FCSS_SASE_AD-23 Exam Questions
63 real FCSS_SASE_AD-23 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Routing and Policy Troubleshooting
Which role does FortiSASE play in supporting zero trust network access (ZTNA) principles?
FortiSASEZTNAendpoint posture checkzero trust - Question #2
When deploying FortiSASE agent-based clients, which three features are available compared to an agentless solution? (Choose three.)
- Question #3Routing and Policy Troubleshooting
Which FortiSASE feature ensures least-privileged user access to all applications?
ZTNAleast privilegeFortiSASEzero trust network access - Question #4Troubleshooting Methodology and Tools
Which two components are part of onboarding a secure web gateway (SWG) endpoint? (Choose two)
SWGCA certificatePAC fileendpoint onboarding - Question #5Routing and Policy Troubleshooting
To complete their day-to-day operations, remote users require access to a TCP-based application that is hosted on a private web server. Which FortiSASE deployment use case provides...
ZTNAprivate accessTCP applicationremote access - Question #6Routing and Policy Troubleshooting
Which secure internet access (SIA) use case minimizes individual workstation or device setup, because you do not need to install FortiClient on endpoints or configure explicit web...
SIAsite-based deploymentagentless accesssecure internet access - Question #7
Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish. Based on the provided configurat...
- Question #8Routing and Policy Troubleshooting
Which two additional components does FortiSASE use for application control to act as an inline- CASB? (Choose two.)
inline-CASBapplication controlSSL deep inspectionIPS - Question #9Routing and Policy Troubleshooting
Which two advantages does FortiSASE bring to businesses with multiple branch offices? (Choose two.)
FortiSASEbranch officecentralized managementSASE architecture - Question #10Troubleshooting Methodology and Tools
When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.)
FortiSASE provisioningdata centerendpoint managementlogging - Question #11Troubleshooting Methodology and Tools
During FortiSASE provisioning, how many security points of presence (POPs) need to be configured by the FortiSASE administrator?
FortiSASEpoint of presencePOPprovisioning - Question #12
An organization needs to resolve internal hostnames using its internal rather than public DNS servers for remotely connected endpoints. Which two components must be configured on F...
- Question #13
When using Secure Private Access (SPA) and SD-WAN, which protocol is used for spoke-to- spoke connectivity?
- Question #14
Which FortiSASE Secure Private Access (SPA) deployment involves installing FortiClient on remote endpoints?
- Question #15
A customer has an existing network that needs access to a secure application on the cloud. Which FortiSASE feature can the customer use to provide secure Software-as-a-Service (Saa...
- Question #16FortiGuard Troubleshooting
Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are st...
antivirus profilecertificate inspectionHTTPS inspectionsecurity profile bypass - Question #17Routing and Policy Troubleshooting
An organization wants to block all video and audio application traffic but grant access to videos from CNN. Which application override action must you configure in the Application...
application controlinline-CASBapplication overridetraffic policy - Question #18
Refer to the exhibits. When remote users connected to FortiSASE require access to internal resources on Branch-2. how will traffic be routed?
- Question #19Routing and Policy Troubleshooting
What are two advantages of using zero-trust tags? (Choose two.)
zero-trust tagsendpoint postureaccess controlZTNA - Question #20Troubleshooting Methodology and Tools
Refer to the exhibit. In the user connection monitor, the FortiSASE administrator notices the user name is showing random characters. Which configuration change must the administra...
log anonymizationconnection monitoruser visibilitylogging - Question #21Routing and Policy Troubleshooting
Refer to the exhibit. To allow access, which web filter configuration must you change on FortiSASE?
web filtercontent filterURL filteringFortiSASE policy - Question #22VPN Troubleshooting
Which policy type is used to control traffic between the FortiClient endpoint to FortiSASE for secure internet access?
VPN policyFortiClientFortiSASEinternet access policy - Question #23
Which FortiSASE feature can you use to see a list of Software-as-a-Service (SaaS) applications and health-check metrics for first-mile connectivity between the geographical points...
- Question #24VPN Troubleshooting
For FortiSASE point of presence (POP) to connect as a spoke, which Fortinet solution is required as standalone IPSec VPN hub?
POP spokeIPsec VPN hubNGFWSD-WAN - Question #25
Which FortiSASE component can be utilized for endpoint compliance?
- Question #26Troubleshooting Methodology and Tools
Which two deployment methods are used to connect a FortiExtender as a FortiSASE LAN extension? (Choose two.)
