Weekend Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

FCSS_SASE_AD-24 FCSS - FortiSASE 24 Administrator Questions and Answers

Questions 4

When you configure FortiSASE Secure Private Access (SPA) with SD-WAN integration, you must establish a routing adjacency between FortiSASE and the FortiGate SD-WAN hub. Which routing protocol must you use?

Options:

A.

BGP

B.

IS-IS

C.

OSPF

D.

EIGRP

Buy Now
Questions 5

Which two components are part of onboarding a secure web gateway (SWG) endpoint? (Choose two)

Options:

A.

FortiSASE CA certificate

B.

proxy auto-configuration (PAC) file

C.

FortiSASE invitation code

D.

FortiClient installer

Buy Now
Questions 6

Which policy type is used to control traffic between the FortiClient endpoint to FortiSASE for secure internet access?

Options:

A.

VPN policy

B.

thin edge policy

C.

private access policy

D.

secure web gateway (SWG) policy

Buy Now
Questions 7

Refer to the exhibits.

FCSS_SASE_AD-24 Question 7

WiMO-Pro and Win7-Pro are endpoints from the same remote location. WiMO-Pro can access the internet though FortiSASE, while Wm7-Pro can no longer access the internet

Given the exhibits, which reason explains the outage on Wm7-Pro?

Options:

A.

The Win7-Pro device posture has changed.

B.

Win7-Pro cannot reach the FortiSASE SSL VPN gateway

C.

The Win7-Pro FortiClient version does not match the FortiSASE endpoint requirement.

D.

Win-7 Pro has exceeded the total vulnerability detected threshold.

Buy Now
Questions 8

Which statement applies to a single sign-on (SSO) deployment on FortiSASE?

Options:

A.

SSO overrides any other previously configured user authentication.

B.

SSO identity providers can be integrated using public and private access types.

C.

SSO is recommended only for agent-based deployments.

D.

SSO users can be imported into FortiSASE and added to user groups.

Buy Now
Questions 9

Refer to the exhibits.

FCSS_SASE_AD-24 Question 9

FCSS_SASE_AD-24 Question 9

FCSS_SASE_AD-24 Question 9

A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy.

Which configuration on FortiSASE is allowing users to perform the download?

Options:

A.

Web filter is allowing the traffic.

B.

IPS is disabled in the security profile group.

C.

The HTTPS protocol is not enabled in the antivirus profile.

D.

Force certificate inspection is enabled in the policy.

Buy Now
Questions 10

Refer to the exhibits.

FCSS_SASE_AD-24 Question 10

Antivirus is installed on a Windows 10 endpoint, but the windows application firewall is stopping it from running.

What will the endpoint security posture check be?

Options:

A.

FortiClient will block the endpoint from getting access to the network.

B.

FortiClient telemetry will be disconnected because of failed compliance.

C.

FortiClient will tag the endpoint as FortiSASE-Non-Compliant.

D.

FortiClient will prompt the user to enable antivirus.

Buy Now
Questions 11

Which two additional components does FortiSASE use for application control to act as an inline-CASB? (Choose two.)

Options:

A.

intrusion prevention system (IPS)

B.

SSL deep inspection

C.

DNS filter

D.

Web filter with inline-CASB

Buy Now
Questions 12

A customer needs to implement device posture checks for their remote endpoints while accessing the protected server. They also want the TCP traffic between the remote endpoints and the protected servers to be processed by FortiGate.

In this scenario, which three setups will achieve the above requirements? (Choose three.)

Options:

A.

Configure ZTNA servers and ZTNA policies on FortiGate.

B.

Configure private access policies on FortiSASE with ZTNA.

C.

Configure ZTNA tags on FortiGate.

D.

Configure FortiGate as a zero trust network access (ZTNA) access proxy.

E.

Sync ZTNA tags from FortiSASE to FortiGate.

Buy Now
Questions 13

Refer to the exhibits.

FCSS_SASE_AD-24 Question 13

FCSS_SASE_AD-24 Question 13

FCSS_SASE_AD-24 Question 13

FCSS_SASE_AD-24 Question 13

FCSS_SASE_AD-24 Question 13

A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGale hub. However, the administrator is not able to ping the webserver hosted behind the FortiGate hub.

Based on the output, what is the reason for the ping failures?

Options:

A.

The Secure Private Access (SPA) policy needs to allow PING service.

B.

Quick mode selectors are restricting the subnet.

C.

The BGP route is not received.

D.

Network address translation (NAT) is not enabled on the spoke-to-hub policy.

Buy Now
Exam Code: FCSS_SASE_AD-24
Exam Name: FCSS - FortiSASE 24 Administrator
Last Update: Jun 12, 2025
Questions: 44

PDF + Testing Engine

$57.75  $164.99

Testing Engine

$43.75  $124.99
buy now FCSS_SASE_AD-24 testing engine

PDF (Q&A)

$36.75  $104.99
buy now FCSS_SASE_AD-24 pdf