あなたを合格させるNSE7_SSE_AD-25お手軽に試験合格リアルNSE7_SSE_AD-25練習問題集で更新されたのは2026年03月02日
2026年最新の実際に出ると確認されたで無料Fortinet NSE7_SSE_AD-25試験問題
質問 # 23
Refer to the exhibits. A FortiSASE administrator has configured FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGate hub. However, the remote FortiClient is not able to access the web server hosted behind the FortiGate hub.
Based on the exhibits, what is the reason for the access failure?




- A. The hub is not advertising the required routes.
- B. A private access policy has denied the traffic because of failed compliance
- C. The hub firewall policy does not include the FortiClient address range.
- D. The server subnet BGP route was not received on FortiSASE.
正解:D
解説:
The FortiSASE BGP learned routes do not include the 10.160.160.0/24 subnet (server network).
Although the FortiGate hub is advertising this route (10.160.160.0/24) to FortiSASE, it is not visible in the FortiSASE BGP route table - indicating a routing issue. Without this route, FortiSASE cannot forward traffic from FortiClient to the server.
質問 # 24
What are two benefits of deploying FortiSASE with FortiGate ZTNA access proxy? (Choose two.)
- A. It offers data center redundancy.
- B. It is ideal for latency-sensitive applications.
- C. It supports both agentless ZTNA and agent-based ZTNA.
- D. The on-premises FortiGate performs a device posture check.
正解:B、C
解説:
Deploying FortiSASE with FortiGate ZTNA access proxy enables efficient access to private applications with reduced latency and supports both agentless and agent-based ZTNA methods for flexible access control.
質問 # 25
Which service is included in a secure access service edge (SASE) solution, but not in a security service edge (SSE) solution?
- A. ZTNA
- B. CASB
- C. SWG
- D. SD-WAN
正解:D
解説:
SD-WAN is a networking component included in a SASE solution but not in an SSE solution. SSE focuses solely on security services (like ZTNA, SWG, and CASB), while SASE combines both networking (e.g., SD-WAN) and security into a unified cloud-delivered service.
質問 # 26
Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org.
Which configuration on FortiSASE is allowing users to perform the download?

- A. Application control is exempting all the browser traffic.
- B. Intrusion prevention is disabled.
- C. Deep inspection is not enabled.
- D. Web filter is allowing the URL.
正解:C
解説:
The SSL inspection mode is set to certificate inspection, which only inspects SSL/TLS headers and does not allow full scanning of encrypted content. Without full (deep) inspection, the antivirus profile cannot scan or block malicious files (like eicar.com-zip) delivered over HTTPS, allowing the download to proceed.
質問 # 27
How do security profile group objects behave when central management is enabled on FortiSASE?
- A. Objects support two-way synchronization.
- B. Objects are considered read-only on FortiSASE.
- C. Objects created on FortiSASE can be retrieved on FortiManager.
- D. Objects that are only flow-based are supported.
正解:B
解説:
When central management is enabled, security profile group objects are managed exclusively through FortiManager, making them read-only on the FortiSASE portal to ensure centralized policy control.
質問 # 28
In the Secure Private Access (SPA) use case, which two FortiSASE features facilitate access to corporate applications? (Choose two.)
- A. cloud access security broker (CASB)
- B. zero trust network access (ZTNA)
- C. SD-WAN
- D. thin edge
正解:B、C
解説:
SD-WAN allows efficient and secure routing of traffic from users to corporate applications, while ZTNA enables secure access control and verification for users connecting to internal resources, both of which are essential for Secure Private Access (SPA) in FortiSASE.
質問 # 29
Refer to the exhibit. While reviewing the traffic logs, the FortiSASE administrator notices that the usernames are showing random characters.
Why are the usernames showing random characters?
- A. Log anonymization is turned on to hash usernames.
- B. FortiSASE uses FortiClient unique identifiers for usernames.
- C. Users are using a shared single sign-on SSO username.
- D. Special characters are used in usernames.
正解:A
解説:
The usernames appear as random character strings because log anonymization is enabled in FortiSASE, which hashes sensitive user information such as usernames to protect privacy while still allowing log analysis.
質問 # 30
In which two ways does FortiSASE help organizations ensure secure access for remote workers?
(Choose two.)
