Sign In
Home/Fortinet/FortiSASE 25 Administrator/Free questions

Fortinet FCSS - FortiSASE 25 Administrator — Free Practice Questions

10 free sample questions from a bank of 40, with the correct answers and explanations. No signup required — start practising right now.

1In the Secure Private Access (SPA) use case, which two FortiSASE features facilitate access to corporate applications? (Choose two.)
  • cloud access security broker (CASB)
  • SD-WAN
  • zero trust network access (ZTNA)
  • thin edge
Answer: B, C

The short version

B and C — SPA app access rides SD-WAN plus ZTNA. Branch path and identity path.

Key concepts in this question

  • SD-WAN carries site-to-app flows.
  • ZTNA brokers user-to-app access.

Why B and C are correct

The two documented SPA facilitators (cross-exam consistent).

Why the others are wrong

  • A. CASB governs SaaS, not corporate apps.
  • D. Thin edge extends sites; it does not broker access.

FortiSASE exam tip

SPA app access = SD-WAN + ZTNA.

2Which two components are part of onboarding a secure web gateway (SWG) endpoint for secure internet access (SIA)? (Choose two.)
  • proxy auto-configuration (PAC) file
  • FortiSASE certificate authority (CA) certificate
  • FortiClient software
  • tunnel policy
Answer: A, B

The short version

A and B — SWG onboarding needs a PAC file plus the SASE CA. Steer browsers, trust inspection.

Key concepts in this question

  • PAC files direct browsers to the proxy.
  • CA certificates let endpoints trust TLS inspection.

Why A and B are correct

The two documented SWG-onboarding components.

Why the others are wrong

  • C. FortiClient software onboards agents, not SWG browsers.
  • D. Tunnel policies serve tunnel users, not SWG.

FortiSASE exam tip

SWG onboard = PAC + CA.

3Which two advantages does FortiSASE bring to businesses with microbranch offices that have FortiAP deployed for unmanaged devices? (Choose two.)
  • It secures internet access both on and off the network.
  • It uses zero trust network access (ZTNA) tags to perform device compliance checks.
  • It eliminates the requirement for an on-premises firewall.
  • It simplifies management and provisioning.
Answer: A, C

The short version

A and C — microbranch value: secure everywhere plus no on-prem firewall. Cover off-net, delete boxes.

Key concepts in this question

  • On/off-network security follows unmanaged devices anywhere.
  • Firewall elimination removes per-site appliances.

Why A and C are correct

The two documented microbranch advantages (6v split).

Why the others are wrong

  • B. ZTNA tags gate access; they are not the microbranch advantage framed.
  • D. Simplified provisioning is real but not banked here.

FortiSASE exam tip

Microbranch = secure anywhere, fewer boxes.

4Which information can an administrator monitor using reports generated on FortiSASE?
  • sanctioned and unsanctioned Software-as-a-Service (SaaS) applications usage
  • FortiClient vulnerability assessment
  • SD-WAN performance
  • FortiSASE administrator and system events
Answer: A

The short version

A — FortiSASE reports reveal sanctioned and unsanctioned SaaS usage. Shadow-IT discovery reporting.

Key concepts in this question

  • SaaS-usage reports surface sanctioned and shadow applications.
  • Vuln, SD-WAN, and admin events report elsewhere.

Why A is correct

SaaS-visibility reporting is the documented report content.

Why the others are wrong

  • B. Vuln assessments live in endpoint reports.
  • C. SD-WAN performance lives in SD-WAN analytics.
  • D. Admin events live in admin logs.

FortiSASE exam tip

SaaS reports = sanctioned + shadow.

5In a FortiSASE secure web gateway (SWG) deployment, which two features protect against web-based threats? (Choose two.)
  • SSL deep inspection for encrypted web traffic
  • malware protection with sandboxing capabilities
  • web application firewall (WAF) for web applications
  • intrusion prevention system (IPS) for web traffic
Answer: A, B

The short version

A and B — SWG web-threat defense pairs SSL deep inspection with sandbox malware protection. See inside encryption, detonate the unknown.

Key concepts in this question

  • SSL deep inspection exposes encrypted threats.
  • Sandboxing judges unknown payloads.

Why A and B are correct

The two documented SWG protections.

Why the others are wrong

  • C. WAF guards hosted apps, not SWG browsing.
  • D. IPS is not the SWG web-threat pair member here.

FortiSASE exam tip

SWG threats = decrypt + detonate.

6Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Which configuration on FortiSASE is allowing users to perform the download?
Fortinet FCSS - FortiSASE 25 Administrator question 6Fortinet FCSS - FortiSASE 25 Administrator question 6
  • Web filter is allowing the URL.
  • Deep inspection is not enabled.
  • Application control is exempting all the browser traffic.
  • Intrusion prevention is disabled.
Answer: B

The short version

B — eicar sailing through means TLS hid it: deep inspection is off. Encrypted downloads dodge AV blind.

