Fortinet FCSS_SASE_AD-23 Exam Practice Questions (P. 2)
- Full Access (54 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Refer to the exhibit.

A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redirect it to the endpoint physical interface.
Which configuration must you apply to achieve this requirement?

A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redirect it to the endpoint physical interface.
Which configuration must you apply to achieve this requirement?
- AExempt the Google Maps FQDN from the endpoint system proxy settings.
- BConfigure a static route with the Google Maps FQDN on the endpoint to redirect traffic
- CConfigure the Google Maps FQDN as a split tunneling destination on the FortiSASE endpoint profile.
- DChange the default DNS server configuration on FortiSASE to use the endpoint system DNS.
send
light_mode
delete
Question #7
Refer to the exhibit.

To allow access, which web filter configuration must you change on FortiSASE?

To allow access, which web filter configuration must you change on FortiSASE?
- AFortiGuard category-based filter
- Bcontent filter
- CURL Filter
- Dinline cloud access security broker (CASB) headers
send
light_mode
delete
Question #8
Refer to the exhibits.


Win10-Pro and Win7-Pro are endpoints from the same remote location. Win10-Pro can access the internet though FortiSASE, while Win7-Pro can no longer access the internet.
Given the exhibits, which reason explains the outage on Win7-Pro?


Win10-Pro and Win7-Pro are endpoints from the same remote location. Win10-Pro can access the internet though FortiSASE, while Win7-Pro can no longer access the internet.
Given the exhibits, which reason explains the outage on Win7-Pro?
- AThe Win7-Pro device posture has changed.
- BWin7-Pro cannot reach the FortiSASE SSL VPN gateway
- CThe Win7-Pro FortiClient version does not match the FortiSASE endpoint requirement.
- DWin-7 Pro has exceeded the total vulnerability detected threshold.
send
light_mode
delete
Question #9
Refer to the exhibits.





A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGate hub. However, the administrator is not able to ping the Webserver hosted behind the FortiGate hub.
Based on the output, what is the reason for the ping failures?





A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGate hub. However, the administrator is not able to ping the Webserver hosted behind the FortiGate hub.
Based on the output, what is the reason for the ping failures?
- AThe Secure Private Access (SPA) policy needs to allow PING service.
- BQuick mode selectors are restricting the subnet.
- CThe BGP route is not received.
- DNetwork address translation (NAT) is not enabled on the spoke-to-hub policy.
send
light_mode
delete
Question #10
An organization wants to block all video and audio application traffic but grant access to videos from CNN.
Which application override action must you configure in the Application Control with Inline-CASB?
Which application override action must you configure in the Application Control with Inline-CASB?
send
light_mode
delete
All Pages