View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 141
Which capability can provide secure, application-specific access to private resources for remote users?
- DNS Security
- Secure Web Gateway
- Data Loss Prevention
- Zero Trust Network Access
Correct Answer: 4
Explanation
Zero Trust Network Access provides controlled access to private applications based on identity and contextual security information. Instead of granting broad network connectivity, ZTNA can authorize users to access only the applications permitted by policy. Access decisions can consider factors such as authentication status, device posture, user identity, and other configured conditions. DNS Security protects domain requests, Secure Web Gateway protects internet traffic, and DLP focuses on sensitive information. ZTNA is therefore the appropriate capability for providing secure, application-specific access to private resources for remote users.
Question 142
Which SSE service primarily protects users when they browse websites on the internet?
- Secure Web Gateway
- CASB
- DLP
- ZTNA
Correct Answer: 1
Explanation
Secure Web Gateway is designed to secure users’ web and internet traffic. It can inspect requests and enforce controls such as URL filtering, web category policies, malware protection, and application control. SWG provides centralized security enforcement for users regardless of where they connect from. CASB focuses on cloud application security, DLP protects sensitive information, and ZTNA controls access to private applications. Therefore, Secure Web Gateway is the primary SSE service for protecting users while they browse internet websites and web applications.
Question 143
Which technology helps organizations discover and control the use of cloud applications?
- ZTNA
- CASB
- DHCP
- NAT
Correct Answer: 2
Explanation
Cloud Access Security Broker provides visibility and security controls for cloud applications. CASB can help organizations discover the cloud services being accessed by employees, monitor application usage, and enforce policies based on organizational requirements. This is particularly useful for managing SaaS environments and identifying unsanctioned cloud applications. ZTNA is primarily used for private application access, DHCP provides network configuration, and NAT performs address translation. CASB is therefore the appropriate technology for discovering and controlling cloud application usage.
Question 144
Which capability is designed to prevent confidential data from being transferred to unauthorized destinations?
- Application Control
- DNS Security
- Data Loss Prevention
- Secure Web Gateway
Correct Answer: 3
Explanation
Data Loss Prevention is designed to identify sensitive information and prevent unauthorized disclosure or transfer. Organizations can configure DLP policies to detect specific data patterns, classifications, or other sensitive content and then apply actions such as blocking, logging, or alerting. This helps protect confidential business information, personal data, intellectual property, and regulated information. Application Control manages application traffic, DNS Security protects domain requests, and SWG protects web traffic. DLP is therefore the capability specifically focused on preventing sensitive data from leaving through unauthorized channels.
Question 145
Which principle requires security decisions to be based on verified identity and other contextual information instead of network location alone?
- Zero Trust
- Open access
- Perimeter trust
- Anonymous access
Correct Answer: 1
Explanation
Zero Trust requires access decisions to be based on verified identity and relevant security context rather than assuming that a user is trustworthy because they are connected to a particular network. Context can include device posture, authentication status, resource being accessed, and other policy conditions. This approach reduces reliance on the traditional network perimeter as the primary security boundary. Open access and anonymous access do not provide the same verification model, while perimeter trust places greater reliance on network location. Zero Trust therefore represents the principle described.
Question 146
Which feature can block access to websites according to predefined URL categories?
- CASB
- DLP
- DNS Security
- URL Filtering
Correct Answer: 4
Explanation
URL filtering allows administrators to control website access based on categories, destinations, reputation, or other configured criteria. Organizations can use URL filtering to block categories associated with malware, phishing, gambling, inappropriate content, or other restricted resources. This capability is commonly implemented within Secure Web Gateway services. CASB focuses on cloud applications, DLP protects sensitive information, and DNS Security operates primarily at the domain request level. URL Filtering is therefore the appropriate feature when the requirement is to enforce access policies based on website categories.
Question 147
Which authentication factor is classified as something the user knows?
- Password
- Fingerprint
- Hardware token
- Security key
Correct Answer: 1
Explanation
A password is a knowledge factor because it represents something the user knows. Authentication factors are commonly divided into knowledge, possession, and inherence categories. A hardware token or security key generally represents something the user possesses, while a fingerprint is something the user is. Combining a password with a possession or biometric factor enables multifactor authentication. Knowledge factors remain widely used, but organizations often strengthen them with additional factors to reduce the risk of unauthorized access when a password is compromised.
