Module 5 ZTNA Flashcards

(17 cards)

1
Q

Where do endpoints get device certificates from?

A

From FortiSASE CA when it first connects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the FortiSASE CA use to sign the cert?

A

FortiClient unique ID
Certificate serial number
and FortiSASE. EMS SN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does FortiGate connect to EMS?

A

FortiClient EMS cloud fabric connector

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Do you have to register FortiSASE and Fortigate under the same FortiCloud account?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

True or false you do not have to install the FortiSASE EMS server cert onto FTG

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or false you must authorize FTG in FortiSASE

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What operating Systems Can have a Tagging rule applied to them?

A

Windows,
MacOS
Linux.
iOS
Andriod

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is ZTNA visible on FTG by default?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What command do you enter to enable ZTNA on entry-level models?

A

Config system global
set prox-and-explicit-proxy enable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the default routing design method for FortiSASE

A

BGP per overlay
IBGP session terminates on tunnel ip add

Must config mode-cfg on hub

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the two routing design methods supported by SASE

A

BGP per overlay
BGP on loop back

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Can you mix and match bgp routing designs?

A

No, all must be the same

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the two hub selection methods

A

Hub health and priority
BGP-MED

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the hub health and priority hub selection method

A

Health check receives

Latency <120ms
Jitter threshold 55ms
Packet los 1%

Sase selects the highest priority hub, that meets the lowest cost sla

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Explain BGP MED hub selection

A

Discriminates amount multiple exit or entry points to the same AS

Lower the MED the more preferred the path

17
Q

What is the highest priority for hubs?