● FCSS - FortiSASE 24 Administrator Exam Materials

Please note that the exam "FCSS - FortiSASE 24 Administrator Exam" is no longer offered by Fortinet and is not available for booking through Pearson VUE, so we opened it on free view,
It has been replaced by the exam "NSE 7 - FortiSASE 25 Enterprise Administrator Exam"

The new exam version is available on Brave-Dumps and can be purchased.




Question #1
Comment Image Comment Image Comment Image

An organization must block user attempts to log in to non-company resources while using Microsoft Office 365 to prevent users from accessing unapproved cloud resources.

Which FortiSASE feature can you implement to achieve this requirement (Choose one answer)

  • A. SSL deep inspection
  • B. Web Filter with Inline-CASB
  • C. Application Control with Inline-CASB
  • D. Data loss prevention (DLP)

Question #2
Comment Image Comment Image Comment Image

Which two advantages does FortiSASE bring to businesses with multiple branch offices? (Choose two answers)

  • A. It eliminates the need to have an on-premises firewall for each branch.
  • B. It offers a local data center installation for the FortiSASE controller.
  • C. It offers customizable dashboard views for each branch location.
  • D. It offers centralized management for simplified administration.

Question #3
Comment Image Comment Image Comment Image

Refer to the exhibit.

To allow access, which web filter configuration must you change on FortiSASE? (Choose one answer)

  • A. URL Filter
  • B. CASB application filter
  • C. DNS Filter
  • D. Content Filter

Question #4
Comment Image Comment Image Comment Image

During FortiSASE provisioning, how many security points of presence (POPs) need to be configured by the FortiSASE administrator? (Choose one answer)

  • A. one
  • B. two
  • C. four
  • D. Three

Question #5
Comment Image Comment Image Comment Image

Win10-Pro and Win7-Pro are endpoints from the same remote location.

Win10-Pro can access the internet through FortiSASE, while Win7-Pro can no longer access the internet.

Given the exhibits, which reason explains the outage on Win7-Pro? (Choose one answer)

  • A. Win7-Pro is disconnected from FortiClient telemetry.
  • B. The Win7-Pro device posture has changed.
  • C. Win7-Pro has exceeded the total vulnerability detected threshold.
  • D. The Win7-Pro FortiClient version does not match the FortiSASE endpoint requirement.

Question #6
Comment Image Comment Image Comment Image

Refer to the exhibit.

A company has a requirement to inspect all the endpoint internet traffic on FortiSASE, and exclude Google Maps traffic from the FortiSASE VPN tunnel and redirect it to the endpoint physical interface.

Which configuration must you apply to achieve this requirement? (Choose one answer)

  • A. Configure a split-tunnel VPN policy using Google Maps FQDN to exclude and redirect the traffic.
  • B. Implement a ZTNA destination rule using Google Maps FQDN on FortiSASE to identify and redirect Google Maps traffic.
  • C. Exempt the Google Maps FQDN from the endpoint system proxy settings.
  • D. Configure the Google Maps FQDN as a split tunneling destination on the FortiSASE endpoint profile

Question #7
Comment Image Comment Image Comment Image

Refer to the exhibits.

When remote users connected to FortiSASE require access to internal resources on Branch-2, how will traffic be routed? (Choose one answer)

  • A. FortiSASE will use the AD VPN protocol and determine that traffic will be directed to Branch-2 directly, using a static route.
  • B. FortiSASE will use the SD-WAN capability and determine that traffic will be directed to HUB-1, which will then route traffic to Branch-2.
  • C. FortiSASE will use the AD VPN protocol and determine that traffic will be directed to Branch-2 directly, using a dynamic route.
  • D. FortiSASE will use the SD-WAN capability and determine that traffic will be directed to HUB-2, which will then route traffic to Branch-2.

Question #8
Comment Image Comment Image Comment Image

Which statement applies to a single sign-on (SSO) deployment on FortiSASE? (Choose one answer)

  • A. SSO identity providers can be integrated using public and private access types.
  • B. SSO users can be imported into FortiSASE and added to user groups.
  • C. SSO is recommended only for agent-based deployments.
  • D. SSO overrides any other previously configured user authentication.

Question #9
Comment Image Comment Image Comment Image

Which two statements describe a zero trust network access (ZTNA) private access use case? (Choose two answers)

  • A. All FortiSASE user-based deployments are supported.
  • B. The security posture of the device is secure.
  • C. All TCP-based applications are supported.
  • D. Data center redundancy is offered.

Question #10
Comment Image Comment Image Comment Image

What are two requirements to enable the MSSP feature on FortiSASE? (Choose two answers)

  • A. Assign role-based access control (RBAC) to IAM users using FortiCloud IAM portal.
  • B. Configure MSSP user accounts and permissions on the FortiSASE portal.
  • C. Add FortiCloud premium subscription on the root FortiCloud account.
  • D. Enable multi-tenancy on the FortiSASE portal.