View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 161
Which SSE capability provides controlled access to private applications based on authenticated identity and contextual information?
- DNS Security
- Secure Web Gateway
- Zero Trust Network Access
- DLP
Correct Answer: 3
Explanation
Zero Trust Network Access provides secure, application-level access to private resources after evaluating identity and other contextual information. A ZTNA policy can consider factors such as user identity, authentication status, device posture, and application requirements. Instead of providing broad network access, it can limit the user to only the applications explicitly authorized by policy. DNS Security focuses on domain requests, Secure Web Gateway protects internet traffic, and DLP protects sensitive information. ZTNA is therefore the appropriate SSE capability for secure, identity-aware access to private applications.
Question 162
Which SSE service is primarily used to secure and control users’ internet web traffic?
- Secure Web Gateway
- CASB
- DLP
- ZTNA
Correct Answer: 1
Explanation
Secure Web Gateway provides centralized security controls for users accessing internet websites and web applications. It can enforce URL filtering, web categories, malware protection, application controls, and other policies. SWG helps organizations apply consistent web security regardless of where users connect from. CASB is focused on cloud applications, DLP protects sensitive data, and ZTNA controls access to private applications. Secure Web Gateway is therefore the service most directly responsible for inspecting and controlling internet-bound web traffic.
Question 163
Which technology provides visibility and security controls for SaaS applications?
- DNS Security
- ZTNA
- DLP
- CASB
Correct Answer: 4
Explanation
Cloud Access Security Broker provides visibility, governance, and security controls for cloud applications such as SaaS services. CASB can help organizations discover applications, monitor usage, and enforce policies based on users, applications, or activities. It is useful for managing cloud adoption and identifying potentially unsanctioned services. DNS Security protects domain requests, ZTNA provides private application access, and DLP focuses on sensitive information. CASB is therefore the appropriate technology when security visibility and policy enforcement are required for SaaS applications.
Question 164
Which principle ensures that a user receives only the permissions needed for a specific task?
- Full trust
- Least privilege
- Open access
- Implicit trust
Correct Answer: 2
Explanation
Least privilege means granting users only the permissions and resources necessary to complete their authorized tasks. This principle is an important part of Zero Trust because it reduces unnecessary access and limits the potential impact of compromised credentials. A user who needs access to one application does not automatically receive access to unrelated systems. Full trust, open access, and implicit trust provide broader permissions and do not follow this restrictive security approach. Least privilege therefore helps organizations minimize exposure while still allowing users to perform their required duties.
Question 165
Which feature can detect sensitive information and apply actions such as blocking or alerting?
- Application Control
- DNS Security
- Secure Web Gateway
- Data Loss Prevention
Correct Answer: 4
Explanation
Data Loss Prevention can inspect supported traffic for sensitive information using configured patterns, rules, dictionaries, or classifications. When protected information is detected, the DLP policy can apply actions such as allowing, blocking, logging, or generating alerts. This helps prevent unauthorized disclosure of confidential business information, personal data, intellectual property, and other protected content. Application Control identifies applications, DNS Security protects domain requests, and Secure Web Gateway secures web traffic. DLP is therefore the capability designed specifically to identify and control sensitive information.
Question 166
Which feature can classify websites and enforce access policies according to their categories?
- Web filtering
- NAT
- DHCP
- NTP
Correct Answer: 1
Explanation
Web filtering allows administrators to classify websites and enforce access policies based on categories, reputation, or specific destinations. Organizations can use web filtering to block malicious, inappropriate, or unauthorized categories such as phishing, malware, or other restricted content. This capability is commonly provided as part of Secure Web Gateway services. NAT translates network addresses, DHCP provides network configuration, and NTP synchronizes system clocks. Web filtering is therefore the appropriate feature for controlling website access based on predefined categories.
Question 167
Which capability can identify the actual application generating network traffic?
