Fortinet FCSS_SASE_AD-23 Exam Practice Questions (P. 1)
- Full Access (54 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Refer to the exhibit.

The daily report for application usage shows an unusually high number of unknown applications by category.
What are two possible explanations for this? (Choose two.)

The daily report for application usage shows an unusually high number of unknown applications by category.
What are two possible explanations for this? (Choose two.)
- ACertificate inspection is not being used to scan application traffic.
- BThe inline-CASB application control profile does not have application categories set to Monitor.
- CZero trust network access (ZTNA) tags are not being used to tag the correct users.
- DDeep inspection is not being used to scan traffic.
send
light_mode
delete
Question #2
What are two advantages of using zero-trust tags? (Choose two.)
- AZero-trust tags can be used to allow or deny access to network resources.
- BZero-trust tags can determine the security posture of an endpoint.
- CZero-trust tags can be used to create multiple endpoint profiles which can be applied to different endpoints.
- DZero-trust tags can be used to allow secure web gateway (SWG) access.
send
light_mode
delete
Question #3
Refer to the exhibits.





A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish.
Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?





A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish.
Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?
- ANAT needs to be enabled in the Spoke-to-Hub firewall policy.
- BThe BGP router ID needs to match on the hub and FortiSASE.
- CFortiSASE spoke devices do not support mode config.
- DThe hub needs IKEv2 enabled in the IPsec phase 1 settings.
send
light_mode
delete
Question #4
Refer to the exhibits.


When remote users connected to FortiSASE require access to internal resources on Branch-2, how will traffic be routed?


When remote users connected to FortiSASE require access to internal resources on Branch-2, how will traffic be routed?
- AFortiSASE will use the SD-WAN capability and determine that traffic will be directed to HUB-2, which will then route traffic to Branch-2.
- BFortiSASE will use the AD VPN protocol and determine that traffic will be directed to Branch-2 directly, using a static route.
- CFortiSASE will use the SD-WAN capability and determine that traffic will be directed to HUB-1, which will then route traffic to Branch-2.
- DFortiSASE will use the AD VPN protocol and determine that traffic will be directed to Branch-2 directly, using a dynamic route.
send
light_mode
delete
Question #5
Refer to the exhibits.



A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy.
Which configuration on FortiSASE is allowing users to perform the download?



A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy.
Which configuration on FortiSASE is allowing users to perform the download?
- AWeb filter is allowing the traffic.
- BIPS is disabled in the security profile group.
- CThe HTTPS protocol is not enabled in the antivirus profile.
- DForce certificate inspection is enabled in the policy.
send
light_mode
delete
All Pages