View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 101
Which FortiSASE capability provides secure access to private applications without granting users unrestricted network access?
- DNS Security
- Secure Web Gateway
- Zero Trust Network Access
- Data Loss Prevention
Correct Answer: 3
Explanation
Zero Trust Network Access provides application-level access to private resources based on security policies. Instead of placing a user on the internal network with broad connectivity, ZTNA evaluates identity, authentication, device posture, and other contextual information before allowing access. This supports the principle of least privilege and reduces the exposure of internal applications. DNS Security protects domain requests, Secure Web Gateway protects web traffic, and DLP protects sensitive information. ZTNA is therefore the appropriate FortiSASE capability when private application access must be controlled without providing unrestricted network-level connectivity.
Question 102
Which technology is primarily used to secure web traffic and enforce internet access policies?
- Secure Web Gateway
- CASB
- ZTNA
- DLP
Correct Answer: 1
Explanation
Secure Web Gateway is designed to inspect and control web traffic before users reach internet resources. It can apply URL filtering, web-category controls, malware protection, application control, and other web security policies. SWG allows administrators to centrally enforce acceptable-use and security requirements for users in different locations. CASB focuses on cloud applications, ZTNA controls private application access, and DLP focuses on sensitive information. Therefore, Secure Web Gateway is the technology most directly associated with securing internet and web traffic.
Question 103
Which SSE component provides visibility and security controls for SaaS applications?
- DNS Security
- ZTNA
- DLP
- CASB
Correct Answer: 4
Explanation
Cloud Access Security Broker provides visibility, governance, and security controls for cloud applications such as SaaS services. CASB can help organizations discover cloud applications, monitor how they are being used, and enforce policies based on users, applications, and activities. This is useful when employees access many cloud services from various devices and locations. DNS Security focuses on domain requests, ZTNA protects access to private applications, and DLP protects sensitive data. CASB is therefore the appropriate SSE component for SaaS application security and visibility.
Question 104
Which principle limits a user’s permissions to only the resources required to perform assigned duties?
- Zero encryption
- Least privilege
- Open trust
- Full network access
Correct Answer: 2
Explanation
Least privilege means that users should receive only the permissions necessary to perform their authorized responsibilities. In a Zero Trust architecture, this principle helps reduce unnecessary exposure to applications and data. If an account is compromised, restricting permissions can limit the number of resources that the compromised account can reach. Full network access and open trust provide much broader permissions, while zero encryption is not an access-control principle. Least privilege is therefore a fundamental approach for limiting authorization according to actual business requirements.
Question 105
Which authentication option is an example of something the user possesses?
- Password
- PIN
- Fingerprint
- Hardware token
Correct Answer: 4
Explanation
A hardware token is a possession factor because it is something the user physically possesses. Authentication methods can generally be categorized as something the user knows, has, or is. Passwords and PINs are knowledge factors, while a fingerprint is a biometric factor representing something the user is. A hardware token can be used together with a password to implement multifactor authentication. This combination provides stronger protection because an attacker would need more than just the user’s password to successfully authenticate.
Question 106
Which feature can block users from accessing web categories that violate an organization’s acceptable-use policy?
- URL or web filtering
- DHCP
- NAT
- NTP
Correct Answer: 1
Explanation
URL and web filtering allow administrators to control website access according to configured categories, destinations, or reputation information. Organizations can use these controls to block websites associated with malware, phishing, gambling, inappropriate content, or other restricted categories. Web filtering is commonly implemented as part of Secure Web Gateway functionality. DHCP provides network configuration, NAT translates addresses, and NTP synchronizes time. URL and web filtering are therefore the appropriate features for enforcing acceptable-use policies on internet websites.
Question 107
Which feature can identify applications in traffic so that administrators can apply application-specific policies?
- DNS Security
- Application Control
- DHCP Relay
- NAT
Correct Answer: 2
Explanation
Application Control identifies network applications and allows administrators to create policies based on detected application traffic. This can provide better visibility than relying only on IP addresses or ports. Administrators can use application control to permit, block, monitor, or restrict applications according to organizational requirements. DNS Security protects domain requests, DHCP Relay forwards DHCP messages, and NAT translates network addresses. Application Control is therefore the appropriate feature when administrators need application-aware identification and policy enforcement.
