ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 5 - FCSS_SASE_AD-23 discussion

Report
Export

Refer to the exhibits.

WiMO-Pro and Win7-Pro are endpoints from the same remote location. WiMO-Pro can access the internet though FortiSASE, while Wm7-Pro can no longer access the internet

Given the exhibits, which reason explains the outage on Wm7-Pro?

A.
The Win7-Pro device posture has changed.
Answers
A.
The Win7-Pro device posture has changed.
B.
Win7-Pro cannot reach the FortiSASE SSL VPN gateway
Answers
B.
Win7-Pro cannot reach the FortiSASE SSL VPN gateway
C.
The Win7-Pro FortiClient version does not match the FortiSASE endpoint requirement.
Answers
C.
The Win7-Pro FortiClient version does not match the FortiSASE endpoint requirement.
D.
Win-7 Pro has exceeded the total vulnerability detected threshold.
Answers
D.
Win-7 Pro has exceeded the total vulnerability detected threshold.
Suggested answer: D

Explanation:

Based on the provided exhibits, the reason why the Win7-Pro endpoint can no longer access the internet through FortiSASE is due to exceeding the total vulnerability detected threshold. This threshold is used to determine if a device is compliant with the security requirements to access the network.

Endpoint Compliance:

FortiSASE monitors endpoint compliance by assessing various security parameters, including the number of vulnerabilities detected on the device.

The compliance status is indicated by the ZTNA tags and the vulnerabilities detected.

Vulnerability Threshold:

The exhibit shows that Win7-Pro has 176 vulnerabilities detected, whereas Win10-Pro has 140 vulnerabilities.

If the endpoint exceeds a predefined vulnerability threshold, it may be restricted from accessing the network to ensure overall network security.

Impact on Network Access:

Since Win7-Pro has exceeded the vulnerability threshold, it is marked as non-compliant and subsequently loses internet access through FortiSASE.

The FortiSASE endpoint profile enforces this compliance check to prevent potentially vulnerable devices from accessing the internet.

FortiOS 7.2 Administration Guide: Provides information on endpoint compliance and vulnerability management.

FortiSASE 23.2 Documentation: Explains how vulnerability thresholds are used to determine endpoint compliance and access control.

asked 18/09/2024
Alexander Goris
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first