View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 61
Which FortiSASE capability can enforce access policies based on a user’s authenticated identity?
- Identity-based policy
- NAT
- DHCP
- Static routing
Correct Answer: 1
Explanation
Identity-based policies allow security controls to be associated with authenticated users, groups, or other identity attributes. Instead of relying only on IP addresses or network locations, administrators can create policies that reflect the actual identity of the user. This is particularly useful in distributed environments where users may connect from different networks and locations. NAT translates network addresses, DHCP provides IP configuration, and static routing determines fixed traffic paths. Identity-based policy enforcement therefore provides a more contextual method for controlling access to protected resources.
Question 62
Which SSE service is responsible for protecting users while they access websites and web applications?
- CASB
- DLP
- Secure Web Gateway
- ZTNA
Correct Answer: 3
Explanation
Secure Web Gateway provides security inspection and policy enforcement for web traffic. It can apply controls such as URL filtering, web category filtering, malware protection, application control, and other web security policies. This makes SWG an important component of an SSE architecture for protecting users who access internet resources. CASB focuses on cloud applications, DLP protects sensitive data, and ZTNA provides controlled access to private applications. Therefore, Secure Web Gateway is the appropriate service for securing general web and internet access.
Question 63
What is the main function of a Cloud Access Security Broker in an SSE environment?
- Assign IP addresses
- Manage cloud application security
- Synchronize system clocks
- Perform hardware replacement
Correct Answer: 2
Explanation
A Cloud Access Security Broker provides visibility, control, and security policies for cloud applications. CASB can help organizations discover cloud services, monitor their use, and apply security controls based on users, applications, and activities. It is especially useful when employees access SaaS applications from multiple locations and devices. Assigning IP addresses is a DHCP function, synchronizing system clocks is handled by NTP, and hardware replacement is unrelated to CASB. Therefore, managing and securing cloud application usage is the primary purpose of CASB.
Question 64
Which Zero Trust principle requires access to be granted only when explicitly authorized by policy?
- Implicit trust
- Least privilege
- Open access
- Perimeter trust
Correct Answer: 2
Explanation
Least privilege is a core principle of Zero Trust that limits access to only the resources required by an authenticated and authorized user. Instead of giving users broad network permissions, organizations can provide access to specific applications and services based on defined policies. This reduces the potential impact of compromised credentials or devices. Implicit trust, open access, and perimeter trust do not represent the restrictive access model associated with Zero Trust. Least privilege therefore helps ensure that users receive only the permissions necessary for their legitimate tasks.
Question 65
Which security feature can inspect DNS requests and block connections to known malicious domains?
- DNS security
- Load balancing
- DHCP
- NAT
Correct Answer: 1
Explanation
DNS security can inspect domain-name requests and apply security intelligence or configured policies. When a requested domain is associated with malware, phishing, command-and-control infrastructure, or another prohibited category, the request can be blocked or redirected. This can prevent users from reaching malicious destinations before a complete connection is established. Load balancing distributes traffic across resources, DHCP provides network configuration, and NAT translates addresses. DNS security is therefore the appropriate security feature for protecting users through domain-level controls.
Question 66
Which FortiSASE function can prevent sensitive data from being uploaded to an unauthorized cloud service?
- DLP
- SD-WAN
- DHCP
- Routing
Correct Answer: 1
Explanation
Data Loss Prevention can inspect supported traffic for sensitive information and enforce policies that prevent unauthorized transmission. If a user attempts to upload confidential information to an unauthorized cloud service, DLP rules can potentially detect the sensitive content and take an action such as blocking, logging, or alerting. SD-WAN manages network connectivity, DHCP provides addressing information, and routing determines traffic paths. DLP is therefore the security capability directly associated with preventing sensitive information from being transferred to unauthorized destinations.
Question 67
Which SSE component provides access to private applications without necessarily providing full network access?
