Fortinet NSE5_SSE_AD-7.6 Practice Test Questions and Exam Dumps Part11 Q201-220

View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 201

Which FortiSASE capability is designed to provide policy-based access to private applications without exposing the entire internal network?

  1. Secure Web Gateway
  2. Zero Trust Network Access
  3. DNS Security
  4. Data Loss Prevention

Correct Answer: 2

Explanation

Zero Trust Network Access provides controlled access to private applications without requiring users to receive unrestricted access to the underlying network. Access decisions can be based on identity, authentication, device posture, and other policy conditions. This application-centric approach supports least privilege and reduces the attack surface associated with broad network connectivity. Secure Web Gateway primarily protects internet traffic, DNS Security focuses on domain requests, and DLP protects sensitive information. ZTNA is therefore the appropriate FortiSASE capability when users need secure access to specific internal applications.

Question 202

Which SSE service primarily inspects and controls traffic destined for internet websites?

  1. CASB
  2. DLP
  3. ZTNA
  4. Secure Web Gateway

Correct Answer: 4

Explanation

Secure Web Gateway is responsible for securing users’ web and internet traffic. It can enforce controls such as URL filtering, web category policies, malware protection, and application-based restrictions. In an SSE architecture, SWG provides a centralized policy enforcement point for users accessing public internet resources. CASB focuses on cloud applications, DLP focuses on sensitive information, and ZTNA controls access to private applications. Secure Web Gateway is therefore the most suitable service for inspecting and controlling internet-bound web traffic.

Question 203

Which capability is used to identify and protect sensitive data during supported traffic flows?

  1. Data Loss Prevention
  2. DNS Security
  3. Application Control
  4. ZTNA

Correct Answer: 1

Explanation

Data Loss Prevention is designed to identify sensitive information and apply security policies to prevent unauthorized disclosure. DLP can inspect supported traffic for configured patterns, rules, or classifications and then take actions such as allowing, blocking, logging, or alerting. This can help protect confidential business information, personally identifiable information, intellectual property, and other sensitive content. DNS Security protects domain requests, Application Control identifies applications, and ZTNA manages private application access. DLP is therefore the capability directly associated with sensitive-data protection.

Question 204

Which security technology provides visibility and policy control over cloud applications used by employees?

  1. DNS Security
  2. Secure Web Gateway
  3. CASB
  4. DHCP

Correct Answer: 3

Explanation

Cloud Access Security Broker provides visibility and security controls for cloud applications, including SaaS services. CASB can help organizations identify cloud applications in use, monitor activity, and enforce policies according to organizational requirements. This is useful for managing sanctioned and unsanctioned cloud services. DNS Security protects domain requests, SWG secures general web traffic, and DHCP provides network configuration. CASB is therefore the appropriate technology when administrators need visibility and policy control over employee use of cloud applications.

Question 205

Which principle requires access to be limited to only the applications and resources necessary for a user’s job?

  1. Zero trust perimeter
  2. Open access
  3. Implicit trust
  4. Least privilege

Correct Answer: 4

Explanation

Least privilege requires users to receive only the access needed to perform their authorized responsibilities. This principle reduces unnecessary exposure to applications, services, and data. In a Zero Trust architecture, least privilege can be implemented by authorizing access to specific applications instead of granting unrestricted network connectivity. Open access and implicit trust allow broader access than necessary, while a perimeter-only model does not itself define the required authorization level. Least privilege therefore provides the specific access-control principle described in the question.

Question 206

Which authentication factor is an example of something the user knows?

  1. Password
  2. Hardware token
  3. Fingerprint
  4. Security key

Correct Answer: 1

Explanation

A password is a knowledge-based authentication factor because it is something the user knows. Other knowledge factors can include PINs and security answers. A hardware token and security key normally represent possession factors because the user has them, while a fingerprint is a biometric factor representing something the user is. Combining different factor types creates multifactor authentication. Knowledge factors remain common in authentication systems, but combining them with possession or biometric factors can provide stronger protection against unauthorized access.

Question 207

Which capability can identify applications such as streaming, messaging, or file-sharing services for security policy enforcement?

  1. DNS Security
  2. Data Loss Prevention
  3. Application Control
  4. DHCP

Correct Answer: 3

Explanation

Application Control identifies applications within network traffic and enables administrators to create policies based on the detected application. This can be useful for controlling services such as streaming, messaging, file sharing, or other applications according to organizational requirements. Application-aware policies provide more granular control than relying solely on IP addresses or ports. DNS Security focuses on domain requests, DLP protects sensitive information, and DHCP provides network configuration. Application Control is therefore the appropriate capability for identifying applications and enforcing application-specific security policies.

Question 208

Which feature can use endpoint security information as part of a Zero Trust access decision?

  1. URL filtering
  2. Device posture
  3. DNS caching
  4. Traffic shaping

Correct Answer: 2

Explanation

Device posture provides information about the security and compliance state of an endpoint. A Zero Trust policy can use this information when determining whether a device should be allowed to access a protected application. Depending on the available integration, posture information may include endpoint protection status, operating system state, compliance information, or other security attributes. URL filtering manages websites, DNS caching stores domain-resolution information, and traffic shaping controls bandwidth. Device posture is therefore the capability that can contribute endpoint security information to an access decision.

Question 209

Which security function can block access when a requested domain is classified as malicious?

  1. CASB
  2. ZTNA
  3. DLP
  4. DNS Security

Correct Answer: 4

Explanation

DNS Security can inspect DNS requests and compare requested domains against security intelligence or configured policies. If a domain is associated with malware, phishing, command-and-control activity, or another prohibited category, the request can be blocked or redirected. This provides an early layer of protection against malicious destinations. CASB focuses on cloud applications, ZTNA controls private application access, and DLP protects sensitive information. DNS Security is therefore the appropriate function for blocking malicious domain requests before users establish connections to the destination.

Question 210

Which capability can apply different security policies based on the authenticated user’s group membership?

  1. Identity-based policy
  2. NAT
  3. Static routing
  4. DHCP

Correct Answer: 1

Explanation

Identity-based policies allow administrators to associate security rules with authenticated users, groups, roles, or other identity attributes. This enables organizations to create different access rules for different departments or roles. For example, administrators may give different website or application access to employees, contractors, and privileged users. NAT translates addresses, static routing determines fixed traffic paths, and DHCP provides network configuration. Identity-based policy is therefore the appropriate capability when security decisions need to reflect the authenticated user’s group or organizational role.

Question 211

Which SSE service is most appropriate for applying centralized web access controls to remote users?

  1. ZTNA
  2. CASB
  3. Secure Web Gateway
  4. DLP

Correct Answer: 3

Explanation

Secure Web Gateway provides centralized security controls for users accessing internet resources. Through a cloud-delivered SSE architecture, remote users can receive policies for URL filtering, web categories, malware protection, and application controls without needing to be physically located at a corporate site. ZTNA is focused on private applications, CASB focuses on cloud application security, and DLP protects sensitive information. SWG is therefore the most appropriate service for centralized web access control for remote and distributed users.

Question 212

Which capability can help an organization discover cloud applications that employees are using without formal approval?

  1. DLP
  2. CASB
  3. DNS Security
  4. ZTNA

Correct Answer: 2

Explanation

CASB can provide visibility into cloud application usage and help organizations identify unsanctioned services. This visibility is useful for detecting shadow IT and assessing the security or compliance risks of cloud applications that have not been formally approved. Once identified, administrators can decide whether applications should be monitored, permitted, restricted, or blocked according to organizational policy. DLP focuses on data protection, DNS Security protects domain requests, and ZTNA controls private application access. CASB is therefore the appropriate capability for discovering and managing unsanctioned cloud services.

Question 213

Which authentication factor is based on a physical characteristic of the user?

  1. Password
  2. PIN
  3. Hardware token
  4. Fingerprint

Correct Answer: 4

Explanation

A fingerprint is a biometric authentication factor and represents something the user is. Biometric factors are based on physical or behavioral characteristics and are commonly used as one component of multifactor authentication. Passwords and PINs are knowledge factors because the user knows them. A hardware token is a possession factor because the user has it. A fingerprint can therefore be combined with a password or token to provide multiple authentication factors and strengthen the overall identity-verification process.

Question 214

Which security principle prevents successful authentication from automatically granting access to every internal resource?

