View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 301
Which SSE capability provides secure access to private applications based on user identity and security context?
- DLP
- CASB
- ZTNA
- Secure Web Gateway
Correct Answer: 3
Explanation
Zero Trust Network Access provides controlled access to private applications based on authenticated identity and relevant contextual information. A ZTNA policy can evaluate factors such as user identity, authentication status, device posture, and application requirements before granting access. This differs from traditional network access, where successful authentication may provide broad connectivity. ZTNA supports least-privilege access by limiting users to applications explicitly authorized by policy. DLP focuses on sensitive information, CASB manages cloud application security, and Secure Web Gateway protects internet traffic. ZTNA is therefore the appropriate SSE capability for secure private application access.
Question 302
Which capability allows administrators to associate security policies with specific users or groups?
- Identity-based policy
- NAT
- DHCP
- Static routing
Correct Answer: 1
Explanation
Identity-based policies allow administrators to apply security controls according to authenticated users, groups, roles, or other identity attributes. This provides more granular control than relying only on IP addresses or network locations. For example, different departments can receive different web access or application access policies. NAT translates network addresses, DHCP provides network configuration, and static routing determines fixed traffic paths. Identity-based policy is therefore the appropriate capability when security decisions need to reflect the authenticated identity or group membership of a user.
Question 303
Which SSE service provides visibility and control for cloud applications such as SaaS platforms?
- DNS Security
- DLP
- Secure Web Gateway
- CASB
Correct Answer: 4
Explanation
Cloud Access Security Broker provides security visibility, governance, and policy controls for cloud applications such as SaaS services. CASB can help organizations discover applications being used, monitor activity, and enforce policies based on users, applications, or actions. This is valuable for managing cloud adoption and identifying unsanctioned services. DNS Security focuses on domain requests, DLP protects sensitive information, and Secure Web Gateway controls general web traffic. CASB is therefore the capability most directly associated with cloud application security and governance.
Question 304
Which authentication factor represents something the user knows?
- Fingerprint
- Password
- Hardware token
- Security key
Correct Answer: 2
Explanation
A password is a knowledge factor because it represents information that the user knows. Authentication factors are generally categorized as knowledge, possession, and inherence. Fingerprints are biometric factors representing something the user is, while hardware tokens and security keys typically represent something the user possesses. Passwords are widely used for authentication, but organizations often combine them with other factor types through multifactor authentication. Combining knowledge with possession or biometric factors can provide stronger authentication than relying on a password alone.
Question 305
Which capability can identify applications in network traffic and apply policies according to the detected application?
- DNS Security
- DHCP
- Application Control
- NTP
Correct Answer: 3
Explanation
Application Control identifies applications within network traffic and enables administrators to create application-specific policies. This provides more granular visibility and control than relying solely on IP addresses or traditional port numbers. Organizations can use application control to allow, block, monitor, or restrict services such as streaming, file sharing, messaging, or other applications. DNS Security protects domain requests, DHCP provides network configuration, and NTP synchronizes time. Application Control is therefore the appropriate capability for identifying applications and enforcing security policies based on application identity.
Question 306
Which feature can protect users by blocking requests to domains known to be malicious?
- DNS Security
- CASB
- DLP
- ZTNA
Correct Answer: 4
Explanation
DNS Security evaluates domain-name requests and applies security policies before users establish full connections to destinations. If a requested domain is associated with malware, phishing, command-and-control activity, or another prohibited category, the request can be blocked or redirected. This provides an important preventive security layer at the DNS level. CASB manages cloud applications, DLP protects sensitive information, and ZTNA controls private application access. DNS Security is therefore the appropriate capability for blocking requests to known malicious domains.
Question 307
Which principle limits users to only the resources required for their assigned responsibilities?
- Least privilege
- Open access
- Full trust
- Implicit trust
Correct Answer: 1
Explanation
Least privilege ensures that users receive only the permissions and resources necessary to perform their authorized duties. This reduces unnecessary access and limits the potential impact if a user’s credentials or endpoint are compromised. In a Zero Trust environment, least privilege can be implemented by authorizing access to specific applications rather than providing broad network connectivity. Open access, full trust, and implicit trust allow broader permissions and do not provide the same restrictive control. Least privilege is therefore a core principle for minimizing unnecessary exposure.
