Fortinet FCSS - FortiSASE 24 Administrator — Free Practice Questions
10 free sample questions from a bank of 23, with the correct answers and explanations. No signup required — start practising right now.
1What are two advantages of using zero-trust tags? (Choose two.)
Zero-trust tags can help in diagnosing connectivity issues.
Zero-trust tags can determine the security posture of an endpoint.
Zero-trust tags can be used to allow or deny access to network resources.
Zero-trust tags can be assigned to endpoint profiles based on user groups.
Answer: B, C
The short version
B and C — zero-trust tags determine posture and gate resources. Assess, then admit.
Key concepts in this question
Posture determination classifies endpoint health.
Allow/deny gating enforces policy by that classification.
Why B and C are correct
The two documented tag advantages.
Why the others are wrong
A. Tags do not diagnose connectivity.
D. Profiles assign by groups; tags do not attach to profiles as framed.
FortiSASE exam tip
Tags = assess + admit.
2Which statement describes the FortiGuard forensics analysis feature on FortiSASE?
It is a 24x7x365 monitoring service of your FortiSASE environment.
It can monitor endpoint resources in real-time.
It can help troubleshoot user-to-application performance issues.
It can help customers identify and mitigate potential risks to their network.
Answer: D
The short version
D — forensics analysis identifies and mitigates network risks. Proactive risk hunting.
Key concepts in this question
Forensics analysis surfaces potential risks for mitigation.
Monitoring services, endpoint telemetry, and performance triage are other features.
Why D is correct
Risk identification is the documented forensics role (7v2).
Why the others are wrong
A. No 24x7 managed monitoring service as framed.
B. Real-time endpoint resources are DEM/EMS territory.
C. User-to-app performance is DEM's job.
FortiSASE exam tip
Forensics = find and fix risks.
3Which statement best describes the Digital Experience Monitor (DEM) feature on FortiSASE?
It can help IT and security teams ensure consistent security monitoring for remote users.
It can be used to request a detailed analysis of the endpoint from the FortiGuard team.
It requires a separate DEM agent to be downloaded from the FortiSASE portal and installed on the endpoint.
It provides end-to-end network visibility from all the FortiSASE security PoPs to a specific SaaS application.
Answer: D
The short version
D — DEM watches end-to-end from PoPs to SaaS apps. Whole-path experience.
Key concepts in this question
End-to-end visibility spans PoP egress to application.
Monitoring consistency, team analysis, and separate agents miss the definition.
Why D is correct
PoP-to-SaaS visibility is the documented DEM description.
Why the others are wrong
A. Security monitoring consistency is a side benefit.
B. Team-requested analysis is SOCaaS, not DEM.
C. No separate DEM agent download exists.
FortiSASE exam tip
DEM = PoP-to-app visibility.
4Refer to the exhibit. A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redirect it to the endpoint physical interface. Which configuration must you apply to achieve this requirement?
Implement a ZTNA destination rule using Google Maps FQDN on FortiSASE to identify and redirect Google Maps traffic.
Configure the Google Maps FQDN as a split tunneling destination on the FortiSASE endpoint profile.
Exempt the Google Maps FQDN from the endpoint system proxy settings.
Configure a split-tunnel VPN policy using Google Maps FQDN to exclude and redirect the traffic.
Answer: B
The short version
B — Google Maps FQDN as a split tunneling destination on the endpoint profile. Trusted traffic bypasses the SASE tunnel and leaves via the endpoint physical interface.
Key concepts in this question
Split tunneling (steering bypass): named destinations are excluded from the FortiSASE cloud security tunnel to save bandwidth.
FQDN destinations: resolved addresses are added to the route table in use and removed after disconnect.
Full-tunnel default: without a bypass destination, all endpoint internet traffic is inspected on FortiSASE.
Why B is correct
Fortinet documents configuring split tunneling destinations on the endpoint profile so trusted traffic such as high-bandwidth apps bypasses FortiSASE and is redirected to the endpoint physical interface. The exhibit shows exactly this: Google Maps arcing past FortiSASE straight to the internet while other traffic enters the SASE cloud.
Why the others are wrong
A. ZTNA destination rules steer private-application access to a FortiGate access proxy, not public internet bypass.
C. Exempting the FQDN from system proxy settings only changes browser proxying, not VPN tunnel steering.
D. There is no split-tunnel VPN policy object for this; steering bypass is configured as a destination in the endpoint profile.
FCSS_SASE_AD-24 exam tip
Inspect-all minus one app equals an FQDN steering bypass on the endpoint profile.
5Which of the following describes the FortiSASE inline-CASB component?
It uses API to connect to the cloud applications.
It detects data at rest.
It provides visibility for unmanaged locations and devices.
It is placed directly in the traffic path between the endpoint and cloud applications.
Answer: D
The short version
D — inline CASB sits in the endpoint-to-cloud traffic path. In-line by name, in-path by design.
Key concepts in this question
Inline placement intercepts live cloud flows.
API connectors, rest-data, and unmanaged visibility describe other CASB facets.
Why D is correct
In-path placement is the documented inline-CASB definition.
Why the others are wrong
A. API connections describe API CASB, not inline.
B. Data-at-rest is DLP territory.
C. Unmanaged visibility is discovery work.
FortiSASE exam tip
Inline CASB = in the traffic path.
6Which two components are part of onboarding a secure web gateway (SWG) endpoint? (Choose two.)
Proxy auto-configuration (PAC) file
FortiSASE SSL VPN gateway URL
FortiSASE CA certificate
FortiSASE invitation code
Answer: A, C
The short version
A and C — SWG onboarding needs a PAC file plus the SASE CA. Steer browsers, trust inspection.
Key concepts in this question
PAC files direct browsers to the proxy.
CA certificates let endpoints trust TLS inspection.
Why A and C are correct
The two documented SWG-onboarding components.
Why the others are wrong
B. SSL VPN URLs serve tunnel users, not SWG onboarding.
D. Invitation codes onboard agents, not SWG browsers.
FortiSASE exam tip
SWG onboard = PAC + CA.
7In which three ways does FortiSASE help organizations ensure secure access for remote workers? (Choose three.)
It enforces granular access policies based on user identities.
It enforces multi-factor authentication (MFA) to validate remote users.
It secures traffic from endpoints to cloud applications.
It uses the identity & access management (IAM) portal to validate the identities of remote workers.
It offers zero trust network access (ZTNA) capabilities.
Answer: A, C, E
The short version
A, C, E — remote-worker security means granular identity policies, secured cloud paths, and ZTNA. Who, where-safe, how-private.
Key concepts in this question
Granular identity policies scope access per user.
Cloud-path security plus ZTNA protect destinations and access.
Why A, C and E are correct
The three documented remote-access assurances (4v2).
Why the others are wrong
B. MFA validates via authenticators, not as a SASE assurance as framed.
D. IAM portals manage identities; they do not directly secure access.