Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE5_SSE_AD-7.6 Exam - Topic 2 Question 4 Discussion

Actual exam question for Fortinet's NSE5_SSE_AD-7.6 exam
Question #: 4
Topic #: 2
[All NSE5_SSE_AD-7.6 Questions]

What is a key use case for FortiSASE Secure Internet Access (SIA) in an agentless deployment? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: B

According to the FortiSASE 7.6 Administration Guide and the FCP - FortiSASE 24/25 Administrator curriculum, the Agentless deployment mode---commonly referred to as Secure Web Gateway (SWG) mode---is a vital component of the Secure Internet Access (SIA) framework.

Deployment Mechanism: In an agentless deployment, FortiSASE functions as an explicit web proxy. This is achieved by distributing a PAC (Proxy Auto-Configuration) file to the user's browser, which instructs the device to send its web traffic to the nearest FortiSASE Point of Presence (PoP).

Target Use Case: This mode is specifically designed for unmanaged endpoints, such as those used by contractors, partners, or temporary workers, where the organization does not have the authority or capability to install the FortiClient agent.

Security Capabilities: Even without an agent, FortiSASE applies a full security stack to the redirected traffic. This includes Web Filtering, Anti-Malware, SSL Inspection, and Inline-CASB to secure HTTP and HTTPS sessions.

Protocol Limitations: Because it relies on proxy settings, this mode is limited to web protocols (HTTP/HTTPS) and does not inherently secure non-web traffic like ICMP, DNS, or custom TCP/UDP applications unless they are specifically proxied.

Why other options are incorrect:

Option A: While it provides secure browsing, session isolation (RBI) is a specific feature that can be used in either mode; the defining characteristic of the agentless use case is the proxy-based redirection for unmanaged devices.

Option C: A PAC file can only secure web traffic (protocols that support proxying), not non-web traffic protocols.

Option D: Agentless mode is the opposite of requiring FortiClient; ZTNA tags generally require the FortiClient agent to provide the necessary telemetry for tag evaluation.


Contribute your Thoughts:

0/2000 characters
Terrilyn
15 days ago
I think B is the best choice. It covers unmanaged endpoints well.
upvoted 0 times
...
Alberta
20 days ago
I’m not convinced about B. What about the PAC file limitations?
upvoted 0 times
...
Rashad
26 days ago
A is interesting too, especially for temporary employees.
upvoted 0 times
...
Cristen
1 month ago
Wait, does it really only apply to unmanaged endpoints? Sounds off.
upvoted 0 times
...
Deangelo
1 month ago
Totally agree with B! Secure web gateway is crucial.
upvoted 0 times
...
Lourdes
1 month ago
I think B is the right answer. It covers unmanaged endpoints well.
upvoted 0 times
...
Jestine
2 months ago
Option C is just too limited. We need a comprehensive solution like B.
upvoted 0 times
...
Dorthy
2 months ago
B) is the way to go. Keeps things simple and secure without agent hassle.
upvoted 0 times
...
Colene
2 months ago
Haha, option D is a joke. Who wants to install FortiClient on every device?
upvoted 0 times
...
Detra
2 months ago
I like how option B covers the full security stack. That's what we need for our contractors.
upvoted 0 times
...
Domitila
2 months ago
B) Definitely the right answer. Securing web traffic for unmanaged endpoints is crucial.
upvoted 0 times
...
Jose
2 months ago
I feel like A could be a contender too, especially with the focus on temporary employees. But I lean towards B for the web proxy aspect.
upvoted 0 times
...
Joanna
3 months ago
I’m a bit confused about the difference between agentless and managed deployments. Does that mean D is definitely wrong?
upvoted 0 times
...
Wilbert
3 months ago
I think option B sounds familiar because we practiced questions about secure web gateways and PAC files. That might be the right choice.
upvoted 0 times
...
Chi
4 months ago
I remember discussing how FortiSASE can secure unmanaged endpoints, but I'm not sure if that's specifically about web traffic or other protocols.
upvoted 0 times
...
Alesia
4 months ago
Based on my understanding of FortiSASE SIA, I believe option B is the correct answer. It describes how the solution can act as a secure web gateway, distributing a PAC file to secure HTTP and HTTPS traffic for unmanaged endpoints, which aligns with the key use case the question is asking about.
upvoted 0 times
...
Sherman
4 months ago
Hmm, this is a tricky one. I think I'm leaning towards option B as well, since it mentions securing web traffic for unmanaged endpoints, which seems to be the focus of the question. But I'm not 100% certain, so I'll need to double-check my understanding of the different options.
upvoted 0 times
...
Keneth
4 months ago
I'm a bit confused by this question. The options seem to cover a lot of different features and capabilities of FortiSASE SIA, and I'm not sure which one is the "key" use case they're looking for. I'll need to review the material more carefully to make sure I understand the specific use case they're asking about.
upvoted 0 times
...
Gladis
4 months ago
I think option B is the best choice here. The question is asking about a key use case for FortiSASE SIA in an agentless deployment, and option B describes how it can act as a secure web gateway to secure web traffic for unmanaged endpoints like contractors.
upvoted 0 times
...

Save Cancel