Which FortiSASE feature monitors SaaS application performance and connectivity to points of presence (POPs)?
-
A
-
B
-
C
-
D
Digital experience monitoring
Reveal answer details
Close answer details
Correct answerD
ExplanationDigital experience monitoring is the FortiSASE feature focused on measuring user and application experience, including SaaS application performance and connectivity to FortiSASE points of presence. Operations widgets, FortiView dashboards, and event logs provide operational views or records, but they are not the feature dedicated to SaaS and POP experience monitoring.
Question 2
Multiple choice
An operations team is using FortiSASE analytics and endpoint vulnerability features. Which three statements are correct? (Choose three.)
-
A
The Shadow IT Report summarizes SaaS application usage, including sanctioned and unsanctioned SaaS applications.
-
B
The Web Usage Summary Report includes web usage and bandwidth information for endpoints.
-
C
The Vulnerability Summary widget can be used to drill down into CVE and severity details for affected endpoints.
-
D
FortiSASE reports are generated only from SD-WAN health-check latency and jitter results.
-
E
Automatic vulnerability patching applies to every application without endpoint profile configuration.
Reveal answer details
Close answer details
Correct answersA, B, C
ExplanationExplanation: The Shadow IT Report summarizes SaaS application usage, including sanctioned and unsanctioned application visibility. The Web Usage Summary Report provides web activity and bandwidth-oriented reporting. FortiSASE vulnerability views allow administrators to drill down into CVE, severity, and affected endpoint details. FortiSASE reporting is not generated only from SD-WAN health checks, and automatic patching is limited to supported or eligible vulnerabilities under configured workflows rather than every application automatically.
Question 3
Multiple choice
You are configuring SD-WAN to load balance network traffic. Which two facts should you consider when setting up SD-WAN? (Choose two.)
-
A
When applicable, FortiGate load balances traffic through all members that meet the SLA target.
-
B
SD-WAN load balancing is possible only when using the manual and the best quality strategies.
-
C
Only the manual and lowest cost (SLA) strategies allow SD-WAN load balancing.
-
D
You can select the outsessions hash mode with all strategies that allow load balancing.
Reveal answer details
Close answer details
Correct answersA, D
ExplanationWhen SD-WAN load balancing is enabled for a strategy that supports it, FortiGate can distribute sessions across members that satisfy the applicable SLA or rule conditions. The outgoing session hash mode is one of the configurable load balancing algorithms. Load balancing is not restricted only to the manual and best quality strategies, and it is not limited only to manual and lowest cost. The exact supported load balancing behavior depends on the selected strategy and rule configuration.
Question 4
Multiple choice
Which two methods can a FortiSASE administrator use to distribute FortiClient installers for managed endpoint onboarding? (Choose two.)
-
A
Download a preconfigured installer directly from the FortiSASE portal and distribute it to users.
-
B
Send invitation emails that include links to FortiClient installers and onboarding information.
-
C
Require each user to build a custom FortiClient installer from FortiOS CLI output.
-
D
Install FortiClient automatically by adding the endpoint to an SD-WAN performance SLA.
-
E
Use a PAC file as a replacement for the FortiClient installer package.
Reveal answer details
Close answer details
Correct answersA, B
ExplanationFortiSASE administrators can download installers from the portal and can send invitation emails containing installer links and onboarding information. These methods support provisioning managed endpoints with the correct invitation-code workflow. Users do not build FortiClient installers from FortiOS CLI output, SD-WAN SLA membership does not install endpoint software, and a PAC file is a proxy configuration artifact rather than an installer package.
An administrator wants FortiGate-generated IPv4 ping traffic to follow SD-WAN rules instead of relying only on the routing table. Which configuration approach is appropriate?
-
A
Configure ping local-out behavior to use SD-WAN, such as with execute ping-options use-sdwan yes.
-
B
Create an inbound firewall policy that allows ICMP from the WAN interface.
-
C
Enable explicit proxy on the SD-WAN zone.
-
D
Add the FortiGate management interface as an SD-WAN member.
Reveal answer details
Close answer details
Correct answerA
ExplanationPing generated by the FortiGate is local-out traffic, so it must be configured through the local-out ping options to use SD-WAN rules. An inbound firewall policy controls traffic entering the FortiGate from another device, not traffic sourced by the FortiGate itself. Explicit proxy configuration and adding the management interface as an SD-WAN member do not make FortiGate-originated ping follow SD-WAN rules.
Question 6
Multiple choice
Which three FortiSASE use cases are possible? (Choose three answers)
-
A
Secure Internet Access (SIA)
-
B
-
C
Secure Private Access (SPA)
-
D
-
E
Secure Browser Access (SBA)
Reveal answer details
Close answer details
Correct answersA, B, C
ExplanationFortiSASE use cases include Secure Internet Access for internet-bound traffic, Secure SaaS Access for SaaS applications, and Secure Private Access for access to private applications. Secure VPN Access and Secure Browser Access are not the named primary FortiSASE use cases in this set. The distinction matters because FortiSASE separates internet security, SaaS visibility and control, and private application access functions.
Question 7
Multiple choice
Which two statements about configuring a steering bypass destination in FortiSASE are correct? (Choose two.)
-
A
Subnet is the only destination type that supports the Apply condition
-
B
Apply condition allows split tunneling destinations to ae applied to On-net. off-net. or both types of endpoints
-
C
You can select from four destination types: Infrastructure, FQDN, Local Application, or Subnet
-
D
Apply condition can be set only to On-net or Off-net. but not both
Reveal answer details
Close answer details
Correct answersB, C
ExplanationFortiSASE steering bypass destinations support destination types such as Infrastructure, FQDN, Local Application, and Subnet. The Apply condition controls whether the bypass destination applies to on-net endpoints, off-net endpoints, or both. Subnet is not the only destination type with applicability controls, and the setting is not limited to only one of on-net or off-net when both can be selected.
|