View all questions & answers for the FCSS - FortiSASE 25 Administrator Exam Materials exam


Question 13 Discussion

Your FortiSASE customer has a small branch office in which ten users will be using their personal laptops and mobile devices to access the internet. Which deployment should they use to secure their internet access with minimal configuration? (Choose one answer)

  • A. Deploy FortiGate as a LAN extension to secure internet access
  • B. Deploy FortiAP to secure internet access.
  • C. Deploy FortiClient endpoint agent to secure internet access.
  • D. Deploy SD-WAN on-ramp to secure internet access.
Correct Answer: D

Brave-Dump Clients Votes

B 50%
D 33.33%
C 16.67%

Comments



Jo 2025-07-29 22:46:37

Selected Answers: D


D- deploy sdwan onramp.
These are personal devices you cannot install software on. Deploying OnRamp will require no configuration on their devices and push all traffic to SASE for full security.


Taz 2025-10-31 12:16:16

Selected Answers: C


C. Deploy FortiClient endpoint agent to secure internet access.


Mohamed 2025-11-06 20:06:39

Selected Answers: B


I'm confused, it should be B
Page 90
FortiSASE can manage a FortiAP deployed in a remote location over a backhaul connection to provide SIA to
Wi-Fi clients. The FortiAP discovers the FortiSASE AC, and establishes an IPsec VPN tunnel that encrypts
the data channel between FortiSASE and FortiAP. The FortiAP carries Control and Provisioning of Wireless
Access Points (CAPWAP) data packets and includes the FortiAP serial number within this tunnel.


Mohamed 2025-11-06 20:08:41

Selected Answers: B


Can someone confirm please ? and map the answer to the guide book?


Taz 2025-11-07 12:01:16

Selected Answers: D


The best deployment option for a small branch office with ten users using personal devices to access the internet with minimal configuration is D. Deploy SD-WAN on-ramp to secure internet access.
Explanation:
SD-WAN on-ramp: This approach provides a simple and efficient way to secure internet access for remote users with minimal configuration on their devices. It leverages the cloud-based FortiSASE platform to manage and enforce security policies, including access control, content filtering, and VPN connections. Users can connect to the internet through a secure tunnel, and the on-ramp handles the authentication, encryption, and policy enforcement. This eliminates the need for individual device setup or agent installation on each user's laptop or mobile device.
Why other options are less suitable:
A. Deploy FortiGate as a LAN extension: While FortiGate can be used as a LAN extension, it might require more configuration and management for a small branch office with ten users, especially if they are using personal devices. It also necessitates on-premises deployment of a FortiGate firewall.
B. Deploy FortiAP to secure internet access: A FortiAP is primarily designed to secure wireless networks. While it can provide internet access, it might not be the most efficient or scalable solution for a small branch office with distributed users, especially considering the need for individual device configuration.
C. Deploy FortiClient endpoint agent: This option requires installing an agent on each user's device, which adds complexity to the setup process and can be time-consuming for a small number of users.


Al 2025-12-12 04:55:43

Selected Answers: B


It mentions mobile devices so wireless is something to support that, FortiAP sounds better in that sense.