View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 261
Which SSE service provides application-specific access to private resources based on identity and device context?
- CASB
- Secure Web Gateway
- DLP
- ZTNA
Correct Answer: 4
Explanation
Zero Trust Network Access provides controlled access to private applications based on identity and contextual security information. ZTNA policies can evaluate user identity, authentication status, device posture, and other conditions before access is granted. Rather than providing broad network connectivity, ZTNA can limit users to the specific applications they are authorized to use. CASB focuses on cloud applications, Secure Web Gateway protects internet traffic, and DLP protects sensitive data. ZTNA is therefore the appropriate SSE service for identity-aware, application-specific access to private resources.
Question 262
Which SSE capability provides centralized inspection and control of internet-bound web traffic?
- Secure Web Gateway
- DLP
- ZTNA
- CASB
Correct Answer: 1
Explanation
Secure Web Gateway provides centralized security inspection and policy enforcement for users accessing internet resources. It can apply controls such as URL filtering, web categorization, malware protection, and application control. This allows organizations to enforce consistent web security policies for users regardless of their location. DLP focuses on sensitive information, ZTNA provides private application access, and CASB focuses on cloud application security. Secure Web Gateway is therefore the SSE capability most directly responsible for securing and controlling general web traffic.
Question 263
Which capability provides visibility into the cloud applications being used by an organization?
- DLP
- CASB
- DNS Security
- DHCP
Correct Answer: 2
Explanation
Cloud Access Security Broker provides visibility into cloud applications and can help administrators understand which SaaS services are being used. CASB can also support monitoring and policy enforcement for cloud applications, helping organizations identify unsanctioned services and manage cloud-related security risks. DLP focuses on sensitive information, DNS Security protects domain requests, and DHCP provides network configuration. CASB is therefore the appropriate capability when an organization needs visibility and control over cloud application usage.
Question 264
Which security capability is specifically designed to detect and control sensitive information leaving an organization?
- Application Control
- DNS Security
- DLP
- ZTNA
Correct Answer: 3
Explanation
Data Loss Prevention is designed to identify sensitive information and enforce policies that help prevent unauthorized disclosure. DLP can inspect supported traffic for configured patterns, classifications, or other indicators of protected information. When sensitive content is detected, the policy can allow, block, log, or generate an alert depending on configuration. Application Control identifies applications, DNS Security protects domain requests, and ZTNA controls access to private resources. DLP is therefore the security capability specifically focused on preventing sensitive information from leaving authorized environments.
Question 265
Which principle limits users to only the resources necessary to perform their assigned duties?
- Open access
- Full trust
- Least privilege
- Implicit trust
Correct Answer: 3
Explanation
Least privilege ensures that a user receives only the permissions and resources necessary to perform authorized tasks. This reduces unnecessary exposure and helps limit the potential impact of compromised accounts or endpoints. In a Zero Trust environment, least privilege can be implemented by allowing access to specific applications rather than giving users unrestricted network connectivity. Open access, full trust, and implicit trust allow broader permissions and do not follow this restrictive model. Least privilege is therefore an important principle for reducing unnecessary access while maintaining required business functionality.
Question 266
Which authentication factor represents something the user possesses?
- Password
- Hardware token
- PIN
- Fingerprint
Correct Answer: 2
Explanation
A hardware token is a possession factor because the user must possess the device or credential used during authentication. Passwords and PINs are knowledge factors because the user knows them, while a fingerprint is a biometric factor representing something the user is. Possession factors are commonly combined with other factor types when implementing multifactor authentication. This provides stronger protection because an attacker who obtains only a password may still be unable to authenticate without the additional possession factor.
Question 267
Which feature can identify the applications generating traffic and allow application-specific security policies?
- Application Control
- DHCP
- NTP
- NAT
Correct Answer: 1
Explanation
Application Control identifies applications within network traffic and enables administrators to create policies based on the detected application. This provides more granular visibility than relying only on IP addresses or network ports. Organizations can use application control to allow, block, monitor, or restrict applications such as streaming, messaging, file sharing, and other services. DHCP provides network configuration, NTP synchronizes time, and NAT performs address translation. Application Control is therefore the feature most directly associated with application-aware traffic identification and policy enforcement.
