Weekend Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet FCSS_SASE_AD-24 FCSS - FortiSASE 24 Administrator Exam Practice Test

Page: 1 / 4
Total 43 questions

FCSS - FortiSASE 24 Administrator Questions and Answers

Question 1

What are two requirements to enable the MSSP feature on FortiSASE? (Choose two.)

Options:

A.

Add FortiCloud premium subscription on the root FortiCloud account.

B.

Configure MSSP user accounts and permissions on the FortiSASE portal.

C.

Assign role-based access control (RBAC) to IAM users using FortiCloud IAM portal.

D.

Enable multi-tenancy on the FortiSASE portal.

Question 2

Which secure internet access (SIA) use case minimizes individual endpoint configuration?

Options:

A.

Site-based remote user internet access

B.

Agentless remote user internet access

C.

SIA for SSL VPN remote users

D.

SIA using ZTNA

Question 3

Which two deployment methods are used to connect a FortiExtender as a FortiSASE LAN extension? (Choose two.)

Options:

A.

Connect FortiExtender to FortiSASE using FortiZTP

B.

Enable Control and Provisioning Wireless Access Points (CAPWAP) access on the FortiSASE portal.

C.

Enter the FortiSASE domain name in the FortiExtender GUI as a static discovery server

D.

Configure an IPsec tunnel on FortiSASE to connect to FortiExtender.

Question 4

Refer to the exhibits.

Question # 4

Question # 4

Question # 4

A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy.

Which configuration on FortiSASE is allowing users to perform the download?

Options:

A.

Web filter is allowing the traffic.

B.

IPS is disabled in the security profile group.

C.

The HTTPS protocol is not enabled in the antivirus profile.

D.

Force certificate inspection is enabled in the policy.

Question 5

Refer to the exhibits.

Question # 5

Question # 5

When remote users connected to FortiSASE require access to internal resources on Branch-2. how will traffic be routed?

Options:

A.

FortiSASE will use the SD-WAN capability and determine that traffic will be directed to HUB-2. which will then route traffic to Branch-2.

B.

FortiSASE will use the AD VPN protocol and determine that traffic will be directed to Branch-2 directly, using a static route

C.

FortiSASE will use the SD-WAN capability and determine that traffic will be directed to HUB-1, which will then route traffic to Branch-2.

D.

FortiSASE will use the AD VPN protocol and determine that traffic will be directed to Branch-2 directly, using a dynamic route

Question 6

An organization wants to block all video and audio application traffic but grant access to videos from CNN Which application override action must you configure in the Application Control with Inline-CASB?

Options:

A.

Allow

B.

Pass

C.

Permit

D.

Exempt

Question 7

A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between the remote endpoints and the protected servers to be processed by FortiGate.

In this scenario, which three setups will achieve the above requirements? (Choose three.)

Options:

A.

Configure ZTNA tags on FortiGate.

B.

Configure FortiGate as a zero trust network access (ZTNA) access proxy.

C.

Configure ZTNA servers and ZTNA policies on FortiGate.

D.

Configure private access policies on FortiSASE with ZTNA.

E.

Sync ZTNA tags from FortiSASE to FortiGate.

Question 8

Which statement applies to a single sign-on (SSO) deployment on FortiSASE?

Options:

A.

SSO overrides any other previously configured user authentication.

B.

SSO identity providers can be integrated using public and private access types.

C.

SSO is recommended only for agent-based deployments.

D.

SSO users can be imported into FortiSASE and added to user groups.

Question 9

Which statement describes the FortiGuard forensics analysis feature on FortiSASE?

Options:

A.

It can help troubleshoot user-to-application performance issues.

B.

It can help customers identify and mitigate potential risks to their network.

C.

It can monitor endpoint resources in real-time.

D.

It is a 24x7x365 monitoring service of your FortiSASE environment.

Question 10

In which three ways does FortiSASE help organizations ensure secure access for remote workers? (Choose three.)

Options:

A.

It enforces multi-factor authentication (MFA) to validate remote users.

B.

It secures traffic from endpoints to cloud applications.

C.

It uses the identity & access management (IAM) portal to validate the identities of remote workers.

D.

It offers zero trust network access (ZTNA) capabilities.

E.

It enforces granular access policies based on user identities.

Question 11

Refer to the exhibit.

Question # 11

A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redirect it to the endpoint physical Interface.

Which configuration must you apply to achieve this requirement?

Options:

A.

Exempt the Google Maps FQDN from the endpoint system proxy settings.

B.

Configure a static route with the Google Maps FQDN on the endpoint to redirect traffic

C.

Configure the Google Maps FQDN as a split tunneling destination on the FortiSASE endpoint profile.

D.

Change the default DNS server configuration on FortiSASE to use the endpoint system DNS.

Question 12

When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.)

Options:

A.

Endpoint management

B.

Points of presence

C.

SD-WAN hub

D.

Logging

E.

Authentication

Page: 1 / 4
Total 43 questions