Practice Free NSE7_SSE_AR-26 Exam Online Questions
(Multiple Choice – Advanced SD-WAN Failover over SPA)
An enterprise utilizes a dual-Hub SPA topology. The primary Hub fails abruptly, but remote users experience a sustained network outage before traffic routes through the secondary Hub. The administrator wants to accelerate this failover without relying on BFD (Bidirectional Forwarding Detection).
Which TWO BGP and SD-WAN configuration adjustments should be implemented? (Choose two)
- A . Decrease the consecutive failure threshold on the SD-WAN Performance SLA probe monitoring the primary SPA tunnel.
- B . Configure the BGP Graceful Restart capability on both the enterprise FortiGate Hubs and the FortiSASE cloud portals.
- C . Decrease the BGP Keepalive timer and the BGP Hold timer within the routing configuration of the enterprise Hubs.
- D . Increase the initial packet delay threshold within the implicit SD-WAN routing rule for the secondary SPA IPsec tunnel.
Enterprise Hub IPsec Certificate
Technical Functions:
- A . Installed on the user’s browser to prevent SSL warning errors when the SASE gateway intercepts and decrypts outbound HTTPS web traffic.
- B . Used by the FortiSASE cloud instances to cryptographically authenticate the identity of the on-premises datacenter firewall during Phase 1 tunnel negotiation.
- C . Issued by FortiClient EMS and presented by the endpoint to the Access Proxy to prove the device is a managed corporate asset.
- D . Used by the FortiSASE Service Provider portal to cryptographically verify that the authentication assertion actually originated from Azure AD or Okta.
Enterprise Hub IPsec Certificate
Technical Functions:
- A . Installed on the user’s browser to prevent SSL warning errors when the SASE gateway intercepts and decrypts outbound HTTPS web traffic.
- B . Used by the FortiSASE cloud instances to cryptographically authenticate the identity of the on-premises datacenter firewall during Phase 1 tunnel negotiation.
- C . Issued by FortiClient EMS and presented by the endpoint to the Access Proxy to prove the device is a managed corporate asset.
- D . Used by the FortiSASE Service Provider portal to cryptographically verify that the authentication assertion actually originated from Azure AD or Okta.
Enterprise Hub IPsec Certificate
Technical Functions:
- A . Installed on the user’s browser to prevent SSL warning errors when the SASE gateway intercepts and decrypts outbound HTTPS web traffic.
- B . Used by the FortiSASE cloud instances to cryptographically authenticate the identity of the on-premises datacenter firewall during Phase 1 tunnel negotiation.
- C . Issued by FortiClient EMS and presented by the endpoint to the Access Proxy to prove the device is a managed corporate asset.
- D . Used by the FortiSASE Service Provider portal to cryptographically verify that the authentication assertion actually originated from Azure AD or Okta.
(Single Choice – FortiClient Split Tunneling Impact)
An organization enables "Split Tunneling" in the FortiSASE FortiClient profile, specifying that only traffic destined for internal corporate subnets (10.0.0.0/8) should be routed into the SASE tunnel. All other traffic should go directly to the local ISP.
What is the primary security trade-off associated with this architectural decision?
- A . Remote endpoints will be completely unable to resolve internal corporate domain names using the enterprise DNS servers.
- B . FortiSASE Secure Internet Access (SIA) security profiles (Web Filter, AV, IPS, DLP) will be completely bypassed for all public internet browsing.
- C . The enterprise FortiGate Hub will be forced to perform Source NAT (SNAT) on all returning traffic from the internal corporate network.
- D . ZTNA device posture tags will cease to synchronize between FortiClient EMS and the FortiSASE cloud gateway.
(Multiple Choice – Secure Private Access DNS)
A remote user is connected to FortiSASE via Agent-based mode and is attempting to access an internal corporate server using its fully qualified domain name (server1.internal.corp). The DNS resolution is failing.
