Pass the Fortinet Fortinet Certified Solution Specialist FCSS_SASE_AD-24 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibits.

Question # 1

Question # 1

Question # 1

Question # 1

Question # 1

A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The VPN tunnel does not establish

Based on the provided configuration, what configuration needs to be modified to bring the tunnel up?

Options:

A.

NAT needs to be enabled in the Spoke-to-Hub firewall policy.


B.

The BGP router ID needs to match on the hub and FortiSASE.


C.

FortiSASE spoke devices do not support mode config.


D.

The hub needs IKEv2 enabled in the IPsec phase 1 settings.


Expert Solution
Questions # 2:

Which of the following describes the FortiSASE inline-CASB component?

Options:

A.

It provides visibility for unmanaged locations and devices.


B.

It is placed directly in the traffic path between the endpoint and cloud applications.


C.

It uses API to connect to the cloud applications.


D.

It detects data at rest.


Expert Solution
Questions # 3:

Refer to the exhibits.

Question # 3

Antivirus is installed on a Windows 10 endpoint, but the windows application firewall is stopping it from running.

What will the endpoint security posture check be?

Options:

A.

FortiClient will block the endpoint from getting access to the network.


B.

FortiClient telemetry will be disconnected because of failed compliance.


C.

FortiClient will tag the endpoint as FortiSASE-Non-Compliant.


D.

FortiClient will prompt the user to enable antivirus.


Expert Solution
Questions # 4:

Refer to the exhibits.

Question # 4

Question # 4

Question # 4

Question # 4

Question # 4

A FortiSASE administrator is trying to configure FortiSASE as a spoke to a FortiGate hub. The tunnel is up to the FortiGale hub. However, the administrator is not able to ping the webserver hosted behind the FortiGate hub.

Based on the output, what is the reason for the ping failures?

Options:

A.

The Secure Private Access (SPA) policy needs to allow PING service.


B.

Quick mode selectors are restricting the subnet.


C.

The BGP route is not received.


D.

Network address translation (NAT) is not enabled on the spoke-to-hub policy.


Expert Solution
Questions # 5:

Which statement applies to a single sign-on (SSO) deployment on FortiSASE?

Options:

A.

SSO overrides any other previously configured user authentication.


B.

SSO identity providers can be integrated using public and private access types.


C.

SSO is recommended only for agent-based deployments.


D.

SSO users can be imported into FortiSASE and added to user groups.


Expert Solution
Questions # 6:

Which two deployment methods are used to connect a FortiExtender as a FortiSASE LAN extension? (Choose two.)

Options:

A.

Connect FortiExtender to FortiSASE using FortiZTP


B.

Enable Control and Provisioning Wireless Access Points (CAPWAP) access on the FortiSASE portal.


C.

Enter the FortiSASE domain name in the FortiExtender GUI as a static discovery server


D.

Configure an IPsec tunnel on FortiSASE to connect to FortiExtender.


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

The daily report for application usage shows an unusually high number of unknown applications by category.

What are two possible explanations for this? (Choose two.)

Options:

A.

Certificate inspection is not being used to scan application traffic.


B.

The inline-CASB application control profile does not have application categories set to Monitor


C.

Zero trust network access (ZTNA) tags are not being used to tag the correct users.


D.

Deep inspection is not being used to scan traffic.


Expert Solution
Questions # 8:

During FortiSASE provisioning, how many security points of presence (POPs) need to be configured by the FortiSASE administrator?

Options:

A.

3


B.

4


C.

2


D.

1


Expert Solution
Questions # 9:

What are two requirements to enable the MSSP feature on FortiSASE? (Choose two.)

Options:

A.

Add FortiCloud premium subscription on the root FortiCloud account.


B.

Configure MSSP user accounts and permissions on the FortiSASE portal.


C.

Assign role-based access control (RBAC) to IAM users using FortiCloud IAM portal.


D.

Enable multi-tenancy on the FortiSASE portal.


Expert Solution
Questions # 10:

Which two components are part of onboarding a secure web gateway (SWG) endpoint? (Choose two)

Options:

A.

FortiSASE CA certificate


B.

proxy auto-configuration (PAC) file


C.

FortiSASE invitation code


D.

FortiClient installer


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions