New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_SASE_AD-23 Questions and answers with CertsForce

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

The daily report for application usage shows an unusually high number of unknown applications by category.

What are two possible explanations for this? (Choose two.)

Options:

A.

Certificate inspection is not being used to scan application traffic.


B.

The inline-CASB application control profile does not have application categories set to Monitor


C.

Zero trust network access (ZTNA) tags are not being used to tag the correct users.


D.

Deep inspection is not being used to scan traffic.


Expert Solution
Questions # 2:

Which policy type is used to control traffic between the FortiClient endpoint to FortiSASE for secure internet access?

Options:

A.

VPN policy


B.

thin edge policy


C.

private access policy


D.

secure web gateway (SWG) policy


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

To allow access, which web tiller configuration must you change on FortiSASE?

Options:

A.

FortiGuard category-based filter


B.

content filter


C.

URL Filter


D.

inline cloud access security broker (CASB) headers


Expert Solution
Questions # 4:

Which FortiSASE feature ensures least-privileged user access to all applications?

Options:

A.

secure web gateway (SWG)


B.

SD-WAN


C.

zero trust network access (ZTNA)


D.

thin branch SASE extension


Expert Solution
Questions # 5:

When viewing the daily summary report generated by FortiSASE. the administrator notices that the report contains very little data. What is a possible explanation for this almost empty report?

Options:

A.

Digital experience monitoring is not configured.


B.

Log allowed traffic is set to Security Events for all policies.


C.

The web filter security profile is not set to Monitor


D.

There are no security profile group applied to all policies.


Expert Solution
Questions # 6:

Which two components are part of onboarding a secure web gateway (SWG) endpoint? (Choose two)

Options:

A.

FortiSASE CA certificate


B.

proxy auto-configuration (PAC) file


C.

FortiSASE invitation code


D.

FortiClient installer


Expert Solution
Questions # 7:

To complete their day-to-day operations, remote users require access to a TCP-based application that is hosted on a private web server. Which FortiSASE deployment use case provides the most efficient and secure method for meeting the remote users' requirements?

Options:

A.

SD-WAN private access


B.

inline-CASB


C.

zero trust network access (ZTNA) private access


D.

next generation firewall (NGFW)


Expert Solution
Questions # 8:

Refer to the exhibits.

Question # 8

Question # 8

Question # 8

A FortiSASE administrator has configured an antivirus profile in the security profile group and applied it to the internet access policy. Remote users are still able to download the eicar.com-zip file from https://eicar.org. Traffic logs show traffic is allowed by the policy.

Which configuration on FortiSASE is allowing users to perform the download?

Options:

A.

Web filter is allowing the traffic.


B.

IPS is disabled in the security profile group.


C.

The HTTPS protocol is not enabled in the antivirus profile.


D.

Force certificate inspection is enabled in the policy.


Expert Solution
Questions # 9:

Which two advantages does FortiSASE bring to businesses with multiple branch offices? (Choose two.)

Options:

A.

It offers centralized management for simplified administration.


B.

It enables seamless integration with third-party firewalls.


C.

it offers customizable dashboard views for each branch location


D.

It eliminates the need to have an on-premises firewall for eachbranch.


Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions