View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 281
Which FortiSASE service is primarily used to secure access to private applications for remote users?
- CASB
- ZTNA
- DLP
- Secure Web Gateway
Correct Answer: 2
Explanation
Zero Trust Network Access provides secure, application-level access to private resources. It verifies the user’s identity and can evaluate contextual information such as device posture and authentication status before allowing access. Unlike traditional network access methods, ZTNA can limit a user to only the applications authorized by policy rather than providing broad internal network connectivity. CASB focuses on cloud applications, DLP protects sensitive data, and Secure Web Gateway protects internet traffic. ZTNA therefore provides the appropriate method for controlled remote access to private applications.
Question 282
Which SSE component is designed to provide visibility into cloud application usage?
- Secure Web Gateway
- DLP
- ZTNA
- CASB
Correct Answer: 4
Explanation
Cloud Access Security Broker provides visibility and control over cloud applications, including SaaS platforms. CASB can help organizations discover cloud services being used by employees, monitor application activity, and enforce policies based on organizational requirements. This is useful for identifying unsanctioned cloud applications and managing associated security risks. Secure Web Gateway primarily protects web traffic, DLP focuses on sensitive information, and ZTNA provides access to private applications. CASB is therefore the appropriate SSE component for cloud application visibility and governance.
Question 283
Which capability is designed to prevent sensitive information from being transferred outside approved channels?
- DLP
- DNS Security
- Application Control
- ZTNA
Correct Answer: 1
Explanation
Data Loss Prevention is designed to identify sensitive information and enforce rules controlling how that information is transmitted. DLP can inspect supported traffic for configured patterns, classifications, or other indicators of protected data. When a policy match occurs, the system can allow, block, log, or generate an alert depending on configuration. DNS Security protects domain requests, Application Control identifies applications, and ZTNA controls private application access. DLP is therefore the capability most directly associated with preventing sensitive information from leaving through unauthorized channels.
Question 284
Which SSE service provides centralized security controls for users accessing websites?
- CASB
- ZTNA
- Secure Web Gateway
- DLP
Correct Answer: 3
Explanation
Secure Web Gateway provides centralized inspection and policy enforcement for users accessing internet websites and web applications. It can support URL filtering, category-based controls, malware inspection, application control, and other web security policies. This allows organizations to apply consistent internet security controls regardless of the user’s location. CASB focuses on cloud applications, ZTNA manages private application access, and DLP protects sensitive information. Secure Web Gateway is therefore the appropriate SSE service for centralized control of general web access.
Question 285
Which security principle gives users only the permissions needed to perform their authorized tasks?
- Full trust
- Open access
- Implicit trust
- Least privilege
Correct Answer: 4
Explanation
Least privilege means granting users only the permissions and resources necessary for their authorized responsibilities. This principle reduces unnecessary exposure and limits the possible impact of compromised accounts or devices. In a Zero Trust environment, least privilege can be implemented by providing access to specific applications instead of granting unrestricted network access. Full trust, open access, and implicit trust allow broader permissions and do not follow this restrictive approach. Least privilege is therefore a core principle for reducing unnecessary access while maintaining required business functionality.
Question 286
Which feature identifies applications in network traffic for policy enforcement?
- DNS Security
- Application Control
- DHCP
- NTP
Correct Answer: 2
Explanation
Application Control identifies applications in network traffic and allows administrators to create policies based on the applications detected. This provides application-aware visibility and more granular control than relying only on IP addresses or port numbers. Organizations can use Application Control to monitor, allow, block, or restrict applications according to business and security requirements. DNS Security protects domain requests, DHCP provides network configuration, and NTP synchronizes system clocks. Application Control is therefore the appropriate feature for identifying applications and applying application-specific policies.
Question 287
Which information can be used by a Zero Trust policy to evaluate an endpoint before access is granted?
- Screen resolution
- Monitor manufacturer
- Device posture
- Keyboard layout
Correct Answer: 3
Explanation
Device posture provides information about the security and compliance state of an endpoint. A Zero Trust policy can use this information together with identity and other contextual conditions when making an access decision. Depending on the available integration, posture can include endpoint protection status, operating system condition, compliance state, or other security attributes. Screen resolution, monitor manufacturer, and keyboard layout do not normally provide meaningful security context. Device posture is therefore the relevant information for evaluating whether an endpoint satisfies access requirements.
