Fortinet NSE5_SSE_AD-7.6 Practice Test Questions and Exam Dumps Part14 Q261-280

View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 261

Which SSE service provides application-specific access to private resources based on identity and device context?

  1. CASB
  2. Secure Web Gateway
  3. DLP
  4. ZTNA

Correct Answer: 4

Explanation

Zero Trust Network Access provides controlled access to private applications based on identity and contextual security information. ZTNA policies can evaluate user identity, authentication status, device posture, and other conditions before access is granted. Rather than providing broad network connectivity, ZTNA can limit users to the specific applications they are authorized to use. CASB focuses on cloud applications, Secure Web Gateway protects internet traffic, and DLP protects sensitive data. ZTNA is therefore the appropriate SSE service for identity-aware, application-specific access to private resources.

Question 262

Which SSE capability provides centralized inspection and control of internet-bound web traffic?

  1. Secure Web Gateway
  2. DLP
  3. ZTNA
  4. CASB

Correct Answer: 1

Explanation

Secure Web Gateway provides centralized security inspection and policy enforcement for users accessing internet resources. It can apply controls such as URL filtering, web categorization, malware protection, and application control. This allows organizations to enforce consistent web security policies for users regardless of their location. DLP focuses on sensitive information, ZTNA provides private application access, and CASB focuses on cloud application security. Secure Web Gateway is therefore the SSE capability most directly responsible for securing and controlling general web traffic.

Question 263

Which capability provides visibility into the cloud applications being used by an organization?

  1. DLP
  2. CASB
  3. DNS Security
  4. DHCP

Correct Answer: 2

Explanation

Cloud Access Security Broker provides visibility into cloud applications and can help administrators understand which SaaS services are being used. CASB can also support monitoring and policy enforcement for cloud applications, helping organizations identify unsanctioned services and manage cloud-related security risks. DLP focuses on sensitive information, DNS Security protects domain requests, and DHCP provides network configuration. CASB is therefore the appropriate capability when an organization needs visibility and control over cloud application usage.

Question 264

Which security capability is specifically designed to detect and control sensitive information leaving an organization?

  1. Application Control
  2. DNS Security
  3. DLP
  4. ZTNA

Correct Answer: 3

Explanation

Data Loss Prevention is designed to identify sensitive information and enforce policies that help prevent unauthorized disclosure. DLP can inspect supported traffic for configured patterns, classifications, or other indicators of protected information. When sensitive content is detected, the policy can allow, block, log, or generate an alert depending on configuration. Application Control identifies applications, DNS Security protects domain requests, and ZTNA controls access to private resources. DLP is therefore the security capability specifically focused on preventing sensitive information from leaving authorized environments.

Question 265

Which principle limits users to only the resources necessary to perform their assigned duties?

  1. Open access
  2. Full trust
  3. Least privilege
  4. Implicit trust

Correct Answer: 3

Explanation

Least privilege ensures that a user receives only the permissions and resources necessary to perform authorized tasks. This reduces unnecessary exposure and helps limit the potential impact of compromised accounts or endpoints. In a Zero Trust environment, least privilege can be implemented by allowing access to specific applications rather than giving users unrestricted network connectivity. Open access, full trust, and implicit trust allow broader permissions and do not follow this restrictive model. Least privilege is therefore an important principle for reducing unnecessary access while maintaining required business functionality.

Question 266

Which authentication factor represents something the user possesses?

  1. Password
  2. Hardware token
  3. PIN
  4. Fingerprint

Correct Answer: 2

Explanation

A hardware token is a possession factor because the user must possess the device or credential used during authentication. Passwords and PINs are knowledge factors because the user knows them, while a fingerprint is a biometric factor representing something the user is. Possession factors are commonly combined with other factor types when implementing multifactor authentication. This provides stronger protection because an attacker who obtains only a password may still be unable to authenticate without the additional possession factor.

Question 267

Which feature can identify the applications generating traffic and allow application-specific security policies?

  1. Application Control
  2. DHCP
  3. NTP
  4. NAT

Correct Answer: 1

Explanation

Application Control identifies applications within network traffic and enables administrators to create policies based on the detected application. This provides more granular visibility than relying only on IP addresses or network ports. Organizations can use application control to allow, block, monitor, or restrict applications such as streaming, messaging, file sharing, and other services. DHCP provides network configuration, NTP synchronizes time, and NAT performs address translation. Application Control is therefore the feature most directly associated with application-aware traffic identification and policy enforcement.

Question 268

Which service can block requests to known malicious domains?

  1. CASB
  2. DLP
  3. ZTNA
  4. DNS Security

Correct Answer: 4

Explanation

DNS Security can inspect DNS requests and compare requested domains against threat intelligence and configured policies. Domains associated with malware, phishing, command-and-control activity, or other prohibited content can be blocked or redirected. This can stop users from reaching malicious destinations before establishing a complete connection. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA controls private application access. DNS Security is therefore the appropriate service for preventing access to known malicious domains through DNS-layer policy enforcement.

Question 269

Which feature can restrict access to websites according to predefined categories?

  1. URL filtering
  2. DHCP
  3. NAT
  4. NTP

Correct Answer: 1

Explanation

URL filtering allows administrators to control website access using categories, specific URLs, reputation, and other configured policy conditions. Organizations can use it to restrict websites associated with malware, phishing, inappropriate content, or other prohibited categories. URL filtering is commonly implemented as part of Secure Web Gateway functionality. DHCP manages network configuration, NAT translates network addresses, and NTP synchronizes system time. URL filtering is therefore the appropriate feature when website access must be controlled according to predefined security categories.

Question 270

Which factor can be evaluated to determine whether an endpoint meets security requirements before access is granted?

  1. Monitor resolution
  2. Device posture
  3. Keyboard language
  4. Screen size

Correct Answer: 2

Explanation

Device posture represents the security and compliance state of an endpoint and can be used during Zero Trust access decisions. Depending on the integration, posture information can include endpoint protection status, operating system condition, compliance state, or other required security attributes. If the endpoint fails the defined requirements, access to protected resources can be restricted or denied. Monitor resolution, keyboard language, and screen size do not normally provide meaningful security context. Device posture is therefore the relevant factor for determining whether an endpoint meets access requirements.

Question 271

Which SSE architecture provides cloud-delivered security services for distributed users?

  1. Traditional LAN
  2. Security Service Edge
  3. Standalone DHCP
  4. Local-only routing

Correct Answer: 2

Explanation

Security Service Edge provides cloud-delivered security services for users and resources distributed across different locations. Depending on the deployment, SSE can include Secure Web Gateway, Zero Trust Network Access, CASB, DLP, and other security functions. This architecture is useful for remote workers, branches, and mobile users because security policies can be delivered and managed through cloud infrastructure. Traditional LAN, DHCP, and local routing provide networking capabilities but do not represent the integrated cloud security architecture described. SSE is therefore the appropriate architecture for distributed cloud-based security enforcement.

Question 272

Which capability can identify unsanctioned SaaS applications used by employees?

  1. DNS Security
  2. ZTNA
  3. CASB
  4. DLP

Correct Answer: 3

Explanation

CASB provides visibility into cloud application usage and can help identify unsanctioned or unapproved SaaS services. This visibility allows organizations to discover shadow IT and evaluate associated security, privacy, and compliance risks. After applications are identified, administrators can apply policies to allow, monitor, restrict, or block them according to organizational requirements. DNS Security protects domain requests, ZTNA controls private application access, and DLP protects sensitive data. CASB is therefore the appropriate capability for discovering and managing unsanctioned cloud applications.

Question 273

Which authentication method requires two or more authentication factors from different categories?

  1. Multifactor authentication
  2. Anonymous authentication
  3. Password-only authentication
  4. Guest access

Correct Answer: 1

Explanation

Multifactor authentication requires two or more authentication factors, generally from categories such as knowledge, possession, and inherence. A password combined with a hardware token or biometric factor is a common example. MFA strengthens account security because compromising one factor alone may not be enough to authenticate successfully. Anonymous authentication and guest access do not provide the same identity verification, while password-only authentication relies on a single factor. Multifactor authentication is therefore the appropriate method for combining different authentication factor types.

Question 274

Which SSE service can inspect web content and help prevent malicious downloads?

