FCSS-SASE-AD-25 Fortinet FCSS - FortiSASE 25 Administrator Practice Questions
Prepare for FCSS-SASE-AD-25 with more than an answer.
- Exam fee
- $200 USD
- Time limit
- 60 minutes
- Questions on the exam
- 30
- Passing score
- Pass/Fail (scale Pass/Fail)
- Level
- Specialist
- Valid for
- 3 years
Domains covered on the exam 4
- SASE Architecture and Components25%
- SASE Deployment30%
- SIA, SSA, and SPA30%
- Analytics15%
- 1
What is a key difference between FortiSASE's Secure Internet Access (SIA) and Secure Software Access (SSA)?
Show answer details
Correct answer: D
Secure Internet Access (SIA) provides foundational Secure Web Gateway (SWG) capabilities, protecting users from web-based threats as they access the internet. Secure Software Access (SSA) builds upon this by providing more granular, CASB-like (Cloud Access Security Broker) controls for specific, sanctioned SaaS applications, such as controlling uploads/downloads or enforcing tenant restrictions.
- 2
A company is using FortiSASE SD-WAN to connect remote sites to a central hub FortiGate. The administrator needs to ensure that latency-sensitive VoIP traffic is prioritized and always uses the link with the lowest jitter, while bulk data transfers use the link with the highest bandwidth. Which SD-WAN feature should be configured to achieve this application steering?
Show answer details
Correct answer: A
Fortinet SD-WAN uses rules combined with performance SLAs (Service Level Agreements) for intelligent application steering. The administrator can define performance SLA targets for jitter, latency, and packet loss for VoIP, and then create a rule that directs VoIP traffic to the member link that meets this SLA. A separate rule can be created for bulk data that prioritizes the link with the highest available bandwidth.
- 3
After analyzing a security report in FortiSASE, an administrator discovers that several users have been visiting websites categorized as 'Phishing and Fraud'. The administrator needs to immediately block access to this category for all users and receive an alert when a block occurs. Which three components must be configured to implement this? (Select THREE)
Show answer details
Correct answer: A, B, D
To receive an alert, the administrator must configure an automation stitch or an alert within the logging and reporting settings to notify them when a web filter block event is logged.
Security profiles are inactive until they are applied to traffic via a security policy.
This is the core component for blocking access based on web content categories.
- 4
A new administrator joins a team managing a large FortiSASE environment. To get familiar with the configuration, they want to view the current logging settings from the CLI. What is the correct FortiOS command to display the system log settings?
Show answer details
Correct answer: A
In FortiOS CLI,
getcommands are used to display the current values of configuration objects. The commandget system log settingswill show the currently configured settings for system logging, including destinations, severity levels, and facilities. - 5
A company is planning a phased rollout of FortiSASE. Phase 1 will provide Secure Internet Access (SIA) for all remote users. Phase 2 will secure access to private applications in their data center. Which FortiSASE feature is central to implementing Phase 2?
Show answer details
Correct answer: C
Secure Private Access (SPA) is the FortiSASE component specifically designed to provide secure, zero-trust access to applications hosted in private data centers or IaaS. While SIA/SWG handles internet access, SPA, which leverages ZTNA, is required for securing access to internal corporate resources.
- 6
A financial services company requires that all remote endpoints connecting via FortiSASE have their disk encryption enabled and an up-to-date EDR agent running. If a device fails these checks, it must be quarantined to a remediation network with limited access. Which FortiSASE components are essential for enforcing this conditional access policy?
Show answer details
Correct answer: A
FortiClient EMS is used to manage and report on the posture of endpoints. FortiSASE security posture checks leverage this information to verify compliance. A ZTNA access rule can then apply a specific action, such as quarantining the device by redirecting it to a remediation portal or network if it fails the posture check. The other options are not directly involved in endpoint compliance enforcement.
- 7
A security analyst at a retail company is reviewing FortiSASE traffic logs. They observe a series of small, encrypted DNS queries to various seemingly random subdomains of a single, non-corporate domain from multiple endpoints. This is followed by small outbound TCP connections to an IP address associated with that domain. This pattern of activity is most indicative of which type of threat?
Show answer details
Correct answer: B
The use of many random subdomains for DNS queries is a classic indicator of DNS tunneling, a technique used by malware to establish a covert Command and Control (C2) channel by encoding data within DNS requests. The small, subsequent TCP connections further support this, representing the actual data exfiltration or command reception. Brute-force, DDoS, and standard proxy usage have different and more distinct log signatures.
- 8
A manufacturing company is extending its corporate network to remote workers using FortiSASE. They have a central FortiGate NGFW at their headquarters. The goal is for remote users to appear as if they are on the local corporate network, using an IP from the internal DHCP scope, to access legacy applications that use Layer 2 discovery protocols. Which VDOM type must be configured on the headquarters' FortiGate to achieve this Layer 2 network extension with FortiSASE?
Show answer details
Correct answer: C
The LAN-Extension VDOM type is specifically designed to create a Layer 2 tunnel between a FortiGate (acting as the Secure Edge) and FortiSASE. This allows remote clients to be part of the same broadcast domain as the internal network, receive IPs from the local DHCP server, and use Layer 2 protocols for discovery and communication. Other VDOM types do not provide this Layer 2 extension capability.
- 9
True or False: FortiSASE Secure Private Access (SPA) is exclusively used for providing access to web-based applications hosted in a private data center.
Show answer details
Correct answer: B
Secure Private Access (SPA) is designed to provide secure access to corporate applications, particularly non-web applications, hosted in private data centers or IaaS environments. It utilizes technologies like ZTNA and SD-WAN to secure access to services using protocols beyond HTTP/S, such as RDP, SSH, and other TCP/UDP-based applications.
- 10
A global consulting firm is onboarding users to FortiSASE. They want to streamline the process by integrating with their existing identity provider and ensure a consistent user experience across company-issued laptops and personal mobile devices. Which two methods should the administrator configure to meet these user onboarding requirements? (Select TWO)
Show answer details
Correct answer: A, D
Integrating with a SAML IdP (like Azure AD or Okta) allows for seamless authentication using existing corporate credentials, which streamlines the user experience and centralizes identity management.
Deploying FortiClient via an email invitation link is a standard and effective method for getting the agent onto both managed and unmanaged (BYOD) devices, which is necessary for enforcing SASE policies consistently.
