FCSS_SASE_AD-24 Exam Questions
52 real FCSS_SASE_AD-24 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1ZTNA Access
Which role does FortiSASE play in supporting zero trust network access (ZTNA) principles?
ZTNAsecurity postureendpoint attributeszero trust - Question #2
When deploying FortiSASE agent-based clients, which three features are available compared to an agentless solution? (Choose three.)
- Question #3ZTNA Access
Which FortiSASE feature ensures least-privileged user access to all applications?
ZTNAleast-privileged accessapplication access - Question #4Deployment
Which two components are part of onboarding a secure web gateway (SWG) endpoint? (Choose two)
SWGPAC fileCA certificateendpoint onboarding - Question #5ZTNA Access
To complete their day-to-day operations, remote users require access to a TCP-based application that is hosted on a private web server. Which FortiSASE deployment use case provides...
ZTNA private accessTCP applicationprivate web serverremote access - Question #6Access Policies
Which secure internet access (SIA) use case minimizes individual workstation or device setup, because you do not need to install FortiClient on endpoints or configure explicit web...
SIAsite-based accessagentlessLAN extension - Question #7
Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish. Based on the provided configurat...
- Question #8Advanced Security Policies
Which two additional components does FortiSASE use for application control to act as an inline- CASB? (Choose two.)
inline-CASBSSL deep inspectionIPSapplication control - Question #9FortiSASE Introduction
Which two advantages does FortiSASE bring to businesses with multiple branch offices? (Choose two.)
centralized managementbranch officesSASE benefitson-premises replacement - Question #10Deployment
When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.)
endpoint managementpoints of presencelogginginitial provisioning - Question #11Deployment
During FortiSASE provisioning, how many security points of presence (POPs) need to be configured by the FortiSASE administrator?
points of presencePOPsprovisioningdeployment - Question #12FortiSASE Deployment and Configuration
An organization needs to resolve internal hostnames using its internal rather than public DNS servers for remotely connected endpoints. Which two components must be configured on F...
split DNSinternal DNS resolutionsplit tunnelingFortiSASE endpoint profile - Question #13
When using Secure Private Access (SPA) and SD-WAN, which protocol is used for spoke-to- spoke connectivity?
- Question #14
Which FortiSASE Secure Private Access (SPA) deployment involves installing FortiClient on remote endpoints?
- Question #15
A customer has an existing network that needs access to a secure application on the cloud. Which FortiSASE feature can the customer use to provide secure Software-as-a-Service (Saa...
- Question #16Security Profiles and Policies
Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are st...
antivirus profilecertificate inspectionSSL deep inspectionHTTPS scanning - Question #17Security Profiles and Policies
An organization wants to block all video and audio application traffic but grant access to videos from CNN. Which application override action must you configure in the Application...
application controlinline-CASBapplication overridecontent filtering - Question #18
Refer to the exhibits. When remote users connected to FortiSASE require access to internal resources on Branch-2. how will traffic be routed?
- Question #19Zero Trust Network Access (ZTNA)
What are two advantages of using zero-trust tags? (Choose two.)
zero-trust tagsendpoint security postureZTNAnetwork access control - Question #20Monitoring and Reporting
Refer to the exhibit. In the user connection monitor, the FortiSASE administrator notices the user name is showing random characters. Which configuration change must the administra...
log anonymizationuser monitoringconnection monitorFortiSASE logging - Question #21Security Profiles and Policies
Refer to the exhibit. To allow access, which web filter configuration must you change on FortiSASE?
web filtercontent filterURL filteringFortiSASE policy - Question #22FortiSASE Deployment and Configuration
Which policy type is used to control traffic between the FortiClient endpoint to FortiSASE for secure internet access?
VPN policyinternet access policyFortiClientsecure internet access - Question #23
Which FortiSASE feature can you use to see a list of Software-as-a-Service (SaaS) applications and health-check metrics for first-mile connectivity between the geographical points...
- Question #24FortiSASE Network Architecture and Connectivity
For FortiSASE point of presence (POP) to connect as a spoke, which Fortinet solution is required as standalone IPSec VPN hub?
IPSec VPNhub-spoke topologyFortiSASE POPNGFW - Question #25
Which FortiSASE component can be utilized for endpoint compliance?
- Question #26FortiSASE Deployment and Configuration
Which two deployment methods are used to connect a FortiExtender as a FortiSASE LAN extension? (Choose two.)
