Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish.
Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?





A. NAT needs to be enabled in the Spoke-to-Hub firewall policy.
B. The BGP router ID needs to match on the hub and FortiSASE.
C. FortiSASE spoke devices do not support mode config.
D. The hub needs IKEv2 enabled in the IPsec phase 1 settings.
正解:D
質問 2:
Which statement best describes the Digital Experience Monitor (DEM) feature on FortiSASE?
A. It requires a separate DEM agent to be downloaded from the FortiSASE portal and installed on the endpoint.
B. It can be used to request a detailed analysis of the endpoint from the FortiGuard team.
C. It can help IT and security teams ensure consistent security monitoring for remote users.
D. It provides end-to-end network visibility from all the FortiSASE security PoPs to a specific SaaS application.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Which two advantages does FortiSASE bring to businesses with multiple branch offices?
(Choose two.)
A. it offers customizable dashboard views for each branch location
B. It eliminates the need to have an on-premises firewall for each branch.
C. It offers centralized management for simplified administration.
D. It enables seamless integration with third-party firewalls.
正解:B,C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Which FortiSASE feature can you use to see a list of Software-as-a-Service (SaaS) applications and health-check metrics for first-mile connectivity between the geographical points of presence (PoPs) provisioned for your FortiSASE instance and these SaaS applications?
A. digital experience monitoring DEM
B. security logs
C. event logs
D. FortiView
正解:A
質問 5:
Which endpoint functionality can you configure using FortiSASE?
A. It can be applied to both SWG and VPN deployments.
B. You can configure inline sandbox to scan zero-day malware attacks.
C. You can enable and push web filter to FortiClient endpoints.
D. Site-based FortiExtender users can perform on-demand vulnerability scans.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
You are designing a new network for Company X and one of the new cybersecurity policy requirements is that all remote user endpoints must always be connected and protected Which FortiSASE component facilitates this always-on security measure?
A. inline-CASB
B. thin-branch SASE extension
C. unified FortiClient
D. site-based deployment
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
Yurin -
是非参考にして合格し就活や転職の成功の足しにしてくれ。
Pass4Testさん、本当に感謝してます!