A financial services company requires that all remote endpoints connecting via FortiSASE have their disk encryption enabled and an up-to-date EDR agent running. If a device fails these checks, it must be quarantined to a remediation network with limited access. Which FortiSASE components are essential for enforcing this conditional access policy?
Answer and explanation
Correct answer: B
FortiClient EMS is used to manage and report on the posture of endpoints. FortiSASE security posture checks leverage this information to verify compliance. A ZTNA access rule can then apply a specific action, such as quarantining the device by redirecting it to a remediation portal or network if it fails the posture check. The other options are not directly involved in endpoint compliance enforcement.
Question 2
A security analyst at a retail company is reviewing FortiSASE traffic logs. They observe a series of small, encrypted DNS queries to various seemingly random subdomains of a single, non-corporate domain from multiple endpoints. This is followed by small outbound TCP connections to an IP address associated with that domain. This pattern of activity is most indicative of which type of threat?
Answer and explanation
Correct answer: C
The use of many random subdomains for DNS queries is a classic indicator of DNS tunneling, a technique used by malware to establish a covert Command and Control (C2) channel by encoding data within DNS requests. The small, subsequent TCP connections further support this, representing the actual data exfiltration or command reception. Brute-force, DDoS, and standard proxy usage have different and more distinct log signatures.
Question 3
A manufacturing company is extending its corporate network to remote workers using FortiSASE. They have a central FortiGate NGFW at their headquarters. The goal is for remote users to appear as if they are on the local corporate network, using an IP from the internal DHCP scope, to access legacy applications that use Layer 2 discovery protocols. Which VDOM type must be configured on the headquarters' FortiGate to achieve this Layer 2 network extension with FortiSASE?
Answer and explanation
Correct answer: C
The LAN-Extension VDOM type is specifically designed to create a Layer 2 tunnel between a FortiGate (acting as the Secure Edge) and FortiSASE. This allows remote clients to be part of the same broadcast domain as the internal network, receive IPs from the local DHCP server, and use Layer 2 protocols for discovery and communication. Other VDOM types do not provide this Layer 2 extension capability.
Question 4
True or False: FortiSASE Secure Private Access (SPA) is exclusively used for providing access to web-based applications hosted in a private data center.
Answer and explanation
Correct answer: B
Secure Private Access (SPA) is designed to provide secure access to corporate applications, particularly non-web applications, hosted in private data centers or IaaS environments. It utilizes technologies like ZTNA and SD-WAN to secure access to services using protocols beyond HTTP/S, such as RDP, SSH, and other TCP/UDP-based applications.
Question 5
Multiple answers
A global consulting firm is onboarding users to FortiSASE. They want to streamline the process by integrating with their existing identity provider and ensure a consistent user experience across company-issued laptops and personal mobile devices. Which two methods should the administrator configure to meet these user onboarding requirements? (Select TWO)
Answer and explanation
Correct answers: B, C
Integrating with a SAML IdP (like Azure AD or Okta) allows for seamless authentication using existing corporate credentials, which streamlines the user experience and centralizes identity management.
Deploying FortiClient via an email invitation link is a standard and effective method for getting the agent onto both managed and unmanaged (BYOD) devices, which is necessary for enforcing SASE policies consistently.
Question 6
HealthForward, a large healthcare provider, is migrating its 10,000 remote clinicians and administrative staff to FortiSASE. Their primary goals are to enforce HIPAA compliance for all internet-bound traffic, prevent data exfiltration of Patient Health Information (PHI), and secure access to both modern SaaS applications (like Office 365) and legacy clinical applications hosted in their on-premises data center. The legacy applications are not web-based and require direct TCP/UDP connectivity.
The CISO has mandated a stringent security posture. All traffic, including to trusted SaaS vendors, must be inspected for threats and data loss. Clinicians often work from untrusted networks, so endpoint compliance is critical; devices must have active antivirus and full-disk encryption. Furthermore, to simplify auditing and interactions with external partners who have IP-based allow-lists, all traffic from the finance department must originate from a single, predictable public IP address, regardless of where the user is located.
The network team has been tasked with implementing a solution that meets all these requirements without significantly impacting user experience, especially for latency-sensitive clinical applications. They must use FortiSASE's native capabilities to achieve this.
Which combination of FortiSASE configurations best addresses all of HealthForward's security and compliance requirements?
Answer and explanation
Correct answer: B
This option correctly addresses all requirements: 1) SPA with ZTNA is the correct method for securing non-web legacy applications. 2) A separate policy with SSL deep inspection, a DLP profile to monitor for PHI, and Application Control is essential for enforcing HIPAA compliance. 3) A Dedicated IP with Source IP Anchoring is the specific feature designed to make a group of users appear from a single, static public IP address. 4) Security posture checks are the mechanism for verifying endpoint compliance (AV, disk encryption).
Question 7
Multiple answers
An administrator needs to configure FortiSASE logging to meet strict data privacy regulations. The requirements are to retain security event logs for one year, traffic logs for 90 days, and to minimize the storage of personally identifiable information (PII) where possible. Which two actions should the administrator take in the logging settings? (Select TWO)
Answer and explanation
Correct answers: A, C
Enabling log anonymization is a direct method to minimize the storage of PII within the logs, helping to meet data privacy requirements.
FortiSASE allows for granular control over retention periods for different log types. Configuring separate periods for security (365 days) and traffic (90 days) logs directly meets the specified requirements.
Question 8
A FortiSASE administrator is troubleshooting a ZTNA connection issue for a remote user. The user can authenticate successfully, but cannot access the protected application. The administrator wants to view real-time debugging information for the ZTNA application gateway. Which FortiOS CLI command is used for this purpose?
Answer and explanation
Correct answer: C
The diagnose debug application ztna -1 command enables real-time debugging for the ZTNA application process. This allows an administrator to see detailed connection information, policy evaluation, and potential errors as the user attempts to connect, which is essential for troubleshooting.
Question 9
What is the primary architectural benefit of integrating FortiSASE with an existing Fortinet SD-WAN deployment at branch offices?
Answer and explanation
Correct answer: C
Integrating FortiSASE with on-premises FortiGate SD-WAN creates a hybrid SASE solution. This allows the organization to apply consistent security policies and profiles (like web filtering, IPS, and DLP) to users whether they are working from a branch office (protected by the FortiGate) or remotely (protected by FortiSASE), ensuring a unified security posture.
Question 10
A company has configured a dedicated IP address in FortiSASE for source IP anchoring. The goal is to ensure that traffic from their European sales team always exits to the internet from a specific IP address when accessing a partner's SaaS platform. After configuration, the sales team reports that their traffic is still egressing from the general shared IP pool. What is the most likely configuration error?
Answer and explanation
Correct answer: B
Simply provisioning a dedicated IP address is not enough. For source IP anchoring to function, a central SNAT policy must be created. This policy explicitly maps source traffic identifiers (like a user group for the European sales team) to the specific dedicated IP address for outbound traffic. Without this policy, FortiSASE will use the default shared IP pool.