Fortinet NSE5_SSE_AD-7.6 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 341

Which SSE capability provides secure access to private applications based on user identity and contextual information?

  1. DLP
  2. Secure Web Gateway
  3. ZTNA
  4. CASB

Correct Answer: 3

Explanation

Zero Trust Network Access provides controlled, application-level access to private resources. Before access is granted, ZTNA can evaluate user identity, authentication status, device posture, and other contextual information. This allows organizations to apply least-privilege principles instead of giving users broad internal network connectivity. DLP is focused on sensitive information, Secure Web Gateway protects internet traffic, and CASB provides cloud application security. ZTNA is therefore the appropriate SSE capability when users need secure access to specific private applications based on identity and security context.

Question 342

Which feature allows security policies to be associated with authenticated users or groups?

  1. Identity-based policy
  2. NAT
  3. DHCP
  4. Static routing

Correct Answer: 1

Explanation

Identity-based policies allow administrators to associate security controls with authenticated users, groups, roles, or other identity attributes. This provides more granular control than using only IP addresses or network locations. For example, employees and contractors can receive different web or application access policies based on their roles. NAT performs address translation, DHCP provides network configuration, and static routing defines fixed traffic paths. Identity-based policy is therefore the appropriate feature when security decisions need to reflect the authenticated identity or group membership of the user.

Question 343

Which security service provides visibility and policy controls for cloud applications such as SaaS platforms?

  1. DLP
  2. DNS Security
  3. Secure Web Gateway
  4. CASB

Correct Answer: 4

Explanation

Cloud Access Security Broker provides visibility and security controls for cloud applications, including SaaS services. CASB can help organizations identify applications, monitor usage, and enforce policies based on users, applications, activities, and organizational requirements. This is especially useful for identifying unsanctioned cloud services and managing cloud-related risks. DLP protects sensitive information, DNS Security protects domain requests, and Secure Web Gateway secures general web traffic. CASB is therefore the appropriate service for cloud application visibility, governance, and policy enforcement.

Question 344

Which authentication factor represents something the user knows?

  1. Fingerprint
  2. Password
  3. Hardware token
  4. Security key

Correct Answer: 2

Explanation

A password is an example of a knowledge authentication factor because it is something the user knows. Authentication factors are generally categorized into knowledge, possession, and inherence. Fingerprints represent something the user is, while hardware tokens and security keys generally represent something the user possesses. A password can be combined with another factor to create multifactor authentication. This provides stronger security because an attacker who obtains the password alone may still be unable to satisfy the additional authentication requirement.

Question 345

Which capability can identify applications in network traffic and enforce application-specific security policies?

  1. Application Control
  2. DNS Security
  3. DHCP
  4. NTP

Correct Answer: 1

Explanation

Application Control identifies applications in network traffic and allows administrators to create policies based on the detected application. This provides application-aware visibility and more granular control than relying only on IP addresses or ports. Organizations can use Application Control to allow, block, monitor, or restrict applications such as messaging, streaming, and file-sharing services. DNS Security protects domain requests, DHCP provides network configuration, and NTP synchronizes system time. Application Control is therefore the appropriate capability for identifying applications and enforcing application-specific security policies.

Question 346

Which service can block requests to domains associated with phishing or malware?

  1. CASB
  2. DLP
  3. ZTNA
  4. DNS Security

Correct Answer: 4

Explanation

DNS Security evaluates DNS requests and uses configured policies or threat intelligence to determine whether requested domains should be allowed. Domains associated with phishing, malware, command-and-control infrastructure, or other prohibited content can be blocked or redirected. This provides protection before a full connection to the malicious destination is established. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA provides access to private applications. DNS Security is therefore the appropriate service for protecting users from malicious domains through DNS-level enforcement.

Question 347

Which principle limits users to only the resources and permissions required for their assigned tasks?

  1. Least privilege
  2. Open access
  3. Full trust
  4. Implicit trust

Correct Answer: 1

Explanation

Least privilege means giving users only the permissions and resources necessary to perform their authorized responsibilities. This reduces unnecessary exposure and can limit the impact of compromised accounts or endpoints. In a Zero Trust architecture, least privilege can be implemented by authorizing access to specific applications instead of providing unrestricted network access. Open access, full trust, and implicit trust provide broader permissions and do not follow the same restrictive approach. Least privilege is therefore a fundamental security principle for minimizing unnecessary access.

