Black Friday Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet NSE7_ZTA-7.2 Fortinet NSE 7 - Zero Trust Access 7.2 Exam Practice Test

Page: 1 / 3
Total 30 questions

Fortinet NSE 7 - Zero Trust Access 7.2 Questions and Answers

Question 1

Which factor is a prerequisite on FortiNAC to add a Layer 3 router to its inventory?

Options:

A.

Allow HTTPS access from the router to the FortiNAC ethO IP address

B.

Allow FTP access to the FortiNAC database from the router

C.

The router responding to ping requests from the FortiNAC eth1 IP address

D.

SNMP or CLI access to the router to carry out remote tasks

Question 2

Which method is used to install passive agent on an endpoint?

Options:

A.

Deployed by using a login/logout script

B.

Agent is downloaded from Playstore

C.

Agent is downloaded and run from captive portal

D.

Installed by user or deployment tools

Question 3

Exhibit.

Question # 3

Which statement is true about the configuration shown in the exhibit?

Options:

A.

The domain that FortiClient is connecting to should match the domain to which the certificate is issued.

B.

It the FortiClient EMS server certificate is invalid, FortiClient connects silently.

C.

The connection from FortiClient to FortiClient EMS uses TCP and TLS 1.2.

D.

default_ZTNARoot CA signs the FortiClient certificate for the SSL connectivity to FortiClient EMS

Question 4

FortiNAC has alarm mappings configured for MDM compliance failure, and FortiClient EMS is added as a MDM connector When an endpoint is quarantined by FortiClient EMS, what action does FortiNAC perform?

Options:

A.

The host is isolated in the registration VLAN

B.

The host is marked at risk

C.

The host is forced to authenticate again

D.

The host is disabled

Question 5

exhibit.

Question # 5

User student is not able to log in to SSL VPN

Given the output showing a real-time debug: which statement describes the login failure?

Options:

A.

Unable to verify chain of trust for the peer certificate

B.

CN does not match the user peer configuration

C.

student is not part of the usergroup SSL_VPN_Users.

D.

Client certificate has expired

Question 6

Which one of the supported communication methods does FortiNAC usefor initial device identification during discovery?

Options:

A.

LLDP

B.

SNMP

C.

API

D.

SSH

Question 7

Which three statements are true about zero-trust telemetry compliance1? (Choose three.)

Options:

A.

FortiClient EMS creates dynamic policies using ZTNAtags

B.

FortiChent checks the endpoint using the ZTNAtags provided by FortiClient EMS

C.

ZTNA tags are configured in FortiClient,based on criteria such as certificates and the logged in domain

D.

FortiOS provides network access to the endpoint based on the zero-trust tagging rules

E.

FortiClient EMS sends the endpoint information received through FortiClient Telemetry to FortiOS

Question 8

Which three methods can you use to trigger layer 2 polling on FortiNAC? (Choose three)

Options:

A.

Polling scripts

B.

Link traps

C.

Manual polling

D.

Scheduled tasks

E.

Polling using API

Question 9

Which statement is true about disabled hosts on FortiNAC?

Options:

A.

They are quarantined and placed in the remediation VLAN

B.

They are placed in the authentication VLAN to reauthenticate

C.

They are marked as unregistered rogue devices

D.

They are placed in the dead end VLAN

Page: 1 / 3
Total 30 questions