View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 361
Which SSE capability provides application-specific access to private resources according to identity and security context?
- Secure Web Gateway
- DLP
- CASB
- ZTNA
Correct Answer: 4
Explanation
Zero Trust Network Access provides controlled access to private applications based on authenticated identity and contextual security information. A ZTNA policy can evaluate user identity, authentication status, device posture, and other conditions before allowing access. Instead of granting broad network connectivity, ZTNA can limit users to specific applications they are authorized to use. Secure Web Gateway protects internet traffic, DLP protects sensitive information, and CASB provides cloud application security. ZTNA is therefore the appropriate SSE capability for secure, application-specific access to private resources.
Question 362
Which feature allows administrators to apply security policies according to authenticated user identity?
- Identity-based policy
- NAT
- DHCP
- Static routing
Correct Answer: 1
Explanation
Identity-based policies allow administrators to associate security rules with authenticated users, groups, or roles. This provides more granular control than relying only on network addresses or locations. For example, different user groups can receive different web access or application access policies according to their responsibilities. NAT translates network addresses, DHCP provides network configuration, and static routing determines fixed traffic paths. Identity-based policy is therefore the appropriate feature when security decisions need to be based on the authenticated identity of a user.
Question 363
Which SSE service provides visibility and control over cloud applications and SaaS platforms?
- DLP
- CASB
- ZTNA
- DNS Security
Correct Answer: 2
Explanation
Cloud Access Security Broker provides visibility, governance, and security controls for cloud applications such as SaaS services. CASB can help organizations discover applications, monitor their use, and apply policies based on users, applications, and activities. This can also help identify unsanctioned cloud services and reduce associated security risks. DLP focuses on sensitive information, ZTNA provides private application access, and DNS Security protects domain requests. CASB is therefore the appropriate SSE service for managing visibility and security policies across cloud application usage.
Question 364
Which security capability is specifically designed to identify sensitive data and control its transmission?
- Application Control
- DNS Security
- ZTNA
- DLP
Correct Answer: 4
Explanation
Data Loss Prevention is designed to identify sensitive information and enforce policies that control how the information is transmitted. DLP can inspect supported traffic for configured patterns, classifications, dictionaries, or other rules. When sensitive information is detected, policies can allow, block, log, or generate alerts depending on the configuration. Application Control identifies applications, DNS Security protects domain requests, and ZTNA controls private application access. DLP is therefore the SSE capability most directly associated with preventing unauthorized disclosure or transfer of sensitive information.
Question 365
Which Zero Trust principle limits a user to only the resources required for their assigned tasks?
- Open access
- Least privilege
- Full trust
- Implicit trust
Correct Answer: 2
Explanation
Least privilege requires that users receive only the permissions and resources necessary to perform their authorized responsibilities. This reduces unnecessary exposure and helps limit the potential impact of compromised credentials or endpoints. In a Zero Trust architecture, least privilege can be implemented through application-specific authorization and narrowly defined policies. Open access, full trust, and implicit trust provide broader permissions and do not follow the same restrictive model. Least privilege is therefore a fundamental principle for reducing unnecessary access while still supporting legitimate business operations.
Question 366
Which authentication factor is an example of something the user possesses?
- Password
- Fingerprint
- Hardware token
- PIN
Correct Answer: 3
Explanation
A hardware token is a possession factor because the user must possess the device or credential during authentication. Passwords and PINs are knowledge factors because the user knows them, while a fingerprint is a biometric factor representing something the user is. Possession factors can be combined with knowledge or biometric factors to create multifactor authentication. This approach strengthens security because an attacker who obtains a password alone may still be unable to complete authentication without the additional possession factor.
Question 367
Which capability identifies applications in network traffic and allows application-specific security policies?
- Application Control
- DHCP
- NTP
- NAT
Correct Answer: 1
Explanation
Application Control identifies applications within network traffic and allows administrators to create policies based on the detected application. This provides application-aware visibility and more granular control than relying only on IP addresses or port numbers. Organizations can use Application Control to allow, block, monitor, or restrict services such as streaming, messaging, and file sharing. DHCP provides network configuration, NTP synchronizes system time, and NAT performs address translation. Application Control is therefore the appropriate capability for application-aware traffic identification and policy enforcement.
