FCSS_SASE_AD-23 Exam Details

  • Exam Code
    :FCSS_SASE_AD-23
  • Exam Name
    :FCSS - FortiSASE 23 Administrator
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :30 Q&As
  • Last Updated
    :Jan 11, 2026

Fortinet FCSS_SASE_AD-23 Online Questions & Answers

  • Question 1:

    Which role does FortiSASE play in supporting zero trust network access (ZTNA) principles9

    A. It offers hardware-based firewalls for network segmentation.
    B. It integrateswith software-defined network (SDN) solutions.
    C. It can identify attributes on the endpoint for security posture check.
    D. It enables VPN connections for remote employees.

  • Question 2:

    Which two deployment methods are used to connect a FortiExtender as a FortiSASE LAN extension? (Choose two.)

    A. Connect FortiExtender to FortiSASE using FortiZTP
    B. Enable Control and Provisioning Wireless Access Points (CAPWAP) access on the FortiSASE portal.
    C. Enter the FortiSASE domain name in the FortiExtender GUI as a static discovery server
    D. Configure an IPsec tunnel on FortiSASE to connect to FortiExtender.

  • Question 3:

    When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.)

    A. Endpoint management
    B. Points of presence
    C. SD-WAN hub
    D. Logging
    E. Authentication

  • Question 4:

    Refer to the exhibits.

    A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGale hub. However, the administrator is not able to ping the webserver hosted behind the FortiGate hub.

    Based on the output, what is the reason for the ping failures?

    A. The Secure Private Access (SPA) policy needs to allow PING service.
    B. Quick mode selectors are restricting the subnet.
    C. The BGP route is not received.
    D. Network address translation (NAT) is not enabled on the spoke-to-hub policy.

  • Question 5:

    Refer to the exhibit.

    To allow access, which web tiller configuration must you change on FortiSASE?

    A. FortiGuard category-based filter
    B. content filter
    C. URL Filter
    D. inline cloud access security broker (CASB) headers

  • Question 6:

    Refer to the exhibits.

    A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish

    Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?

    A. NAT needs to be enabled in the Spoke-to-Hub firewall policy.
    B. The BGP router ID needs to match on the hub and FortiSASE.
    C. FortiSASE spoke devices do not support mode config.
    D. The hub needs IKEv2 enabled in the IPsec phase 1 settings.

  • Question 7:

    A FortiSASE administrator is configuring a Secure Private Access (SPA) solution to share endpoint information with a corporate FortiGate.

    Which three configuration actions will achieve this solution? (Choose three.)

    A. Add the FortiGate IP address in the secure private access configuration on FortiSASE.
    B. Use the FortiClient EMS cloud connector on the corporate FortiGate to connect to FortiSASE
    C. Register FortiGate and FortiSASE under the same FortiCloud account.
    D. Authorize the corporate FortiGate on FortiSASE as a ZTNA access proxy.
    E. Apply the FortiSASE zero trust network access (ZTNA) license on the corporate FortiGate.

  • Question 8:

    Refer to the exhibits.

    A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy.

    Which configuration on FortiSASE is allowing users to perform the download?

    A. Web filter is allowing the traffic.
    B. IPS is disabled in the security profile group.
    C. The HTTPS protocol is not enabled in the antivirus profile.
    D. Force certificate inspection is enabled in the policy.

  • Question 9:

    Which two advantages does FortiSASE bring to businesses with multiple branch offices? (Choose two.)

    A. It offers centralized management for simplified administration.
    B. It enables seamless integration with third-party firewalls.
    C. it offers customizable dashboard views for each branch location
    D. It eliminates the need to have an on-premises firewall for eachbranch.

  • Question 10:

    When deploying FortiSASE agent-based clients, which three features are available compared to an agentless solution? (Choose three.)

    A. Vulnerability scan
    B. SSL inspection
    C. Anti-ransomware protection
    D. Web filter
    E. ZTNA tags

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your FCSS_SASE_AD-23 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.