NSE5_SSE_AD-7.6 Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Practice Questions
Prepare for NSE5_SSE_AD-7.6 with more than an answer.
- Exam fee
- $200 USD
- Time limit
- 65 minutes
- Questions on the exam
- 30-35
- Passing score
- Pass/Fail (threshold not publicly disclosed)
- Level
- Professional (FCP)
- Valid for
- 2 years
Domains covered on the exam 5
- Decentralized SD-WAN25%
- Rules and Routing20%
- SASE Deployment25%
- Secure Internet Access (SIA) and Secure SaaS Access (SSA)15%
- Analytics15%
- 1
Regarding the SD-WAN Route Lookup process in FortiOS, which statement is correct about the precedence of SD-WAN rules compared to the routing table?
Show answer details
Correct answer: C
FortiOS first checks the routing table to ensure a valid route exists to the destination. If a route exists (e.g., a default route 0.0.0.0/0 via SD-WAN members), only then does it evaluate SD-WAN rules to select the specific egress interface. SD-WAN rules do not create routes; they steer traffic among existing routes.
- 2
A company requires that all traffic from the 'Engineering' user group is inspected for DLP compliance, while 'Sales' traffic is only scanned for malware. Both groups are remote and use FortiClient connected to FortiSASE.
How should the administrator configure the policies in FortiSASE to achieve this?
Show answer details
Correct answer: A
FortiSASE allows granular policy creation based on Source User Groups. By creating specific policies for 'Engineering' and 'Sales' and placing them in correct priority order, different security profiles (like DLP) can be applied to each group.
- 3
The 'Lowest Cost (SLA)' strategy in FortiOS SD-WAN differs from the standard 'Lowest Cost' strategy in which key aspect?
Show answer details
Correct answer: C
Lowest Cost (SLA) filters the available members first by SLA compliance. Among those that pass the SLA check, it then selects the one with the lowest assigned cost (or priority/order if costs are equal). Standard 'Lowest Cost' does not strictly enforce an SLA pre-check in the same way.
- 4
A multinational retail corporation is deploying Fortinet Secure SD-WAN across 500 locations. Each location has two WAN links: a high-cost, low-latency MPLS link (Member A) and a low-cost, high-bandwidth Broadband link (Member B). The administrator creates an SD-WAN zone named 'Overlay' containing both members.
The requirement is to route VoIP traffic over the MPLS link unless its latency exceeds 50ms, in which case it should fail over to Broadband. For all other traffic, the Broadband link should be used unless it is down.
Which combination of SD-WAN Rule configurations fulfills this requirement?
Show answer details
Correct answer: C
The 'Lowest Cost (SLA)' strategy is ideal here. It respects the interface preference (MPLS) as long as the SLA (50ms latency) is met. If the SLA fails, it switches to the next available member (Broadband) if configured in the preference list or based on cost. For the remaining traffic, a Manual or implicit rule preferring Broadband satisfies the second requirement.
- 5
An administrator is configuring a Performance SLA on a FortiGate SD-WAN device to monitor connectivity to a cloud-based CRM application. The application does not respond to ICMP pings, but it exposes a REST API health endpoint.
Which protocol should the administrator select for the Health Check probe to accurately monitor the application's availability?
Show answer details
Correct answer: C
The HTTP (or HTTPS) probe is designed to monitor web-based services. It can send a GET or HEAD request to a specific URL (the health endpoint) and validate the response code. Since the application blocks ICMP, Ping would fail even if the app is up.
- 6
A network architect is designing a FortiSASE solution for a remote workforce. The organization uses Microsoft Entra ID (formerly Azure AD) as their Identity Provider (IdP). The goal is to allow users to authenticate to FortiSASE using their existing credentials without requiring a separate user database on FortiSASE.
Which configuration step is essential to achieve this integration?
Show answer details
Correct answer: B
SAML SSO is the standard method for federating identity between FortiSASE and cloud IdPs like Entra ID. FortiSASE acts as the SP, redirecting authentication requests to the IdP, which validates credentials and returns a SAML assertion.