Question 288
Which service can block access to domains associated with phishing or malware?
- DNS Security
- CASB
- DLP
- ZTNA
Correct Answer: 1
Explanation
DNS Security can inspect domain requests and apply threat intelligence or configured policies before users connect to a destination. If a requested domain is associated with phishing, malware, command-and-control activity, or another prohibited category, the request can be blocked or redirected. This provides an early layer of protection against malicious destinations. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA controls access to private applications. DNS Security is therefore the appropriate service for blocking malicious domains through DNS-level enforcement.
Question 289
Which authentication factor is an example of something the user is?
- Password
- Hardware token
- PIN
- Fingerprint
Correct Answer: 4
Explanation
A fingerprint is a biometric authentication factor and represents something the user is. Authentication factors are commonly grouped into knowledge, possession, and inherence categories. Passwords and PINs are knowledge factors because the user knows them, while a hardware token is a possession factor because the user has it. A fingerprint is based on a physical characteristic and therefore represents an inherence factor. Combining biometric authentication with another factor can provide multifactor authentication and stronger identity verification.
Question 290
Which feature can restrict website access according to URL categories?
- Application Control
- URL Filtering
- DHCP
- NAT
Correct Answer: 2
Explanation
URL Filtering allows administrators to control website access using URL categories, specific destinations, or reputation-based policies. Organizations can use it to block or allow categories such as malware, phishing, gambling, social media, or other content according to security requirements. URL Filtering is commonly provided through Secure Web Gateway functionality. Application Control identifies applications, DHCP provides network configuration, and NAT performs address translation. URL Filtering is therefore the appropriate feature for applying security policies based on website categories.
Question 291
Which security architecture combines multiple cloud-delivered services for web, application, and data protection?
- Security Service Edge
- Standalone DHCP
- Traditional LAN
- Basic routing
Correct Answer: 1
Explanation
Security Service Edge combines multiple cloud-delivered security capabilities to protect distributed users and resources. Depending on the deployment, SSE can include Secure Web Gateway for internet traffic, ZTNA for private applications, CASB for cloud application security, and DLP for sensitive-data protection. This architecture is useful for remote workers, branch offices, and mobile users because security policies can be centrally managed and delivered through cloud infrastructure. DHCP, traditional LANs, and basic routing provide networking functions but do not represent the integrated SSE security architecture.
Question 292
Which capability can identify unsanctioned cloud applications used by employees?
- DLP
- DNS Security
- CASB
- ZTNA
Correct Answer: 3
Explanation
CASB provides visibility into cloud application usage and can help organizations identify unsanctioned or unapproved SaaS services. This visibility can reveal shadow IT and help security teams evaluate application-related security, compliance, and data protection risks. Once applications are identified, administrators can apply policies to permit, monitor, restrict, or block them according to organizational requirements. DLP focuses on protecting sensitive information, DNS Security protects domain requests, and ZTNA controls private application access. CASB is therefore the appropriate capability for discovering and managing unapproved cloud applications.
Question 293
Which security function can generate an alert when sensitive information is detected?
- DLP
- DNS Security
- ZTNA
- DHCP
Correct Answer: 2
Explanation
Data Loss Prevention can detect sensitive information in supported traffic and trigger configured actions when policy conditions are met. These actions can include generating alerts, logging events, blocking transfers, or allowing the activity while recording it. DLP helps security teams identify potential data leakage involving confidential documents, personal information, intellectual property, or other protected content. DNS Security protects domain requests, ZTNA manages private application access, and DHCP provides network configuration. DLP is therefore the capability directly associated with identifying sensitive information and generating policy-based alerts.
Question 294
Which service provides controlled access to internal applications without granting unrestricted network access?
