Skip to main content

FCSS_SASE_AD-24 Online Exam

FCSS - FortiSASE 24 Administrator

43 questions available ยท Page 1 of 5

View study plans
Question 1 Single choice

Which statement applies to a single sign-on (SSO) deployment on FortiSASE?

  1. A

    SSO overrides any other previously configured user authentication.

  2. B

    SSO identity providers can be integrated using public and private access types.

  3. C

    SSO is recommended only for agent-based deployments.

  4. D

    SSO users can be imported into FortiSASE and added to user groups.

Show answer and explanation

Correct answer: D

Explanation

In aSingle Sign-On (SSO)deployment on FortiSASE,SSO users can be imported into FortiSASE and added to user groups. This allows administrators to manage SSO users within FortiSASE, enabling them to apply policies, permissions, and group-based access controls. By integrating SSO with FortiSASE, organizations can streamline user authentication and simplify access management while maintaining security.
Here's why the other options are incorrect:
A. SSO overrides any other previously configured user authentication:This is incorrect because SSO does
not automatically override other authentication methods. FortiSASE supports multiple authentication mechanisms, and SSO is just one of them. Administrators can configure fallback authentication methods if needed.
B. SSO identity providers can be integrated using public and private access types:While FortiSASE
supports integration with various identity providers (e.g., SAML, LDAP, OAuth), the concept of "public and private access types" is not applicable to SSO configurations.
C. SSO is recommended only for agent-based deployments:This is incorrect because SSO can be used in
both agent-based and agentless deployments. It is not limited to environments where agents are installed.
References:
Fortinet FCSS FortiSASE Documentation - Single Sign-On (SSO) Integration FortiSASE Administration Guide - User Authentication and SSO ================

Question 2 Multiple choice

When deploying FortiSASE agent-based clients, which three features are available compared to an agentless solution? (Choose three.)

  1. A

    Vulnerability scan

  2. B

    SSL inspection

  3. C

    Anti-ransomware protection

  4. D

    Web filter

  5. E

    ZTNA tags

Show answer and explanation

Correct answers: A, C, E

Question 3 Multiple choice

An organization needs to resolve internal hostnames using its internal rather than public DNS servers for remotely connected endpoints.

Which two components must be configured on FortiSASE to achieve this? (Choose two.)

  1. A

    SSL deep inspection

  2. B

    Split DNS rules

  3. C

    Split tunnelling destinations

  4. D

    DNS filter

Show answer and explanation

Correct answers: A, B

Explanation

To resolve internal hostnames using internal DNS servers for remotely connected endpoints, the following two components must be configured on FortiSASE: Split DNS Rules: Split Tunneling Destinations:
References:
FortiOS 7.2 Administration Guide: Provides details on configuring split DNS and split tunneling for VPN clients.
FortiSASE 23.2 Documentation: Explains the implementation and configuration of split DNS and split tunneling for securely resolving internal hostnames.

Question 4 Single choice

A customer wants to upgrade their legacy on-premises proxy to a could-based proxy for a hybrid network.

Which FortiSASE features would help the customer to achieve this outcome?

  1. A

    SD-WAN and NGFW

  2. B

    SD-WAN and inline-CASB

  3. C

    zero trust network access (ZTNA) and next generation firewall (NGFW)

  4. D

    secure web gateway (SWG) and inline-CASB

Show answer and explanation

Correct answer: D

Explanation

For a customer looking to upgrade their legacy on-premises proxy to a cloud-based proxy for a hybrid network, the combination of Secure Web Gateway (SWG) and Inline Cloud Access Security Broker (CASB) features in FortiSASE will provide the necessary capabilities.
Secure Web Gateway (SWG):
Inline Cloud Access Security Broker (CASB):
References:
FortiOS 7.2 Administration Guide: Details on SWG and CASB features. FortiSASE 23.2 Documentation: Explains how SWG and inline-CASB are used in cloud-based proxy solutions.

Question 5 Multiple choice

Refer to the exhibit.

The daily report for application usage shows an unusually high number of unknown applications by category.

What are two possible explanations for this? (Choose two.)

  1. A

    Certificate inspection is not being used to scan application traffic.

  2. B

    The inline-CASB application control profile does not have application categories set to Monitor

  3. C

    Zero trust network access (ZTNA) tags are not being used to tag the correct users.

  4. D

    Deep inspection is not being used to scan traffic.

Show answer and explanation

Correct answers: B, D

Question 6 Single choice

Which statement best describes the Digital Experience Monitor (DEM) feature on FortiSASE?

  1. A

    It provides end-to-end network visibility from all the FortiSASE security PoPs to a specific SaaS application.

  2. B

    It can be used to request a detailed analysis of the endpoint from the FortiGuard team.

  3. C

    It requires a separate DEM agent to be downloaded from the FortiSASE portal and installed on the endpoint.

  4. D

    It can help IT and security teams ensure consistent security monitoring for remote users.