Question 348

Which SSE service primarily secures and controls users’ internet-bound web traffic?

  1. CASB
  2. Secure Web Gateway
  3. DLP
  4. ZTNA

Correct Answer: 2

Explanation

Secure Web Gateway provides centralized inspection and policy enforcement for internet-bound web traffic. It can apply controls such as URL filtering, web category policies, malware protection, and application control. This allows organizations to provide consistent web security to users working from offices, homes, branches, or mobile locations. CASB focuses on cloud application security, DLP protects sensitive information, and ZTNA controls access to private applications. Secure Web Gateway is therefore the service most directly responsible for protecting and controlling general web traffic.

Question 349

Which capability can evaluate whether an endpoint satisfies security requirements before access is granted?

  1. URL filtering
  2. DNS caching
  3. Device posture
  4. Traffic shaping

Correct Answer: 3

Explanation

Device posture provides information about the security and compliance condition of an endpoint. A Zero Trust policy can use posture information along with identity and other contextual data before granting access to a protected application. Depending on the integration, posture can include endpoint security status, operating system conditions, compliance information, or other attributes. URL filtering controls websites, DNS caching stores domain information, and traffic shaping manages bandwidth. Device posture is therefore the relevant capability for determining whether an endpoint meets the security requirements for access.

Question 350

Which capability can identify sensitive information and apply actions such as blocking, logging, or alerting?

  1. DLP
  2. ZTNA
  3. Application Control
  4. DNS Security

Correct Answer: 1

Explanation

Data Loss Prevention can inspect supported traffic for sensitive information using configured patterns, classifications, dictionaries, or other rules. When protected information is detected, DLP policies can specify actions such as blocking the transfer, logging the event, generating an alert, or allowing it under controlled conditions. This helps organizations protect confidential business information, personal data, and regulated content. ZTNA manages private application access, Application Control identifies applications, and DNS Security protects domain requests. DLP is therefore the capability specifically designed for sensitive-data detection and policy enforcement.

Question 351

Which cloud-delivered architecture combines web security, private application access, cloud application controls, and data protection?

  1. Traditional LAN
  2. Standalone DHCP
  3. Basic routing
  4. Security Service Edge

Correct Answer: 4

Explanation

Security Service Edge combines multiple cloud-delivered security services for distributed users and resources. Depending on the deployment, SSE can include Secure Web Gateway for internet security, ZTNA for private application access, CASB for cloud application protection, and DLP for sensitive-data security. This architecture supports users working remotely, from branches, or from mobile locations while maintaining centralized security policies. Traditional LAN, DHCP, and basic routing provide networking functions but do not represent this integrated cloud security framework. SSE therefore matches the architecture described in the question.

Question 352

Which capability can discover unsanctioned SaaS applications being used by employees?

  1. DLP
  2. CASB
  3. DNS Security
  4. ZTNA

Correct Answer: 2

Explanation

CASB provides visibility into cloud application usage and can help organizations discover unsanctioned or unapproved SaaS applications. This can reveal shadow IT and allow administrators to assess security, compliance, and data protection risks. Once applications are identified, policies can be applied to monitor, permit, restrict, or block them according to organizational requirements. DLP focuses on sensitive information, DNS Security protects domain requests, and ZTNA controls private application access. CASB is therefore the appropriate capability for discovering and managing cloud applications that have not been formally approved.

Question 353

Which authentication factor represents something the user possesses?

  1. Password
  2. Hardware token
  3. PIN
  4. Fingerprint

Correct Answer: 2

Explanation

A hardware token is a possession factor because the user must possess the token to complete authentication. Passwords and PINs are knowledge factors because the user knows them, while a fingerprint is a biometric factor representing something the user is. A possession factor can be combined with another factor to implement multifactor authentication. Using multiple factor types provides stronger security because an attacker who obtains only a password may still be unable to complete authentication without the required token or additional factor.

Question 354

Which feature controls website access using URL categories and security policies?