Question 368
Which service can block DNS requests for domains associated with malware or phishing?
- CASB
- DLP
- ZTNA
- DNS Security
Correct Answer: 4
Explanation
DNS Security evaluates domain-name requests and applies security policies using threat intelligence, reputation information, or configured rules. If a requested domain is identified as malicious, phishing-related, or otherwise prohibited, the request can be blocked or redirected. This can prevent users from reaching harmful destinations before establishing a complete connection. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA controls private application access. DNS Security is therefore the appropriate service for preventing access to malicious domains through DNS-level enforcement.
Question 369
Which feature can restrict website access according to categories such as malware or phishing?
- URL Filtering
- DHCP
- NAT
- NTP
Correct Answer: 1
Explanation
URL Filtering allows administrators to control website access based on URL categories, specific destinations, reputation, and configured policies. Organizations can use it to block malicious, phishing-related, inappropriate, or otherwise restricted web content. URL filtering is commonly provided through Secure Web Gateway functionality and can be centrally managed for users in different locations. DHCP provides network configuration, NAT translates addresses, and NTP synchronizes system clocks. URL Filtering is therefore the appropriate feature when website access must be controlled according to predefined content or security categories.
Question 370
Which information can be used to determine whether an endpoint satisfies Zero Trust security requirements?
- Keyboard language
- Screen size
- Device posture
- Monitor resolution
Correct Answer: 3
Explanation
Device posture represents the security and compliance state of an endpoint. A Zero Trust policy can evaluate posture information together with user identity and other contextual factors before granting access to protected resources. Depending on the integration, posture can include endpoint security status, operating system conditions, compliance state, or other required security attributes. Keyboard language, screen size, and monitor resolution do not normally provide meaningful security context. Device posture is therefore the relevant information for evaluating endpoint security before allowing application access.
Question 371
Which architecture provides cloud-delivered security services for distributed users and locations?
- Traditional LAN
- Standalone DHCP
- Security Service Edge
- Local-only routing
Correct Answer: 3
Explanation
Security Service Edge provides cloud-delivered security capabilities for users and resources distributed across different locations. Depending on the deployment, SSE can include Secure Web Gateway, Zero Trust Network Access, CASB, DLP, and other security functions. This architecture is useful for remote employees, branch offices, and mobile users because centralized policies can be delivered through cloud infrastructure. Traditional LANs, DHCP, and local routing provide networking services but do not represent the integrated cloud security architecture described. SSE is therefore the appropriate architecture for distributed cloud-based security enforcement.
Question 372
Which capability can identify unsanctioned SaaS applications used by employees?
- DLP
- DNS Security
- ZTNA
- CASB
Correct Answer: 4
Explanation
CASB provides visibility into cloud application usage and helps organizations identify unsanctioned or unapproved SaaS services. This capability can reveal shadow IT and allow security teams to assess security, privacy, and compliance risks associated with cloud applications. Once applications are identified, administrators can apply policies to monitor, permit, restrict, or block them according to organizational requirements. DLP focuses on sensitive information, DNS Security protects domain requests, and ZTNA provides private application access. CASB is therefore the appropriate capability for discovering and managing unsanctioned cloud applications.
Question 373
Which security capability can generate an alert when sensitive information is detected in monitored traffic?
- DLP
- Application Control
- DNS Security
- ZTNA
Correct Answer: 1
Explanation
DLP can inspect supported traffic for sensitive information using configured patterns, rules, classifications, or dictionaries. When protected data is detected, the DLP policy can generate an alert, create a log entry, block the transfer, or perform another configured action. This helps security teams identify potential data leakage and investigate policy violations. Application Control identifies applications, DNS Security protects domain requests, and ZTNA controls private application access. DLP is therefore the appropriate capability for detecting sensitive information and generating policy-based alerts.
Question 374
Which service provides centralized inspection and security policies for internet web traffic?