Key concepts in this question

  • HTTPS downloads need decryption before AV scanning.
  • Without deep inspection, AV profiles never see the payload.

Why B is correct

Missing decryption is the documented eicar-pass cause (4v2).

Why the others are wrong

  • A. Allowed URLs still get AV-scanned when decrypted.
  • C. App-control exemptions are a different bypass.
  • D. IPS state does not gate AV scanning.

FortiSASE exam tip

Eicar over HTTPS passes = enable deep inspection.

7Refer to the exhibit. Based on the configuration shown, in which two ways will FortiSASE process sessions that require FortiSandbox inspection? (Choose two.)
Fortinet FCSS - FortiSASE 25 Administrator question 7
  • Only endpoints assigned a profile for sandbox detection will be processed by the sandbox feature.
  • FortiClient quarantines only infected files that FortiSandbox detects as medium level.
  • All files executed on a USB drive will be sent to FortiSandbox for analysis.
  • All files will be sent to a on-premises FortiSandbox for inspection.
Answer: A, C

The short version

A and C — profile-gated FortiSASE cloud sandbox submits USB-executed files for analysis. Sandbox Mode is FortiSASE with removable-media submission enabled.

Key concepts in this question

  • Profile-gated sandboxing: only endpoints with sandbox detection in their endpoint profile are processed.
  • Removable-media submission: files executed from removable media are forwarded for sandbox analysis.
  • Cloud versus on-premises mode: FortiSASE mode uses cloud sandboxing, not a standalone appliance.

Why A and C are correct

The exhibit shows the Default endpoint profile with Sandbox Mode set to FortiSASE and All Files Executed from Removable Media enabled, so assigned endpoints have USB-executed files sent to the FortiSASE cloud sandbox for analysis.

Why the others are wrong

  • B. The Medium verdict level is a threshold that triggers quarantine at Medium and above, not only Medium detections.
  • D. Sandbox Mode is FortiSASE cloud in the exhibit, so files are not sent to an on-premises FortiSandbox.

FortiSASE exam tip

Sandbox exhibit = check mode, submission toggles, then threshold.

8An administrator must restrict endpoints from certain countries from connecting to FortiSASE. Which configuration can achieve this?
  • Configure a network lockdown policy on the endpoint profiles.
  • Configure a geography address object as the source for a deny policy.
  • Configure geofencing to restrict access from the required countries.
  • Configure source IP anchoring to restrict access from the specified countries.
Answer: C

The short version

C — country blocks ride geofencing. Borders for SASE attachments.

Key concepts in this question

  • Geofencing admits or denies POP connections by country.
  • Lockdown, geo-objects, and anchoring serve other ends.

Why C is correct

Country-gated access is the documented geofencing use.

Why the others are wrong

  • A. Lockdown policies manage endpoints, not countries.
  • B. Geo-object deny policies are firewall work, not the SASE feature.
  • D. Anchoring fixes egress IPs; it does not block countries.

FortiSASE exam tip

Country block = geofencing.

9What is the benefit of SD-WAN on-ramp deployment with FortiSASE?
  • To provide access to private applications using the bookmark portal
  • To provide device compliance checks using ZTNA tags
  • To secure internet traffic for branch users
  • To manage branch location endpoints
Answer: C

The short version

C — on-ramp secures branch internet traffic. Site pipe, cloud scrubbing.

Key concepts in this question

  • SD-WAN on-ramp backhauls branch internet to SASE inspection.
  • Portals, posture, and endpoint management are other features.

Why C is correct

Branch-internet security is the documented on-ramp benefit.

Why the others are wrong

  • A. Bookmark portals serve contractors, not branches.
  • B. Posture checks run on endpoints, not on-ramps.
  • D. Endpoint management is EMS work.

FortiSASE exam tip

On-ramp benefit = branch internet.

10Which two settings are automatically pushed from FortiSASE to FortiClient in a new FortiSASE deployment with default settings? (Choose two.)
  • zero trust network access (ZTNA) tags
  • tunnel profile
  • FortiSASE certificate authority (CA) certificate
  • real-time protection
Answer: B, C

The short version

B and C — onboarding pushes tunnel profiles plus the SASE CA. Connectivity plus trust.

Key concepts in this question

  • Tunnel profiles connect endpoints to POPs.
  • CA certificates let endpoints trust inspection.

Why B and C are correct

The two documented auto-pushed settings (cross-exam consistent).

Why the others are wrong

  • A. ZTNA tags sync via policy, not onboarding push.
  • D. Real-time protection is endpoint config, not pushed SASE state.

FortiSASE exam tip

Onboarding push = tunnel + CA.

Want the full bank of 40 questions for Fortinet FCSS - FortiSASE 25 Administrator? See all practice exams.