Question 308
Which SSE service primarily inspects and controls internet web traffic?
- DLP
- Secure Web Gateway
- CASB
- ZTNA
Correct Answer: 2
Explanation
Secure Web Gateway provides centralized inspection and security policy enforcement for internet-bound web traffic. It can support features such as URL filtering, web category controls, malware protection, and application policies. SWG allows organizations to maintain consistent web security for users working from offices, homes, or other locations. DLP protects sensitive data, CASB focuses on cloud applications, and ZTNA controls private application access. Secure Web Gateway is therefore the service most directly responsible for securing and controlling general internet web traffic.
Question 309
Which capability can evaluate an endpoint’s security state before granting access to a protected application?
- URL filtering
- DNS caching
- Traffic shaping
- Device posture
Correct Answer: 4
Explanation
Device posture represents the security and compliance condition of an endpoint. Zero Trust policies can evaluate posture information along with user identity and other contextual factors before allowing access to protected applications. Depending on the integration, posture can include endpoint security status, operating system conditions, compliance state, and other attributes. URL filtering controls websites, DNS caching stores resolution information, and traffic shaping manages bandwidth. Device posture is therefore the relevant capability for determining whether an endpoint satisfies the required security conditions.
Question 310
Which capability is specifically designed to detect sensitive information and control its transmission?
- DLP
- ZTNA
- Application Control
- DNS Security
Correct Answer: 1
Explanation
Data Loss Prevention is designed to identify sensitive information within supported traffic and enforce policies around its transmission. DLP can use configured patterns, rules, dictionaries, or classifications to identify protected content. When a policy match occurs, the system can allow, block, log, or generate an alert depending on the configuration. ZTNA controls private application access, Application Control identifies applications, and DNS Security protects domain requests. DLP is therefore the SSE capability most directly associated with detecting sensitive information and preventing unauthorized data transfer.
Question 311
Which authentication factor is an example of something the user possesses?
- PIN
- Password
- Hardware token
- Fingerprint
Correct Answer: 3
Explanation
A hardware token is a possession factor because it is something the user has. Authentication factors are commonly categorized as knowledge, possession, and inherence. Passwords and PINs are knowledge factors because the user knows them, while a fingerprint is a biometric factor representing something the user is. A hardware token can be combined with a password or biometric factor to create multifactor authentication. Using multiple factor types provides stronger protection because an attacker generally needs more than one credential or characteristic to successfully authenticate.
Question 312
Which feature can block websites according to categories such as phishing, malware, or inappropriate content?
- CASB
- URL filtering
- DLP
- ZTNA
Correct Answer: 2
Explanation
URL filtering allows administrators to control access to websites according to categories, specific URLs, reputation, or other configured conditions. Organizations can use it to block malicious, phishing-related, inappropriate, or otherwise restricted web destinations. URL filtering is commonly delivered through Secure Web Gateway functionality and can be applied consistently to users through centralized policies. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA provides private application access. URL filtering is therefore the appropriate feature for enforcing category-based website restrictions.
Question 313
Which SSE architecture delivers cloud-based security controls to distributed users and locations?
- Security Service Edge
- Traditional LAN
- Standalone DHCP
- Local-only routing
Correct Answer: 1
Explanation
Security Service Edge provides cloud-delivered security services for distributed users and applications. Depending on the deployment, SSE can include Secure Web Gateway for internet protection, Zero Trust Network Access for private applications, CASB for cloud application security, and DLP for data protection. This architecture supports users working from remote locations, branch offices, and mobile environments. Traditional LAN, DHCP, and local routing provide networking functions but do not represent the integrated cloud security architecture described. SSE therefore provides the appropriate model for centralized security enforcement across distributed environments.
Question 314
Which capability can identify cloud applications that employees are using without formal approval?