  1. CASB
  2. DLP
  3. Secure Web Gateway
  4. ZTNA

Correct Answer: 3

Explanation

Secure Web Gateway can inspect web traffic and apply security controls to websites and downloaded content. Depending on the enabled features, SWG can provide URL filtering, malware detection, category-based controls, and other protections against unsafe web resources. This helps protect users while they browse the internet or use web applications. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA provides private application access. Secure Web Gateway is therefore the appropriate service for inspecting web content and helping prevent malicious downloads.

Question 275

Which capability allows access policies to be associated with authenticated users or groups?

  1. Static routing
  2. Identity-based policy
  3. NAT
  4. DHCP

Correct Answer: 2

Explanation

Identity-based policies allow administrators to associate security controls with authenticated users, groups, roles, or other identity attributes. This enables different users or groups to receive different security policies based on their organizational responsibilities. For example, different web or application access rules can be applied to employees, contractors, and administrators. Static routing determines network paths, NAT performs address translation, and DHCP provides network configuration. Identity-based policy is therefore the appropriate capability for creating security rules according to authenticated user identity.

Question 276

Which capability can prevent confidential information from being uploaded to an unauthorized cloud service?

  1. DLP
  2. DNS Security
  3. Application Control
  4. DHCP

Correct Answer: 1

Explanation

DLP can identify sensitive information in supported traffic and enforce rules governing how that information is transferred. If a user attempts to upload confidential data to an unauthorized cloud service, DLP can detect the sensitive content and take an action such as blocking, logging, or alerting. DNS Security protects domain requests, Application Control identifies applications, and DHCP provides network configuration. DLP is therefore the capability most directly associated with preventing sensitive information from being transferred to unauthorized cloud destinations.

Question 277

Which SSE component controls access to private applications instead of providing broad network connectivity?

  1. CASB
  2. Secure Web Gateway
  3. ZTNA
  4. DLP

Correct Answer: 3

Explanation

ZTNA provides application-level access to private resources instead of granting broad network connectivity. A ZTNA policy can evaluate user identity, authentication status, device posture, and other contextual conditions before permitting access. This supports least privilege and reduces exposure of internal systems. CASB provides cloud application security, Secure Web Gateway protects internet traffic, and DLP protects sensitive information. ZTNA is therefore the SSE component designed to provide controlled access to private applications without automatically exposing the broader internal network.

Question 278

Which security control can evaluate DNS requests and enforce policies based on the requested domain?

  1. DNS Security
  2. CASB
  3. DLP
  4. ZTNA

Correct Answer: 1

Explanation

DNS Security evaluates DNS requests and applies security policies to requested domains. It can use threat intelligence, reputation information, and configured rules to block or redirect domains associated with malware, phishing, or other prohibited content. This provides an important security layer before the user establishes a full network connection to a destination. CASB manages cloud applications, DLP protects sensitive data, and ZTNA controls private application access. DNS Security is therefore the appropriate control for enforcing policies based on requested domains.

Question 279

Which security principle prevents users from automatically trusting a resource simply because it is located on an internal network?

  1. Open access
  2. Full trust
  3. Zero Trust
  4. Perimeter trust

Correct Answer: 3

Explanation

Zero Trust does not automatically trust users, devices, or resources based on network location. Instead, access decisions are based on explicit verification of identity and relevant security context. Policies can evaluate factors such as authentication, device posture, application, and user role before granting access. Open access and full trust provide broader assumptions of trust, while perimeter trust relies more heavily on the traditional network boundary. Zero Trust therefore provides the model in which internal location alone is not sufficient to establish trust.

Question 280

Which architecture combines web security, private application access, cloud application controls, and data protection through cloud-delivered services?

  1. Traditional LAN
  2. Basic NAT
  3. Standalone DHCP
  4. Security Service Edge

Correct Answer: 4

Explanation

Security Service Edge combines multiple cloud-delivered security capabilities for distributed users and applications. These capabilities can include Secure Web Gateway for web traffic, Zero Trust Network Access for private applications, CASB for cloud application security, and DLP for sensitive-data protection. SSE is designed to support users working from branch offices, homes, and mobile locations while maintaining centralized security policies. Traditional LAN, NAT, and DHCP provide networking functions but do not represent this integrated cloud security architecture. Security Service Edge is therefore the architecture described in the question.