Practice Free NSE7_SSE_AR-26 Exam Online Questions
Identity Provider (IdP)
Responsibilities:
- A . Evaluates incoming application requests against security policies and verifies both the client certificate and dynamic tags before allowing the connection.
- B . Authenticates the user’s foundational credentials and provides assertion tokens validating the individual’s corporate identity and group memberships.
- C . Requests a unique device certificate upon registration, continuously monitors local operating system telemetry, and intercepts application requests.
- D . Acts as the central Certificate Authority for devices, evaluates telemetry against zero-trust rules, and dynamically assigns compliance tags.
Identity Provider (IdP)
Responsibilities:
- A . Evaluates incoming application requests against security policies and verifies both the client certificate and dynamic tags before allowing the connection.
- B . Authenticates the user’s foundational credentials and provides assertion tokens validating the individual’s corporate identity and group memberships.
- C . Requests a unique device certificate upon registration, continuously monitors local operating system telemetry, and intercepts application requests.
- D . Acts as the central Certificate Authority for devices, evaluates telemetry against zero-trust rules, and dynamically assigns compliance tags.
Manual
Behaviors:
- A . Distributes traffic across multiple participating links utilizing an ECMP hashing mechanism as long as all links meet the specified SLA targets.
- B . Selects the single participating link that currently exhibits the most optimal performance metrics regardless of predefined threshold targets.
- C . Forces traffic out of a explicitly specified interface in a rigid priority order, entirely ignoring any real-time link quality measurements.
- D . Selects the first available link in the interface preference list that successfully satisfies the defined latency, jitter, and packet loss SLA thresholds.
Manual
Behaviors:
- A . Distributes traffic across multiple participating links utilizing an ECMP hashing mechanism as long as all links meet the specified SLA targets.
- B . Selects the single participating link that currently exhibits the most optimal performance metrics regardless of predefined threshold targets.
- C . Forces traffic out of a explicitly specified interface in a rigid priority order, entirely ignoring any real-time link quality measurements.
- D . Selects the first available link in the interface preference list that successfully satisfies the defined latency, jitter, and packet loss SLA thresholds.
(Single Choice – SPA IPsec Overlay Design)
When implementing Secure Private Access (SPA) between the FortiSASE cloud environment and the enterprise on-premises infrastructure, what is the mandatory topological requirement for the IPsec VPN configuration?
- A . The deployment must utilize an Auto-Discovery VPN (ADVPN) architecture to allow dynamic shortcut tunnels between individual remote FortiSASE clients.
- B . The enterprise FortiGate must be configured as the IPsec Dialup Server (Responder), while the FortiSASE POPs act as the dynamic Dialup Clients (Initiators).
- C . Both the enterprise FortiGate and the FortiSASE POPs must be configured with static public IP addresses to establish a rigid Site-to-Site VPN overlay.
- D . The tunnel interfaces must be configured in Policy-Based VPN mode to ensure seamless integration with the FortiSASE cloud firewall inspection engines.
(Multiple Choice – BGP Community Routing Controls)
An enterprise operates two datacenters connected to FortiSASE via SPA IPsec tunnels. The administrator wants to control how the FortiSASE POPs route traffic to specific enterprise subnets without modifying AS-Path length or MED values.
Which TWO BGP configuration actions will allow the enterprise Hubs to selectively steer traffic using BGP Communities? (Choose two)
- A . Configure a BGP route map on the enterprise Hubs to tag outbound route advertisements with specific BGP community values corresponding to routing priorities.
- B . Configure FortiSASE to matching incoming BGP community tags and assign custom Local Preference values to influence internal cloud routing decisions.
- C . Enable BGP Graceful Restart on the FortiSASE cloud instances to automatically pass community attributes across non-connected Autonomous Systems.
- D . Configure the enterprise Hubs to strip all standard BGP communities before sending updates to ensure the FortiSASE POPs default to ECMP routing.
(Multiple Choice – BGP Community Routing Controls)
An enterprise operates two datacenters connected to FortiSASE via SPA IPsec tunnels. The administrator wants to control how the FortiSASE POPs route traffic to specific enterprise subnets without modifying AS-Path length or MED values.
Which TWO BGP configuration actions will allow the enterprise Hubs to selectively steer traffic using BGP Communities? (Choose two)
- A . Configure a BGP route map on the enterprise Hubs to tag outbound route advertisements with specific BGP community values corresponding to routing priorities.
- B . Configure FortiSASE to matching incoming BGP community tags and assign custom Local Preference values to influence internal cloud routing decisions.
- C . Enable BGP Graceful Restart on the FortiSASE cloud instances to automatically pass community attributes across non-connected Autonomous Systems.
- D . Configure the enterprise Hubs to strip all standard BGP communities before sending updates to ensure the FortiSASE POPs default to ECMP routing.
