View all questions & answers for the NSE 7 - FortiSASE 25 Enterprise Administrator Exam Materials exam


NSE 7 - FortiSASE 25 Enterprise Administrator Exam Materials-Question 7 Discussion

Refer to the exhibit. Which two prerequisites must be met to use the feature shown in the exhibit? (Choose two answers)

  • A. The secure private access (SPA) feature must be configured in FortiSASE.
  • B. The relevant FortiGate ZTNA application gateway must be configured.
  • C. FortiClient must be installed on the user's device to access the private application.
  • D. The proxy and proxy user single sign-on (SSO) features must be configured in FortiSASE.
Correct Answer: A,D

Brave-Dump Clients Votes

AD 57.14%
AB 28.57%
BD 14.29%

Comments



Brave-Dumps.com Admin 2025-10-29 22:59:31

Selected Answers: A, B


it needs additional check.


javaughn Bryan 2025-11-21 02:34:24

Selected Answers: A, B


This is agentless so no need for FortiClient and SSO doesn't really apply here. This question is purely about application access. Since it's agentless... an ZTNA application gateway is need and a SPA tunnel also


Anonymous User 2026-02-16 21:26:17

Selected Answers: B, D


Agentless means proxy


Anonymous User 2026-03-13 05:19:54

Selected Answers: A, D


FortiSASE Agentless ZTNA (Does NOT require FortiGate App Gateway). The heavy lifting moves to the cloud. The user logs into the FortiSASE web portal. The FortiSASE cloud itself acts as the proxy and the gateway.

Here is the exact flow:

The user authenticates to the FortiSASE portal (using proxy SSO).

FortiSASE verifies their identity and permissions.

FortiSASE proxies the connection and sends the already-authorized traffic down the standard Secure Private Access (SPA) IPsec tunnel to your branch FortiGate.

The FortiGate receives this traffic over the tunnel and simply routes it to the internal server like normal network traffic.

Because FortiSASE handles the proxying and the gateway duties in the cloud, your on-premise FortiGate just acts as a standard router/firewall for that traffic. No ZTNA Application Gateway configuration is needed on the FortiGate itself for Agentless ZTNA.


I Am Weird 2026-03-30 04:43:54

Selected Answers: A, D


AD


mahmoud mostafa 2026-04-12 02:48:20

Selected Answers: A, D


AD is correct answer
this is agenless access so no forticlient and authentication is via SWG SSO (mostly with SAML)
And with the user authenticated, FortiSASE Gives it the Access accordingly SPA Configuration

page 173: FortiSASE 25 Administrator Study Guide


Matthias Strauß 2026-04-18 15:56:17

Selected Answers: A, D


A & D
https://docs.fortinet.com/document/fortisase/latest/feature-administration-guide/329570/agentless-ztna