FCSS_SASE_AD-23 Exam Questions
63 real FCSS_SASE_AD-23 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
Which role does FortiSASE play in supporting zero trust network access (ZTNA) principles?
- Question #2
When deploying FortiSASE agent-based clients, which three features are available compared to an agentless solution? (Choose three.)
- Question #3
Which FortiSASE feature ensures least-privileged user access to all applications?
- Question #4
Which two components are part of onboarding a secure web gateway (SWG) endpoint? (Choose two)
- Question #5
To complete their day-to-day operations, remote users require access to a TCP-based application that is hosted on a private web server. Which FortiSASE deployment use case provides...
- Question #6
Which secure internet access (SIA) use case minimizes individual workstation or device setup, because you do not need to install FortiClient on endpoints or configure explicit web...
- Question #7
Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish. Based on the provided configurat...
- Question #8
Which two additional components does FortiSASE use for application control to act as an inline- CASB? (Choose two.)
- Question #9
Which two advantages does FortiSASE bring to businesses with multiple branch offices? (Choose two.)
- Question #10
When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.)
- Question #11
During FortiSASE provisioning, how many security points of presence (POPs) need to be configured by the FortiSASE administrator?
- Question #12
An organization needs to resolve internal hostnames using its internal rather than public DNS servers for remotely connected endpoints. Which two components must be configured on F...
- Question #13
When using Secure Private Access (SPA) and SD-WAN, which protocol is used for spoke-to- spoke connectivity?
- Question #14
Which FortiSASE Secure Private Access (SPA) deployment involves installing FortiClient on remote endpoints?
- Question #15
A customer has an existing network that needs access to a secure application on the cloud. Which FortiSASE feature can the customer use to provide secure Software-as-a-Service (Saa...
- Question #16
Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are st...
- Question #17
An organization wants to block all video and audio application traffic but grant access to videos from CNN. Which application override action must you configure in the Application...
- Question #18
Refer to the exhibits. When remote users connected to FortiSASE require access to internal resources on Branch-2. how will traffic be routed?
- Question #19
What are two advantages of using zero-trust tags? (Choose two.)
- Question #20
Refer to the exhibit. In the user connection monitor, the FortiSASE administrator notices the user name is showing random characters. Which configuration change must the administra...
- Question #21
Refer to the exhibit. To allow access, which web filter configuration must you change on FortiSASE?
- Question #22
Which policy type is used to control traffic between the FortiClient endpoint to FortiSASE for secure internet access?
- Question #23
Which FortiSASE feature can you use to see a list of Software-as-a-Service (SaaS) applications and health-check metrics for first-mile connectivity between the geographical points...
- Question #24
For FortiSASE point of presence (POP) to connect as a spoke, which Fortinet solution is required as standalone IPSec VPN hub?
- Question #25
Which FortiSASE component can be utilized for endpoint compliance?
- Question #26
Which two deployment methods are used to connect a FortiExtender as a FortiSASE LAN extension? (Choose two.)
- Question #27
How does FortiSASE hide user information when viewing and analyzing logs?
- Question #28
Refer to the exhibit. A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redir...
- Question #29
Refer to the exhibits. Win10-Pro and Win7-Pro are endpoints from the same remote location. Win10-Pro can access the internet though FortiSASE, while Win7-Pro can no longer access t...
- Question #30
A customer wants to upgrade their legacy on-premises proxy to a cloud-based proxy for a hybrid network. Which FortiSASE features would help the customer to achieve this outcome?
- Question #31
When you configure FortiSASE Secure Private Access (SPA) with SD-WAN integration, you must establish a routing adjacency between FortiSASE and the FortiGate SD-WAN hub. Which routi...
- Question #32
FortiSASE delivers a converged networking and security solution. Which two features help with integrating FortiSASE into an existing network? (Choose two.)
- Question #33
Which endpoint functionality can you configure using FortiSASE?
- Question #34
How does integrating endpoint detection and response (EDR) systems into SASE contribute to security posture?
- Question #35
Which three ways does FortiSASE provide Secure Private Access (SPA) to corporate, non-web applications? (Choose three.)
- Question #36
A FortiSASE administrator is configuring a Secure Private Access (SPA) solution to share endpoint information with a corporate FortiGate. Which three configuration actions will ach...
- Question #37
Refer to the exhibit. The daily report for application usage shows an unusually high number of unknown applications by category. What are two possible explanations for this? (Choos...
- Question #38
When viewing the daily summary report generated by FortiSASE. the administrator notices that the report contains very little data. What is a possible explanation for this almost em...
- Question #39
You are designing a new network for Company X and one of the new cybersecurity policy requirements is that all remote user endpoints must always be connected and protected Which Fo...
- Question #40
Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGate hub. However, the administrator i...
- Question #41
Refer to the exhibit. Based on the configuration shown, in which two ways will FortiSASE process sessions that require FortiSandbox inspection? (Choose two.)
- Question #42
In a FortiSASE secure web gateway (SWG) deployment, which three features protect against web-based threats? (Choose three.)
- Question #43
When deploying FortiSASE agentless secure web gateway (SWG) clients, which three features can you use to scan client traffic? (Choose three.)
- Question #44
Refer to the exhibit. A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between th...
- Question #45
In which three ways does FortiSASE help organizations ensure secure access for remote workers? (Choose three.)
- Question #46
Which two additional components does FortiSASE use for application control to act as an inline- CASB? (Choose two.)
- Question #47
An organization must block user attempts to log in to non-company resources while using Microsoft Office 365 to prevent users from accessing unapproved cloud resources. Which Forti...
- Question #48
Your organization is currently using FortiSASE for its cybersecurity. They have recently hired a contractor who will work from the HQ office and who needs temporary internet access...
- Question #49
Refer to the exhibit. Users are unable to access https://login.live.com. To allow access, which web filter configuration must you change on FortiSASE?
- Question #50
Which two settings are automatically pushed from FortiSASE to FortiClient in a new FortiSASE deployment with default settings? (Choose two.)