FCSS_SASE_AD-25 Exam Questions
55 real FCSS_SASE_AD-25 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1FortiSASE Access Control
An administrator must restrict endpoints from certain countries from connecting to FortiSASE. Which configuration can achieve this?
geofencinggeo-restrictioncountry blockingaccess control - Question #2FortiSASE Deployment Scenarios
What is the benefit of SD-WAN on-ramp deployment with FortiSASE?
SD-WAN on-rampbranch securityinternet trafficSASE deployment - Question #3FortiSASE Agent Deployment
Which two settings are automatically pushed from FortiSASE to FortiClient in a new FortiSASE deployment with default settings? (Choose two.)
FortiClienttunnel profileCA certificateauto-provisioning - Question #4FortiSASE Troubleshooting
Refer to the exhibits. Jumpbox and Windows-AD are endpoints from the same remote location. Jumpbox can access the internet through FortiSASE, while Windows-AD can no longer access...
device postureZTNA tagsendpoint compliancetroubleshooting - Question #5Cloud Access Security Broker
Which description of the FortiSASE inline-CASB component is true?
inline-CASBdata in motiontraffic inspectionCASB - Question #6FortiSASE Identity and Authentication
Which authentication method overrides any other previously configured user authentication on FortiSASE?
SSOauthentication overrideidentity managementuser authentication - Question #7Zero Trust Network Access
What are two advantages of using zero-trust tags? (Choose two.)
zero-trust tagsdevice postureaccess controlendpoint security - Question #8Zero Trust Network Access
Which FortiSASE feature ensures least-privileged user access to corporate applications that are protected by an on-premises FortiGate device?
ZTNAleast privilegeprivate accessFortiGate integration - Question #9FortiSASE Secure Private Access
A company must provide access to a web server through FortiSASE secure private access for contractors. What is the recommended method to provide access?
bookmark portalprivate accesscontractor accessagentless access - Question #10FortiSASE Deployment Scenarios
Your FortiSASE customer has a small branch office in which ten users will be using their personal laptops and mobile devices to access the internet. Which deployment should they us...
FortiAPbranch deploymentagentless securityBYOD - Question #11ZTNA Access
Which information does FortiSASE use to bring network lockdown into effect on an endpoint?
network lockdownZTNA tagsendpoint posturesecurity compliance - Question #12Monitoring and Reporting
For monitoring potentially unwanted applications on endpoints, which information is available on the FortiSASE software installations page?
software inventoryendpoint monitoringpotentially unwanted applicationsFortiSASE portal - Question #13FortiClient for SASE
What is the recommended method to upgrade FortiClient in a FortiSASE deployment?
FortiClient upgradeendpoint groupsupgrade rulesendpoint management - Question #14Administration
Which two are required to enable central management on FortiSASE? (Choose two.)
central managementFortiManager integrationFortiCloud accountFortiSASE connector - Question #15Advanced Security Policies
Which FortiSASE component protects users from online threats by hosting their browsing sessions on a remote container within a secure environment?
remote browser isolationRBIbrowsing securitycloud container - Question #16ZTNA Access
What are two benefits of deploying FortiSASE with FortiGate ZTNA access proxy? (Choose two.)
ZTNA access proxyFortiGate integrationagentless ZTNAlatency-sensitive applications - Question #17SD-WAN Integration
In a FortiSASE SD-WAN deployment with dual hubs, what are two benefits of assigning hubs with different priorities? (Choose two.)
dual hubhub prioritytraffic steeringSD-WAN redundancy - Question #18FortiClient for SASE
Refer to the exhibits. Antivirus is installed on a Windows 10 endpoint, but the windows application firewall is stopping it from running. What will the endpoint security posture ch...
security posture checkcompliance taggingZTNA tagsantivirus status - Question #19FortiClient for SASE
What can be configured on FortiSASE as an additional layer of security for FortiClient registration?
FortiClient registrationdevice identificationendpoint securityauthentication - Question #20Monitoring and Reporting
Which statement best describes the Digital Experience Monitor (DEM) feature on FortiSASE?
DEMdigital experience monitoringnetwork visibilitySaaS applications - Question #21FortiSASE Introduction
In which two ways does FortiSASE help organizations ensure secure access for remote workers? (Choose two.)
ZTNAremote accesscloud applicationssecure access - Question #22Monitoring and Reporting
How does FortiSASE hide user information when viewing and analyzing logs?
log anonymizationhashinguser privacytraffic logs - Question #23Administration
How do security profile group objects behave when central management is enabled on FortiSASE?
central managementFortiManagersecurity profile objectsobject synchronization - Question #24Deployment
A customer wants to upgrade their legacy on-premises proxy to a cloud-based proxy for a hybrid network. Which two FortiSASE features would help the customer achieve this outcome? (...
SWGinline-CASBhybrid networkcloud proxy migration - Question #25SD-WAN Integration
Refer to the exhibits. A FortiSASE administrator has configured FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGate hub. However, the remote FortiClient is n...