- ZTNA
- SWG
- CASB
- DNS security
Correct Answer: 1
Explanation
ZTNA provides application-specific access rather than broad network-level connectivity. After evaluating identity and other contextual information, ZTNA can authorize a user to access only the private applications permitted by policy. This supports least-privilege access and reduces the exposure of internal network resources. SWG secures web traffic, CASB focuses on cloud applications, and DNS security protects domain requests. ZTNA is therefore the appropriate SSE component when users need access to private applications without receiving unrestricted access to the surrounding network.
Question 68
Which authentication factor represents something a user knows?
- Fingerprint
- Hardware token
- Password
- Security key
Correct Answer: 3
Explanation
A password is an example of a knowledge authentication factor because it is something the user knows. Authentication factors are commonly divided into categories such as knowledge, possession, and inherence. A fingerprint represents something the user is, while a hardware token or security key generally represents something the user possesses. Multifactor authentication can combine a password with another factor to strengthen identity verification. Understanding these factor categories is important when designing secure authentication policies for users accessing SSE and Zero Trust resources.
Question 69
Which capability allows administrators to block access to websites based on predefined categories?
- URL filtering
- NAT
- DHCP
- NTP
Correct Answer: 1
Explanation
URL filtering allows administrators to control access to websites according to configured categories and policies. Categories can include malicious websites, phishing, gambling, social media, adult content, or other classifications depending on the security service and available categorization. URL filtering is commonly associated with Secure Web Gateway functionality. NAT translates network addresses, DHCP assigns network configuration, and NTP synchronizes system time. Therefore, URL filtering is the appropriate capability for blocking websites based on predefined content categories.
Question 70
What can CASB provide for organizations using multiple cloud applications?
- Cloud application visibility and control
- Physical cable management
- IP address allocation
- Local disk formatting
Correct Answer: 1
Explanation
CASB provides organizations with visibility and control over cloud application usage. It can help administrators identify cloud services, monitor their use, and apply security policies to supported cloud applications. This is useful when employees access many SaaS platforms and the organization needs better control over cloud-related risks. IP address allocation is generally provided by DHCP, while physical cable management and disk formatting are unrelated to CASB. Cloud application visibility and control are therefore key functions of CASB in an SSE architecture.
Question 71
Which factor can be used by Zero Trust policies to determine whether a device should receive application access?
- Device posture
- Monitor brand
- Keyboard language
- Screen size
Correct Answer: 1
Explanation
Device posture represents the security condition or compliance state of an endpoint and can be used as part of a Zero Trust access decision. Depending on the configured integrations, posture information can include endpoint protection status, operating system conditions, compliance information, and other security attributes. If the endpoint does not meet the required conditions, access can be restricted or denied. Monitor brand, keyboard language, and screen size do not normally provide meaningful security context. Device posture is therefore an important factor for contextual access decisions.
Question 72
Which service is primarily responsible for applying security policies to users’ web browsing sessions?
- DLP
- SWG
- ZTNA
- CASB
Correct Answer: 2
Explanation
Secure Web Gateway applies security controls to users’ web browsing traffic. It can enforce URL filtering, web categories, malware protection, application controls, and other policies depending on the deployed configuration. SWG provides a centralized enforcement point for internet-bound traffic and helps organizations maintain consistent web security policies. DLP focuses on sensitive data, ZTNA provides private application access, and CASB focuses on cloud application security. SWG is therefore the service most directly associated with securing and controlling users’ web browsing sessions.
Question 73
Which security control helps ensure that a compromised user account cannot automatically access every internal application?
- Application-level access control
- Open network access
- Shared administrator passwords
- Unrestricted VPN access
Correct Answer: 1
Explanation
Application-level access control restricts users to the applications and resources for which they are authorized. In a Zero Trust architecture, this approach reduces the impact of compromised credentials because successful authentication does not automatically provide unrestricted access to every internal resource. Policies can evaluate identity, device posture, and other contextual factors before granting application access. Open network access and unrestricted VPN access can provide broader connectivity, while shared administrator passwords create additional security risks. Application-level access control therefore supports least-privilege security.
Question 74
Which FortiSASE capability can identify applications such as file-sharing or streaming services for policy enforcement?
