Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet NSE7_ZTA-7.2 Fortinet NSE 7 - Zero Trust Access 7.2 Exam Practice Test

Fortinet NSE 7 - Zero Trust Access 7.2 Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

With the increase in loT devices, which two challenges do enterprises face? (Choose two.)

Options:

A.

Bandwidth consumption due to added overhead of loT

B.

Maintaining a high performance network

C.

Unpatched vulnerabilities in loT devices

D.

Achieving full network visibility

Question 2

Exhibit.

Which statement is true about the configuration shown in the exhibit?

Options:

A.

The domain that FortiClient is connecting to should match the domain to which the certificate is issued.

B.

It the FortiClient EMS server certificate is invalid, FortiClient connects silently.

C.

The connection from FortiClient to FortiClient EMS uses TCP and TLS 1.2.

D.

default_ZTNARoot CA signs the FortiClient certificate for the SSL connectivity to FortiClient EMS

Question 3

Exhibit.

Which port group membership should you enable on FortiNAC to isolate rogue hosts'?

Options:

A.

Forced Authentication

B.

Forced Registration

C.

Forced Remediation

D.

Reset Forced Registration

Question 4

Which statement is true regarding a FortiClient quarantine using FortiAnalyzer playbooks?

Options:

A.

FortiGate sends a notification to FortiClient EMS to quarantine the endpoint

B.

FortiAnalyzer discovers malicious activity in the logs and notifies FortiGate

C.

FortiAnalyzer sends an API to FortiClient EMS to quarantine the endpoint

D.

FortiClient sends logs to FortiAnalyzer

Question 5

What are the three core principles of ZTA? (Choose three.)

Options:

A.

Verity

B.

Be compliant

C.

Certify

D.

Minimal access

E.

Assume breach

Question 6

Exhibit.

Which two statements are true about the hr endpoint? (Choose two.)

Options:

A.

The endpoint application inventory could not be retrieved

B.

The endpoint is marked as a rogue device

C.

The endpoint has failed the compliance scan

D.

The endpoint will be moved to the remediation VLAN

Question 7

An administrator is trying to create a separate web tittering profile for off-fabric and on-fabric clients and push it to managed FortiClient devices

Where can you enable this feature on FortiClient EMS?

Options:

A.

Endpoint policy

B.

ZTNA connection rules

C.

System settings

D.

On-fabric rule sets

Question 8

Which one of the supported communication methods does FortiNAC usefor initial device identification during discovery?

Options:

A.

LLDP

B.

SNMP

C.

API

D.

SSH

Question 9

Which three methods can you use to trigger layer 2 polling on FortiNAC? (Choose three)

Options:

A.

Polling scripts

B.

Link traps

C.

Manual polling

D.

Scheduled tasks

E.

Polling using API