View all questions & answers for the FCSS - FortiSASE 25 Administrator Exam Materials exam
Question 13 Discussion
Comments
Selected Answers: D
These are personal devices you cannot install software on. Deploying OnRamp will require no configuration on their devices and push all traffic to SASE for full security.
Selected Answers: C
Selected Answers: B
Page 90
FortiSASE can manage a FortiAP deployed in a remote location over a backhaul connection to provide SIA to
Wi-Fi clients. The FortiAP discovers the FortiSASE AC, and establishes an IPsec VPN tunnel that encrypts
the data channel between FortiSASE and FortiAP. The FortiAP carries Control and Provisioning of Wireless
Access Points (CAPWAP) data packets and includes the FortiAP serial number within this tunnel.
Selected Answers: B
Selected Answers: D
Explanation:
SD-WAN on-ramp: This approach provides a simple and efficient way to secure internet access for remote users with minimal configuration on their devices. It leverages the cloud-based FortiSASE platform to manage and enforce security policies, including access control, content filtering, and VPN connections. Users can connect to the internet through a secure tunnel, and the on-ramp handles the authentication, encryption, and policy enforcement. This eliminates the need for individual device setup or agent installation on each user's laptop or mobile device.
Why other options are less suitable:
A. Deploy FortiGate as a LAN extension: While FortiGate can be used as a LAN extension, it might require more configuration and management for a small branch office with ten users, especially if they are using personal devices. It also necessitates on-premises deployment of a FortiGate firewall.
B. Deploy FortiAP to secure internet access: A FortiAP is primarily designed to secure wireless networks. While it can provide internet access, it might not be the most efficient or scalable solution for a small branch office with distributed users, especially considering the need for individual device configuration.
C. Deploy FortiClient endpoint agent: This option requires installing an agent on each user's device, which adds complexity to the setup process and can be time-consuming for a small number of users.
Selected Answers: B
Your FortiSASE customer has a small branch office in which ten users will be using their personal laptops and mobile devices to access the internet. Which deployment should they use to secure their internet access with minimal configuration? (Choose one answer)
Brave-Dump Clients Votes