Question 148
Which feature can help identify applications such as streaming, file sharing, or messaging for policy enforcement?
- DNS Security
- Application Control
- DHCP
- NTP
Correct Answer: 2
Explanation
Application Control identifies applications in network traffic and allows administrators to apply security policies based on detected applications. This can help organizations manage applications such as streaming, file sharing, messaging, social networking, and other services according to acceptable-use and security requirements. Application-aware policies provide more granular control than simply relying on IP addresses or ports. DNS Security protects domain requests, DHCP provides network configuration, and NTP synchronizes time. Application Control is therefore the appropriate capability for identifying specific applications and enforcing application-based security policies.
Question 149
What information can be used to determine whether an endpoint satisfies a Zero Trust access requirement?
- Monitor resolution
- Device posture
- Keyboard layout
- Screen size
Correct Answer: 2
Explanation
Device posture provides information about the security and compliance state of an endpoint. In a Zero Trust environment, posture information can be evaluated before granting access to protected applications. Depending on the available integrations, posture may include endpoint security status, operating system conditions, compliance state, or other security attributes. If a device does not satisfy the required policy conditions, access can be restricted or denied. Monitor resolution, keyboard layout, and screen size do not normally provide useful security context. Device posture is therefore the relevant information for endpoint-based access decisions.
Question 150
Which security capability can block a request to a domain known to host phishing content?
- DLP
- CASB
- ZTNA
- DNS Security
Correct Answer: 4
Explanation
DNS Security can inspect DNS requests and apply threat intelligence or configured policies to domain destinations. If a requested domain is associated with phishing, malware, command-and-control infrastructure, or another prohibited category, the request can be blocked or redirected. This provides a preventive control before the user establishes a full connection to the destination. DLP protects sensitive information, CASB focuses on cloud application security, and ZTNA provides private application access. DNS Security is therefore the capability most directly associated with blocking malicious or prohibited domains.
Question 151
Which approach can restrict a user to only the specific private applications authorized by policy?
- Full network access
- Open VPN access
- ZTNA application access
- Anonymous access
Correct Answer: 3
Explanation
ZTNA application access allows organizations to provide users with access only to private applications that have been explicitly authorized by policy. Rather than placing users on a broad internal network after authentication, ZTNA evaluates the user and device context and then provides access to the permitted application. This supports least privilege and reduces unnecessary exposure of internal resources. Full network access and open VPN access can provide broader connectivity, while anonymous access does not provide appropriate identity controls. ZTNA therefore best fits the requirement for restricted application-level access.
Question 152
Which component is responsible for providing security visibility and controls for SaaS applications?
- Secure Web Gateway
- CASB
- DNS Security
- DLP
Correct Answer: 2
Explanation
CASB is designed to provide security visibility, governance, and policy controls for cloud applications, including SaaS services. It can help administrators discover applications, monitor activity, and enforce organizational rules for cloud usage. This can reduce risks associated with unmanaged or unsanctioned cloud services. Secure Web Gateway primarily protects general web traffic, DNS Security protects domain requests, and DLP focuses on sensitive data. CASB is therefore the component most directly associated with security visibility and policy enforcement for SaaS applications.
Question 153
Which authentication factor is an example of something the user possesses?
- PIN
- Password
- Fingerprint
- Authentication token
Correct Answer: 4
Explanation
An authentication token is a possession factor because the user has physical or logical possession of the token used during authentication. Passwords and PINs are knowledge factors because the user knows them, while a fingerprint is a biometric factor representing something the user is. Combining a possession factor with a knowledge or biometric factor is a common way to implement multifactor authentication. Using multiple factor types provides stronger security than relying solely on one credential type, especially when protecting access to sensitive applications and services.
Question 154
Which policy type allows security controls to be assigned according to authenticated users or groups?
