Module 2 Flashcards
(19 cards)
How do you use fortiguard forensics analysis
You submit in the portal
What can DEM help with?
Connectivity
Bandwidth
CPU
MEMORY
Hard disk
SaaS monitoring
Three common use cases for dedicated public IP address deployments are:
Traffic identification and isolation
* Geolocation rules (TAC Ticket)
* Source IP anchoring (TAC Ticket)
Can you get Add on IP licenses for Standard licensing?
Yes, costs extra.
In version 24, how many IP addresses can you add per POP?
One, per POP.
Describe Geolocation IP add
In the geolocation rules use case, the customer can request the dedicated public IP address of a POP to be
mapped to a different geolocation, while traffic still transits through its actual geolocation.
Describe Source IP anchoring
Additional dedicated public IP add-on
license is required with four additional
dedicated IP addresses
Source IP anchoring policy can be used
to SNAT a specific user, group, or country
of incoming remote users
Describe Endpoint mode
Uses SSL VPN
The VPN policy
on FortiSASE is configured with the required security components, such as web filter, application control, and
so on, to secure the internet traffic. Endpoint mode also supports configuring zero trust network access
(ZTNA) for compliance checks.
Describe SWG mode
Explicit Proxy for HTTP/HTTPS
Uses PAC file or configures web browser.
Does SWG Require you to download a CA certificate?
Yes, it is required as SWG mode intercepts SSL
What options do you have for Remote Auth of users for FortISASE?
LDAP
RADIUS
SAML
Common Name Identifier
is the attribute name you use to find the username.
What is Distinguished Name
setting identifies the top of the tree where the users are located, which is generally
the domain controller (DC) value; however, it can be a specific container or organizational unit (OU)
What are the three roles of SAML?
Principal
Identity Provider
Service Provider
Describe SAML Principal
An entity that requests access to a service that
requires authentication and authorization
* Can be a user, group, or device
What is a SAML IdP
Identity Provider
Creates, maintains, and manages identity information
* Responds to requests for SAML assertions made by a
service provider
What is SAML Sp?
Requires service to a principal
Relies on an IdP for authentication and authorization
information
What happens when you configure SSO
It overrides all other authentication method