Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE7_ZTA-7.2 Topic 4 Question 6 Discussion

Actual exam question for Fortinet's NSE7_ZTA-7.2 exam
Question #: 6
Topic #: 4
[All NSE7_ZTA-7.2 Questions]

Which two types of configuration can you associate with a user/host profile on FortiNAC? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: A

Based on the ZTNA logs provided, the true statement is:

A) The Remote_user ZTNA tag has matched the ZTNA rule: The log includes a user tag 'ztna_user' and a policy name 'External_Access_FAZ', which suggests that the ZTNA tag for 'Remote_User' has successfully matched the ZTNA rule defined in the policy to allow access.

The other options are not supported by the information in the log:

B) An authentication scheme is configured: The log does not provide details about an authentication scheme.

C) The external IP for ZTNA server is 10.122.0.139: The log entry indicates 'dstip=10.122.0.139' which suggests that this is the destination IP address for the traffic, not necessarily the external IP of the ZTNA server.

D) Traffic is allowed by firewall policy 1: The log entry 'policyid=1' indicates that the traffic is matched to firewall policy ID 1, but it does not explicitly state that the traffic is allowed; although the term 'action=accept' suggests that the action taken by the policy is to allow the traffic, the answer option D could be considered correct as well.


Interpretation of FortiGate ZTNA Log Files.

Analyzing Traffic Logs for Zero Trust Network Access.

Contribute your Thoughts:

Tiera
1 months ago
Oh man, this one's a real head-scratcher. I'm just gonna go with my gut and say Service Connectors and Inventory. Worst case, I can always blame the caffeine withdrawal for my questionable choices.
upvoted 0 times
...
Olen
1 months ago
Network Access and Endpoint compliance, without a doubt. Although I do wonder if the exam writers are trying to sneak in a trick question with those other options. Gotta stay vigilant, you know!
upvoted 0 times
...
Jin
1 months ago
I've got a feeling that Inventory and Endpoint compliance are the two right answers here. Guess I'll just have to trust my FortiNAC instincts and hope for the best!
upvoted 0 times
...
Roxanne
1 months ago
Ah, this one's tricky. I think Service Connectors and Network Access are the way to go, but I'm not 100% sure. Gotta love these certification exams, they really keep you on your toes!
upvoted 0 times
Maynard
12 days ago
I agree, Service Connectors and Network Access seem like the most logical choices.
upvoted 0 times
...
...
My
2 months ago
Hmm, I'm pretty sure Network Access and Endpoint compliance are the two types of configuration I can associate with a user/host profile on FortiNAC. Time to double-check my notes!
upvoted 0 times
Danilo
16 days ago
B) Network Access
upvoted 0 times
...
Merrilee
22 days ago
A) Service Connectors
upvoted 0 times
...
...
Marlon
2 months ago
I'm not sure, but I think A and D make sense because service connectors and endpoint compliance are important for user/host profiles.
upvoted 0 times
...
Sabra
2 months ago
I believe it's B and C.
upvoted 0 times
...
Marlon
3 months ago
I think it's A and D.
upvoted 0 times
...

Save Cancel