The two documented microbranch advantages (6v split).
Why the others are wrong
B. ZTNA tags gate access; they are not the microbranch advantage framed.
D. Simplified provisioning is real but not banked here.
FortiSASE exam tip
Microbranch = secure anywhere, fewer boxes.
4Which information can an administrator monitor using reports generated on FortiSASE?
sanctioned and unsanctioned Software-as-a-Service (SaaS) applications usage
FortiClient vulnerability assessment
SD-WAN performance
FortiSASE administrator and system events
Answer: A
The short version
A — FortiSASE reports reveal sanctioned and unsanctioned SaaS usage. Shadow-IT discovery reporting.
Key concepts in this question
SaaS-usage reports surface sanctioned and shadow applications.
Vuln, SD-WAN, and admin events report elsewhere.
Why A is correct
SaaS-visibility reporting is the documented report content.
Why the others are wrong
B. Vuln assessments live in endpoint reports.
C. SD-WAN performance lives in SD-WAN analytics.
D. Admin events live in admin logs.
FortiSASE exam tip
SaaS reports = sanctioned + shadow.
5In a FortiSASE secure web gateway (SWG) deployment, which two features protect against web-based threats? (Choose two.)
SSL deep inspection for encrypted web traffic
malware protection with sandboxing capabilities
web application firewall (WAF) for web applications
intrusion prevention system (IPS) for web traffic
Answer: A, B
The short version
A and B — SWG web-threat defense pairs SSL deep inspection with sandbox malware protection. See inside encryption, detonate the unknown.
Key concepts in this question
SSL deep inspection exposes encrypted threats.
Sandboxing judges unknown payloads.
Why A and B are correct
The two documented SWG protections.
Why the others are wrong
C. WAF guards hosted apps, not SWG browsing.
D. IPS is not the SWG web-threat pair member here.
FortiSASE exam tip
SWG threats = decrypt + detonate.
6Refer to the exhibits. A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Which configuration on FortiSASE is allowing users to perform the download?
Web filter is allowing the URL.
Deep inspection is not enabled.
Application control is exempting all the browser traffic.
Intrusion prevention is disabled.
Answer: B
The short version
B — eicar sailing through means TLS hid it: deep inspection is off. Encrypted downloads dodge AV blind.
Key concepts in this question
HTTPS downloads need decryption before AV scanning.
Without deep inspection, AV profiles never see the payload.
Why B is correct
Missing decryption is the documented eicar-pass cause (4v2).
Why the others are wrong
A. Allowed URLs still get AV-scanned when decrypted.
C. App-control exemptions are a different bypass.
D. IPS state does not gate AV scanning.
FortiSASE exam tip
Eicar over HTTPS passes = enable deep inspection.
7Refer to the exhibit. Based on the configuration shown, in which two ways will FortiSASE process sessions that require FortiSandbox inspection? (Choose two.)
Only endpoints assigned a profile for sandbox detection will be processed by the sandbox feature.
FortiClient quarantines only infected files that FortiSandbox detects as medium level.
All files executed on a USB drive will be sent to FortiSandbox for analysis.
All files will be sent to a on-premises FortiSandbox for inspection.
Answer: A, C
The short version
A and C — profile-gated FortiSASE cloud sandbox submits USB-executed files for analysis. Sandbox Mode is FortiSASE with removable-media submission enabled.
Key concepts in this question
Profile-gated sandboxing: only endpoints with sandbox detection in their endpoint profile are processed.
Removable-media submission: files executed from removable media are forwarded for sandbox analysis.
Cloud versus on-premises mode: FortiSASE mode uses cloud sandboxing, not a standalone appliance.
Why A and C are correct
The exhibit shows the Default endpoint profile with Sandbox Mode set to FortiSASE and All Files Executed from Removable Media enabled, so assigned endpoints have USB-executed files sent to the FortiSASE cloud sandbox for analysis.
Why the others are wrong
B. The Medium verdict level is a threshold that triggers quarantine at Medium and above, not only Medium detections.
D. Sandbox Mode is FortiSASE cloud in the exhibit, so files are not sent to an on-premises FortiSandbox.
FortiSASE exam tip
Sandbox exhibit = check mode, submission toggles, then threshold.
8An administrator must restrict endpoints from certain countries from connecting to FortiSASE. Which configuration can achieve this?
Configure a network lockdown policy on the endpoint profiles.
Configure a geography address object as the source for a deny policy.
Configure geofencing to restrict access from the required countries.
Configure source IP anchoring to restrict access from the specified countries.
Answer: C
The short version
C — country blocks ride geofencing. Borders for SASE attachments.
Key concepts in this question
Geofencing admits or denies POP connections by country.
Lockdown, geo-objects, and anchoring serve other ends.
Why C is correct
Country-gated access is the documented geofencing use.
Why the others are wrong
A. Lockdown policies manage endpoints, not countries.
B. Geo-object deny policies are firewall work, not the SASE feature.
D. Anchoring fixes egress IPs; it does not block countries.
FortiSASE exam tip
Country block = geofencing.
9What is the benefit of SD-WAN on-ramp deployment with FortiSASE?
To provide access to private applications using the bookmark portal
To provide device compliance checks using ZTNA tags
To secure internet traffic for branch users
To manage branch location endpoints
Answer: C
The short version
C — on-ramp secures branch internet traffic. Site pipe, cloud scrubbing.
Key concepts in this question
SD-WAN on-ramp backhauls branch internet to SASE inspection.
Portals, posture, and endpoint management are other features.
Why C is correct
Branch-internet security is the documented on-ramp benefit.
Why the others are wrong
A. Bookmark portals serve contractors, not branches.
B. Posture checks run on endpoints, not on-ramps.
D. Endpoint management is EMS work.
FortiSASE exam tip
On-ramp benefit = branch internet.
10Which two settings are automatically pushed from FortiSASE to FortiClient in a new FortiSASE deployment with default settings? (Choose two.)
zero trust network access (ZTNA) tags
tunnel profile
FortiSASE certificate authority (CA) certificate
real-time protection
Answer: B, C
The short version
B and C — onboarding pushes tunnel profiles plus the SASE CA. Connectivity plus trust.
Key concepts in this question
Tunnel profiles connect endpoints to POPs.
CA certificates let endpoints trust inspection.
Why B and C are correct
The two documented auto-pushed settings (cross-exam consistent).
Why the others are wrong
A. ZTNA tags sync via policy, not onboarding push.
D. Real-time protection is endpoint config, not pushed SASE state.