FortiClient endpoint agent installed.
- D . The application server infrastructure is hosted across multiple cloud providers requiring dynamic BGP route reflections.
(Single Choice – ZTNA Access Proxy vs IPsec Overlay)
An organization needs to secure access to a legacy client-server application that uses a proprietary TCP protocol. The architect must decide between deploying a ZTNA TCP Access Proxy or routing the application traffic over an SPA IPsec tunnel.
Which technical factor strictly mandates using the SPA IPsec overlay instead of the ZTNA Access Proxy?
- A . The proprietary application requires the remote FortiClient endpoint to perform deep SSL inspection on all outbound server responses.
- B . The application relies on server-initiated incoming connections (back-connects) directly from the datacenter back to the remote endpoint client.
- C . The remote user endpoints are unmanaged contractor laptops that do not have the FortiClient endpoint agent installed.
- D . The application server infrastructure is hosted across multiple cloud providers requiring dynamic BGP route reflections.
(Multiple Choice – DEM Performance Metrics)
FortiSASE provides Digital Experience Monitoring (DEM) to quickly isolate application access performance bottlenecks for remote users.
Which TWO core network telemetry metrics does DEM primarily collect from the client’s underlying transport to calculate the overall application health score? (Choose two)
- A . Total BGP route convergence time.
- B . End-to-end network latency.
- C . Average packet loss rate.
- D . Real-time concurrent IPS sessions
(Single Choice – SAML Attribute Mapping)
An administrator wants to apply different levels of web filtering policies in FortiSASE based on the departments (e.g., IT, HR, Sales) employees belong to in Azure AD.
When using SAML authentication, what is the best practice and lowest-overhead method to achieve this?
- A . Manually create local user groups for each department within FortiSASE and manually update these mappings every time a new employee is onboarded.
- B . Enable Group Attribute Mapping in the FortiSASE SAML configuration to dynamically map IdP department claims to the respective cloud security policies.
- C . Deploy separate and independent FortiClient EMS tenant instances for each internal department to isolate their respective web filtering configurations.
- D . Configure a local RADIUS server on the FortiSASE gateway that points directly to an internal corporate NPS server for secondary policy verification.
(Multiple Choice – Advanced SD-WAN Failover over SPA)
An enterprise utilizes a dual-Hub SPA topology. The primary Hub fails abruptly, but remote users experience a sustained network outage before traffic routes through the secondary Hub. The administrator wants to accelerate this failover without relying on BFD (Bidirectional Forwarding Detection).
Which TWO BGP and SD-WAN configuration adjustments should be implemented? (Choose two)
- A . Decrease the consecutive failure threshold on the SD-WAN Performance SLA probe monitoring the primary SPA tunnel.
- B . Configure the BGP Graceful Restart capability on both the enterprise FortiGate Hubs and the FortiSASE cloud portals.
- C . Decrease the BGP Keepalive timer and the BGP Hold timer within the routing configuration of the enterprise Hubs.
- D . Increase the initial packet delay threshold within the implicit SD-WAN routing rule for the secondary SPA IPsec tunnel.