Question 108
Which service can evaluate domain requests and block access to destinations associated with malicious activity?
- CASB
- DLP
- DNS Security
- ZTNA
Correct Answer: 3
Explanation
DNS Security protects users by inspecting DNS requests and applying security intelligence or configured policies. When a requested domain is identified as malicious, phishing-related, or otherwise prohibited, the request can be blocked or redirected. This can prevent users from connecting to harmful destinations before the full connection is established. CASB manages cloud application security, DLP protects sensitive information, and ZTNA controls access to private applications. DNS Security is therefore the service specifically focused on protecting users through domain-level security controls.
Question 109
What does device posture represent in a Zero Trust environment?
- The physical location of a data center
- The security and compliance condition of an endpoint
- The bandwidth of an internet link
- The number of users in a group
Correct Answer: 2
Explanation
Device posture describes the security and compliance condition of an endpoint. A Zero Trust policy can use posture information when deciding whether a device should be allowed to access protected applications. Depending on the available integrations, posture can include endpoint security status, operating system conditions, compliance information, or other security attributes. A device that fails required posture checks may be denied or restricted from accessing sensitive resources. Device posture is therefore an important contextual factor in modern Zero Trust access decisions.
Question 110
Which FortiSASE capability is designed to identify and control sensitive information in monitored traffic?
- DLP
- SD-WAN
- Routing
- DHCP
Correct Answer: 1
Explanation
Data Loss Prevention identifies sensitive information in supported traffic and applies configured security policies. Administrators can define patterns or rules for confidential data and then specify actions such as allow, block, log, or alert. DLP can help protect sensitive business information, personal data, intellectual property, and other regulated content from unauthorized disclosure. SD-WAN manages network connectivity, routing determines traffic paths, and DHCP provides network configuration. DLP is therefore the FortiSASE capability specifically designed to identify and control sensitive information.
Question 111
Which SSE service is intended to provide security controls for cloud applications used by employees?
- ZTNA
- CASB
- Secure Web Gateway
- DNS Security
Correct Answer: 2
Explanation
CASB provides security and governance capabilities for cloud applications. It can help identify applications, monitor cloud usage, and enforce policies for supported SaaS environments. This makes CASB valuable for organizations where employees rely on many cloud services from remote locations and different devices. ZTNA provides access to private applications, Secure Web Gateway protects general web traffic, and DNS Security protects domain requests. CASB is therefore the SSE service most directly associated with security controls for employee use of cloud applications.
Question 112
Which security service can inspect users’ web traffic for malicious downloads and unsafe websites?
- DLP
- CASB
- Secure Web Gateway
- ZTNA
Correct Answer: 3
Explanation
Secure Web Gateway can inspect web traffic and apply security controls to internet content. Depending on the enabled security services, SWG can identify malicious websites, enforce URL filtering, inspect downloads, and block dangerous web resources. This creates a security enforcement point for users accessing internet content. DLP focuses on sensitive data, CASB focuses on cloud applications, and ZTNA provides private application access. Secure Web Gateway is therefore the appropriate service for inspecting and protecting users from web-based threats and malicious downloads.
Question 113
Which Zero Trust capability can use identity and device information together when making an access decision?
- ZTNA
- DNS filtering
- NTP
- DHCP
Correct Answer: 1
Explanation
ZTNA can use both user identity and device-related information when determining whether access should be granted. This allows security policies to consider authenticated users together with endpoint posture and other contextual factors. As a result, organizations can provide access only when the combination of identity and device conditions satisfies policy requirements. DNS filtering focuses on domain requests, NTP synchronizes time, and DHCP provides network configuration. ZTNA is therefore the capability that combines identity and device context for controlled application access.
Question 114
Which capability can apply different security policies to users based on their group membership?