Which TWO configurations must be correctly implemented to ensure FortiSASE can resolve these internal corporate domains over the SPA tunnel? (Choose two)
- A . A split DNS rule must be configured in FortiSASE, explicitly defining internal.corp and pointing it to the IP addresses of the internal enterprise DNS servers.
- B . A BGP route for the specific subnet containing the internal enterprise DNS servers must be advertised from the Hub to the FortiSASE POPs.
- C . The FortiClient endpoint must be manually configured with a secondary network adapter strictly dedicated to querying the internal DNS servers.
- D . The enterprise FortiGate Hub must have a DNS translation policy configured to rewrite all incoming public DNS requests to the internal suffix.
(Multiple Choice – SD-WAN SLA Probe Behavior)
An administrator configures an SD-WAN Performance SLA probe in FortiOS to monitor an SPA tunnel utilizing an HTTP GET request.
What TWO specific technical requirements must be satisfied for this specific type of SLA probe to successfully report the link as "Alive" and healthy? (Choose two)
- A . The target web server must successfully receive the HTTP GET request and respond with a valid HTTP status code, explicitly confirming application-layer responsiveness.
- B . The underlying network infrastructure must establish a successful three-way TCP handshake over port 80 or 443 with the specified target IP address before sending the GET request.
- C . The target web server must present a digitally signed HTML payload that precisely matches a pre-configured hash value stored within the FortiSASE SD-WAN health check profile.
- D . The intermediate internet service provider must explicitly permit unencrypted ICMP echo requests to traverse the network alongside the application-layer HTTP probe packets.
(Multiple Choice – Endpoint Logging and Telemetry)
To meet compliance audits, a security administrator needs to verify exactly which ZTNA tags a specific FortiClient endpoint was presenting during a failed application access attempt yesterday.
Which TWO centralized components hold historical logging data regarding endpoint ZTNA tag assignments and policy evaluation results? (Choose two)
- A . The local Windows Event Viewer application logs residing directly on the user’s specific endpoint hard drive.
- B . The centralized FortiAnalyzer appliance configured to receive real-time traffic and security event logs from the FortiSASE gateways.
- C . The Azure AD (Entra ID) sign-in logs portal tracking the SAML authentication assertions issued during the proxy access request.
- D . The FortiClient EMS server console containing the historical endpoint telemetry records and device posture compliance events.
(Multiple Choice – FortiClient Profile Management)
An organization utilizes FortiClient EMS to centrally manage SASE endpoints. The security team wants to ensure that remote users cannot tamper with the active FortiClient configuration or manually disconnect the SASE tunnel.
Which TWO specific configuration enforcement mechanisms must be applied within the EMS Endpoint Profile? (Choose two)
- A . The administrator must enable the "Require Password to Disconnect" feature within the VPN profile to prevent unauthorized manual termination of the active SASE IPsec connection.
- B . The administrator must mandate the installation of a secondary, non-removable FortiCASB agent specifically designed to monitor and lock the local operating system network configuration settings.
- C . The administrator must actively deploy the "Lock Configuration" setting within the System Settings profile to prevent users from altering the local endpoint security application parameters.
- D . The administrator must enforce a strict Application Control policy within the FortiSASE portal that globally denies execution of the Windows Task Manager and command prompt tools.
(Drag and Drop /Ordering – Agentless SWG Auth Sequence)
Arrange the following technical processes in the exact chronological sequence they occur when an unauthenticated remote user attempts to access a public website using the FortiSASE Agentless (PAC file) Explicit Proxy mode.
Steps:
- A . The user enters their corporate credentials into the IdP login portal, and the IdP issues a signed SAML assertion token back to the user’s local web browser.
- B . The FortiSASE proxy intercepts the initial HTTP request, detects a lack of authentication context, and redirects the browser to the configured SAML Identity Provider (IdP).
- C . The user’s web browser receives the Proxy Auto-Configuration (PAC) file and routes the outbound internet web request directly to the nearest FortiSASE proxy endpoint.
- D . The FortiSASE proxy validates the SAML token, associates the authenticated user identity with the session, and applies the corresponding web filtering security policy.
