BlackFriday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam FCSS_SASE_AD-23 Topic 1 Question 11 Discussion

Actual exam question for Fortinet's FCSS_SASE_AD-23 exam
Question #: 11
Topic #: 1
[All FCSS_SASE_AD-23 Questions]

An organization needs to resolve internal hostnames using its internal rather than public DNS servers for remotely connected endpoints. Which two components must be configured on FortiSASE to achieve this? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, C

To resolve internal hostnames using internal DNS servers for remotely connected endpoints, the following two components must be configured on FortiSASE:

Split DNS Rules:

Split DNS allows the configuration of specific DNS queries to be directed to internal DNS servers instead of public DNS servers.

This ensures that internal hostnames are resolved using the organization's internal DNS infrastructure, maintaining privacy and accuracy for internal network resources.

Split Tunneling Destinations:

Split tunneling allows specific traffic (such as DNS queries for internal domains) to be routed through the VPN tunnel while other traffic is sent directly to the internet.

By configuring split tunneling destinations, you can ensure that DNS queries for internal hostnames are directed through the VPN to the internal DNS servers.


FortiOS 7.2 Administration Guide: Provides details on configuring split DNS and split tunneling for VPN clients.

FortiSASE 23.2 Documentation: Explains the implementation and configuration of split DNS and split tunneling for securely resolving internal hostnames.

Contribute your Thoughts:

Mee
1 months ago
This is a piece of cake! Split DNS rules and DNS filter are the obvious choices. I'm surprised they even included the other options - they don't make any sense for this scenario.
upvoted 0 times
Clare
12 days ago
It's important to configure the right components for this scenario.
upvoted 0 times
...
Sueann
20 days ago
Definitely, those are the components needed to resolve internal hostnames.
upvoted 0 times
...
Virgie
23 days ago
I agree, Split DNS rules and DNS filter are the way to go.
upvoted 0 times
...
...
Vannessa
2 months ago
I'd go with B and D. Split DNS rules to route internal hostnames to internal DNS, and DNS filter to enforce the use of internal DNS. Seems straightforward enough.
upvoted 0 times
...
Pearly
2 months ago
B and D, no doubt. Why would SSL deep inspection or split tunneling be relevant for this? Hmm, maybe the exam writer is trying to trick us.
upvoted 0 times
Markus
27 days ago
It's always important to carefully read and understand the question before selecting the answers.
upvoted 0 times
...
Diane
28 days ago
I agree, the exam writer might be trying to trick us with those options.
upvoted 0 times
...
Lizette
29 days ago
Yeah, it seems like a trick question. Split DNS rules and DNS filter make more sense.
upvoted 0 times
...
Malcolm
1 months ago
B and D are the correct choices. SSL deep inspection and split tunneling are not needed for this scenario.
upvoted 0 times
...
Christiane
1 months ago
I agree, SSL deep inspection and split tunneling are not necessary for this scenario.
upvoted 0 times
...
Rosamond
1 months ago
D) DNS filter
upvoted 0 times
...
Linsey
1 months ago
B) Split DNS rules
upvoted 0 times
...
...
Rima
2 months ago
DNS filter can be used to block access to public DNS servers, forcing endpoints to use internal DNS servers.
upvoted 0 times
...
Cordie
2 months ago
Split DNS rules and DNS filter seem like the way to go. Internal hostname resolution is the key here.
upvoted 0 times
Sylvia
1 months ago
B) Split DNS rules
upvoted 0 times
...
Jaclyn
1 months ago
A) SSL deep inspection
upvoted 0 times
...
...
Tamesha
2 months ago
I agree with Rima. Split DNS rules will help resolve internal hostnames using internal DNS servers.
upvoted 0 times
...
Reita
2 months ago
I'm not sure about DNS filter. Can someone explain how it helps in this scenario?
upvoted 0 times
...
Rima
3 months ago
I think we need to configure Split DNS rules and DNS filter on FortiSASE.
upvoted 0 times
...

Save Cancel