- CASB
- Secure Web Gateway
- DLP
- ZTNA
Correct Answer: 2
Explanation
Secure Web Gateway provides centralized inspection and policy enforcement for users accessing internet websites and web applications. It can support URL filtering, web categorization, malware protection, and application controls. This allows organizations to apply consistent web security policies regardless of user location. CASB focuses on cloud application security, DLP protects sensitive data, and ZTNA controls access to private applications. Secure Web Gateway is therefore the service most directly responsible for securing and controlling general internet web traffic within an SSE architecture.
Question 375
Which authentication method requires two or more authentication factors?
- Password-only authentication
- Guest access
- Multifactor authentication
- Anonymous access
Correct Answer: 3
Explanation
Multifactor authentication requires two or more authentication factors, typically from different categories such as knowledge, possession, and inherence. A password combined with a hardware token or biometric factor is a common example. MFA improves security because compromising a single factor may not be enough to gain access to protected resources. Password-only authentication relies on one factor, while guest and anonymous access do not provide the same identity assurance. Multifactor authentication is therefore the appropriate method when multiple authentication factors are required.
Question 376
Which feature allows different security policies to be applied according to authenticated user groups?
- Identity-based policy
- NAT
- Static routing
- DHCP
Correct Answer: 1
Explanation
Identity-based policies allow administrators to associate security controls with authenticated users, groups, roles, or other identity attributes. This makes it possible to give different departments or user groups different web access and application permissions. For example, contractors may receive more restrictive policies than employees, while administrators may receive privileged access according to their role. NAT translates addresses, static routing defines traffic paths, and DHCP provides network configuration. Identity-based policy is therefore the appropriate feature for enforcing security rules based on user identity and group membership.
Question 377
Which SSE component provides controlled access to private applications without granting broad network connectivity?
- CASB
- DLP
- ZTNA
- Secure Web Gateway
Correct Answer: 3
Explanation
ZTNA provides application-specific access to private resources instead of giving users unrestricted network connectivity. Before granting access, ZTNA can evaluate identity, authentication status, device posture, and other contextual conditions. This approach supports least privilege and reduces the exposure of unrelated internal systems. CASB manages cloud application security, DLP protects sensitive information, and Secure Web Gateway secures internet traffic. ZTNA is therefore the appropriate SSE component when private application access must be granular, policy-driven, and separated from broad network access.
Question 378
Which capability can protect sensitive information from being uploaded to unauthorized cloud destinations?
- DNS Security
- Application Control
- DLP
- DHCP
Correct Answer: 3
Explanation
DLP can inspect supported traffic for sensitive information and enforce policies governing how protected data is transferred. If a user attempts to upload confidential information to an unauthorized cloud service, DLP can detect the content and take an action such as blocking, logging, or alerting. DNS Security protects domain requests, Application Control identifies applications, and DHCP provides network configuration. DLP is therefore the capability most directly associated with preventing sensitive data from being uploaded to unauthorized destinations and reducing the risk of data leakage.
Question 379
Which capability allows a Zero Trust policy to evaluate the security state of an endpoint?
- URL Filtering
- Device Posture
- DNS Caching
- Traffic Shaping
Correct Answer: 2
Explanation
Device posture provides information about the security and compliance condition of an endpoint. Zero Trust policies can use posture information along with identity and other contextual factors when deciding whether access should be granted. Depending on the integration, posture can include endpoint protection status, operating system state, compliance information, or other security attributes. URL Filtering controls websites, DNS Caching stores domain-resolution information, and Traffic Shaping manages bandwidth. Device Posture is therefore the capability that supplies endpoint security context for Zero Trust access decisions.
Question 380
Which SSE capability provides centralized web security for remote users accessing internet resources?
- Secure Web Gateway
- CASB
- ZTNA
- DLP
Correct Answer: 1
Explanation
Secure Web Gateway provides centralized security controls for users accessing internet resources, including remote and mobile users. Through cloud-delivered SSE, administrators can apply URL filtering, web category policies, malware protection, and application controls regardless of where users connect. CASB focuses on cloud applications, ZTNA manages private application access, and DLP protects sensitive information. Secure Web Gateway is therefore the appropriate SSE capability for centrally securing internet access for distributed users.