NSE5_SSE_AD-7.6 Sample Questions

NSE5_SSE_AD-7.6 Sample Questions & Answers

Deployment basics for SD-WAN, including zones and SLA tuning, tie with FortiSASE administration and onboarding for the top weighting, next to SD-WAN rules and routing, reaching the internet and SaaS apps with endpoint compliance, and SD-WAN and FortiSASE log analytics.

Launch the full NSE5_SSE_AD-7.6 simulator →

Showing 6 of 12 free samples.

  1. Question 1Beginner

    Decentralized SD-WAN · Configure SD-WAN members and zones

    In a decentralized SD-WAN deployment using FortiOS 7.6, an administrator wants to ensure that firewall policies are applied efficiently to multiple WAN links. The administrator has grouped 'wan1' and 'wan2' into an SD-WAN Zone named 'Internet_Zone'.

    How does this zone configuration affect firewall policy creation?

    Show answer & explanation

    Correct answer: B

    SD-WAN Zones simplify policy management. By referencing the Zone object in the firewall policy, the policy automatically applies to all members (interfaces) within that zone, reducing the number of policies needed.

  2. Question 2IntermediateSelect 2

    Rules and Routing · Configure SD-WAN rules

    Which TWO statements accurately describe the behavior of the 'Maximize Bandwidth (SLA)' SD-WAN rule strategy in FortiOS? (Select TWO)

    Show answer & explanation

    Correct answers: A, C

    If all members fail the SLA check, the strategy typically falls back to the preference order defined in the rule or the implicit rule behavior, depending on specific configuration options like 'packet loss' handling.

    Maximize Bandwidth (SLA) is designed for load balancing. It identifies the set of links that satisfy the SLA target and distributes sessions among them to aggregate capacity.

  3. Question 3Beginner

    Secure Internet Access (SIA) and Secure SaaS Access (SSA) · Implement security profiles to perform content inspection

    True or False: When configuring FortiSASE for Agentless Secure Web Gateway (SWG) access, installing the FortiSASE root CA certificate on the client browser is mandatory for successful SSL Deep Inspection.

    Show answer & explanation

    Correct answer: A

    This is True. For SSL Deep Inspection to work without generating certificate warnings or errors in the browser, the client must trust the Certificate Authority (CA) that signs the re-encrypted traffic. In FortiSASE, this is the FortiSASE CA.

  4. Question 4Intermediate

    Analytics · Identify potential security threats using FortiSASE logs

    A security analyst is investigating a potential data exfiltration attempt in FortiSASE. They need to view logs that specifically detail which files were uploaded to a sanctioned cloud storage application and whether any sensitive data patterns were detected.

    Which log type in the FortiSASE dashboard provides this specific visibility?

    Show answer & explanation

    Correct answer: C

    DLP Logs are specifically designed to record incidents where data matches configured sensitive patterns (e.g., credit card numbers, SSNs) during transmission. This includes file uploads to SaaS applications.

  5. Question 5Intermediate

    Rules and Routing · Configure SD-WAN rules

    When configuring an SD-WAN rule with the 'Best Quality' strategy, an administrator selects 'Latency' as the quality criteria. Three members (WAN1, WAN2, WAN3) are available.

    WAN1: 20ms latency
    WAN2: 25ms latency
    WAN3: 60ms latency

    The 'Link Cost Factor' is disabled. Which interface will be selected for traffic matching this rule?

    Show answer & explanation

    Correct answer: B

    The 'Best Quality' strategy selects the single interface with the best measured value for the chosen criteria (lowest latency in this case). Since WAN1 has 20ms (lowest), it is selected.

    graph TD Traffic[Traffic Match Rule] --> Compare{Compare Latency} Compare -->|WAN1: 20ms| Select1[Select WAN1] Compare -->|WAN2: 25ms| Ignore2[Ignore] Compare -->|WAN3: 60ms| Ignore3[Ignore]
  6. Question 6Advanced

    SASE Deployment · Integrate FortiSASE with SD-WAN

    A FortiSASE administrator needs to onboard a fleet of IoT devices that do not support the FortiClient agent. These devices are located in a microbranch behind a FortiExtender.

    Which FortiSASE integration method supports securing traffic from these devices?

    Show answer & explanation

    Correct answer: A

    FortiExtender can be deployed as a 'Thin Edge' device. It establishes a secure tunnel to FortiSASE and routes traffic from devices behind it (like IoT sensors) through the tunnel for inspection, without needing agents on the end devices.

Ready for the real thing?

The full NSE5_SSE_AD-7.6 simulator has every exam-style question, timed mode, and instant scoring.