View all questions & answers for the NSE 7 - FortiSASE 25 Enterprise Administrator Exam Materials exam


Question 35 Discussion

You have configured FortiSASE Secure Private Access (SPA) deployment. Which statement is true about traffic flows? (Choose two answers)

  • A. When using SD-WAN private access, traffic goes from an endpoint directly to an SPA hub.
  • B. When using zero trust network access, traffic goes from an endpoint to a FortiSASE POP, and then to a ZTNA access proxy.
  • C. When using zero trust network access (ZTNA) traffic goes from an endpoint directly to a ZTNA access proxy.
  • D. When using SD-WAN private access, traffic goes from an endpoint to a FortiSASE POP, and then to an SPA hub.
Correct Answer: B,D

Brave-Dump Clients Votes

BD 100%

Comments



Brave-Dumps Admin 2025-10-30 14:52:15

Selected Answers: B, D


It needs additional check.


javaughn Bryan 2025-11-21 21:04:37

Selected Answers: B, D


PAGE 55 & 61. SASE NSE7 ENTERPRISE GUIDE (THE DIAGRAMS)

ZTNA traffic is brokered by the FortiSASE POP first, which then forwards to the ZTNA access proxy — so traffic goes endpoint → FortiSASE POP → ZTNA access proxy (B).

For SD-WAN private access, the endpoint’s traffic is also sent to the FortiSASE POP and then forwarded to the SPA hub (the hub is where the SD-WAN/SPA hub terminates), so it’s endpoint → FortiSASE POP → SPA hub (D).