- Identity-based policy
- Static routing
- NAT policy
- DHCP policy
Correct Answer: 1
Explanation
Identity-based policies allow administrators to associate security controls with authenticated users or groups rather than relying only on IP addresses or network locations. This makes it possible to provide different access permissions to departments, roles, contractors, administrators, or other user groups. Identity-based policies are particularly useful in Zero Trust architectures where user identity is an important part of authorization decisions. Static routing controls traffic paths, NAT policies handle address translation, and DHCP policies manage network configuration. Identity-based policy is therefore the appropriate choice.
Question 155
Which capability is useful for preventing users from uploading sensitive information to unauthorized cloud services?
- DNS Security
- DLP
- DHCP
- Traffic Shaping
Correct Answer: 2
Explanation
DLP can inspect supported traffic for sensitive information and enforce policies that control how the information is transmitted. If a user attempts to upload confidential content to an unauthorized cloud service, DLP may identify the content and perform a configured action such as blocking, logging, or alerting. DNS Security focuses on domain requests, DHCP provides network configuration, and traffic shaping manages bandwidth usage. DLP is therefore the capability most directly associated with preventing sensitive information from being uploaded to unauthorized destinations.
Question 156
Which service provides centralized inspection and control of users’ internet-bound web traffic?
- ZTNA
- CASB
- DLP
- Secure Web Gateway
Correct Answer: 4
Explanation
Secure Web Gateway provides centralized security inspection for users accessing internet resources. It can enforce web filtering, URL policies, malware protection, application controls, and other security measures according to organizational requirements. In an SSE architecture, SWG can deliver consistent web security to users working from offices, homes, or other locations. ZTNA focuses on private applications, CASB focuses on cloud services, and DLP protects sensitive information. Secure Web Gateway is therefore the most appropriate service for centralized control of internet-bound web traffic.
Question 157
Which security principle assumes that authentication alone is not sufficient to grant unrestricted access?
- Zero Trust
- Open network access
- Implicit trust
- Perimeter-only access
Correct Answer: 1
Explanation
Zero Trust does not consider authentication to be sufficient justification for unrestricted access. After a user’s identity is verified, policies can still evaluate device posture, application, resource, and other contextual information before allowing access. The user should receive only the resources that are explicitly authorized. Open network access and implicit trust assume broader access, while perimeter-only access relies heavily on network boundaries. Zero Trust therefore provides the security principle in which authentication is only one part of the overall access decision.
Question 158
Which feature can help organizations identify cloud applications that have not been officially approved?
- DHCP
- CASB
- NAT
- NTP
Correct Answer: 2
Explanation
CASB can provide visibility into cloud application usage and help organizations identify unsanctioned services. Discovering these applications allows security teams to assess risks related to data protection, compliance, and unauthorized cloud usage. Administrators can then establish policies to permit, monitor, restrict, or block applications according to organizational requirements. DHCP provides network configuration, NAT translates addresses, and NTP synchronizes time. CASB is therefore the appropriate technology for identifying cloud applications that have not been officially approved.
Question 159
Which capability can evaluate endpoint security status as part of a Zero Trust access decision?
- Web Filtering
- Application Control
- Device Posture
- DNS Filtering
Correct Answer: 3
Explanation
Device posture allows a security system to evaluate the condition and compliance state of an endpoint before granting access. A Zero Trust policy can use posture information alongside user identity and other contextual factors. Depending on the integration, posture checks may include endpoint protection status, operating system conditions, compliance state, or other required security attributes. Web Filtering controls website access, Application Control identifies applications, and DNS Filtering manages domain requests. Device Posture is therefore the capability most directly associated with endpoint security evaluation during access authorization.
Question 160
Which SSE architecture is designed to deliver security controls consistently to distributed and remote users?
- Cloud-delivered SSE
- Standalone DHCP
- Local-only switching
- Traditional storage architecture
Correct Answer: 1
Explanation
Cloud-delivered SSE provides centralized security services through cloud infrastructure and can protect users regardless of their physical location. Remote employees, branch users, and mobile workers can receive consistent security controls for web access, private applications, cloud services, and sensitive data. This reduces dependence on a traditional model where traffic must always return to a corporate data center for inspection. DHCP and switching provide networking functions, while storage architecture is unrelated to SSE. Cloud-delivered SSE is therefore designed to provide consistent security enforcement for distributed users.