View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 321
Which FortiSASE capability provides policy-based access to private applications without granting full network-level access?
- Secure Web Gateway
- CASB
- ZTNA
- DLP
Correct Answer: 3
Explanation
Zero Trust Network Access provides controlled access to private applications based on configured security policies. Instead of connecting a user broadly to an internal network, ZTNA can authorize access to specific applications after evaluating identity, authentication, device posture, and other contextual information. This supports the principle of least privilege and reduces exposure of internal resources. Secure Web Gateway protects internet traffic, CASB focuses on cloud applications, and DLP protects sensitive information. ZTNA is therefore the appropriate capability when users need secure access to private applications without receiving unrestricted network connectivity.
Question 322
Which feature allows administrators to create web access rules based on user identity?
- Identity-based policy
- NAT
- DHCP
- Static routing
Correct Answer: 1
Explanation
Identity-based policies allow administrators to associate security rules with authenticated users, groups, or roles. This makes it possible to apply different web access policies to different users based on their organizational responsibilities. For example, employees, contractors, and administrators can receive separate security controls. NAT translates network addresses, DHCP provides network configuration, and static routing defines fixed traffic paths. Identity-based policy is therefore the appropriate feature when web access rules need to be based on who the user is rather than only on the user’s network address.
Question 323
Which SSE capability provides security visibility into cloud applications and SaaS services?
- DLP
- DNS Security
- Secure Web Gateway
- CASB
Correct Answer: 4
Explanation
Cloud Access Security Broker provides visibility, governance, and security controls for cloud applications. CASB can help identify cloud services being used, monitor application activity, and enforce policies according to organizational requirements. It is particularly useful for identifying unsanctioned SaaS applications and managing cloud-related security risks. DLP focuses on sensitive information, DNS Security protects domain requests, and Secure Web Gateway protects general web traffic. CASB is therefore the capability most directly associated with cloud application visibility and policy enforcement.
Question 324
Which authentication factor is an example of something the user knows?
- Password
- Hardware token
- Fingerprint
- Security key
Correct Answer: 1
Explanation
A password is a knowledge-based authentication factor because it is something the user knows. Authentication factors are generally categorized as knowledge, possession, and inherence. Hardware tokens and security keys typically represent possession factors because the user has them, while fingerprints are biometric factors representing something the user is. A password can be combined with another factor to provide multifactor authentication. Using multiple authentication categories strengthens security because compromising a single factor may not provide enough information to gain access.
Question 325
Which capability can identify applications in traffic so that administrators can apply application-specific security policies?
- DHCP
- NTP
- Application Control
- DNS caching
Correct Answer: 3
Explanation
Application Control identifies applications within network traffic and enables administrators to apply policies based on the detected application. This provides application-aware visibility and can be used to allow, block, monitor, or restrict services according to organizational requirements. Application Control is useful for managing applications such as streaming, messaging, file sharing, and other services. DHCP provides network configuration, NTP synchronizes time, and DNS caching stores domain-resolution information. Application Control is therefore the appropriate feature for application-aware security policy enforcement.
Question 326
Which service can prevent users from reaching domains classified as malicious?
- CASB
- DLP
- ZTNA
- DNS Security
Correct Answer: 4
Explanation
DNS Security evaluates domain-name requests and applies security policies based on domain reputation, threat intelligence, and configured rules. If a domain is associated with malware, phishing, command-and-control activity, or another prohibited category, the request can be blocked or redirected. This provides protection before the user establishes a full connection to the destination. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA controls access to private applications. DNS Security is therefore the appropriate service for preventing access to malicious domains at the DNS layer.
Question 327
Which principle limits access to only the resources a user needs to perform their assigned tasks?
- Least privilege
- Full trust
- Open access
- Implicit trust
Correct Answer: 1
Explanation
Least privilege requires users to receive only the permissions and resources necessary for their authorized responsibilities. This reduces unnecessary exposure and limits the potential impact of compromised accounts or endpoints. In a Zero Trust architecture, least privilege can be implemented through application-specific authorization and tightly scoped policies. Full trust, open access, and implicit trust allow broader access and do not follow the same restrictive approach. Least privilege therefore helps organizations reduce risk while still giving users enough access to perform legitimate business functions.
Question 328
Which SSE service is designed to inspect and control internet-bound web traffic?
- CASB
- Secure Web Gateway
- DLP
- ZTNA
Correct Answer: 2
Explanation
Secure Web Gateway provides inspection and security policy enforcement for users accessing internet websites and web applications. It can support functions such as URL filtering, web categorization, malware protection, and application control. This allows organizations to enforce consistent web security policies for users regardless of their location. CASB focuses on cloud application security, DLP protects sensitive information, and ZTNA controls private application access. Secure Web Gateway is therefore the service most directly responsible for securing and controlling general internet web traffic.
Question 329
Which capability can use endpoint security information when making a Zero Trust access decision?
- URL Filtering
- DNS Security
- Device Posture
- Traffic Shaping
Correct Answer: 3
Explanation
Device posture provides information about the security and compliance state of an endpoint. Zero Trust policies can use posture information together with identity and other contextual factors before granting access to protected resources. Depending on the integration, posture can include endpoint protection status, operating system conditions, compliance state, or other security attributes. URL Filtering controls websites, DNS Security protects domain requests, and Traffic Shaping manages bandwidth. Device Posture is therefore the capability most directly associated with evaluating endpoint security as part of an access decision.
Question 330
Which capability is specifically designed to prevent confidential information from being transferred through unauthorized channels?
- DLP
- ZTNA
- Application Control
- DNS Security
Correct Answer: 1
Explanation
Data Loss Prevention identifies sensitive information and applies policies that control its movement through monitored channels. DLP can use configured patterns, rules, dictionaries, or classifications to detect confidential or regulated information. When a match occurs, actions can include blocking, logging, or generating an alert. ZTNA manages private application access, Application Control identifies applications, and DNS Security protects domain requests. DLP is therefore the security capability most directly associated with preventing unauthorized disclosure or transfer of sensitive data.
Question 331
Which authentication factor represents something the user possesses?
- PIN
- Password
- Fingerprint
- Hardware token
Correct Answer: 4
Explanation
A hardware token represents a possession factor because the user must possess the device or credential used for authentication. Passwords and PINs are knowledge factors, while fingerprints are biometric factors representing something the user is. Possession factors are often combined with knowledge or biometric factors as part of multifactor authentication. This makes it more difficult for an attacker to authenticate using a stolen password alone. A hardware token is therefore the correct example of something the user possesses during authentication.
Question 332
Which feature can identify websites according to categories and enforce access policies?
- URL Filtering
- DHCP
- NAT
- NTP
Correct Answer: 1
Explanation
URL Filtering classifies websites and allows administrators to create policies for specific categories, destinations, or reputations. Organizations can use this functionality to block malicious, phishing-related, inappropriate, or otherwise restricted websites. URL filtering is commonly delivered through Secure Web Gateway capabilities and can provide centralized control for users in different locations. DHCP provides network configuration, NAT performs address translation, and NTP synchronizes clocks. URL Filtering is therefore the appropriate feature for controlling website access according to predefined categories and security requirements.
Question 333
Which architecture integrates cloud-delivered security services for web access, private applications, cloud applications, and data?
- Traditional LAN
- Standalone DHCP
- Security Service Edge
- Basic routing
Correct Answer: 3
Explanation
Security Service Edge integrates multiple cloud-delivered security functions for distributed users and applications. Depending on the deployment, SSE can provide Secure Web Gateway for internet access, ZTNA for private application access, CASB for cloud application security, and DLP for sensitive-data protection. This architecture supports users working from offices, branches, homes, and mobile locations while allowing centralized security policy management. Traditional LANs, DHCP, and basic routing provide networking functions but do not represent the integrated cloud security framework described. Security Service Edge therefore matches the architecture in the question.
Question 334
Which capability can help identify cloud applications that employees are using without formal approval?
- DLP
- CASB
- DNS Security
- ZTNA
Correct Answer: 2
Explanation
CASB provides visibility into cloud application usage and can help organizations discover unsanctioned or unapproved SaaS applications. Identifying these applications allows administrators to assess security, privacy, and compliance risks and establish appropriate policies. Applications can then be monitored, permitted, restricted, or blocked according to organizational requirements. DLP focuses on sensitive information, DNS Security protects domain requests, and ZTNA provides private application access. CASB is therefore the appropriate capability for discovering and managing cloud applications that employees use outside approved processes.
Question 335
Which security capability can generate an alert when sensitive information is detected in supported traffic?
- DLP
- Secure Web Gateway
- Application Control
- DNS Security
Correct Answer: 1
Explanation
DLP can inspect supported traffic for sensitive information using configured patterns, dictionaries, classifications, or other rules. When protected content is detected, the policy can generate an alert, create a log entry, block the transfer, or take another configured action. This helps security teams identify potential data leakage and investigate policy violations involving confidential information. Secure Web Gateway protects web traffic, Application Control identifies applications, and DNS Security protects domain requests. DLP is therefore the capability specifically designed to identify sensitive information and generate alerts when policy conditions are met.
Question 336
Which SSE service provides controlled access to internal applications without granting broad network connectivity?
- ZTNA
- CASB
- Secure Web Gateway
- DLP
Correct Answer: 1
Explanation
Zero Trust Network Access provides application-level access to private resources rather than broad network connectivity. Before access is granted, the system can evaluate identity, authentication, device posture, and other policy conditions. This allows users to reach only the applications they are authorized to use and supports least-privilege access. CASB focuses on cloud applications, Secure Web Gateway protects internet traffic, and DLP protects sensitive information. ZTNA is therefore the appropriate SSE service for controlled internal application access without exposing the broader network.
Question 337
Which capability can enforce security policies according to the identity of an authenticated user?
- NAT
- DHCP
- Identity-based policy
- Static routing
Correct Answer: 3
Explanation
Identity-based policies allow administrators to associate security rules with authenticated users, groups, roles, or other identity attributes. This provides granular control and allows different policies to be applied to different user populations. For example, an organization can create separate web access rules for employees, contractors, and administrators. NAT translates addresses, DHCP provides network configuration, and static routing determines traffic paths. Identity-based policy is therefore the appropriate capability for security enforcement based on authenticated user identity.
Question 338
Which capability can prevent users from uploading protected information to unauthorized cloud destinations?
- DNS Security
- DLP
- Application Control
- DHCP
Correct Answer: 2
Explanation
DLP can inspect supported traffic for sensitive data and enforce rules that control its transmission. If a user attempts to upload confidential information to an unauthorized cloud destination, DLP can detect the sensitive content and take a configured action such as blocking, logging, or generating an alert. DNS Security protects domain requests, Application Control identifies applications, and DHCP provides network configuration. DLP is therefore the most appropriate capability for preventing sensitive information from being uploaded to unauthorized cloud destinations.
Question 339
Which capability allows a Zero Trust policy to consider the security condition of a user’s endpoint?
- Device posture
- URL Filtering
- DNS Caching
- Traffic Shaping
Correct Answer: 1
Explanation
Device posture provides information about an endpoint’s security and compliance status and can be used by Zero Trust policies during access decisions. Depending on the available integration, posture can include endpoint protection status, operating system condition, compliance information, and other security attributes. If the endpoint fails required checks, access can be restricted or denied. URL Filtering controls websites, DNS Caching stores domain-resolution information, and Traffic Shaping manages bandwidth usage. Device Posture is therefore the capability that provides endpoint security context for Zero Trust authorization.
Question 340
Which SSE service provides centralized protection for users browsing internet websites from remote locations?
- CASB
- DLP
- Secure Web Gateway
- ZTNA
Correct Answer: 3
Explanation
Secure Web Gateway provides centralized security controls for users accessing internet resources, including users working remotely. Through cloud-delivered SSE services, administrators can enforce policies for URL filtering, web categories, malware protection, and application control regardless of the user’s physical location. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA manages private application access. Secure Web Gateway is therefore the appropriate SSE service for centrally protecting remote users while they browse internet websites and web applications.