Fortinet NSE5_SSE_AD-7.6 Practice Test Questions and Exam Dumps Part13 Q241-260

View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 241

Which SSE capability provides application-specific access to private resources based on identity and security context?

  1. DNS Security
  2. DLP
  3. CASB
  4. ZTNA

Correct Answer: 4

Explanation

Zero Trust Network Access provides controlled access to private applications according to identity and contextual security information. Instead of granting users broad access to an internal network, ZTNA can authorize access to individual applications based on configured policies. These policies may consider user identity, authentication status, device posture, and other conditions. DNS Security protects domain requests, DLP protects sensitive information, and CASB focuses on cloud applications. ZTNA therefore provides the application-level access model required when organizations want to implement least privilege and reduce unnecessary exposure of internal resources.

Question 242

Which SSE service is responsible for filtering and controlling general internet web traffic?

  1. Secure Web Gateway
  2. CASB
  3. ZTNA
  4. DLP

Correct Answer: 1

Explanation

Secure Web Gateway provides security inspection and policy enforcement for users accessing internet websites and web applications. It can support functions such as URL filtering, web category controls, malware protection, and application-based policies. SWG allows organizations to centrally control internet access regardless of where users connect. CASB is focused on cloud application security, ZTNA controls private application access, and DLP focuses on sensitive data. Therefore, Secure Web Gateway is the appropriate SSE service for filtering and controlling general internet web traffic.

Question 243

Which capability provides visibility and control over cloud applications such as SaaS services?

  1. DLP
  2. DNS Security
  3. CASB
  4. DHCP

Correct Answer: 3

Explanation

Cloud Access Security Broker provides visibility and security controls for cloud applications. CASB can help organizations identify cloud services being used by employees, monitor activity, and apply policies according to organizational requirements. This can also help identify unsanctioned applications and manage the risks associated with cloud usage. DLP protects sensitive information, DNS Security protects domain requests, and DHCP provides network configuration. CASB is therefore the capability most directly associated with visibility and policy enforcement for SaaS and other cloud applications.

Question 244

Which security principle restricts users to only the resources required for their assigned responsibilities?

  1. Full trust
  2. Least privilege
  3. Open access
  4. Implicit trust

Correct Answer: 2

Explanation

Least privilege requires that users receive only the permissions and resources needed to perform their authorized tasks. This reduces unnecessary access and limits the potential impact of compromised credentials or endpoints. In a Zero Trust architecture, least privilege can be applied by granting access to specific applications instead of an entire network. Full trust, open access, and implicit trust allow broader access and do not follow the same restrictive approach. Least privilege is therefore a fundamental security principle for reducing exposure while still allowing users to perform legitimate business activities.

Question 245

Which authentication factor is an example of something the user possesses?

  1. Password
  2. PIN
  3. Fingerprint
  4. Hardware security token

Correct Answer: 4

Explanation

A hardware security token is a possession factor because it is something the user has. Authentication factors are commonly categorized as knowledge, possession, and inherence. Passwords and PINs are knowledge factors, while a fingerprint is a biometric factor representing something the user is. A hardware token can be combined with another factor to provide multifactor authentication. Using multiple factor categories strengthens authentication because possession of one credential alone is not necessarily sufficient to gain access to protected resources.

Question 246

Which capability can detect sensitive data and take an action such as blocking or logging the transfer?

  1. Application Control
  2. DLP
  3. DNS Security
  4. ZTNA

Correct Answer: 2

Explanation

Data Loss Prevention can inspect supported traffic for sensitive information based on configured patterns, rules, classifications, or dictionaries. When protected content is detected, DLP policies can specify actions such as allowing, blocking, logging, or generating alerts. This helps organizations protect confidential business information, personal data, intellectual property, and other sensitive content. Application Control identifies applications, DNS Security protects domain requests, and ZTNA provides private application access. DLP is therefore the capability specifically designed to identify sensitive information and control its transmission.

Question 247

Which feature can apply security policies according to the actual application identified in traffic?

  1. Application Control
  2. DHCP
  3. NTP
  4. DNS caching

Correct Answer: 1

Explanation

Application Control identifies applications within network traffic and allows administrators to create application-specific security policies. This provides more granular visibility than relying only on IP addresses or ports. Organizations can use application control to permit, block, monitor, or restrict services such as streaming, messaging, file sharing, or other applications. DHCP provides network configuration, NTP synchronizes system time, and DNS caching stores domain-resolution information. Application Control is therefore the appropriate feature for identifying applications and applying policies based on the actual service detected in traffic.

Question 248

Which security service can block DNS requests for domains classified as malicious?

  1. CASB
  2. DLP
  3. DNS Security
  4. ZTNA

Correct Answer: 3

Explanation

DNS Security can inspect DNS requests and compare domain destinations against threat intelligence and configured security policies. If a requested domain is associated with malware, phishing, command-and-control infrastructure, or another prohibited category, the request can be blocked or redirected. This provides an early security control before users establish a full connection to a harmful destination. CASB manages cloud applications, DLP protects sensitive information, and ZTNA controls private application access. DNS Security is therefore the appropriate service for blocking malicious domain requests.

Question 249

Which feature can control access to websites based on categories such as malware, phishing, or inappropriate content?

  1. Web filtering
  2. DHCP
  3. NAT
  4. NTP

Correct Answer: 1

Explanation

Web filtering allows administrators to control access to websites according to categories, reputation, or configured URLs. It can be used to block websites associated with malware, phishing, inappropriate content, gambling, or other restricted categories. This function is commonly provided through Secure Web Gateway capabilities. DHCP provides network addressing, NAT performs address translation, and NTP synchronizes clocks. Web filtering is therefore the appropriate security feature when an organization needs to enforce web access policies based on content or security categories.

Question 250

Which capability can evaluate the security condition of an endpoint before granting access to a private application?

  1. URL Filtering
  2. Device Posture
  3. DNS Caching
  4. Traffic Shaping

Correct Answer: 4

Explanation

Device posture provides information about the security and compliance state of an endpoint. In a Zero Trust environment, this information can be evaluated as part of an access policy before a user receives access to a protected application. Depending on the available integration, posture may include endpoint protection status, operating system state, compliance information, or other security attributes. URL filtering manages websites, DNS caching stores resolution information, and traffic shaping controls bandwidth. Device posture is therefore the relevant capability for evaluating endpoint security as part of application authorization.

Question 251

Which SSE architecture delivers cloud-based security services to users working from different locations?

  1. Security Service Edge
  2. Standalone DHCP
  3. Traditional LAN switching
  4. Local-only routing

Correct Answer: 4

Explanation

Security Service Edge is an architecture designed to provide cloud-delivered security services to distributed users and locations. Depending on the deployment, SSE can include Secure Web Gateway, Zero Trust Network Access, CASB, DLP, and other security capabilities. This model is useful for remote employees, branch users, and mobile workers because security policies can be enforced through cloud infrastructure. DHCP and LAN switching provide networking services, while local-only routing does not represent the integrated cloud security architecture. SSE is therefore the appropriate architecture for distributed cloud-delivered security.

Question 252

Which capability helps discover cloud applications that have not been approved by an organization?

  1. DNS Security
  2. CASB
  3. DLP
  4. ZTNA

Correct Answer: 2

Explanation

CASB provides visibility into cloud application usage and can help organizations discover unsanctioned or unapproved SaaS services. Identifying these applications allows security teams to evaluate risks related to data protection, privacy, compliance, and unauthorized cloud usage. Administrators can then create policies to permit, monitor, restrict, or block applications based on organizational requirements. DNS Security protects domain requests, DLP focuses on sensitive information, and ZTNA controls private application access. CASB is therefore the capability most directly associated with discovering and managing unapproved cloud applications.

Question 253

Which authentication method requires two or more different authentication factors?

  1. Password-only authentication
  2. Single sign-on
  3. Multifactor authentication
  4. Anonymous authentication

Correct Answer: 4

Explanation

Multifactor authentication requires two or more authentication factors, typically from different categories such as knowledge, possession, and inherence. For example, a password can be combined with a hardware token or biometric factor. This provides stronger identity protection because compromising one factor alone may not be enough to gain access. Password-only authentication uses a single factor, while anonymous authentication does not provide equivalent identity verification. MFA is therefore the authentication method designed to require multiple factors for a stronger authentication process.

Question 254

Which SSE component protects internet users by inspecting web traffic and applying security policies?

  1. Secure Web Gateway
  2. CASB
  3. DLP
  4. ZTNA

Correct Answer: 1

Explanation

Secure Web Gateway provides inspection and policy enforcement for users’ internet-bound web traffic. It can support URL filtering, web category controls, malware protection, application identification, and other security features. This allows organizations to apply consistent security policies to users regardless of where they connect. CASB focuses on cloud application security, DLP protects sensitive data, and ZTNA controls access to private applications. Secure Web Gateway is therefore the primary SSE component for protecting users while they access internet websites and web applications.

Question 255

Which capability can provide access to private applications without exposing the applications directly to the public internet?

  1. DLP
  2. CASB
  3. ZTNA
  4. DNS Security

Correct Answer: 2

Explanation

Zero Trust Network Access can provide controlled access to private applications while keeping those applications from being broadly exposed to the public internet. Users are authenticated and evaluated against access policies before being allowed to connect to specific applications. This approach reduces attack surface and supports least-privilege access. DLP protects sensitive information, CASB manages cloud applications, and DNS Security protects domain requests. ZTNA is therefore the appropriate technology for providing secure application access without requiring public exposure of internal applications.

Question 256

Which capability can identify sensitive information and generate an alert when a policy violation occurs?

  1. DLP
  2. Application Control
  3. DNS Security
  4. SWG

Correct Answer: 1

Explanation

DLP can detect sensitive information within supported traffic and apply configured actions when policy conditions are met. These actions may include logging, generating an alert, blocking the transaction, or allowing it while recording the event. This capability helps organizations identify potential data leakage and protect confidential or regulated information. Application Control identifies applications, DNS Security evaluates domain requests, and SWG protects web traffic. DLP is therefore the appropriate capability for detecting sensitive information and alerting administrators when a data protection policy is violated.

Question 257

Which principle assumes that access must be explicitly verified rather than automatically trusted based on network location?

  1. Open access
  2. Zero Trust
  3. Full trust
  4. Perimeter-only trust

Correct Answer: 2

Explanation

Zero Trust requires access to be explicitly verified rather than automatically granted because a user or device is connected to a trusted network. Access decisions can evaluate identity, authentication, device posture, application, and other contextual factors. This approach reduces reliance on the traditional network perimeter and limits unnecessary access. Open access and full trust allow broader permissions, while perimeter-only trust relies primarily on network boundaries. Zero Trust therefore represents the security principle in which trust is not automatically granted based on network location.

Question 258

Which capability allows security policies to be based on authenticated user identity?

  1. NAT
  2. DHCP
  3. Static Routing
  4. Identity-based policy

Correct Answer: 4

Explanation

Identity-based policies allow security controls to be associated with authenticated users, groups, roles, or other identity attributes. This provides more granular access control than relying only on IP addresses or network locations. For example, administrators can give different web or application access to employees, contractors, and privileged users. NAT translates network addresses, DHCP provides network configuration, and static routing controls traffic paths. Identity-based policy is therefore the capability that allows security decisions to directly reflect the authenticated identity of the user.

Question 259

Which service can enforce security controls for cloud applications based on users and activities?

  1. CASB
  2. DNS Security
  3. DLP
  4. DHCP

Correct Answer: 1

Explanation

CASB provides cloud application visibility and security controls that can be applied according to users, applications, activities, and other policy conditions. This helps organizations govern cloud services and manage risks associated with SaaS usage. Administrators can monitor activity and create controls for sanctioned or unsanctioned applications based on organizational requirements. DNS Security focuses on domain requests, DLP protects sensitive information, and DHCP provides network configuration. CASB is therefore the most appropriate service for applying security controls to cloud application activity.

Question 260

Which SSE capability provides centralized policy enforcement for users accessing web resources from remote locations?

  1. DLP
  2. ZTNA
  3. Secure Web Gateway
  4. CASB

Correct Answer: 3

Explanation

Secure Web Gateway provides centralized security policy enforcement for users accessing internet web resources. In a cloud-delivered SSE architecture, remote users can receive consistent controls such as URL filtering, web category restrictions, malware protection, and application policies without needing to be physically located at a corporate site. DLP protects sensitive information, ZTNA controls private application access, and CASB manages cloud applications. Secure Web Gateway is therefore the appropriate SSE capability for centrally securing web access for remote and distributed users.