- Secure Web Gateway
- CASB
- DLP
- ZTNA
Correct Answer: 4
Explanation
ZTNA provides controlled access to private applications without requiring broad network-level connectivity. Before access is granted, the system can evaluate user identity, authentication status, device posture, and other policy conditions. This supports least privilege and reduces the exposure of internal systems. Secure Web Gateway is intended for internet traffic, CASB manages cloud application security, and DLP protects sensitive information. ZTNA is therefore the service most appropriate when users need access to specific internal applications without receiving unrestricted access to the broader network.
Question 295
Which capability allows administrators to associate policies with authenticated users and groups?
- Identity-based policy
- NAT
- DHCP
- Static routing
Correct Answer: 3
Explanation
Identity-based policy allows administrators to create security rules based on authenticated users, groups, roles, or other identity attributes. This provides more precise control than using only IP addresses or network locations. Different departments or user groups can receive different access permissions according to their responsibilities. NAT performs address translation, DHCP provides network configuration, and static routing determines fixed network paths. Identity-based policy is therefore the capability that enables security decisions to be associated directly with authenticated user identities and group membership.
Question 296
Which feature can protect users from malicious websites by inspecting web traffic?
- CASB
- Secure Web Gateway
- DLP
- ZTNA
Correct Answer: 4
Explanation
Secure Web Gateway inspects and controls web traffic and can apply protections against malicious or inappropriate websites. Depending on its configured services, SWG can provide URL filtering, web category controls, malware inspection, and application policies. This makes it an important part of an SSE architecture for users accessing internet resources. CASB focuses on cloud applications, DLP protects sensitive data, and ZTNA controls private application access. Secure Web Gateway is therefore the capability best suited to protecting users from malicious websites through web traffic inspection.
Question 297
Which authentication method uses multiple factor categories to strengthen account security?
- Anonymous authentication
- Guest access
- Password-only authentication
- Multifactor authentication
Correct Answer: 4
Explanation
Multifactor authentication combines two or more authentication factors, typically from categories such as knowledge, possession, and inherence. A password combined with a security token or fingerprint is a common example. MFA provides stronger protection because an attacker who compromises one factor may still be unable to authenticate without the additional factor. Anonymous authentication and guest access do not provide the same identity assurance, while password-only authentication relies on a single factor. Multifactor authentication is therefore the appropriate method for strengthening identity verification through multiple factors.
Question 298
Which capability can prevent a user from accessing a protected application when the endpoint fails required security checks?
- Device posture
- URL filtering
- DNS caching
- Traffic shaping
Correct Answer: 1
Explanation
Device posture can evaluate whether an endpoint meets defined security and compliance requirements. In a Zero Trust environment, the posture result can be included in the policy decision before access to a protected application is granted. If the endpoint does not satisfy required conditions, access can be restricted or denied. URL filtering controls website access, DNS caching stores domain-resolution information, and traffic shaping manages bandwidth. Device posture is therefore the capability most directly associated with enforcing endpoint security requirements during application access decisions.
Question 299
Which SSE component is responsible for security controls over cloud applications?
- ZTNA
- CASB
- Secure Web Gateway
- DNS Security
Correct Answer: 2
Explanation
CASB provides visibility and security controls for cloud applications such as SaaS services. It can help organizations discover cloud applications, monitor activity, and enforce policies based on users, applications, and other supported conditions. This is important for managing cloud usage and identifying potential risks from unsanctioned services. ZTNA focuses on private application access, Secure Web Gateway protects internet traffic, and DNS Security protects domain requests. CASB is therefore the SSE component most directly associated with cloud application security and governance.
Question 300
Which SSE capability provides centralized security enforcement for users accessing internet resources from remote locations?
- DLP
- Secure Web Gateway
- CASB
- ZTNA
Correct Answer: 3
Explanation
Secure Web Gateway provides centralized security policies for users accessing internet resources, including users working remotely or from branch locations. It can enforce web filtering, URL policies, malware protection, application controls, and other security requirements through cloud-delivered SSE services. DLP focuses on sensitive data, CASB focuses on cloud applications, and ZTNA controls private application access. Secure Web Gateway is therefore the capability most directly responsible for centralized internet security enforcement for distributed users.