Fortinet Enterprise Firewall 7.6 FCSS_EFW_AD-7.6 Security Fabric Architecture Connectors Practice Test

 

This practice test focuses on security fabric architecture connectors and automation through original applied scenarios aligned to the final published Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator 7.6 blueprint. It is intended for study and does not reproduce live exam content. For broader exam preparation, review the Fortinet FCSS_EFW_AD-7.6 Exam Dumps page.

Question 1

A production review at Blue Yonder Airlines identifies this requirement: extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member. Which Fortinet action is most appropriate? The team will validate the result immediately after the change. Only one site is affected; peer sites are healthy.

  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: B

Explanation

  1. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  2. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This directly addresses the stated requirement.
  3. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  4. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products.

Question 2

While troubleshooting at Trey Research, the network operations engineer needs to trigger a repeatable response when a specified security event occurs. What is the best next step? The change is taking place in a controlled maintenance window. The change must be validated on a pilot device before broader rollout.

  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Create an automation stitch with the required event trigger and narrowly scoped action
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source

Correct answer: C

Explanation

  1. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  2. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  3. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This directly addresses the stated requirement.
  4. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  5. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create an automation stitch with the required event trigger and narrowly scoped action. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable.

Question 3

Apex Retail is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown? Choose the smallest targeted change. Existing production IP addressing must remain unchanged.

  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Create an automation stitch with the required event trigger and narrowly scoped action
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action

Correct answer: A

Explanation

  1. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This directly addresses the stated requirement.
  2. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  3. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  4. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  5. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts.

Question 4

A change ticket for Proseware Media states that administrators must use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device. Which choice is correct? The answer must address the stated cause rather than a different feature. The resulting configuration must remain centrally auditable.

  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: D

Explanation

  1. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  2. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  3. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  4. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This directly addresses the stated requirement.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the appropriate external connector and reference the dynamic data where policy requires it. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric.

Question 5

The security team at City Power & Light wants to provide SAML-based SSO consistently across a Security Fabric design. Which configuration or operational action most directly satisfies that goal? Preserve the existing design unless the requirement says otherwise. A known-good rollback point is available before the change.

  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source

Correct answer: E

Explanation

  1. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  2. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  3. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  4. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  5. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design.

Question 6

An incident at VanArsdel requires the network security architect to back up configuration automatically after a high-risk administrative change. What should be done first? Prefer a change that is reversible and easy to verify. The design must preserve the current segmentation boundaries.

  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: B

Explanation

  1. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  2. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This directly addresses the stated requirement.
  3. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  4. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up.

Question 7

For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Woodgrove Bank, which option correctly addresses the need to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member? The team needs an auditable result. The team is not allowed to disable the security feature globally.

  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: C

Explanation

  1. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  2. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  3. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This directly addresses the stated requirement.
  4. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products.

Question 8

Alpine Ski House has verified basic IP reachability. The remaining requirement is to trigger a repeatable response when a specified security event occurs. Which action should the team take? Use normal enterprise Fortinet administration practice. The symptom appeared immediately after a planned configuration change.

  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: E

Explanation

  1. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  2. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  3. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  4. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create an automation stitch with the required event trigger and narrowly scoped action. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable.

Question 9

At Datum Corporation, the security infrastructure engineer must quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown. Which action best addresses the requirement? Assume the platform versions are compatible with the feature. Logs from the affected traffic are available for verification.

  • Create an automation stitch with the required event trigger and narrowly scoped action
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization

Correct answer: C

Explanation

  1. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  2. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  3. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This directly addresses the stated requirement.
  4. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  5. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts.

Question 10

During an enterprise firewall change at Contoso Finance, the team needs to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device. What should it do? No unrelated control should be weakened. The equivalent configuration works correctly at a separate site.

  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Create an automation stitch with the required event trigger and narrowly scoped action
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point

Correct answer: B

Explanation

  1. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  2. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This directly addresses the stated requirement.
  3. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  4. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  5. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the appropriate external connector and reference the dynamic data where policy requires it. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric.

Question 11

A production review at Litware Logistics identifies this requirement: provide SAML-based SSO consistently across a Security Fabric design. Which Fortinet action is most appropriate? The team will validate the result immediately after the change. The change must be reversible within the same maintenance window.

  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: B

Explanation

  1. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  2. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This directly addresses the stated requirement.
  3. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  4. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design.

Question 12

While troubleshooting at Wide World Importers, the network security architect needs to back up configuration automatically after a high-risk administrative change. What is the best next step? The change is taking place in a controlled maintenance window. The device is already synchronized with its central-management database.

  • Create an automation stitch with the required event trigger and narrowly scoped action
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Configure the appropriate external connector and reference the dynamic data where policy requires it

Correct answer: C

Explanation

  1. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  2. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  3. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This directly addresses the stated requirement.
  4. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  5. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up.

Question 13

Relecloud is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member? Choose the smallest targeted change. The current routing table contains the expected connected networks.

  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Create an automation stitch with the required event trigger and narrowly scoped action
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization

Correct answer: E

Explanation

  1. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  2. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  3. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  4. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  5. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products.

Question 14

A change ticket for Adventure Works states that administrators must trigger a repeatable response when a specified security event occurs. Which choice is correct? The answer must address the stated cause rather than a different feature. Basic IP reachability to the remote endpoint has already been verified.

  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: E

Explanation

  1. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  2. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  3. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  4. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create an automation stitch with the required event trigger and narrowly scoped action. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable.

Question 15

The security team at Fourth Coffee wants to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown. Which configuration or operational action most directly satisfies that goal? Preserve the existing design unless the requirement says otherwise. Hardware replacement is outside the approved change scope.