- DNS Security
- Application Control
- DLP
- DHCP
Correct Answer: 2
Explanation
Application Control identifies applications in network traffic and allows administrators to create policies based on the detected application. This gives organizations better visibility than relying only on IP addresses or port numbers. Administrators can use this information to monitor, allow, block, or restrict applications according to security and acceptable-use requirements. DNS Security focuses on domain requests, DLP protects sensitive information, and DHCP provides network configuration. Application Control is therefore the appropriate capability for identifying the actual applications responsible for network traffic.
Question 168
Which authentication factor is an example of something the user possesses?
- Password
- PIN
- Security token
- Fingerprint
Correct Answer: 3
Explanation
A security token is a possession factor because it represents something the user has. Authentication factors are commonly divided into knowledge, possession, and inherence categories. Passwords and PINs are knowledge factors because they are information known by the user. A fingerprint is an inherence factor because it represents something the user is. A security token can be combined with a password or biometric factor to implement multifactor authentication and provide stronger protection against unauthorized access.
Question 169
Which service can protect users by blocking requests to domains associated with malware or phishing?
- DNS Security
- CASB
- ZTNA
- DLP
Correct Answer: 1
Explanation
DNS Security evaluates domain-name requests and can use threat intelligence or configured policies to determine whether a requested destination should be allowed. Domains associated with malware, phishing, command-and-control activity, or other prohibited content can be blocked or redirected. This provides protection before the user establishes a complete connection to a malicious destination. CASB manages cloud application security, ZTNA controls private application access, and DLP protects sensitive information. DNS Security is therefore the appropriate service for domain-level protection against malicious destinations.
Question 170
What is one purpose of integrating identity information with SSE security policies?
- Increase network storage
- Remove authentication
- Apply policies according to users or groups
- Disable endpoint security
Correct Answer: 3
Explanation
Identity integration allows security policies to be associated with authenticated users, groups, or roles. This provides more granular control than relying only on IP addresses or network locations. For example, administrators can create different web access or application access rules for employees, contractors, or administrators. Identity integration does not remove authentication, increase storage, or disable endpoint security. Its primary benefit is enabling security decisions to reflect who the user is and what group or role the user belongs to.
Question 171
Which SSE component provides application-level access to internal resources while following Zero Trust principles?
- CASB
- ZTNA
- SWG
- DNS Security
Correct Answer: 2
Explanation
ZTNA provides application-level access to private resources while following Zero Trust principles. Instead of allowing broad network connectivity, ZTNA can authorize access to specific applications after evaluating identity and security context. This reduces the exposure of internal resources and supports least-privilege access. CASB is focused on cloud applications, SWG secures internet web traffic, and DNS Security protects domain requests. ZTNA is therefore the appropriate SSE component for providing controlled access to internal applications without automatically exposing the wider network.
Question 172
Which capability can evaluate an endpoint’s security condition before allowing access to a protected application?
- Device posture
- URL filtering
- DNS caching
- Traffic shaping
Correct Answer: 1
Explanation
Device posture provides information about an endpoint’s security and compliance status. In a Zero Trust environment, access policies can evaluate this information alongside user identity and other contextual factors. A device may be denied or restricted if it does not satisfy the required security conditions. URL filtering controls website access, DNS caching stores domain information, and traffic shaping manages bandwidth. Device posture is therefore the capability most directly associated with determining whether an endpoint is sufficiently secure before granting access to a protected application.
Question 173
Which capability is responsible for identifying and protecting sensitive data in monitored traffic?
- ZTNA
- CASB
- DLP
- Application Control
Correct Answer: 3
Explanation
DLP identifies sensitive information in supported traffic and enforces policies designed to prevent unauthorized disclosure. Administrators can define patterns or classifications for information that needs protection and configure actions such as blocking, logging, or alerting. DLP can help protect confidential documents, personal data, intellectual property, and regulated information. ZTNA focuses on private application access, CASB manages cloud application security, and Application Control identifies applications. DLP is therefore the capability specifically responsible for sensitive-data detection and protection.
Question 174
Which SSE service can provide centralized control over web access for remote and mobile users?