FortiExtenderLAN extensionFortiZTPstatic discovery server - Question #27Monitoring and Reporting
How does FortiSASE hide user information when viewing and analyzing logs?
log anonymizationdata privacysalted hashinguser identity - Question #28FortiSASE Deployment and Configuration
Refer to the exhibit. A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redir...
split tunnelingFQDN exclusionendpoint profileVPN tunnel - Question #29
Refer to the exhibits. Win10-Pro and Win7-Pro are endpoints from the same remote location. Win10-Pro can access the internet though FortiSASE, while Win7-Pro can no longer access t...
- Question #30SASE Architecture and Cloud Security
A customer wants to upgrade their legacy on-premises proxy to a cloud-based proxy for a hybrid network. Which FortiSASE features would help the customer to achieve this outcome?
SWGinline-CASBcloud proxyhybrid network migration - Question #31FortiSASE SD-WAN Integration
When you configure FortiSASE Secure Private Access (SPA) with SD-WAN integration, you must establish a routing adjacency between FortiSASE and the FortiGate SD-WAN hub. Which routi...
BGPSD-WAN integrationSecure Private Accessrouting adjacency - Question #32
FortiSASE delivers a converged networking and security solution. Which two features help with integrating FortiSASE into an existing network? (Choose two.)
- Question #33Endpoint Security and Management
Which endpoint functionality can you configure using FortiSASE?
endpoint managementweb filter pushFortiClientendpoint profile - Question #34
How does integrating endpoint detection and response (EDR) systems into SASE contribute to security posture?
- Question #35
Which three ways does FortiSASE provide Secure Private Access (SPA) to corporate, non-web applications? (Choose three.)
- Question #36Zero Trust Network Access (ZTNA)
A FortiSASE administrator is configuring a Secure Private Access (SPA) solution to share endpoint information with a corporate FortiGate. Which three configuration actions will ach...
Secure Private AccessFortiGate integrationZTNAFortiCloud account - Question #37Monitoring and Reporting
Refer to the exhibit. The daily report for application usage shows an unusually high number of unknown applications by category. What are two possible explanations for this? (Choos...
application visibilitySSL deep inspectioncertificate inspectionunknown applications - Question #38Monitoring and Reporting
When viewing the daily summary report generated by FortiSASE. the administrator notices that the report contains very little data. What is a possible explanation for this almost em...
traffic loggingsecurity events loggingreport dataFortiSASE reporting - Question #39Endpoint Security and Management
You are designing a new network for Company X and one of the new cybersecurity policy requirements is that all remote user endpoints must always be connected and protected Which Fo...
always-on VPNFortiClientendpoint protectionremote user security - Question #40
Refer to the exhibits. A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGate hub. However, the administrator i...
- Question #41Monitoring and Reporting
Which statement best describes the Digital Experience Monitor (DEM) feature on FortiSASE?
Digital Experience MonitoringDEMnetwork visibilitySaaS application monitoring - Question #42FortiSASE Administration and Multi-tenancy
What are two requirements to enable the MSSP feature on FortiSASE? (Choose two.)
MSSPmulti-tenancyFortiCloud IAMRBAC - Question #43FortiSASE Logging and Monitoring
Which event log subtype captures FortiSASE SSL VPN user creation?
event loggingSSL VPNlog subtypesFortiSASE monitoring - Question #44FortiSASE Deployment and Configuration
Your organization is currently using FortiSASE for its cybersecurity. They have recently hired a contractor who will work from the HQ office and who needs temporary internet access...
ZTNAunmanaged endpointscontractor accessagentless access - Question #45Zero Trust Network Access
Which two statements describe a zero trust network access (ZTNA) private access use case? (Choose two.)
ZTNAprivate accessTCP applicationsdevice posture - Question #46FortiSASE Identity and Authentication
Which statement applies to a single sign-on (SSO) deployment on FortiSASE?
SSOuser authenticationidentity providersuser groups - Question #47FortiSASE Security Features
Which statement describes the FortiGuard forensics analysis feature on FortiSASE?
FortiGuard forensicsrisk mitigationthreat analysissecurity analytics - Question #48Zero Trust Network Access
A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between the remote endpoints and...
ZTNA tagsFortiGate integrationaccess proxydevice posture checks - Question #49Cloud Access Security Broker
Which of the following describes the FortiSASE inline-CASB component?
inline-CASBcloud applicationstraffic inspectionCASB deployment - Question #50Secure Internet Access
An organization must block user attempts to log in to non-company resources while using Microsoft Office 365 to prevent users from accessing unapproved cloud resources. Which Forti...
Web Filterinline-CASBtenant restrictionsSaaS access control