01. During a security investigation, an analyst wants to enrich a suspicious detection with reputation and threat context.
Which role does FortiGuard play in this forensic analysis?
a) It is the on-device CLI diagnostic toolset used to run packet captures and sniffer traces to troubleshoot a branch FortiGate.
b) It supplies threat intelligence such as reputation, categorization, and threat analysis to enrich a suspicious detection.
c) It provisions ZTNA security posture tags to endpoints based on their evaluated compliance state.
d) It stores the tenant's historical SD-WAN performance metrics and analytics for long-term reporting and capacity planning.
02. A team is integrating its FortiSASE tenant into the existing Fortinet Security Fabric.
Which outcomes does this integration provide?
(Choose two.)
a) Endpoint and threat telemetry is shared between FortiSASE and Fabric devices for unified visibility.
b) It removes the need to define any endpoint profile or security posture tag.
c) It is the mechanism that tunnels users' internet-bound traffic to the nearest POP.
d) It converts FortiSASE from a cloud-delivered service into an on-premises FortiGate appliance.
e) FortiSASE-enforced identity and posture context can be correlated with FortiGate and FortiAnalyzer data.
03. An architect is enabling SPA so that tunneled remote users can reach a set of internal corporate web applications. FortiSASE will join the corporate network as a spoke that terminates on an on-premises hub FortiGate.
Which two configuration outcomes on the hub FortiGate are required to make the private applications reachable over secure private access?
(Choose two.)
a) The hub must be provisioned as a FortiSASE POP so that endpoints connect to it as their nearest point of presence.
b) The hub FortiGate terminates the overlay from FortiSASE
c) The hub must publish each application to the public internet through an HTTPS access proxy virtual server reachable from any browser without a tunnel.
d) The hub FortiGate must run a full secure web gateway inspection profile so that users' internet-bound SaaS traffic is proxied through it.
e) A ZTNA access policy on the hub governs which private applications the tunneled users may reach, enforcing identity and posture at the private-access boundary.
04. A retail branch has dozens of point-of-sale terminals and IoT devices that cannot run endpoint software, but all of their internet traffic must be inspected by FortiSASE.
Which SIA delivery mode best fits this branch?
a) Secure Private Access (SPA), brokering per-application ZTNA sessions to each terminal rather than inspecting its internet traffic.
b) Edge-based SIA, where a site edge device steers the whole branch's traffic to FortiSASE with no per-endpoint agent.
c) Agentless SIA, requiring each headless terminal to browse out through an explicit proxy configured individually.
d) Agent-based SIA, installing and enrolling the FortiClient agent on each point-of-sale terminal and IoT device.
05. Users have discovered they can disable the endpoint agent or change adapter settings to send traffic straight to the internet, bypassing FortiSASE inspection.
Which FortiSASE capability is designed to prevent this bypass?
a) Network lockdown, which forces the endpoint's traffic through FortiSASE and can restrict connectivity for non-compliant or unprotected devices.
b) A security posture tag, which simply labels the device's compliance state for policy matching and reporting, with no enforcement of its own.
c) The HTTPS access proxy, which publishes a single internal web application for clientless browser access rather than steering traffic through FortiSASE.
d) Digital Experience Monitoring (DEM), which proactively measures latency, hops, and path quality toward the key applications users depend on.
06. External contractors use their own unmanaged laptops on which the security team cannot install endpoint software, yet their internet browsing must still pass through FortiSASE inspection.
Which SIA delivery mode is designed for this case?
a) Agent-based SIA, tunneling all endpoint traffic through the installed and enrolled FortiClient agent to the POP.
b) Secure Private Access (SPA), which brokers ZTNA sessions to published internal apps rather than inspecting internet browsing.
c) Edge-based SIA, steering an entire branch site's traffic to FortiSASE from a site edge device.
d) Agentless SIA, using browser or explicit-proxy access to the FortiSASE secure web gateway without a full FortiClient agent.
07. FortiSASE remote users must reach private data-center applications. The corporate network is built as a FortiGate SD-WAN hub-and-spoke, and the architect is weighing two integration designs for the private-access path.
Which statement correctly distinguishes the available designs for SPA?
a) Both designs require a full, always-on network-level VPN client on each endpoint before any single private application becomes reachable.
b) An SD-WAN on-ramp carries only internet-bound traffic, so FortiSASE-as-spoke is the only one of the two designs related to private-application access.
c) FortiSASE can join the corporate SD-WAN as a spoke into the hub (FortiSASE-as-spoke), or ride an SD-WAN on-ramp at a site FortiGate; both are valid SPA paths to private apps.
d) Edge SIA at the branch is the correct choice because it steers the private-app traffic to the internet POP, where the secure web gateway inspects it before it returns to the data center.
08. Remote users must reach several internal corporate web applications hosted in the data center, and the security team wants per-application, identity- and posture-gated access instead of broad network-level VPN.
Which FortiSASE service and method meet this requirement?
a) SIA edge mode using a FortiExtender at the site to steer the whole branch's application traffic to a POP, applying secure web gateway inspection but giving no per-application private-access control.
b) SPA using ZTNA, granting per-application access gated by identity and posture, with FortiSASE reaching the private apps as a spoke into the corporate network or via an SD-WAN on-ramp.
c) SIA in agentless mode, sending the users through an explicit browser proxy out to the public internet, which secures internet- and SaaS-bound sessions but never reaches the private data-center applications.
d) An SD-WAN Direct Internet Access breakout configured on each endpoint to route the corporate application traffic straight out the local internet link, with no identity or posture evaluation on the path.
09. A dual-hub design gives each spoke two hubs for redundancy. Traffic should normally prefer one hub and fail over to the second only when the first is unreachable, rather than splitting evenly.
How is that hub preference most appropriately achieved for a given overlay?
a) Spokes always load-balance sessions evenly across both hubs at a fixed fifty-fifty ratio, with no BGP attribute or member-priority setting available to express a primary and a backup between the two overlays.
b) The second hub can only be used for out-of-band management and monitoring, and is barred from carrying any production overlay traffic even when the primary hub is completely unreachable.
c) Both hubs must share one identical public IP address and advertise the same BGP local preference so the spokes cannot tell them apart or express any primary-versus-backup ordering.
d) Route preference is expressed through BGP attributes and SD-WAN member priority so one hub is primary and the other is backup, with BGP reconverging to the second hub when the primary fails.
10. In a centrally managed SD-WAN, the architect must place two management components: one that provisions and monitors SD-WAN configuration across many devices, and one that aggregates forwarded logs to produce SD-WAN analytics and reports.
Which mapping is correct?
a) FortiManager forwards logs for analytics and reporting, while FortiAnalyzer pushes the SD-WAN templates and firmware out to the managed devices and monitors their runtime health.
b) FortiAnalyzer provisions and pushes the SD-WAN configuration and templates to devices, while FortiManager only stores raw captured packets for later manual review.
c) FortiManager centrally provisions and monitors SD-WAN across the devices, while FortiAnalyzer aggregates the forwarded logs to produce SD-WAN analytics and reports.
d) Both provisioning and log analytics are handled solely by FortiManager, with FortiAnalyzer used only to hold firmware images and configuration backups for later rollback.