  1. Application-specific authorization
  2. Open network access
  3. Implicit trust
  4. Full network access

Correct Answer: 1

Explanation

Application-specific authorization limits users to the applications and resources explicitly permitted by policy. This supports Zero Trust by separating authentication from authorization and preventing a successful login from automatically providing broad network access. A user may authenticate successfully but still receive access only to specific applications required for their work. Open network access, implicit trust, and full network access provide broader permissions. Application-specific authorization therefore supports granular, least-privilege access and reduces unnecessary exposure of internal resources.

Question 215

Which capability is specifically designed to detect and control sensitive information being transmitted through monitored channels?

  1. DNS Security
  2. Application Control
  3. DLP
  4. ZTNA

Correct Answer: 3

Explanation

Data Loss Prevention is designed to detect sensitive information and apply policies governing its transmission. DLP can inspect supported traffic for predefined data patterns, rules, or classifications and take actions such as blocking, logging, or alerting. This helps organizations protect confidential information and reduce the risk of accidental or intentional data leakage. DNS Security protects domains, Application Control identifies applications, and ZTNA controls private application access. DLP is therefore the capability most directly responsible for identifying and controlling sensitive information in monitored traffic.

Question 216

Which component provides secure access to private applications without requiring users to receive broad network connectivity?

  1. CASB
  2. ZTNA
  3. Secure Web Gateway
  4. DNS Security

Correct Answer: 2

Explanation

ZTNA provides application-level access to private resources while avoiding broad network-level permissions. The user is authenticated and evaluated against configured policies before being allowed to access specific applications. This model supports least privilege and reduces the exposure of internal network resources. CASB focuses on cloud applications, Secure Web Gateway protects internet traffic, and DNS Security provides domain-level protection. ZTNA is therefore the appropriate component when private application access must be secure, controlled, and limited to explicitly authorized resources.

Question 217

Which SSE service can inspect web content and help prevent users from accessing malicious websites?

  1. Secure Web Gateway
  2. CASB
  3. DLP
  4. ZTNA

Correct Answer: 1

Explanation

Secure Web Gateway provides inspection and policy enforcement for web traffic. It can apply URL filtering, category controls, malware protection, and other security policies to help prevent users from reaching malicious or prohibited websites. SWG is suitable for protecting users who access public internet resources from offices, homes, or mobile locations. CASB manages cloud application security, DLP focuses on sensitive information, and ZTNA controls private application access. SWG is therefore the most appropriate SSE service for securing web content and website access.

Question 218

Which feature allows administrators to restrict applications according to their identity rather than only their destination IP address?

  1. DNS Filtering
  2. Application Control
  3. DHCP
  4. NTP

Correct Answer: 2

Explanation

Application Control identifies applications in network traffic and enables administrators to create rules based on those applications. This provides more precise control than using only destination IP addresses or traditional port-based rules. For example, administrators can allow or restrict specific application categories according to organizational policy. DNS Filtering focuses on domain requests, DHCP manages network configuration, and NTP synchronizes system time. Application Control is therefore the feature that enables administrators to enforce policies according to the actual application identified in traffic.

Question 219

Which SSE capability can protect users by preventing access to known malicious domains before the connection is established?

  1. DLP
  2. CASB
  3. DNS Security
  4. ZTNA

Correct Answer: 3

Explanation

DNS Security can evaluate domain-name requests before the user establishes a full connection to the destination. If the requested domain is known to be malicious or prohibited, the security policy can block or redirect the request. This can help prevent phishing, malware, and other threats at the DNS layer. DLP protects sensitive information, CASB manages cloud applications, and ZTNA controls private application access. DNS Security is therefore the capability that provides domain-level protection before access to a malicious destination is completed.

Question 220

Which security architecture combines cloud-delivered services such as SWG, ZTNA, CASB, and DLP for distributed users?

  1. Traditional LAN
  2. Security Service Edge
  3. Standalone DHCP
  4. Basic NAT

Correct Answer: 2

Explanation

Security Service Edge brings together multiple cloud-delivered security capabilities for users, applications, and data. Depending on the deployment, services can include Secure Web Gateway for web security, ZTNA for private application access, CASB for cloud application security, and DLP for sensitive-data protection. This architecture is designed for modern distributed environments where users may work from branch offices, homes, or mobile locations. Traditional LAN, standalone DHCP, and basic NAT provide networking functionality but do not represent the integrated cloud security model provided by SSE.