Weekend Sale Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save75geek

NSE5_SSE_AD-7.6 Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator Questions and Answers

Questions 4

Refer to the exhibit.

The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.

The administrator wants to know through which interface FortiGate will steer traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the social media application Facebook.

Based on the exhibits, which two statements are correct? (Choose two.)

Options:

A.

FortiGate steers traffic for social media applications according to the service rule 2 and steers traffic through port2.

B.

There is no service defined for the Facebook application, so FortiGate applies service rule 3 and directs the traffic to headquarters.

C.

When FortiGate cannot recognize the application of the flow, it load balances the traffic through the tunnels HQ_T1, HQ_T2, HQ_T3.

D.

When FortiGate cannot recognize the application of the flow, it steers the traffic through the preferred member of rule 3, HQ_T1.

Buy Now
Questions 5

Which statement is true about scheduling a FortiClient upgrade using an endpoint upgrade rule?

Options:

A.

If the scheduled time is already past in the local time zone of the endpoint, installation starts the next day at that time.

B.

An endpoint upgrade rule can be assigned to a user group.

C.

When scheduled, the installation always starts immediately if the endpoint is online.

D.

Scheduled upgrades automatically reboot macOS endpoints after installation.

Buy Now
Questions 6

Which three FortiSASE use cases are possible? (Choose three answers)

Options:

A.

Secure Internet Access (SIA)

B.

Secure SaaS Access (SSA)

C.

Secure Private Access (SPA)

D.

Secure VPN Access (SVA)

E.

Secure Browser Access (SBA)

Buy Now
Questions 7

Which two statements about configuring a steering bypass destination in FortiSASE are correct? (Choose two.)

Options:

A.

Subnet is the only destination type that supports the Apply condition

B.

Apply condition allows split tunneling destinations to ae applied to On-net. off-net. or both types of endpoints

C.

You can select from four destination types: Infrastructure, FQDN, Local Application, or Subnet

D.

Apply condition can be set only to On-net or Off-net, but not both

Buy Now
Questions 8

Which authentication method overrides any other previously configured user authentication on FortiSASE?

Options:

A.

Local

B.

SSO

C.

RADIUS

D.

MFA

Buy Now
Questions 9

Which three authentication sources support secure identity verification and access control for FortiSASE remote users? (Choose three.)

Options:

A.

Security Assertion Markup Language (SAML)

B.

OpenID Connect (OIDC)

C.

Lightweight Directory Access Protocol (LDAP)

D.

Terminal Access Controller Access-Control System Plus (TACACS+)

E.

Remote Authentication Dial-In User Service (RADIUS)

Buy Now
Questions 10

Which statement about FortiSASE CASB capabilities is true?

Options:

A.

FortiSASE provides both API-based CASB and inline CASB

B.

FortiSASE provides only API-based CASB

C.

FortiSASE provides only inline CASB

D.

FortiSASE provides CASB capabilities only through Security Fabric integration

Buy Now
Questions 11

Which three challenges in a work-from-anywhere environment does FortiSASE address? (Choose three.)

Options:

A.

Inconsistent security levels

B.

Lack of bandwidth

C.

Lack of visibility and control

D.

Poor performance

E.

Remote internet connectivity

Buy Now
Questions 12

SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.

Which three configuration elements must you configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)

Options:

A.

Firewall policies

B.

Security profiles

C.

Interfaces

D.

Routing

E.

Traffic shaping

Buy Now
Questions 13

Refer to the exhibit.

Which conclusion can you draw from the exhibit?

Options:

A.

Over the past 60 seconds, the member port2 latency was temporarily above the latency criteria defined for HUB1_HC.

B.

The administrator configured the Corp_HC performance service-level agreement (SLA) with SLA targets for the three criteria: packet loss, latency, and jitter.

C.

Over the past 60 seconds, the member port1 was monitored healthy for both latency criteria of the Corp_HC definition.

D.

The administrator configured the packet loss threshold for Corp_HC and HUB1_HC to 5%.

Buy Now
Questions 14

Which two configurations are required for Agentless ZTNA to work? (Choose two.)

Options:

A.

Proxy user single sign-on (SSO)

B.

FortiGate with ZTNA proxy

C.

FortiClient Agent

D.

SD-WAN Private Access (SPA)

Buy Now
Questions 15

Which statement is true about FortiSASE supported deployment?

Options:

A.

FortiSASE supports VPN mode and Agentless mode, based on user requirements.

B.

FortiSASE supports both Endpoint mode and SWG mode, depending on deployment.

C.

FortiSASE operates only in SWG mode, where all traffic is forced through FortiSASE POPs.

D.

FortiSASE relies on ZTNA-only mode, which replaces SWG and endpoint functions.

Buy Now
Exam Code: NSE5_SSE_AD-7.6
Exam Name: Fortinet NSE 5 - FortiSASE and SD-WAN 7.6 Core Administrator
Last Update: Oct 5, 2026
Questions: 50
NSE5_SSE_AD-7.6 pdf

NSE5_SSE_AD-7.6 PDF

$21.25  $84.99
NSE5_SSE_AD-7.6 Engine

NSE5_SSE_AD-7.6 Testing Engine

$25  $99.99
NSE5_SSE_AD-7.6 PDF + Engine

NSE5_SSE_AD-7.6 PDF + Testing Engine

$33.75  $134.99