FCSS-SASE-AD-25 Sample Questions

FCSS-SASE-AD-25 Sample Questions & Answers

Deployment work like user onboarding and compliance checks ties with securely reaching the internet, SaaS apps, and private resources via SD-WAN and ZTNA for the top weighting, alongside hybrid-network architecture and analyzing logs, dashboards, and traffic reports.

Launch the full FCSS-SASE-AD-25 simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    SIA, SSA, and SPA · Design security profiles to perform content inspection

    HealthForward, a large healthcare provider, is migrating its 10,000 remote clinicians and administrative staff to FortiSASE. Their primary goals are to enforce HIPAA compliance for all internet-bound traffic, prevent data exfiltration of Patient Health Information (PHI), and secure access to both modern SaaS applications (like Office 365) and legacy clinical applications hosted in their on-premises data center. The legacy applications are not web-based and require direct TCP/UDP connectivity.

    The CISO has mandated a stringent security posture. All traffic, including to trusted SaaS vendors, must be inspected for threats and data loss. Clinicians often work from untrusted networks, so endpoint compliance is critical; devices must have active antivirus and full-disk encryption. Furthermore, to simplify auditing and interactions with external partners who have IP-based allow-lists, all traffic from the finance department must originate from a single, predictable public IP address, regardless of where the user is located.

    The network team has been tasked with implementing a solution that meets all these requirements without significantly impacting user experience, especially for latency-sensitive clinical applications. They must use FortiSASE's native capabilities to achieve this.

    Which combination of FortiSASE configurations best addresses all of HealthForward's security and compliance requirements?

    Show answer & explanation

    Correct answer: C

    This option correctly addresses all requirements: 1) SPA with ZTNA is the correct method for securing non-web legacy applications. 2) A separate policy with SSL deep inspection, a DLP profile to monitor for PHI, and Application Control is essential for enforcing HIPAA compliance. 3) A Dedicated IP with Source IP Anchoring is the specific feature designed to make a group of users appear from a single, static public IP address. 4) Security posture checks are the mechanism for verifying endpoint compliance (AV, disk encryption).

  2. Question 2IntermediateSelect 2

    Analytics · Configure dashboards and logging settings

    An administrator needs to configure FortiSASE logging to meet strict data privacy regulations. The requirements are to retain security event logs for one year, traffic logs for 90 days, and to minimize the storage of personally identifiable information (PII) where possible. Which two actions should the administrator take in the logging settings? (Select TWO)

    Show answer & explanation

    Correct answers: B, E

    Enabling log anonymization is a direct method to minimize the storage of PII within the logs, helping to meet data privacy requirements.

    FortiSASE allows for granular control over retention periods for different log types. Configuring separate periods for security (365 days) and traffic (90 days) logs directly meets the specified requirements.

  3. Question 3Intermediate

    SIA, SSA, and SPA · Deploy ZTNA

    A FortiSASE administrator is troubleshooting a ZTNA connection issue for a remote user. The user can authenticate successfully, but cannot access the protected application. The administrator wants to view real-time debugging information for the ZTNA application gateway. Which FortiOS CLI command is used for this purpose?

    Show answer & explanation

    Correct answer: D

    The diagnose debug application ztna -1 command enables real-time debugging for the ZTNA application process. This allows an administrator to see detailed connection information, policy evaluation, and potential errors as the user attempts to connect, which is essential for troubleshooting.

  4. Question 4Beginner

    SASE Architecture and Components · Integrate FortiSASE in a hybrid network

    What is the primary architectural benefit of integrating FortiSASE with an existing Fortinet SD-WAN deployment at branch offices?

    Show answer & explanation

    Correct answer: A

    Integrating FortiSASE with on-premises FortiGate SD-WAN creates a hybrid SASE solution. This allows the organization to apply consistent security policies and profiles (like web filtering, IPS, and DLP) to users whether they are working from a branch office (protected by the FortiGate) or remotely (protected by FortiSASE), ensuring a unified security posture.

  5. Question 5Advanced

    SIA, SSA, and SPA · Secure Internet Access (SIA) and dedicated IP use cases

    A company has configured a dedicated IP address in FortiSASE for source IP anchoring. The goal is to ensure that traffic from their European sales team always exits to the internet from a specific IP address when accessing a partner's SaaS platform. After configuration, the sales team reports that their traffic is still egressing from the general shared IP pool. What is the most likely configuration error?

