Question 1 of 30
Anya, a network security engineer at a rapidly growing tech firm, is facing a challenge in enforcing granular application control policies on their FortiGate firewall. The current setup relies on static IP address assignments to define user groups for policy application, which has become cumbersome to manage due to frequent user onboarding and offboarding. Anya needs to implement a more dynamic and scalable solution to restrict access to a newly adopted cloud-based project management suite for specific departments, while ensuring seamless access for others. Considering the need for adaptability and the adoption of new methodologies in network security, what is the most effective strategic pivot Anya can make within FortiOS to achieve this objective, moving away from IP-based segmentation?
Implement user-based firewall policies by integrating the FortiGate with an identity provider and creating user groups based on authenticated user credentials.
Configure static NAT rules for each user group's IP range to isolate their traffic and apply application control policies to these NATted IP addresses.
Deploy a separate FortiManager instance solely for managing application control policies, allowing for more granular rule creation based on network segments.
Utilize traffic shaping policies to limit the bandwidth consumption of the cloud-based suite for all users, indirectly controlling its usage without explicit user-based restrictions.

Preparing for NSE4FGT6.4 Fortinet NSE 4 FortiOS 6.4? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free