- NAT
- Identity-based policy
- Static routing
- DHCP
Correct Answer: 2
Explanation
Identity-based policies allow security rules to be associated with users or groups. This enables administrators to provide different access permissions and security controls according to organizational roles. For example, employees, contractors, and administrators may receive different web or application access policies. NAT translates addresses, static routing defines fixed network paths, and DHCP assigns network configuration. Identity-based policy is therefore the appropriate capability when security controls must reflect the authenticated user’s group membership or organizational role.
Question 115
Which feature can discover cloud applications that employees are using without official authorization?
- DNS Security
- ZTNA
- CASB
- DLP
Correct Answer: 3
Explanation
CASB can provide visibility into cloud application usage and help organizations identify unsanctioned services. Discovering these applications is important because employees may use cloud platforms that have not been evaluated for security, privacy, or compliance requirements. Once applications are identified, administrators can determine whether they should be allowed, monitored, restricted, or blocked. DNS Security protects domain requests, ZTNA controls private application access, and DLP focuses on sensitive data. CASB is therefore the appropriate capability for discovering and managing unsanctioned cloud application usage.
Question 116
Which authentication method uses multiple independent factors to verify a user’s identity?
- Password-only authentication
- Anonymous authentication
- Multifactor authentication
- Guest access
Correct Answer: 3
Explanation
Multifactor authentication requires two or more authentication factors, typically from different categories such as knowledge, possession, and inherence. A common example is combining a password with a security token or biometric verification. MFA provides stronger protection because compromising one factor alone may not be sufficient to gain access. Password-only authentication uses a single factor, while anonymous authentication and guest access do not provide the same identity-verification mechanism. MFA is therefore the authentication approach designed to use multiple independent factors.
Question 117
Which capability can help ensure that an endpoint does not receive application access when it fails a security compliance check?
- Device posture validation
- URL categorization
- DNS caching
- Traffic shaping
Correct Answer: 1
Explanation
Device posture validation evaluates whether an endpoint meets defined security and compliance requirements. A Zero Trust policy can use the result of this validation before granting access to a protected application. If the endpoint is missing required security controls or otherwise fails the policy requirements, access can be restricted or denied. URL categorization classifies websites, DNS caching stores resolution information, and traffic shaping controls bandwidth usage. Device posture validation is therefore the capability directly associated with checking endpoint compliance before allowing access.
Question 118
Which SSE capability can prevent confidential information from being transmitted to unauthorized destinations?
- Application Control
- DLP
- CASB
- DNS Security
Correct Answer: 2
Explanation
DLP is designed to identify sensitive information and enforce controls that help prevent its unauthorized transmission. Policies can inspect supported traffic and detect configured data patterns, then take actions such as blocking the activity, generating an alert, or logging the event. This can help protect confidential business documents, personal information, or regulated data. Application Control identifies applications, CASB manages cloud application security, and DNS Security protects domain requests. DLP is therefore the SSE capability most directly associated with preventing sensitive information from reaching unauthorized destinations.
Question 119
Which security service can centrally enforce web access policies for users working from different locations?
- Secure Web Gateway
- DHCP
- NTP
- Routing
Correct Answer: 1
Explanation
Secure Web Gateway can provide centralized web security and policy enforcement for users regardless of their physical location. In a cloud-delivered SSE architecture, users can receive consistent controls for web filtering, URL categories, malware protection, and other security requirements through cloud-based services. DHCP provides network configuration, NTP synchronizes system clocks, and routing controls network paths. SWG is therefore the service that most directly provides centralized policy enforcement for users accessing internet resources from different locations.
Question 120
Which architecture combines cloud-delivered security controls for web access, private applications, cloud applications, and data protection?
- Traditional LAN
- Basic NAT architecture
- Security Service Edge
- Standalone DHCP
Correct Answer: 3
Explanation
Security Service Edge is an architecture that brings together cloud-delivered security services for distributed users and applications. Depending on the implementation, SSE can include Secure Web Gateway for internet access, Zero Trust Network Access for private applications, CASB for cloud application security, and DLP for sensitive-data protection. This model is designed for users working from branch offices, remote locations, or mobile environments. Traditional LAN, NAT, and DHCP provide networking functions but do not represent this integrated cloud security architecture. SSE therefore provides the combined security framework described in the question.