Fortinet NSE5_SSE_AD-7.6 Practice Test Questions and Exam Dumps Part20 Q381-400

View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 381

Which SSE capability provides application-level access to private resources according to user identity and device context?

  1. DLP
  2. CASB
  3. ZTNA
  4. Secure Web Gateway

Correct Answer: 3

Explanation

Zero Trust Network Access provides controlled access to private applications based on identity and contextual information. A ZTNA policy can evaluate factors such as user identity, authentication status, device posture, and application requirements before access is granted. Instead of providing broad network connectivity, users can be limited to the specific applications authorized by policy. DLP protects sensitive information, CASB focuses on cloud applications, and Secure Web Gateway secures internet traffic. ZTNA is therefore the appropriate SSE capability for secure, application-specific access to private resources.

Question 382

Which feature allows administrators to apply security policies based on authenticated users or groups?

  1. Identity-based policy
  2. NAT
  3. DHCP
  4. Static routing

Correct Answer: 1

Explanation

Identity-based policies associate security controls with authenticated users, groups, roles, or other identity attributes. This provides more granular access control than relying only on IP addresses or network locations. Organizations can create different web and application policies for employees, contractors, administrators, or other groups. NAT performs address translation, DHCP provides network configuration, and static routing controls fixed traffic paths. Identity-based policy is therefore the appropriate feature when security decisions need to reflect the authenticated identity or group membership of a user.

Question 383

Which SSE service provides visibility and policy enforcement for cloud applications?

  1. Secure Web Gateway
  2. DLP
  3. ZTNA
  4. CASB

Correct Answer: 4

Explanation

Cloud Access Security Broker provides visibility, governance, and security controls for cloud applications such as SaaS services. CASB can help administrators identify applications, monitor their usage, and apply policies based on users, applications, and activities. This is useful for managing cloud adoption and identifying unsanctioned services. Secure Web Gateway primarily protects general web traffic, DLP focuses on sensitive data, and ZTNA controls private application access. CASB is therefore the appropriate SSE service for cloud application visibility and policy enforcement.

Question 384

Which security capability is designed to detect sensitive information and control its transmission?

  1. Application Control
  2. DLP
  3. DNS Security
  4. ZTNA

Correct Answer: 2

Explanation

Data Loss Prevention identifies sensitive information and applies policies governing how that information can be transmitted. DLP can inspect supported traffic for configured patterns, classifications, or other sensitive-data indicators. When protected information is detected, actions can include blocking, logging, or generating an alert. Application Control identifies applications, DNS Security protects domain requests, and ZTNA provides private application access. DLP is therefore the security capability specifically designed to reduce unauthorized disclosure of confidential or regulated information.

Question 385

Which principle ensures that users receive only the access necessary for their assigned responsibilities?

  1. Least privilege
  2. Full trust
  3. Open access
  4. Implicit trust

Correct Answer: 1

Explanation

Least privilege requires that users receive only the permissions and resources necessary to complete authorized tasks. This reduces unnecessary exposure and limits the potential impact of compromised accounts or devices. In a Zero Trust architecture, least privilege can be implemented by allowing access to specific applications instead of providing unrestricted network connectivity. Full trust, open access, and implicit trust allow broader permissions and do not follow the same restrictive security model. Least privilege is therefore an important principle for minimizing unnecessary access while supporting legitimate business operations.

Question 386

Which authentication factor represents something the user possesses?

  1. Password
  2. PIN
  3. Fingerprint
  4. Hardware token

Correct Answer: 4

Explanation

A hardware token is a possession factor because the user must possess the token to authenticate. Passwords and PINs are knowledge factors because the user knows them, while a fingerprint is a biometric factor representing something the user is. Possession factors can be combined with knowledge or biometric factors to provide multifactor authentication. This strengthens authentication because an attacker who obtains only a password may still be unable to authenticate without the additional possession factor. Hardware tokens are therefore a common example of possession-based authentication.

Question 387

Which capability identifies applications in network traffic and allows administrators to enforce application-specific policies?

  1. DNS Security
  2. DHCP
  3. Application Control
  4. NTP

Correct Answer: 3

Explanation

Application Control identifies applications within network traffic and allows administrators to apply policies based on the detected application. This provides more granular visibility and control than relying only on IP addresses or ports. Organizations can use Application Control to permit, block, monitor, or restrict services such as streaming, messaging, file sharing, and other applications. DNS Security protects domain requests, DHCP provides network configuration, and NTP synchronizes system time. Application Control is therefore the appropriate capability for application-aware traffic identification and security policy enforcement.

