NSE7_SSE_AD-25 Fortinet NSE 7 - FortiSASE 25 Enterprise Administrator Practice Questions
Prepare for NSE7_SSE_AD-25 with more than an answer.
- Exam fee
- $200 USD
- Level
- Expert (NSE 7)
- Valid for
- 2 years
Domains covered on the exam 4
- SASE Architecture and Integration25%
- SASE Deployment and Management30%
- Secure Private Access (SPA)30%
- Analytics and Troubleshooting15%
- 1
When configuring a Web Filter profile in FortiSASE, which action should be selected to allow a user to access a blocked category only after they acknowledge a warning message?
Show answer details
Correct answer: B
The 'Warning' action in a Web Filter profile presents the user with a notification page stating the site is blocked/discouraged, but provides a button to 'Proceed' or 'Accept', allowing access after acknowledgment.
- 2
Which component is responsible for enforcing compliance rules on an endpoint before it is allowed to connect to the FortiSASE tunnel?
Show answer details
Correct answer: A
FortiClient running on the endpoint checks the device's posture (AV status, OS patches, etc.) against the compliance rules received from EMS/FortiSASE. If the device is non-compliant, FortiClient can block the connection or move the device to a remediation VLAN/status.
- 3
Select TWO valid methods for deploying the FortiClient installer to remote Windows endpoints in a managed environment. (Select TWO)
Show answer details
Correct answer: A, C
Enterprise deployments often use MDM solutions like Microsoft Intune to push the FortiClient MSI installer silently to managed devices.
GPO is a standard method for deploying software in Active Directory environments. The FortiClient MSI can be assigned to computers via GPO for automatic installation.
- 4
A deployment requires that FortiClient automatically connects the VPN tunnel whenever the user is outside the corporate network ('Always On'). Which configuration setting controls this behavior?
Show answer details
Correct answer: A
The Endpoint Profile (configured in FortiSASE/EMS) defines On-net (inside corporate network) and Off-net (outside) detection rules. 'Always On' VPN is triggered when the client detects it is 'Off-net'.
- 5
What is the purpose of the 'Deep Inspection' (SSL Inspection) profile in FortiSASE security policies?
Show answer details
Correct answer: B
Deep Inspection acts as a Man-in-the-Middle. It decrypts the SSL/TLS encrypted traffic from the user, allowing engines like Antivirus, Intrusion Prevention, and Data Loss Prevention to scan the actual content (payload) for malware or sensitive data, then re-encrypts it to the destination.
- 6
Which mechanism is used to install the FortiSASE CA certificate on endpoints to prevent browser security warnings during Deep SSL Inspection?
Show answer details
Correct answer: B
To avoid browser warnings ('Connection is not private'), the CA certificate used by FortiSASE for re-encryption must be trusted by the endpoint. The standard enterprise method is pushing this CA cert to the 'Trusted Root Certification Authorities' store using management tools like GPO or MDM.
- 7
You are configuring a DLP (Data Loss Prevention) profile in FortiSASE to prevent employees from uploading credit card numbers to cloud storage. Which sensor type should you configure?
Show answer details
Correct answer: B
A Data Pattern Sensor allows you to define patterns (like Credit Card numbers using Luhn algorithm or Regex) to scan the content of files or traffic. This is the correct sensor for detecting sensitive data inside traffic.
- 8
An architect is designing a FortiSASE solution for a global retail company with 500 remote users and 20 branch offices. The branches currently use FortiGate SD-WAN. The goal is to secure internet access for all remote users while ensuring optimal performance for latency-sensitive SaaS applications like Microsoft 365. Which architectural approach best meets these requirements?
Show answer details
Correct answer: B
Connecting remote users to the nearest FortiSASE PoP ensures security inspection for general internet traffic. However, for latency-sensitive SaaS applications like Microsoft 365, best practice is to offload trusted traffic directly to the internet using Split Tunneling to avoid the additional latency of hair-pinning through the SASE cloud.
- 9
A multinational corporation is integrating its existing FortiGate SD-WAN infrastructure with FortiSASE to provide Secure Private Access (SPA) to internal resources. Which configuration object is essential on the FortiGate Hub to allow FortiSASE to dynamically route traffic to the correct internal subnets?
Show answer details
Correct answer: B
To enable dynamic routing and reachability between the FortiSASE cloud and the on-premises network behind a FortiGate Hub, BGP is required. The FortiGate must peer with the FortiSASE gateway to advertise internal subnets so remote users can reach them via SPA.
- 10
When designing a Secure Private Access (SPA) solution using FortiSASE, which TWO components are required to establish the data plane connection between the FortiSASE cloud and the customer's on-premises data center? (Select TWO)
Show answer details
Correct answer: B, C
An IPsec VPN tunnel is the primary method for establishing a secure connection between the FortiSASE cloud PoP and the customer's FortiGate at the data center.
A FortiGate (or another IPsec-capable device) is required at the edge of the customer network to terminate the IPsec tunnel from FortiSASE.