- A. It offers zero trust network access (ZTNA) capabilities.
- B. It uses the identity and access management (IAM) portal to validate the identities of remote workers.
- C. It uses the FortiCloud organizational units to assign endpoint profiles to remote workers.
- D. It secures traffic from endpoints to cloud applications.
正解:A、D
解説:
FortiSASE ensures secure access for remote workers by protecting traffic between endpoints and cloud applications and enforcing ZTNA policies that validate user identity and device posture before granting access to corporate resources.
質問 # 31
Which authentication method overrides any other previously configured user authentication on FortiSASE?
- A. RADIUS
- B. SSO
- C. MFA
- D. Local
正解:B
解説:
Single Sign-On (SSO) overrides any other previously configured user authentication method on FortiSASE, taking precedence for user authentication.
質問 # 32
When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.)
- A. Endpoint management
- B. Sandbox
- C. Identity & access management (IAM)
- D. Logging
- E. Points of presence
正解:A、B、D
解説:
When first accessing the FortiSASE portal, the administrator must select data center locations for endpoint management, logging, and sandbox services to ensure optimized performance and compliance with data residency requirements.
質問 # 33
What are two benefits of deploying secure private access with SD-WAN? (Choose two.)
- A. a direct access proxy tunnel from FortiClient to the on-premises FortiGate
- B. ZTNA posture check performed by the hub FortiGate
- C. inline security inspection by FortiSASE
- D. support of both TCP and UDP applications
正解:B、D
解説:
Deploying secure private access with SD-WAN enables the hub FortiGate to perform ZTNA posture checks, and supports both TCP and UDP applications over the tunnel, allowing for flexible and secure access to internal resources.
質問 # 34
Refer to the exhibits. Jumpbox and Windows-AD are endpoints from the same remote location.
Jumpbox can access the internet through FortiSASE, while Windows-AD can no longer access the internet.
Based on the information in the exhibits, which reason explains the outage on Windows-AD?


- A. Windows-AD is excluded from FortiSASE management.
- B. The FortiClient version installed on Windows AD does not match the expected version on FortiSASE.
- C. The device posture for Windows-AD has changed.
- D. The remote VPN user on Windows-AD no longer matches any VPN policy.
正解:C
解説:
The Windows-AD endpoint now has both "FortiSASE-Compliant" and "FortiSASE-Non- Compliant" tags due to failing the antivirus software check. As a result, the Secure Internet Access Policy matches the "Non-Compliant" rule, which is set to Deny, causing the device to lose internet access.
質問 # 35
Your FortiSASE customer has a small branch office in which ten users will be using their personal laptops and mobile devices to access the internet.
Which deployment should they use to secure their internet access with minimal configuration?
- A. Deploy FortiAP to secure internet access.
- B. Deploy SD-WAN on-ramp to secure internet access.
- C. Deploy FortiClient endpoint agent to secure internet access.
- D. Deploy FortiGate as a LAN extension to secure internet access.
正解:A
解説:
Deploying FortiAP enables secure internet access for unmanaged personal devices in small branch offices with minimal configuration by automatically directing traffic through FortiSASE, eliminating the need for endpoint installation or complex setup.
質問 # 36
Which information can an administrator monitor using reports generated on FortiSASE?
- A. SD-WAN performance
- B. FortiSASE administrator and system events
- C. FortiClient vulnerability assessment
- D. sanctioned and unsanctioned Software-as-a-Service (SaaS) applications usage
正解:D
解説:
FortiSASE reporting provides visibility into the usage of sanctioned and unsanctioned SaaS applications, enabling administrators to monitor cloud application activity and enforce security policies.
質問 # 37
An administrator must restrict endpoints from certain countries from connecting to FortiSASE.
Which configuration can achieve this?
- A. Configure geofencing to restrict access from the required countries.
- B. Configure a network lockdown policy on the endpoint profiles.
- C. Configure a geography address object as the source for a deny policy.
- D. Configure source IP anchoring to restrict access from the specified countries.
正解:A
解説:
Geofencing allows the administrator to restrict or allow access to FortiSASE services based on the geographic location of the endpoints, effectively blocking connections from specified countries.
質問 # 38
In a FortiSASE SD-WAN deployment with dual hubs, what are two benefits of assigning hubs with different priorities? (Choose two.)