Question 388

Which service can block access to domains associated with malware or phishing?

  1. CASB
  2. DNS Security
  3. DLP
  4. ZTNA

Correct Answer: 2

Explanation

DNS Security evaluates domain-name requests and applies security policies using threat intelligence, reputation information, or configured rules. If a requested domain is associated with malware, phishing, command-and-control activity, or another prohibited category, the request can be blocked or redirected. This can prevent users from reaching harmful destinations before a complete connection is established. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA controls private application access. DNS Security is therefore the appropriate service for blocking malicious domains at the DNS layer.

Question 389

Which feature can restrict website access according to predefined security categories?

  1. URL Filtering
  2. DHCP
  3. NAT
  4. NTP

Correct Answer: 4

Explanation

URL Filtering allows administrators to control website access using categories, specific URLs, reputation, and other configured policy conditions. Organizations can use it to block websites associated with malware, phishing, inappropriate content, or other restricted categories. URL Filtering is commonly provided through Secure Web Gateway functionality and can be centrally managed for users across different locations. DHCP provides network configuration, NAT performs address translation, and NTP synchronizes system clocks. URL Filtering is therefore the appropriate feature for applying category-based website access policies.

Question 390

Which capability can evaluate an endpoint’s security condition before granting access to a protected application?

  1. URL filtering
  2. Device posture
  3. DNS caching
  4. Traffic shaping

Correct Answer: 2

Explanation

Device posture represents the security and compliance state of an endpoint. A Zero Trust policy can evaluate posture information together with user identity and other contextual factors before granting access to a protected application. Depending on the integration, posture can include endpoint security status, operating system conditions, compliance information, or other security attributes. URL filtering controls websites, DNS caching stores domain-resolution information, and traffic shaping manages bandwidth. Device posture is therefore the capability most directly associated with evaluating endpoint security during an access decision.

Question 391

Which architecture combines cloud-delivered security services for web access, private applications, cloud applications, and data protection?

  1. Traditional LAN
  2. Standalone DHCP
  3. Security Service Edge
  4. Basic routing

Correct Answer: 3

Explanation

Security Service Edge integrates multiple cloud-delivered security capabilities for distributed users and resources. Depending on the deployment, SSE can include Secure Web Gateway for internet security, ZTNA for private application access, CASB for cloud application security, and DLP for sensitive-data protection. This architecture is useful for remote workers, branch locations, and mobile users because security policies can be centrally managed through cloud infrastructure. Traditional LANs, DHCP, and basic routing provide networking functions but do not represent the integrated cloud security architecture described.

Question 392

Which capability can identify unsanctioned SaaS applications being used by employees?

  1. DLP
  2. CASB
  3. DNS Security
  4. ZTNA

Correct Answer: 2

Explanation

CASB provides visibility into cloud application usage and can help organizations identify unapproved or unsanctioned SaaS services. This can reveal shadow IT and allow security teams to evaluate security, privacy, and compliance risks. Once applications are identified, administrators can establish policies to monitor, permit, restrict, or block them according to organizational requirements. DLP focuses on sensitive information, DNS Security protects domain requests, and ZTNA controls private application access. CASB is therefore the appropriate capability for discovering and managing unsanctioned cloud applications.

Question 393

Which security capability can generate an alert when sensitive information is detected in monitored traffic?

  1. DLP
  2. Application Control
  3. DNS Security
  4. ZTNA

Correct Answer: 1

Explanation

DLP can inspect supported traffic for sensitive information using configured patterns, classifications, dictionaries, or other rules. When protected information is detected, DLP policies can generate alerts, create logs, block transfers, or take other configured actions. This helps security teams identify possible data leakage and investigate policy violations involving confidential information. Application Control identifies applications, DNS Security protects domain requests, and ZTNA controls private application access. DLP is therefore the capability most directly associated with detecting sensitive information and generating policy-based alerts.

Question 394

Which service provides centralized security inspection and control for internet-bound web traffic?