Show answer and explanation

Correct answer: A

Explanation

TheDigital Experience Monitor (DEM)feature in FortiSASE is designed to provideend-to-end network visibilityby monitoring the performance and health of connections between FortiSASE security Points of Presence (PoPs) and specific SaaS applications. This ensures that administrators can identify and troubleshoot issues related to latency, jitter, packet loss, and other network performance metrics that could impact user experience when accessing cloud-based services.
Here's why the other options are incorrect:
B. It can be used to request a detailed analysis of the endpoint from the FortiGuard team:This is incorrect
because DEM focuses on network performance monitoring, not endpoint analysis. Endpoint analysis would typically involve tools like FortiClient or FortiEDR, not DEM.
C. It requires a separate DEM agent to be downloaded from the FortiSASE portal and installed on the
endpoint:This is incorrect because DEM operates at the network level and does not require an additional agent to be installed on endpoints.
D. It can help IT and security teams ensure consistent security monitoring for remote users:While DEM
indirectly supports security by ensuring optimal network performance, its primary purpose is to monitor and improve the digital experience rather than enforce security policies.
References:
Fortinet FCSS FortiSASE Documentation - Digital Experience Monitoring Overview FortiSASE
Administration Guide - Configuring DEM ================

Question 7 Single choice

Which FortiSASE feature ensures least-privileged user access to all applications?

  1. A

    secure web gateway (SWG)

  2. B

    SD-WAN

  3. C

    zero trust network access (ZTNA)

  4. D

    thin branch SASE extension

Show answer and explanation

Correct answer: C

Explanation

Zero Trust Network Access (ZTNA) is the FortiSASE feature that ensures least-privileged user access to all applications. ZTNA operates on the principle of "never trust, always verify," providing secure access based on the identity of users and devices, regardless of their location.
Zero Trust Network Access (ZTNA):
Implementation:
References:
FortiOS 7.2 Administration Guide: Provides detailed information on ZTNA and its role in ensuring least-privileged access.
FortiSASE 23.2 Documentation: Explains the implementation and benefits of ZTNA within the FortiSASE environment.

Question 8 Multiple choice

What are two advantages of using zero-trust tags? (Choose two.)

  1. A

    Zero-trust tags can be used to allow or deny access to network resources

  2. B

    Zero-trust tags can determine the security posture of an endpoint.

  3. C

    Zero-trust tags can be used to create multiple endpoint profiles which can be applied to different endpoints

  4. D

    Zero-trust tags can be used to allow secure web gateway (SWG) access

Show answer and explanation

Correct answers: A, B

Explanation

Zero-trust tags are critical in implementing zero-trust network access (ZTNA) policies. Here are the two key advantages of using zero-trust tags: Access Control (Allow or Deny): Determining Security Posture:
References:
FortiOS 7.2 Administration Guide: Provides detailed information on configuring and using zero-trust tags for access control and security posture assessment. FortiSASE 23.2 Documentation: Explains how zero-trust tags are implemented and used within the FortiSASE environment for enhancing security and compliance.

Question 9 Single choice

Which of the following describes the FortiSASE inline-CASB component?

  1. A

    It provides visibility for unmanaged locations and devices.

  2. B

    It is placed directly in the traffic path between the endpoint and cloud applications.

  3. C

    It uses API to connect to the cloud applications.

  4. D

    It detects data at rest.

Show answer and explanation

Correct answer: B

Explanation

TheFortiSASE inline-CASB (Cloud Access Security Broker)component is designed to provide real-time security and visibility by beingplaced directly in the traffic path between the endpoint and cloud applications. Inline-CASB inspects traffic as it flows to and from cloud applications, enablingenforcement of security policies, detection of threats, and prevention of unauthorized access. This approach ensures that all interactions with cloud applications are monitored and controlled in real time.
Here's why the other options are incorrect:
A. It provides visibility for unmanaged locations and devices:While inline-CASB enhances visibility, its
primary function is to inspect and secure traffic in real time. Visibility for unmanaged locations and devices is typically achieved through other components like endpoint agents or API-based CASB. C. It uses API to connect to the cloud applications:API-based CASB is a different approach that relies on APIs provided by cloud applications to monitor and manage data. Inline-CASB operates directly in the traffic flow rather than using APIs.
D. It detects data at rest:Detecting data at rest is typically handled by Data Loss Prevention (DLP) tools or
API-based CASB solutions. Inline-CASB focuses on inspecting traffic in motion, not data stored in cloud applications.
References:
Fortinet FCSS FortiSASE Documentation - Inline-CASB Overview FortiSASE Administration Guide - Cloud
Application Security

Question 10 Single choice

An organization wants to block all video and audio application traffic but grant access to videos from CNN

Which application override action must you configure in the Application Control with Inline-CASB?

  1. A

    Allow

  2. B

    Pass

  3. C

    Permit

  4. D

    Exempt

Show answer and explanation

Correct answer: A