exam questions

Exam NSE5_FCT-7.0 All Questions

View all questions & answers for the NSE5_FCT-7.0 exam

Exam NSE5_FCT-7.0 topic 1 question 8 discussion

Actual exam question from Fortinet's NSE5_FCT-7.0
Question #: 8
Topic #: 1
[All NSE5_FCT-7.0 Questions]

Refer to the exhibit, which shows the output of the ZTNA traffic log on FortiGate.

What can you conclude from the log message?

  • A. The remote user connection does not match the explicit proxy policy.
  • B. The remote user connection does not match the ZTNA server configuration.
  • C. The remote user connection does not match the ZTNA firewall policy.
  • D. The remote user connection does not match the ZTNA rule configuration.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Tomer676
Highly Voted 11 months ago
The Answer is C API gateway cannot be matched: When connecting to the ZTNA access proxy, the client tries to connect to an API gateway that does not match any virtual host. take from fortinet Docs: https://docs.fortinet.com/document/fortigate/7.0.0/new-features/608477/ztna-logging-enhancements-7-0-1 Its meen that is no firewall policy to the server that client want to access
upvoted 7 times
...
jr01239a
Highly Voted 10 months ago
C. Empty Client Certificate = "Denied: empty client certificate" Failed Client Certificate = "Denied: client certificate authentication failed" API gateway that does not match any virtual host = "Denied: failed to match an API-gateway" API gateway but the real server cannot be reached = "Denied: failed to match an API-gateway" A ZTNA rule (proxy policy ) cannot be matched = "Denied: failed to match a proxy-policy" HTTPS SNI virtual host does not match the HTTP host header = "Denied: failed to match an API-gateway" ======================= Wrong Access Proxy Right Access Proxy, down/missing Real Server Right Access Proxy, wrong URI ====================== ZTNA Server = defines the access proxy VIP and the real servers that clients will connect to ZTNA Rule (Proxy Policy) = enforce access control Firewall Policy (Full ZTNA) = The firewall policy matches and redirects client requests to the access proxy VIP.
upvoted 5 times
...
Wanduka
Most Recent 3 months, 2 weeks ago
More than one answer seems right. Any additional comments?
upvoted 1 times
...
johnnd
4 months, 4 weeks ago
Selected Answer: B
Page 286 of study Guide.
upvoted 2 times
...
erosramos322
5 months, 3 weeks ago
Selected Answer: B
API gateway cannot be matched or real servers cannot be reached
upvoted 3 times
...
aguilazoo
11 months, 3 weeks ago
Selected Answer: B
The aswer is B
upvoted 3 times
...
mhizha
12 months ago
The answer is D. Page 238 of the study guide reads, "This slide shows the UTM and traffic logs that are generated when FortiGate connects to the ZTNA access proxy but is unable to match the ZTNA rule (proxy policy). For example, no ZTNA rule is matched for the ZTNA tag assigned to the endpoint." I had now way to paste the slide but if you check page 238 you will see the slide with the logs.
upvoted 1 times
Eggrolls
4 months, 4 weeks ago
I think he meant page 286 Study Guide seems its B
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago