Sign In
Home/Fortinet/FortiSASE 24 Administrator/Free questions

Fortinet FCSS - FortiSASE 24 Administrator — Free Practice Questions

10 free sample questions from a bank of 23, with the correct answers and explanations. No signup required — start practising right now.

1What are two advantages of using zero-trust tags? (Choose two.)
  • Zero-trust tags can help in diagnosing connectivity issues.
  • Zero-trust tags can determine the security posture of an endpoint.
  • Zero-trust tags can be used to allow or deny access to network resources.
  • Zero-trust tags can be assigned to endpoint profiles based on user groups.
Answer: B, C

The short version

B and C — zero-trust tags determine posture and gate resources. Assess, then admit.

Key concepts in this question

  • Posture determination classifies endpoint health.
  • Allow/deny gating enforces policy by that classification.

Why B and C are correct

The two documented tag advantages.

Why the others are wrong

  • A. Tags do not diagnose connectivity.
  • D. Profiles assign by groups; tags do not attach to profiles as framed.

FortiSASE exam tip

Tags = assess + admit.

2Which statement describes the FortiGuard forensics analysis feature on FortiSASE?
  • It is a 24x7x365 monitoring service of your FortiSASE environment.
  • It can monitor endpoint resources in real-time.
  • It can help troubleshoot user-to-application performance issues.
  • It can help customers identify and mitigate potential risks to their network.
Answer: D

The short version

D — forensics analysis identifies and mitigates network risks. Proactive risk hunting.

Key concepts in this question

  • Forensics analysis surfaces potential risks for mitigation.
  • Monitoring services, endpoint telemetry, and performance triage are other features.

Why D is correct

Risk identification is the documented forensics role (7v2).

Why the others are wrong

  • A. No 24x7 managed monitoring service as framed.
  • B. Real-time endpoint resources are DEM/EMS territory.
  • C. User-to-app performance is DEM's job.

FortiSASE exam tip

Forensics = find and fix risks.

3Which statement best describes the Digital Experience Monitor (DEM) feature on FortiSASE?
  • It can help IT and security teams ensure consistent security monitoring for remote users.
  • It can be used to request a detailed analysis of the endpoint from the FortiGuard team.
  • It requires a separate DEM agent to be downloaded from the FortiSASE portal and installed on the endpoint.
  • It provides end-to-end network visibility from all the FortiSASE security PoPs to a specific SaaS application.
Answer: D

The short version

D — DEM watches end-to-end from PoPs to SaaS apps. Whole-path experience.

Key concepts in this question

  • End-to-end visibility spans PoP egress to application.
  • Monitoring consistency, team analysis, and separate agents miss the definition.

Why D is correct

PoP-to-SaaS visibility is the documented DEM description.

Why the others are wrong

  • A. Security monitoring consistency is a side benefit.
  • B. Team-requested analysis is SOCaaS, not DEM.
  • C. No separate DEM agent download exists.

FortiSASE exam tip

DEM = PoP-to-app visibility.

4Refer to the exhibit. A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redirect it to the endpoint physical interface. Which configuration must you apply to achieve this requirement?
Fortinet FCSS - FortiSASE 24 Administrator question 4
  • Implement a ZTNA destination rule using Google Maps FQDN on FortiSASE to identify and redirect Google Maps traffic.
  • Configure the Google Maps FQDN as a split tunneling destination on the FortiSASE endpoint profile.
  • Exempt the Google Maps FQDN from the endpoint system proxy settings.
  • Configure a split-tunnel VPN policy using Google Maps FQDN to exclude and redirect the traffic.
Answer: B

The short version

B — Google Maps FQDN as a split tunneling destination on the endpoint profile. Trusted traffic bypasses the SASE tunnel and leaves via the endpoint physical interface.

Key concepts in this question

  • Split tunneling (steering bypass): named destinations are excluded from the FortiSASE cloud security tunnel to save bandwidth.
  • FQDN destinations: resolved addresses are added to the route table in use and removed after disconnect.
  • Full-tunnel default: without a bypass destination, all endpoint internet traffic is inspected on FortiSASE.

Why B is correct

Fortinet documents configuring split tunneling destinations on the endpoint profile so trusted traffic such as high-bandwidth apps bypasses FortiSASE and is redirected to the endpoint physical interface. The exhibit shows exactly this: Google Maps arcing past FortiSASE straight to the internet while other traffic enters the SASE cloud.

Why the others are wrong

  • A. ZTNA destination rules steer private-application access to a FortiGate access proxy, not public internet bypass.
  • C. Exempting the FQDN from system proxy settings only changes browser proxying, not VPN tunnel steering.
  • D. There is no split-tunnel VPN policy object for this; steering bypass is configured as a destination in the endpoint profile.

FCSS_SASE_AD-24 exam tip

Inspect-all minus one app equals an FQDN steering bypass on the endpoint profile.

5Which of the following describes the FortiSASE inline-CASB component?
  • It uses API to connect to the cloud applications.
  • It detects data at rest.
  • It provides visibility for unmanaged locations and devices.
  • It is placed directly in the traffic path between the endpoint and cloud applications.
Answer: D

The short version

D — inline CASB sits in the endpoint-to-cloud traffic path. In-line by name, in-path by design.

Key concepts in this question

  • Inline placement intercepts live cloud flows.
  • API connectors, rest-data, and unmanaged visibility describe other CASB facets.

Why D is correct

In-path placement is the documented inline-CASB definition.

Why the others are wrong

  • A. API connections describe API CASB, not inline.
  • B. Data-at-rest is DLP territory.
  • C. Unmanaged visibility is discovery work.

FortiSASE exam tip

Inline CASB = in the traffic path.

6Which two components are part of onboarding a secure web gateway (SWG) endpoint? (Choose two.)
  • Proxy auto-configuration (PAC) file
  • FortiSASE SSL VPN gateway URL
  • FortiSASE CA certificate
  • FortiSASE invitation code
Answer: A, C

The short version

A and C — SWG onboarding needs a PAC file plus the SASE CA. Steer browsers, trust inspection.

Key concepts in this question

  • PAC files direct browsers to the proxy.
  • CA certificates let endpoints trust TLS inspection.

Why A and C are correct

The two documented SWG-onboarding components.

Why the others are wrong

  • B. SSL VPN URLs serve tunnel users, not SWG onboarding.
  • D. Invitation codes onboard agents, not SWG browsers.

FortiSASE exam tip

SWG onboard = PAC + CA.

7In which three ways does FortiSASE help organizations ensure secure access for remote workers? (Choose three.)
  • It enforces granular access policies based on user identities.
  • It enforces multi-factor authentication (MFA) to validate remote users.
  • It secures traffic from endpoints to cloud applications.
  • It uses the identity & access management (IAM) portal to validate the identities of remote workers.
  • It offers zero trust network access (ZTNA) capabilities.
Answer: A, C, E

The short version

A, C, E — remote-worker security means granular identity policies, secured cloud paths, and ZTNA. Who, where-safe, how-private.

Key concepts in this question

  • Granular identity policies scope access per user.
  • Cloud-path security plus ZTNA protect destinations and access.

Why A, C and E are correct

The three documented remote-access assurances (4v2).

Why the others are wrong

  • B. MFA validates via authenticators, not as a SASE assurance as framed.
  • D. IAM portals manage identities; they do not directly secure access.

FortiSASE exam tip

Remote security = identity policy + safe paths + ZTNA.

8Which two statements describe a zero trust network access (ZTNA) private access use case? (Choose two.)
  • All FortiSASE user-based deployments are supported.
  • Data center redundancy is offered.
  • All TCP-based applications are supported.
  • The security posture of the device is secure.
Answer: C, D

The short version

C and D — ZTNA private access covers all TCP apps on posture-healthy devices. Every TCP service, verified endpoints.

Key concepts in this question

  • TCP-wide coverage spans private applications.
  • Posture health gates the access.

Why C and D are correct

The two documented ZTNA use-case statements.

Why the others are wrong

  • A. Deployment coverage varies; all-deployments framing overstates.
  • B. DC redundancy is architectural, not a use-case statement.

FortiSASE exam tip

ZTNA private = all TCP, healthy devices.

9Which statement applies to a single sign-on (SSO) deployment on FortiSASE?
  • SSO is recommended only for agent-based deployments.
  • SSO users can be imported into FortiSASE and added to user groups.
  • SSO overrides any other previously configured user authentication.
  • SSO identity providers can be integrated using public and private access types.
Answer: C

The short version

C — SSO overrides all other FortiSASE authentication. Consistent across every SASE exam.

Key concepts in this question

  • SSO precedence is uniform FortiSASE doctrine.
  • Agent scope, imports, and IdP types are secondary facts.

Why C is correct

The documented SSO-override rule.

Why the others are wrong

  • A. SSO serves agentless equally.
  • B. Imports are admin workflow, not the SSO statement.
  • D. Access-type IdP framing is not the headline truth.

FortiSASE exam tip

SSO = overrides everything.

10During FortiSASE provisioning, how many security points of presence (POPs) need to be configured by the FortiSASE administrator?
  • three
  • one
  • two
  • four
Answer: C

The short version

C — provisioning selects two POPs. Primary plus backup.

Key concepts in this question

  • Dual-POP selection bakes redundancy into onboarding.
  • One, three, and four break the documented pair.

Why C is correct

Two-POP provisioning is the documented requirement (6v split).

Why the others are wrong

  • A/B/D. Non-two counts mismatch the provisioning design.

FortiSASE exam tip

Provisioning POPs = two.

Want the full bank of 23 questions for Fortinet FCSS - FortiSASE 24 Administrator? See all practice exams.