About the Exam

This exam evaluates applied knowledge of FortiSASE configuration and operation for enterprise deployments. It is intended for network and security professionals who design, administer, and support multisite FortiSASE environments. The exam covers advanced deployment scenarios, secure private access, analytics, troubleshooting, and integration with SD-WAN, FortiGate devices, and FortiManager. Fortinet's release notice lists the exam's last delivery date as July 15, 2026.

Exam Topics

  • Network Security100%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated March 11, 2026 at 4:16 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Network Security

Which statement most accurately describes the Digital Experience Monitor (DEM) feature in FortiSASE?

  • A It provides end-to-end network visibility from all the FortiSASE security PoPs to a specific SaaS application.
  • B It gathers all the vulnerability information from all the FortiClient endpoints.
  • C It is used for performing device compliance checks on endpoints.
  • D It monitors the FortiSASE POP health based on ping probes.
Explanation

Digital Experience Monitoring provides health and performance visibility for connectivity between FortiSASE security PoPs and SaaS applications, and supports end-to-end performance tracing for remote-user connectivity.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Network Security

Which secure internet access (SIA) use case requires the least individual endpoint configuration?

  • A Agentless remote user internet access
  • B Site-based remote user internet access
  • C SIA using ZTNA
  • D SIA for FortiClient agent remote users
Explanation

Agentless remote-user SIA does not require a FortiClient endpoint agent. It uses browser proxy settings or a proxy auto-configuration (PAC) file to send web traffic through the FortiSASE secure web gateway, whereas agent-based SIA requires FortiClient to be installed and configured on each endpoint.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Network Security

Refer to the exhibits.

Question Image

Question Image

A FortiSASE administrator configured an antivirus profile in the security profile group and applied it to the internet-access policy. Remote users can still download the eicar.com-zip file from https://eicar.org.

Which FortiSASE configuration is allowing users to download it?

  • A Web filter is allowing the URL.
  • B Deep inspection is not enabled.
  • C Application control is exempting all the browser traffic.
  • D Intrusion prevention is disabled.
Explanation

FortiSASE requires deep SSL inspection to decrypt and inspect content within HTTPS traffic for antivirus scanning. Certificate inspection examines only information up to the SSL/TLS layer, so it cannot inspect and block the EICAR ZIP payload downloaded over HTTPS. Web filtering can still allow or block the URL based on its category without inspecting that encrypted file content.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Network Security

Which two benefits does FortiSASE provide to organizations with microbranch offices that use FortiAP for unmanaged devices?

Choose two
  • A It secures internet access both on and off the network.
  • B It uses zero trust network access (ZTNA) tags to perform device compliance checks.
  • C It eliminates the requirement for an on-premises firewall.
  • D It simplifies management and provisioning.
Explanation

FortiSASE extends security to thin-edge FortiAP deployments, enabling secure access for users both on and off the network. It also provides cloud-delivered FortiAP management with zero-touch provisioning, simplifying deployment and ongoing administration.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Network Security

Which two requirements are necessary to enable central management in FortiSASE?

Choose two
  • A FortiSASE connector configured on FortiManager.
  • B FortiManager and FortiSASE registered under the same FortiCloud account.
  • C The FortiManager IP address in the FortiSASE central management configuration.
  • D FortiSASE central management entitlement applied to FortiManager.
Explanation

Central management requires FortiManager and FortiSASE to be registered under the same FortiCloud account and the FortiSASE connector to be enabled in FortiManager. The shared account allows FortiManager to discover the FortiSASE subscription, after which the connector establishes configuration synchronization.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
Network Security
Know a question that should be here? Contribute to this exam
Back home