Question 268
Which service can block requests to known malicious domains?
- CASB
- DLP
- ZTNA
- DNS Security
Correct Answer: 4
Explanation
DNS Security can inspect DNS requests and compare requested domains against threat intelligence and configured policies. Domains associated with malware, phishing, command-and-control activity, or other prohibited content can be blocked or redirected. This can stop users from reaching malicious destinations before establishing a complete connection. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA controls private application access. DNS Security is therefore the appropriate service for preventing access to known malicious domains through DNS-layer policy enforcement.
Question 269
Which feature can restrict access to websites according to predefined categories?
- URL filtering
- DHCP
- NAT
- NTP
Correct Answer: 1
Explanation
URL filtering allows administrators to control website access using categories, specific URLs, reputation, and other configured policy conditions. Organizations can use it to restrict websites associated with malware, phishing, inappropriate content, or other prohibited categories. URL filtering is commonly implemented as part of Secure Web Gateway functionality. DHCP manages network configuration, NAT translates network addresses, and NTP synchronizes system time. URL filtering is therefore the appropriate feature when website access must be controlled according to predefined security categories.
Question 270
Which factor can be evaluated to determine whether an endpoint meets security requirements before access is granted?
- Monitor resolution
- Device posture
- Keyboard language
- Screen size
Correct Answer: 2
Explanation
Device posture represents the security and compliance state of an endpoint and can be used during Zero Trust access decisions. Depending on the integration, posture information can include endpoint protection status, operating system condition, compliance state, or other required security attributes. If the endpoint fails the defined requirements, access to protected resources can be restricted or denied. Monitor resolution, keyboard language, and screen size do not normally provide meaningful security context. Device posture is therefore the relevant factor for determining whether an endpoint meets access requirements.
Question 271
Which SSE architecture provides cloud-delivered security services for distributed users?
- Traditional LAN
- Security Service Edge
- Standalone DHCP
- Local-only routing
Correct Answer: 2
Explanation
Security Service Edge provides cloud-delivered security services for users and resources distributed across different locations. Depending on the deployment, SSE can include Secure Web Gateway, Zero Trust Network Access, CASB, DLP, and other security functions. This architecture is useful for remote workers, branches, and mobile users because security policies can be delivered and managed through cloud infrastructure. Traditional LAN, DHCP, and local routing provide networking capabilities but do not represent the integrated cloud security architecture described. SSE is therefore the appropriate architecture for distributed cloud-based security enforcement.
Question 272
Which capability can identify unsanctioned SaaS applications used by employees?
- DNS Security
- ZTNA
- CASB
- DLP
Correct Answer: 3
Explanation
CASB provides visibility into cloud application usage and can help identify unsanctioned or unapproved SaaS services. This visibility allows organizations to discover shadow IT and evaluate associated security, privacy, and compliance risks. After applications are identified, administrators can apply policies to allow, monitor, restrict, or block them according to organizational requirements. DNS Security protects domain requests, ZTNA controls private application access, and DLP protects sensitive data. CASB is therefore the appropriate capability for discovering and managing unsanctioned cloud applications.
Question 273
Which authentication method requires two or more authentication factors from different categories?
- Multifactor authentication
- Anonymous authentication
- Password-only authentication
- Guest access
Correct Answer: 1
Explanation
Multifactor authentication requires two or more authentication factors, generally from categories such as knowledge, possession, and inherence. A password combined with a hardware token or biometric factor is a common example. MFA strengthens account security because compromising one factor alone may not be enough to authenticate successfully. Anonymous authentication and guest access do not provide the same identity verification, while password-only authentication relies on a single factor. Multifactor authentication is therefore the appropriate method for combining different authentication factor types.
Question 274
Which SSE service can inspect web content and help prevent malicious downloads?