- Application control
- DNS forwarding
- DHCP relay
- NAT
Correct Answer: 1
Explanation
Application control identifies network applications and allows administrators to create policies based on the applications detected in traffic. This can be used to monitor or restrict applications such as file-sharing, streaming, messaging, or other services according to organizational requirements. Application control provides more application-aware visibility than relying solely on ports or IP addresses. DNS forwarding handles DNS requests, DHCP relay forwards address-assignment traffic, and NAT translates addresses. Application control is therefore the appropriate capability for identifying applications for policy enforcement.
Question 75
What is one purpose of integrating endpoint information with Zero Trust policies?
- Evaluate device security before granting access
- Increase monitor resolution
- Replace all network routing
- Disable authentication
Correct Answer: 1
Explanation
Integrating endpoint information allows a Zero Trust system to consider the security state of the device when making access decisions. Information about endpoint protection, compliance, operating system status, or other security attributes can be used to determine whether the device satisfies organizational requirements. This can reduce the risk of allowing an insecure or noncompliant endpoint to access sensitive resources. Monitor resolution and network routing are unrelated to this purpose, and Zero Trust does not eliminate authentication. Device security evaluation is therefore a key benefit of endpoint integration.
Question 76
Which SSE function can generate an alert when sensitive information is detected in monitored traffic?
- DLP
- NAT
- Routing
- DHCP
Correct Answer: 1
Explanation
DLP policies can identify sensitive information within supported traffic and generate alerts when configured conditions are met. Administrators can define data patterns or rules for information that should be protected and specify actions such as logging, alerting, blocking, or allowing the activity. This helps security teams identify possible data leakage events and investigate them. NAT, routing, and DHCP perform networking functions rather than sensitive-data inspection. DLP is therefore the appropriate SSE function for generating alerts when protected information is detected.
Question 77
Which access model continuously evaluates whether a user and device should retain access to a protected resource?
- Zero Trust
- Open access
- Perimeter-only trust
- Anonymous access
Correct Answer: 1
Explanation
Zero Trust supports continuous evaluation of access conditions rather than relying entirely on an initial authentication event or network location. Policies can consider identity, device posture, resource, authentication state, and other contextual information. If relevant conditions change, access can be restricted according to policy. Open or anonymous access does not provide this type of security model, while perimeter-only trust relies heavily on network boundaries. Zero Trust therefore provides the architectural approach associated with continuous and contextual access evaluation.
Question 78
Which cloud security capability helps organizations manage risks created by users accessing unsanctioned SaaS services?
- CASB
- DHCP
- NTP
- NAT
Correct Answer: 1
Explanation
CASB helps organizations discover and manage cloud application usage, including potentially unsanctioned SaaS services. Visibility into cloud applications can help administrators identify services that employees are using outside approved processes. Organizations can then establish policies to permit, restrict, monitor, or block applications according to security and compliance requirements. DHCP, NTP, and NAT provide networking services rather than cloud application governance. CASB is therefore the capability most closely associated with managing risks from unsanctioned SaaS usage.
Question 79
Which security service can inspect web content and help detect malicious files downloaded from websites?
- Secure Web Gateway
- DHCP
- DNS
- Static routing
Correct Answer: 1
Explanation
Secure Web Gateway can inspect web traffic and apply security controls to content accessed through websites. Depending on the enabled security features, it can help detect malicious downloads, enforce URL policies, and block dangerous web resources. This provides protection for users while they browse internet resources. DHCP assigns network parameters, DNS resolves domain names, and static routing defines fixed traffic paths. SWG is therefore the security service most directly associated with inspecting web content and protecting users from malicious web-based downloads.
Question 80
Which security principle ensures that users receive only the access required for their specific responsibilities?
- Least privilege
- Full trust
- Open access
- Any-to-any access
Correct Answer: 1
Explanation
Least privilege ensures that users receive only the permissions necessary to perform their authorized responsibilities. This principle reduces unnecessary access and limits potential damage if an account or device is compromised. In Zero Trust environments, least privilege can be implemented by granting access to specific applications and resources rather than providing unrestricted network connectivity. Full trust, open access, and any-to-any access provide broader permissions and do not follow the least-privilege model. Therefore, least privilege is the security principle that restricts access according to actual business requirements.