View all questions & answers for the NSE 7 - FortiSASE 25 Enterprise Administrator Exam Materials exam
NSE 7 - FortiSASE 25 Enterprise Administrator Exam Materials-Question 35 Discussion
Comments
Selected Answers: B, D
Selected Answers: B, D
ZTNA traffic is brokered by the FortiSASE POP first, which then forwards to the ZTNA access proxy — so traffic goes endpoint → FortiSASE POP → ZTNA access proxy (B).
For SD-WAN private access, the endpoint’s traffic is also sent to the FortiSASE POP and then forwarded to the SPA hub (the hub is where the SD-WAN/SPA hub terminates), so it’s endpoint → FortiSASE POP → SPA hub (D).
-
mahmoud mostafa
2026-04-13 21:13:41
You have correctly discribed that: in case of SPA with ZTNA, FortiSASE is the Trust Borcker just trust the client for the ZTNA Access Proxy and forward the ZTNA Tags to it to allow client toaccess their ZTNA Dst. SO I think, the answe is C,D
Selected Answers: C, D
Selected Answers: C, D
Selected Answers: C, D
Selected Answers: C, D
Also C is correct not B
in case of SPA with ZTNA, FortiSASE is the Trust Borcker just trust the client for the ZTNA Access Proxy and forward the ZTNA Tags to ZTNA Access Proxy(Mostly the onprime firewall ) So to allow client toaccess their ZTNA Dst.
You have configured FortiSASE Secure Private Access (SPA) deployment. Which statement is true about traffic flows? (Choose two answers)
Brave-Dump Clients Votes