- A. bandwidth allocated traffic shaping
- B. redundancy to seamlessly steer traffic
- C. load balancing based on session identification
- D. optimized performance that meets the minimum SLA requirements
正解:B、D
解説:
Assigning hubs with different priorities in a FortiSASE SD-WAN deployment allows traffic to be routed through the optimal hub to meet SLA requirements and ensures redundancy by enabling automatic failover if the preferred hub becomes unavailable.
質問 # 39
An organization must block user attempts to log in to non-company resources while using Microsoft Office 365 to prevent users from accessing unapproved cloud resources.
Which FortiSASE feature can you implement to meet this requirement?
- A. web filter with inline-CASB
- B. DNS filter with domain filter
- C. data loss prevention (DLP) with Microsoft Purview Information Protection (MPIP)
- D. application control with inline-CASB
正解:D
解説:
Application control with inline-CASB allows FortiSASE to inspect and control application behavior at a granular level. This enables the organization to block login attempts to personal or non- corporate Microsoft Office 365 accounts, ensuring that only approved cloud resources are accessed.
質問 # 40
Which information does FortiSASE use to bring network lockdown into effect on an endpoint?
- A. The number of critical vulnerabilities detected on the endpoint
- B. The security posture of the endpoint based on ZTNA tags
- C. Zero-day malware detection on endpoint
- D. The connection status of the tunnel to FortiSASE
正解:B
解説:
FortiSASE uses ZTNA tags to assess the endpoint's security posture. If the posture is non- compliant based on predefined rules, FortiSASE enforces network lockdown to restrict access accordingly.
質問 # 41
What is required to enable the MSSP feature on FortiSASE?
- A. Role-based access control (RBAC) must be assigned to identity and access management (IAM) users using the FortiCloud IAM portal.
- B. Multi-tenancy must be enabled on the FortiSASE portal.
- C. MSSP user accounts and permissions must be configured on the FortiSASE portal.
- D. The MSSP add-on license must be applied to FortiSASE.
正解:A
解説:
To enable the MSSP feature on FortiSASE, you must use the FortiCloud IAM portal to assign RBAC permissions to users. This grants appropriate access to manage multiple tenants or customer accounts securely.
質問 # 42
In a FortiSASE secure web gateway (SWG) deployment, which two features protect against web- based threats? (Choose two.)
- A. intrusion prevention system (IPS) for web traffic
- B. web application firewall (WAF) for web applications
- C. SSL deep inspection for encrypted web traffic
- D. malware protection with sandboxing capabilities
正解:C、D
解説:
SSL deep inspection allows FortiSASE to analyze encrypted web traffic for threats, while malware protection with sandboxing detects and blocks malicious files delivered through web channels.
質問 # 43
Which statement best describes the Digital Experience Monitor (DEM) feature on FortiSASE?
- A. It gathers all the vulnerability information from all the FortiClient endpoints.
- B. It monitors the FortiSASE POP health based on ping probes.
- C. It is used for performing device compliance checks on endpoints.
- D. It provides end-to-end network visibility from all the FortiSASE security PoPs to a specific SaaS application.
正解:D
解説:
The Digital Experience Monitor (DEM) in FortiSASE measures and monitors network performance from the FortiSASE Points of Presence (PoPs) to specific SaaS or cloud applications, helping identify and troubleshoot performance issues across the service path.
質問 # 44
Which two are required to enable central management on FortiSASE? (Choose two.)
- A. FortiSASE connector configured on FortiManager.
- B. FortiSASE central management entitlement applied to FortiManager.
- C. The FortiManager IP address in the FortiSASE central management configuration.
- D. FortiManager and FortiSASE registered under the same FortiCloud account.
正解:A、D
解説:
To enable central management, FortiManager must have a FortiSASE connector configured, and both FortiSASE and FortiManager must be registered under the same FortiCloud account to establish trust and synchronization.
質問 # 45
......
NSE7_SSE_AD-25リアル試験問題解答は無料:https://jp.fast2test.com/NSE7_SSE_AD-25-premium-file.html
NSE7_SSE_AD-25試験問題、リアルNSE7_SSE_AD-25練習問題集:https://drive.google.com/open?id=1dqd_fRbxPNH1UsXD4-gQLEX7P2m9ZUdz