Free FCSS_SASE_AD-23 Sample Questions — FCSS - FortiSASE 23 Administrator

Free FCSS_SASE_AD-23 sample questions for the FCSS - FortiSASE 23 Administrator exam. No account required: study at your own pace.

Want an interactive quiz? Take the full FCSS_SASE_AD-23 practice test

Looking for more? Click here to get the full PDF with 32+ practice questions for $5 for offline study and deeper preparation.

Question 1

Which FortiSASE feature ensures least-privileged user access to all applications?

  • A. secure web gateway (SWG)
  • B. SD-WAN
  • C. zero trust network access (ZTNA)
  • D. thin branch SASE extension
Show Answer
Correct Answer:
C. zero trust network access (ZTNA)
Question 2

A customer wants to upgrade their legacy on-premises proxy to a cloud-based proxy for a hybrid network. Which FortiSASE features would help the customer to achieve this outcome?

  • A. SD-WAN and NGFW
  • B. SD-WAN and inline-CASB
  • C. zero trust network access (ZTNA) and next generation firewall (NGFW)
  • D. secure web gateway (SWG) and inline-CASB
Show Answer
Correct Answer:
D. secure web gateway (SWG) and inline-CASB
Question 3

An organization wants to block all video and audio application traffic but grant access to videos from CNN. Which application override action must you configure in the Application Control with Inline-CASB?

  • A. Allow
  • B. Pass
  • C. Permit
  • D. Exempt
Show Answer
Correct Answer:
A. Allow
Question 4

Which two settings are automatically pushed from FortiSASE to FortiClient in a new FortiSASE deployment with default settings? (Choose two.)

  • A. FortiSASE CA certificate
  • B. Real-time protection
  • C. SSL VPN profile
  • D. ZTNA tags
Show Answer
Correct Answer:
  • B. Real-time protection
  • C. SSL VPN profile
Question 5

In the Secure Private Access (SPA) use case, which two FortiSASE features facilitate access to corporate applications? (Choose two.)

  • A. Zero trust network access (ZTNA)
  • B. Cloud access security broker (CASB)
  • C. Thin edge
  • D. SD-WAN
Show Answer
Correct Answer:
  • A. Zero trust network access (ZTNA)
  • D. SD-WAN
Question 6

An organization needs to resolve internal hostnames using its internal rather than public DNS servers for remotely connected endpoints. Which two components must be configured on FortiSASE to achieve this? (Choose two.)

  • A. SSL deep inspection
  • B. Split DNS rules
  • C. Split tunneling destinations
  • D. DNS filter
Show Answer
Correct Answer:
  • A. SSL deep inspection
  • B. Split DNS rules
Question 7

When deploying FortiSASE agentless secure web gateway (SWG) clients, which three features can you use to scan client traffic? (Choose three.)

  • A. Antiransomware protection
  • B. Intrusion prevention system (IPS)
  • C. Inline-CASB HTTP header insertion
  • D. DNS filter
  • E. SSL inspection
Show Answer
Correct Answer:
  • B. Intrusion prevention system (IPS)
  • D. DNS filter
  • E. SSL inspection
Question 8

When accessing the FortiSASE portal for the first time, an administrator must select data center locations for which three FortiSASE components? (Choose three.)

  • A. Logging
  • B. Sandbox
  • C. Endpoint management
  • D. Identity & access management (IAM)
  • E. Points of presence
Show Answer
Correct Answer:
  • A. Logging
  • C. Endpoint management
  • E. Points of presence
Question 9

What are two advantages of using zero-trust tags? (Choose two.)

  • A. Zero-trust tags can be used to allow or deny access to network resources
  • B. Zero-trust tags can determine the security posture of an endpoint
  • C. Zero-trust tags can be used to create multiple endpoint profiles which can be applied to different endpoints
  • D. Zero-trust tags can be used to allow secure web gateway (SWG) access
Show Answer
Correct Answer:
  • A. Zero-trust tags can be used to allow or deny access to network resources
  • B. Zero-trust tags can determine the security posture of an endpoint
Question 10

When viewing the daily summary report generated by FortiSASE. the administrator notices that the report contains very little data. What is a possible explanation for this almost empty report?

  • A. Digital experience monitoring is not configured
  • B. Log allowed traffic is set to Security Events for all policies
  • C. The web filter security profile is not set to Monitor
  • D. There are no security profile group applied to all policies
Show Answer
Correct Answer:
B. Log allowed traffic is set to Security Events for all policies

Aced these? Get the Full Exam

Download the complete FCSS_SASE_AD-23 study bundle with 32+ questions in a single printable PDF.