- CASB
- DLP
- Secure Web Gateway
- ZTNA
Correct Answer: 3
Explanation
Secure Web Gateway can inspect web traffic and apply security controls to websites and downloaded content. Depending on the enabled features, SWG can provide URL filtering, malware detection, category-based controls, and other protections against unsafe web resources. This helps protect users while they browse the internet or use web applications. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA provides private application access. Secure Web Gateway is therefore the appropriate service for inspecting web content and helping prevent malicious downloads.
Question 275
Which capability allows access policies to be associated with authenticated users or groups?
- Static routing
- Identity-based policy
- NAT
- DHCP
Correct Answer: 2
Explanation
Identity-based policies allow administrators to associate security controls with authenticated users, groups, roles, or other identity attributes. This enables different users or groups to receive different security policies based on their organizational responsibilities. For example, different web or application access rules can be applied to employees, contractors, and administrators. Static routing determines network paths, NAT performs address translation, and DHCP provides network configuration. Identity-based policy is therefore the appropriate capability for creating security rules according to authenticated user identity.
Question 276
Which capability can prevent confidential information from being uploaded to an unauthorized cloud service?
- DLP
- DNS Security
- Application Control
- DHCP
Correct Answer: 1
Explanation
DLP can identify sensitive information in supported traffic and enforce rules governing how that information is transferred. If a user attempts to upload confidential data to an unauthorized cloud service, DLP can detect the sensitive content and take an action such as blocking, logging, or alerting. DNS Security protects domain requests, Application Control identifies applications, and DHCP provides network configuration. DLP is therefore the capability most directly associated with preventing sensitive information from being transferred to unauthorized cloud destinations.
Question 277
Which SSE component controls access to private applications instead of providing broad network connectivity?
- CASB
- Secure Web Gateway
- ZTNA
- DLP
Correct Answer: 3
Explanation
ZTNA provides application-level access to private resources instead of granting broad network connectivity. A ZTNA policy can evaluate user identity, authentication status, device posture, and other contextual conditions before permitting access. This supports least privilege and reduces exposure of internal systems. CASB provides cloud application security, Secure Web Gateway protects internet traffic, and DLP protects sensitive information. ZTNA is therefore the SSE component designed to provide controlled access to private applications without automatically exposing the broader internal network.
Question 278
Which security control can evaluate DNS requests and enforce policies based on the requested domain?
- DNS Security
- CASB
- DLP
- ZTNA
Correct Answer: 1
Explanation
DNS Security evaluates DNS requests and applies security policies to requested domains. It can use threat intelligence, reputation information, and configured rules to block or redirect domains associated with malware, phishing, or other prohibited content. This provides an important security layer before the user establishes a full network connection to a destination. CASB manages cloud applications, DLP protects sensitive data, and ZTNA controls private application access. DNS Security is therefore the appropriate control for enforcing policies based on requested domains.
Question 279
Which security principle prevents users from automatically trusting a resource simply because it is located on an internal network?
- Open access
- Full trust
- Zero Trust
- Perimeter trust
Correct Answer: 3
Explanation
Zero Trust does not automatically trust users, devices, or resources based on network location. Instead, access decisions are based on explicit verification of identity and relevant security context. Policies can evaluate factors such as authentication, device posture, application, and user role before granting access. Open access and full trust provide broader assumptions of trust, while perimeter trust relies more heavily on the traditional network boundary. Zero Trust therefore provides the model in which internal location alone is not sufficient to establish trust.
Question 280
Which architecture combines web security, private application access, cloud application controls, and data protection through cloud-delivered services?
- Traditional LAN
- Basic NAT
- Standalone DHCP
- Security Service Edge
Correct Answer: 4
Explanation
Security Service Edge combines multiple cloud-delivered security capabilities for distributed users and applications. These capabilities can include Secure Web Gateway for web traffic, Zero Trust Network Access for private applications, CASB for cloud application security, and DLP for sensitive-data protection. SSE is designed to support users working from branch offices, homes, and mobile locations while maintaining centralized security policies. Traditional LAN, NAT, and DHCP provide networking functions but do not represent this integrated cloud security architecture. Security Service Edge is therefore the architecture described in the question.