  1. DLP
  2. Secure Web Gateway
  3. CASB
  4. ZTNA

Correct Answer: 4

Explanation

Secure Web Gateway provides centralized security inspection and policy enforcement for users accessing internet resources. It can support URL filtering, web category controls, malware protection, and application-aware policies. This allows organizations to apply consistent web security controls to users regardless of their physical location. DLP protects sensitive data, CASB focuses on cloud applications, and ZTNA controls private application access. Secure Web Gateway is therefore the service most directly responsible for securing and controlling users’ general internet web traffic.

Question 395

Which authentication method requires two or more independent authentication factors?

  1. Password-only authentication
  2. Guest access
  3. Anonymous access
  4. Multifactor authentication

Correct Answer: 4

Explanation

Multifactor authentication requires two or more authentication factors, generally from different categories such as knowledge, possession, and inherence. A password combined with a hardware token or biometric factor is a common example. MFA strengthens authentication because compromising one factor alone may not be sufficient to gain access. Password-only authentication uses a single factor, while guest and anonymous access do not provide equivalent identity assurance. Multifactor authentication is therefore the appropriate method when multiple independent authentication factors are required.

Question 396

Which capability allows security policies to be associated with authenticated users or groups?

  1. NAT
  2. DHCP
  3. Static routing
  4. Identity-based policy

Correct Answer: 3

Explanation

Identity-based policies allow security controls to be associated with authenticated users, groups, roles, or other identity attributes. This enables organizations to apply different access rules according to user responsibilities and group membership. For example, employees, contractors, and administrators can receive different web or application policies. NAT translates addresses, DHCP provides network configuration, and static routing determines fixed traffic paths. Identity-based policy is therefore the appropriate capability for enforcing security decisions according to authenticated user identity and group membership.

Question 397

Which SSE component provides controlled access to private applications without giving users broad network connectivity?

  1. ZTNA
  2. CASB
  3. Secure Web Gateway
  4. DLP

Correct Answer: 1

Explanation

Zero Trust Network Access provides application-level access to private resources rather than unrestricted network connectivity. A ZTNA policy can evaluate identity, authentication status, device posture, and other contextual conditions before allowing access to a specific application. This supports least privilege and limits exposure of unrelated internal systems. CASB manages cloud applications, Secure Web Gateway protects internet traffic, and DLP protects sensitive information. ZTNA is therefore the appropriate SSE component for controlled access to private applications while minimizing unnecessary network exposure.

Question 398

Which capability can prevent sensitive information from being uploaded to an unauthorized cloud destination?

  1. DNS Security
  2. DLP
  3. Application Control
  4. DHCP

Correct Answer: 2

Explanation

DLP can inspect supported traffic for sensitive information and enforce policies governing how protected content is transferred. If a user attempts to upload confidential information to an unauthorized cloud destination, DLP can identify the sensitive content and take an action such as blocking, logging, or generating an alert. DNS Security protects domain requests, Application Control identifies applications, and DHCP provides network configuration. DLP is therefore the most appropriate capability for preventing sensitive information from being transferred to unauthorized cloud destinations.

Question 399

Which capability can use endpoint security information as part of a Zero Trust access decision?

  1. Device posture
  2. URL Filtering
  3. DNS Caching
  4. Traffic Shaping

Correct Answer: 1

Explanation

Device posture provides information about the security and compliance status of an endpoint. Zero Trust policies can evaluate this information together with identity and other contextual factors before granting access to protected applications. Depending on the integration, posture information can include endpoint security status, operating system conditions, compliance state, or other security attributes. URL Filtering controls website access, DNS Caching stores domain-resolution information, and Traffic Shaping manages bandwidth. Device Posture is therefore the appropriate capability for including endpoint security state in access decisions.

Question 400

Which SSE capability provides centralized web security policies for users accessing internet resources from remote locations?

  1. CASB
  2. Secure Web Gateway
  3. ZTNA
  4. DLP

Correct Answer: 2

Explanation

Secure Web Gateway provides centralized security controls for users accessing internet resources, including remote and mobile users. Through cloud-delivered SSE, administrators can enforce URL filtering, web category policies, malware protection, and application controls regardless of the user’s physical location. CASB focuses on cloud applications, ZTNA manages private application access, and DLP protects sensitive information. Secure Web Gateway is therefore the appropriate SSE capability for centrally securing web access for distributed and remote users.