- CASB
- DNS Security
- ZTNA
- DLP
Correct Answer: 4
Explanation
CASB provides visibility into cloud application usage and can help organizations discover unsanctioned or unapproved SaaS services. This can reveal shadow IT and allow administrators to assess security, privacy, and compliance risks. Once applications are identified, administrators can determine whether they should be monitored, permitted, restricted, or blocked according to organizational policy. DNS Security protects domain requests, ZTNA controls private applications, and DLP protects sensitive information. CASB is therefore the appropriate capability for discovering and managing unauthorized cloud application usage.
Question 315
Which Zero Trust concept requires a user to receive only the access explicitly authorized by policy?
- Full network trust
- Open access
- Perimeter trust
- Least privilege
Correct Answer: 2
Explanation
Least privilege ensures that users receive only the access required for authorized tasks and resources. In Zero Trust environments, this means authentication does not automatically provide unrestricted network access. Instead, access can be limited to specific applications based on identity, device posture, and other policy conditions. Full network trust and open access provide broader permissions, while perimeter trust relies more heavily on network location. Least privilege is therefore the principle that most directly supports explicit and restricted access according to policy.
Question 316
Which SSE service provides centralized inspection for users accessing internet websites from remote locations?
- DLP
- CASB
- Secure Web Gateway
- ZTNA
Correct Answer: 3
Explanation
Secure Web Gateway provides centralized security inspection and policy enforcement for internet-bound traffic. In a cloud-delivered SSE environment, users can receive consistent controls for URL filtering, web categories, malware protection, and application policies regardless of where they are connecting from. DLP focuses on sensitive information, CASB manages cloud application security, and ZTNA provides access to private applications. SWG is therefore the appropriate SSE service for centrally securing web access for remote, mobile, and distributed users.
Question 317
Which capability can generate an alert when protected information is detected in monitored traffic?
- DLP
- DNS Security
- CASB
- Application Control
Correct Answer: 1
Explanation
DLP can inspect supported traffic for sensitive information and trigger configured actions when policy conditions are met. These actions can include alerting administrators, logging the event, blocking the transfer, or allowing it while recording the activity. This helps security teams identify potential data leakage and investigate incidents involving confidential or regulated information. DNS Security protects domain requests, CASB focuses on cloud applications, and Application Control identifies applications. DLP is therefore the appropriate capability for detecting protected information and generating policy-based security alerts.
Question 318
Which authentication method requires two or more independent authentication factors?
- Password-only authentication
- Multifactor authentication
- Guest access
- Anonymous access
Correct Answer: 2
Explanation
Multifactor authentication requires two or more authentication factors, normally from different categories such as knowledge, possession, and inherence. A password combined with a hardware token or fingerprint is a common example. MFA provides stronger protection because compromising one factor alone may not be enough to gain access. Password-only authentication uses a single factor, while guest and anonymous access do not provide equivalent identity assurance. Multifactor authentication is therefore the appropriate method when multiple independent authentication factors are required.
Question 319
Which SSE component provides application-level access to internal resources without requiring broad network connectivity?
- CASB
- Secure Web Gateway
- DLP
- ZTNA
Correct Answer: 4
Explanation
ZTNA provides controlled, application-specific access to private resources. Rather than placing a user on the internal network with broad connectivity, ZTNA evaluates identity, authentication, device posture, and other contextual conditions before allowing access to specific applications. This supports least privilege and reduces exposure of unrelated internal systems. CASB focuses on cloud applications, Secure Web Gateway protects internet traffic, and DLP protects sensitive information. ZTNA is therefore the appropriate SSE component when internal application access needs to be secure, granular, and policy-driven.
Question 320
Which capability allows administrators to enforce different security rules based on user identity or group membership?
- NAT
- Identity-based policy
- DHCP
- Static routing
Correct Answer: 2
Explanation
Identity-based policies associate security rules with authenticated users, groups, roles, or other identity information. This allows administrators to apply different access controls according to organizational responsibilities. For example, employees, contractors, and administrators can receive different web or application access policies. NAT performs address translation, DHCP provides network configuration, and static routing determines fixed network paths. Identity-based policy is therefore the appropriate capability for enforcing security rules that depend on the authenticated identity or group membership of the user.