- CASB
- Secure Web Gateway
- ZTNA
- DLP
Correct Answer: 2
Explanation
Secure Web Gateway provides centralized security controls for users accessing internet resources, including remote and mobile users. Through cloud-delivered SSE, users can receive consistent web filtering, malware protection, application control, and other policies regardless of their physical location. CASB focuses on cloud applications, ZTNA controls private application access, and DLP protects sensitive information. SWG is therefore the most appropriate SSE service for centrally controlling web access for distributed users.
Question 175
Which authentication factor is based on a physical characteristic of the user?
- Password
- PIN
- Hardware token
- Fingerprint
Correct Answer: 4
Explanation
A fingerprint is a biometric authentication factor and represents something the user is. Biometric factors are based on physical or behavioral characteristics of the individual. Passwords and PINs are knowledge factors because the user knows them, while a hardware token is a possession factor because the user has it. Organizations can combine a biometric factor with another factor to implement multifactor authentication. This approach can improve identity assurance and reduce the risk associated with compromised knowledge-based credentials.
Question 176
Which feature can discover cloud services that employees are accessing without approval?
- DLP
- CASB
- DNS Security
- ZTNA
Correct Answer: 2
Explanation
CASB can provide visibility into cloud application usage and help identify unsanctioned or unapproved services. Discovering these applications is important because they may introduce security, privacy, or compliance risks. Once identified, administrators can determine whether an application should be permitted, monitored, restricted, or blocked. DLP protects sensitive information, DNS Security protects domain requests, and ZTNA controls private application access. CASB is therefore the appropriate capability for discovering and managing cloud services that employees use without formal organizational approval.
Question 177
Which policy approach prevents an authenticated user from automatically receiving access to every internal system?
- Full network access
- Implicit trust
- Application-specific authorization
- Open VPN access
Correct Answer: 3
Explanation
Application-specific authorization restricts users to the particular applications and resources for which they have been explicitly authorized. This supports Zero Trust and least-privilege principles because successful authentication does not automatically provide unrestricted internal connectivity. A user can be granted access to one business application while being denied access to unrelated systems. Full network access, implicit trust, and open VPN access can provide broader connectivity. Application-specific authorization therefore provides more granular and controlled access to internal resources.
Question 178
Which service can inspect web traffic for unsafe content and malicious downloads?
- Secure Web Gateway
- CASB
- ZTNA
- DHCP
Correct Answer: 1
Explanation
Secure Web Gateway can inspect web traffic and apply security controls to websites and downloaded content. Depending on the enabled features, SWG can enforce URL filtering, detect malicious destinations, and inspect web-based content for threats. This protects users while they browse the internet and use web applications. CASB focuses on cloud application security, ZTNA controls private application access, and DHCP provides network configuration. Secure Web Gateway is therefore the service most directly associated with protecting users from unsafe websites and malicious web content.
Question 179
Which SSE capability can enforce policies based on the application detected in user traffic?
- DNS Security
- DLP
- Application Control
- NTP
Correct Answer: 3
Explanation
Application Control identifies applications in traffic and allows administrators to apply policies based on those applications. This enables organizations to control services such as streaming, file sharing, messaging, or other applications according to security and acceptable-use requirements. It provides application-aware visibility that is more granular than simply using IP addresses or ports. DNS Security protects domain requests, DLP focuses on sensitive information, and NTP synchronizes system time. Application Control is therefore the appropriate capability for applying security policies according to detected applications.
Question 180
Which architecture provides cloud-delivered security services to users regardless of their network location?
- Standalone DHCP
- Local-only firewall
- Traditional LAN
- Security Service Edge
Correct Answer: 4
Explanation
Security Service Edge delivers security capabilities from cloud infrastructure and is designed to protect distributed users regardless of their physical network location. Depending on the deployment, SSE can provide Secure Web Gateway, Zero Trust Network Access, CASB, DLP, and other security services. This architecture supports remote workers, branch users, and mobile users while maintaining centralized security policies. Standalone DHCP, local-only firewalls, and traditional LAN architectures do not provide the same integrated cloud-delivered security model. SSE is therefore the architecture described in the question.