BGP routesspoke-hub topologySD-WAN troubleshootingFortiGate hub - Question #26Deployment
Which two purposes is the dedicated IP address used for in a FortiSASE deployment? (Choose two.)
dedicated IPIP allocationregulatory complianceuser isolation - Question #27Monitoring and Reporting
How can digital experience monitoring (DEM) on an endpoint assist in diagnosing connectivity and network issues?
DEMtrace jobSaaS connectivityendpoint diagnostics - Question #28Monitoring and Reporting
Refer to the exhibit. While reviewing the traffic logs, the FortiSASE administrator notices that the usernames are showing random characters. Why are the usernames showing random c...
log anonymizationusername hashingtraffic logsuser privacy - Question #29ZTNA Access
A customer wants to ensure secure access for private applications for their users by replacing their VPN. Which two SASE technologies can you use to accomplish this task? (Choose t...
ZTNAVPN replacementSD-WAN on-rampprivate application access - Question #30Deployment
Which secure internet access (SIA) use case minimizes individual endpoint configuration?
SIAsite-based internet accessendpoint configurationFortiSASE deployment - Question #31FortiSASE Introduction
Which service is included in a secure access service edge (SASE) solution, but not in a security service edge (SSE) solution?
SASESSESD-WANservice components - Question #32FortiClient for SASE
Which two additional features does FortiClient integration provide with FortiSASE, when compared to secure web gateway (SWG) deployment? (Choose two.)
FortiClientSWG deploymentvulnerability managementdevice posture check - Question #33Advanced Security Policies
An organization must block user attempts to log in to non-company resources while using Microsoft Office 365 to prevent users from accessing unapproved cloud resources. Which Forti...
inline-CASBapplication controltenant restrictionsOffice 365 - Question #34ZTNA Access
Refer to the exhibit. A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between th...
ZTNAdevice posture checkaccess proxyZTNA policies - Question #35FortiClient for SASE
Refer to the exhibit. An organization must inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redirect it to...
split tunnelingsteering bypassendpoint profileVPN tunnel - Question #36Monitoring and Reporting
What happens to the logs on FortiSASE that are older than the configured log retention period?
log retentionlog lifecycleFortiSASE logging - Question #37Administration
What is required to enable the MSSP feature on FortiSASE?
MSSPRBACIAMmulti-tenancy - Question #38Deployment
When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.)
FortiSASE provisioningdata center locationsinitial setuppoints of presence - Question #39Access Policies
Which statement applies to a single sign-on (SSO) deployment on FortiSASE?
SSOidentity provideruser authenticationauthentication override - Question #40SD-WAN Integration
What are two benefits of deploying secure private access with SD-WAN? (Choose two.)
secure private accessSD-WANZTNA posture checkUDP support - Question #41FortiClient for SASE
Refer to the exhibits. How will the application vulnerabilities be patched, based on the exhibits provided?
vulnerability managementremote patchingendpoint managementFortiClient - Question #42Access Policies
Which two of the following can release the network lockdown on the endpoint applied by FortiSASE? (Choose two.)
network lockdownZTNA tagsendpoint complianceFortiSASE tunnel - Question #43Deployment
Your organization is currently using FortiSASE for its cybersecurity. They have recently hired a contractor who will work from the HQ office and who needs temporary internet access...
self-registration portalguest accessagentlessinternet access - Question #44Monitoring and Reporting
Refer to the exhibit. The daily report for application usage for internet traffic shows an unusually high number of unknown applications by category. What are two possible explanat...
application visibilitydeep inspectioncertificate inspectionunknown applications - Question #45ZTNA Access
To complete their day-to-day operations, remote users require access to a TCP-based application that is hosted on a private web server. Which FortiSASE deployment use case provides...
ZTNA private accessTCP applicationsremote accessprivate web server - Question #46Deployment
Which secure internet access (SIA) use case minimizes individual workstation or device setup, because you do not need to install FortiClient on endpoints or configure explicit web...
secure internet accesssite-based usersSWGagentless deployment - Question #47FortiSASE Introduction
Which two advantages does FortiSASE bring to businesses with multiple branch offices? (Choose two.)
SASE benefitsbranch officescentralized managementon-premises firewall - Question #48Deployment
During FortiSASE provisioning, how many security points of presence (POPs) need to be configured by the FortiSASE administrator?
provisioningpoints of presenceFortiSASE setupPOP configuration - Question #49SD-WAN Integration
In the Secure Private Access (SPA) use case, which two FortiSASE features facilitate access to corporate applications? (Choose two.)
secure private accessSD-WANZTNAthin edge - Question #50Deployment
Which two components are part of onboarding a secure web gateway (SWG) endpoint for secure internet access (SIA)? (Choose two.)
SWG onboardingPAC fileFortiClientsecure internet access