Fortinet NSE7_ZTA-7.2 Fortinet NSE 7 – Zero Trust Access 7.2 Online Training
Fortinet NSE7_ZTA-7.2 Online Training
The questions for NSE7_ZTA-7.2 were last updated at Nov 19,2024.
- Exam Code: NSE7_ZTA-7.2
- Exam Name: Fortinet NSE 7 - Zero Trust Access 7.2
- Certification Provider: Fortinet
- Latest update: Nov 19,2024
An administrator has to configure LDAP authentication tor ZTNA HTTPS access proxy Which authentication scheme can the administrator apply1?
- A . Basic
- B . Form-based
- C . Digest
- D . NTLM
FortiNAC has alarm mappings configured for MDM compliance failure, and FortiClient EMS is added as a MDM connector.
When an endpoint is quarantined by FortiClient EMS, what action does FortiNAC perform?
- A . The host is isolated in the registration VLAN
- B . The host is marked at risk
- C . The host is forced to authenticate again
- D . The host is disabled
Exhibit.
Based on the ZTNA logs provided, which statement is true?
- A . The Remote_user ZTNA tag has matched the ZTNA rule
- B . An authentication scheme is configured
- C . The external IP for ZTNA server is 10 122 0 139.
- D . Traffic is allowed by firewall policy 1
Exhibit.
Which port group membership should you enable on FortiNAC to isolate rogue hosts’?
- A . Forced Authentication
- B . Forced Registration
- C . Forced Remediation
- D . Reset Forced Registration
Exhibit.
Which statement is true about the hr endpoint?
- A . The endpoint is a rogue device
- B . The endpoint is disabled
- C . The endpoint is unauthenticated
- D . The endpoint has been marked at risk
Which two statements are true regarding certificate-based authentication for ZTNA deployment? (Choose two.)
- A . FortiGate signs the client certificate submitted by FortiClient.
- B . The default action for empty certificates is block
- C . Certificate actions can be configured only on the FortiGate CLI
- D . Client certificate configuration is a mandatory component for ZTNA
Which one of the supported communication methods does FortiNAC use for initial device identification during discovery?
- A . LLDP
- B . SNMP
- C . API
- D . SSH
What happens when FortiClient EMS is configured as an MDM connector on FortiNAC?
- A . FortiNAC sends the host data to FortiClient EMS to update its host database
- B . FortiClient EMS verifies with FortiNAC that the device is registered
- C . FortiNAC polls FortiClient EMS periodically to update already registered hosts in FortiNAC
- D . FortiNAC checks for device vulnerabilities and compliance with FortiClient
Which two types of configuration can you associate with a user/host profile on FortiNAC? (Choose two.)
- A . Service Connectors
- B . Network Access
- C . Inventory
- D . Endpoint compliance
Which statement is true about disabled hosts on FortiNAC?
- A . They are quarantined and placed in the remediation VLAN
- B . They are placed in the authentication VLAN to reauthenticate
- C . They are marked as unregistered rogue devices
- D . They are placed in the dead end VLAN