  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point

Correct answer: E

Explanation

  1. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  2. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  3. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  4. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  5. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts.

Question 16

An incident at Coho Winery requires the NOC engineer to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device. What should be done first? Prefer a change that is reversible and easy to verify. The requirement applies only to one policy, peer, or managed device group.

  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: C

Explanation

  1. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  2. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  3. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This directly addresses the stated requirement.
  4. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the appropriate external connector and reference the dynamic data where policy requires it. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric.

Question 17

For a FortiGate/FortiManager/FortiAnalyzer 7.6 deployment at Fabrikam Manufacturing, which option correctly addresses the need to provide SAML-based SSO consistently across a Security Fabric design? The team needs an auditable result. The team must avoid broadening administrative trust or permissions.

  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: C

Explanation

  1. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  2. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  3. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This directly addresses the stated requirement.
  4. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design.

Question 18

Wingtip Energy has verified basic IP reachability. The remaining requirement is to back up configuration automatically after a high-risk administrative change. Which action should the team take? Use normal enterprise Fortinet administration practice. The design must preserve existing centralized logging and telemetry.

  • Create an automation stitch with the required event trigger and narrowly scoped action
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action

Correct answer: E

Explanation

  1. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  2. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  3. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  4. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  5. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This directly addresses the stated requirement.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up.

Question 19

At Lucerne Publishing, the Fortinet administrator must extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member. Which action best addresses the requirement? Assume the platform versions are compatible with the feature. Production subnets cannot be renumbered as part of this change.

  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: B

Explanation

  1. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  2. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This directly addresses the stated requirement.
  3. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  4. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products.

Question 20

During an enterprise firewall change at Bellows College, the team needs to trigger a repeatable response when a specified security event occurs. What should it do? No unrelated control should be weakened. A maintenance window is open, but service interruption must be minimized.

  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Create an automation stitch with the required event trigger and narrowly scoped action
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point

Correct answer: D

Explanation

  1. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  2. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  3. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.
  4. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This directly addresses the stated requirement.
  5. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to trigger a repeatable response when a specified security event occurs.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, create an automation stitch with the required event trigger and narrowly scoped action. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable.

Question 21

A production review at Tailspin Toys identifies this requirement: quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown. Which Fortinet action is most appropriate? The team will validate the result immediately after the change. The team must preserve existing certificate-trust relationships unless the requirement explicitly changes them.

  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: A

Explanation

  1. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This directly addresses the stated requirement.
  2. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  3. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  4. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to quarantine a compromised endpoint identified by the fabric while avoiding a broad network shutdown.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts.

Question 22

While troubleshooting at Humongous Insurance, the NOC engineer needs to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device. What is the best next step? The change is taking place in a controlled maintenance window. The change will be reviewed later using the configuration and event audit trail.

  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Create an automation stitch with the required event trigger and narrowly scoped action

Correct answer: A

Explanation

  1. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This directly addresses the stated requirement.
  2. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  3. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  4. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.
  5. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to use an external cloud or SaaS service as data input without incorrectly adding it as a Fortinet fabric device.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the appropriate external connector and reference the dynamic data where policy requires it. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric.

Question 23

Margie Travel is standardizing a FortiOS 7.6 enterprise deployment. Which approach should it use to provide SAML-based SSO consistently across a Security Fabric design? Choose the smallest targeted change. The chosen approach must continue to work as additional branch sites are added.

  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action

Correct answer: C

Explanation

  1. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  2. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  3. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This directly addresses the stated requirement.
  4. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.
  5. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to provide SAML-based SSO consistently across a Security Fabric design.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design.

Question 24

A change ticket for Northwind Health states that administrators must back up configuration automatically after a high-risk administrative change. Which choice is correct? The answer must address the stated cause rather than a different feature. A second engineer will verify the result using independent operational evidence.

  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action
  • Create an automation stitch with the required event trigger and narrowly scoped action
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization

Correct answer: B

Explanation

  1. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  2. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This directly addresses the stated requirement.
  3. Automation stitches bind an event trigger to one or more actions so the response is repeatable and auditable. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  4. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.
  5. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to back up configuration automatically after a high-risk administrative change.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up.

Question 25

The security team at Blue Yonder Airlines wants to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member. Which configuration or operational action most directly satisfies that goal? Preserve the existing design unless the requirement says otherwise. The team requires a deterministic rollback path if validation fails.

  • Configure the supported SAML identity integration and make sure the relevant fabric members use the intended identity source
  • Add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization
  • Use the Security Fabric quarantine mechanism for the identified endpoint and verify the quarantine action propagates to the enforcement point
  • Configure the appropriate external connector and reference the dynamic data where policy requires it
  • Use an automation stitch that reacts to the administrative event and performs the supported configuration-backup action

Correct answer: B

Explanation

  1. SAML integration centralizes identity assertions and can support consistent SSO behavior across the design. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  2. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products. This directly addresses the stated requirement.
  3. Targeted quarantine isolates the affected endpoint while preserving service for unrelated hosts. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  4. External connectors import context or objects from external services; they are not the same as Fortinet devices joining the Security Fabric. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.
  5. An event-driven backup creates a recoverable configuration point without depending on a manual follow-up. This can be correct in another enterprise firewall scenario, but it does not directly satisfy the requirement to extend fabric visibility to a supported Fortinet product without treating a third-party API as a fabric member.

Learning point: For this Fortinet NSE 7 – Enterprise Firewall 7.6 Administrator scenario, add the supported Fortinet device through the appropriate Security Fabric integration and verify fabric authorization. Security Fabric membership and connectors provide integrated topology, telemetry, and coordinated control between supported Fortinet products.

Popular posts

img