    Show answer & explanation

    Correct answer: D

    Simply provisioning a dedicated IP address is not enough. For source IP anchoring to function, a central SNAT policy must be created. This policy explicitly maps source traffic identifiers (like a user group for the European sales team) to the specific dedicated IP address for outbound traffic. Without this policy, FortiSASE will use the default shared IP pool.

  6. Question 6Beginner

    Analytics · Configure dashboards and logging settings

    An administrator is creating a custom dashboard in FortiSASE to monitor endpoint compliance over time. Which widget would be most effective for visualizing the percentage of compliant versus non-compliant devices over the last 30 days?

    Show answer & explanation

    Correct answer: C

    A historical trend chart is specifically designed to display data over a period of time. Using this widget for endpoint posture status would clearly show the trend of compliant vs. non-compliant devices, allowing the administrator to spot changes or persistent issues over the last 30 days.

  7. Question 7Intermediate

    SASE Deployment · Implement various types of user onboarding methods

    When constructing a FortiSASE deployment for a company with a large number of small, autonomous branch offices that have no on-premises IT staff, which user onboarding method is most scalable and requires the least administrative overhead?

    Show answer & explanation

    Correct answer: C

    For branch offices without IT staff, an endpoint-centric approach is the most scalable. Deploying FortiClient to all devices and integrating with a central Identity Provider (IdP) via SAML allows for zero-touch provisioning. Users can self-enroll using their corporate credentials without any on-site configuration, and policies are centrally managed and pushed from the cloud.

  8. Question 8Intermediate

    SIA, SSA, and SPA · Design security profiles to perform content inspection

    A FortiSASE administrator is designing a security profile to inspect traffic to SaaS applications. The primary goal is to prevent users from uploading sensitive documents containing project codenames to personal cloud storage accounts, while still allowing general use of approved corporate cloud storage. Which security feature is most critical for this policy?

    Show answer & explanation

    Correct answer: B

    Data Loss Prevention (DLP) is the feature designed to inspect content for sensitive information, such as project codenames defined in a custom dictionary. To inspect the content of encrypted SaaS traffic (HTTPS), SSL deep inspection must also be enabled. Together, these features allow FortiSASE to see the files being uploaded and block them if they contain sensitive data.

  9. Question 9Beginner

    Analytics · Identify potential security threats using FortiSASE logs

    True or False: In a FortiSASE deployment, the AI-driven analytics engine primarily relies on signatures and static rules to identify security threats.

    Show answer & explanation

    Correct answer: B

    The AI-driven analytics engine in FortiSASE goes beyond static rules and signatures. It uses machine learning and behavioral analysis to establish baselines of normal user and network activity. It then identifies potential threats by detecting anomalous deviations from these baselines, allowing it to uncover novel or zero-day threats that signatures would miss.

  10. Question 10Advanced

    SASE Deployment · Configure SASE administration settings

    A media company is adopting FortiSASE to provide secure access for its freelance journalists who work globally. The security team wants to define ZTNA access policies based on the journalist's role (e.g., 'Editor', 'Field Reporter') and the security posture of their device. The user role information is managed in their Azure Active Directory. What must the administrator configure to achieve this role-based access control?

    sequenceDiagram participant User participant FortiClient participant FortiSASE participant AzureAD as Azure AD (IdP) User->>FortiClient: Authenticate FortiClient->>FortiSASE: Initiate Connection FortiSASE->>AzureAD: SAML AuthN Request AzureAD-->>FortiSASE: SAML Assertion (with Group Claims) FortiSASE->>FortiSASE: Evaluate ZTNA Policy Note over FortiSASE: Match User Group from Assertion FortiSASE-->>FortiClient: Grant/Deny Access

    Show answer & explanation

    Correct answer: D

    To implement role-based access control using an external IdP like Azure AD, the administrator must first configure SAML SSO. Then, they must create user groups within FortiSASE that exactly match the names of the security groups being passed in the SAML assertion from Azure AD. The ZTNA policies can then reference these FortiSASE user groups to grant access based on the user's role.

Ready for the real thing?

The full FCSS-SASE-AD-25 simulator has every exam-style question, timed mode, and instant scoring.