  1. URL filtering
  2. DHCP
  3. NAT
  4. NTP

Correct Answer: 1

Explanation

URL filtering allows administrators to control access to websites based on categories, specific URLs, reputation, or other configured conditions. Organizations can use it to block malware, phishing, inappropriate content, or other restricted website categories. URL filtering is commonly implemented through Secure Web Gateway functionality and can be centrally managed for distributed users. DHCP provides network configuration, NAT performs address translation, and NTP synchronizes system time. URL filtering is therefore the appropriate feature for enforcing website access policies based on URL categories.

Question 355

Which capability can provide application-level access to internal resources without giving users unrestricted network connectivity?

  1. Secure Web Gateway
  2. CASB
  3. ZTNA
  4. DLP

Correct Answer: 3

Explanation

ZTNA provides controlled, application-specific access to private resources. Instead of giving a user broad access to an internal network after authentication, ZTNA can evaluate identity, device posture, authentication status, and other contextual conditions before allowing access to a specific application. This supports least privilege and reduces exposure of unrelated internal systems. Secure Web Gateway protects internet traffic, CASB focuses on cloud applications, and DLP protects sensitive information. ZTNA is therefore the appropriate capability for secure application-level access without unrestricted network connectivity.

Question 356

Which service can evaluate DNS requests and block malicious domains before a full connection is established?

  1. DLP
  2. DNS Security
  3. CASB
  4. ZTNA

Correct Answer: 2

Explanation

DNS Security examines DNS requests and applies security policies based on domain reputation, threat intelligence, and configured rules. If a requested domain is associated with malware, phishing, command-and-control infrastructure, or another prohibited category, the request can be blocked or redirected. This provides an early layer of protection before the user connects to the destination. DLP protects sensitive information, CASB manages cloud applications, and ZTNA controls private application access. DNS Security is therefore the appropriate service for enforcing domain-level security controls.

Question 357

Which capability allows different security rules to be applied according to authenticated user groups?

  1. Identity-based policy
  2. Static routing
  3. NAT
  4. DHCP

Correct Answer: 1

Explanation

Identity-based policies allow administrators to associate security rules with authenticated users, groups, roles, or other identity attributes. This makes it possible to provide different web and application access controls to different organizational groups. For example, employees, contractors, and administrators can receive policies appropriate to their responsibilities. Static routing determines traffic paths, NAT translates addresses, and DHCP provides network configuration. Identity-based policy is therefore the appropriate capability for enforcing different security rules based on user identity and group membership.

Question 358

Which SSE component provides cloud application visibility and policy enforcement for SaaS services?

  1. DLP
  2. Secure Web Gateway
  3. CASB
  4. DNS Security

Correct Answer: 3

Explanation

CASB provides security visibility and policy controls for cloud applications, including SaaS platforms. It can help organizations discover cloud services, monitor application usage, and apply policies based on users, applications, and activities. This supports cloud governance and can help identify unsanctioned applications. DLP protects sensitive information, Secure Web Gateway secures internet traffic, and DNS Security protects domain requests. CASB is therefore the appropriate SSE component for managing security and visibility across cloud application usage.

Question 359

Which capability is used to protect sensitive information from unauthorized transfer?

  1. ZTNA
  2. DLP
  3. CASB
  4. Application Control

Correct Answer: 2

Explanation

Data Loss Prevention is designed to identify sensitive information and enforce controls over its transmission. DLP can inspect supported traffic for configured patterns or classifications and take actions such as blocking, logging, or alerting when protected data is detected. This helps reduce the risk of confidential information being exposed through unauthorized channels. ZTNA provides private application access, CASB manages cloud applications, and Application Control identifies applications. DLP is therefore the capability most directly responsible for protecting sensitive information from unauthorized transfer.

Question 360

Which SSE service provides centralized security policies for users browsing the internet from remote locations?

  1. CASB
  2. ZTNA
  3. Secure Web Gateway
  4. DLP

Correct Answer: 3

Explanation

Secure Web Gateway provides centralized security controls for users accessing internet resources, including remote and mobile users. Through cloud-delivered SSE, administrators can enforce policies for URL filtering, web categories, malware protection, and application controls regardless of user location. CASB focuses on cloud applications, ZTNA controls private application access, and DLP protects sensitive information. Secure Web Gateway is therefore the appropriate SSE service for centrally securing web access for users who connect from remote or distributed locations.