FortiExtenderLAN extensionFortiZTPstatic discovery - Question #27Troubleshooting Methodology and Tools
How does FortiSASE hide user information when viewing and analyzing logs?
log anonymizationhashingsaltdata privacy - Question #28VPN Troubleshooting
Refer to the exhibit. A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redir...
split tunnelingFQDNendpoint profileVPN exclusion - Question #29FortiClient for SASE
Refer to the exhibits. Win10-Pro and Win7-Pro are endpoints from the same remote location. Win10-Pro can access the internet though FortiSASE, while Win7-Pro can no longer access t...
device postureFortiClientendpoint complianceVPN access - Question #30FortiSASE Introduction
A customer wants to upgrade their legacy on-premises proxy to a cloud-based proxy for a hybrid network. Which FortiSASE features would help the customer to achieve this outcome?
SWGinline-CASBcloud proxyhybrid network - Question #31SD-WAN Integration
When you configure FortiSASE Secure Private Access (SPA) with SD-WAN integration, you must establish a routing adjacency between FortiSASE and the FortiGate SD-WAN hub. Which routi...
BGProuting protocolSD-WAN hubSPA - Question #32
FortiSASE delivers a converged networking and security solution. Which two features help with integrating FortiSASE into an existing network? (Choose two.)
- Question #33FortiClient for SASE
Which endpoint functionality can you configure using FortiSASE?
web filterFortiClientendpoint managementSWG - Question #34
How does integrating endpoint detection and response (EDR) systems into SASE contribute to security posture?
- Question #35
Which three ways does FortiSASE provide Secure Private Access (SPA) to corporate, non-web applications? (Choose three.)
- Question #36SD-WAN Integration
A FortiSASE administrator is configuring a Secure Private Access (SPA) solution to share endpoint information with a corporate FortiGate. Which three configuration actions will ach...
SPAEMS cloud connectorFortiCloudZTNA access proxy - Question #37Monitoring and Reporting
Refer to the exhibit. The daily report for application usage shows an unusually high number of unknown applications by category. What are two possible explanations for this? (Choos...
application controldeep inspectioninline-CASBtraffic reporting - Question #38Monitoring and Reporting
When viewing the daily summary report generated by FortiSASE. the administrator notices that the report contains very little data. What is a possible explanation for this almost em...
loggingsecurity eventstraffic logsreporting - Question #39FortiClient for SASE
You are designing a new network for Company X and one of the new cybersecurity policy requirements is that all remote user endpoints must always be connected and protected Which Fo...
always-on VPNFortiClientremote endpointsSASE - Question #40
Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGate hub. However, the administrator i...
- Question #41Advanced Security Policies
Refer to the exhibit. Based on the configuration shown, in which two ways will FortiSASE process sessions that require FortiSandbox inspection? (Choose two.)
FortiSandboxmalware inspectionfile quarantineUSB scanning - Question #42Access Policies
In a FortiSASE secure web gateway (SWG) deployment, which three features protect against web-based threats? (Choose three.)
SWGsandboxingSSL inspectionDLP - Question #43Access Policies
When deploying FortiSASE agentless secure web gateway (SWG) clients, which three features can you use to scan client traffic? (Choose three.)
agentless SWGinline-CASBDNS filterSSL inspection - Question #44ZTNA Access
Refer to the exhibit. A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between th...
ZTNAdevice postureZTNA tagsFortiGate integration - Question #45FortiSASE Introduction
In which three ways does FortiSASE help organizations ensure secure access for remote workers? (Choose three.)
ZTNAremote accesscloud applicationsaccess policies - Question #46Advanced Security Policies
Which two additional components does FortiSASE use for application control to act as an inline- CASB? (Choose two.)
inline-CASBSSL deep inspectionweb filterapplication control - Question #47Access Policies
An organization must block user attempts to log in to non-company resources while using Microsoft Office 365 to prevent users from accessing unapproved cloud resources. Which Forti...
inline-CASBweb filtertenant restrictionMicrosoft 365 - Question #48Deployment
Your organization is currently using FortiSASE for its cybersecurity. They have recently hired a contractor who will work from the HQ office and who needs temporary internet access...
agentless SWGPAC fileproxy configurationtemporary access - Question #49Access Policies
Refer to the exhibit. Users are unable to access https://login.live.com. To allow access, which web filter configuration must you change on FortiSASE?
web filterinline-CASBHTTP headerstenant restriction - Question #50FortiClient for SASE
Which two settings are automatically pushed from FortiSASE to FortiClient in a new FortiSASE deployment with default settings? (Choose two.)
FortiClientCA certificateZTNA tagsdefault settings