Fortinet NSE5_SSE_AD-7.6 Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 121

Which SSE capability is most appropriate for controlling access to private applications based on user identity and device context?

  1. DNS Security
  2. Secure Web Gateway
  3. CASB
  4. ZTNA

Correct Answer: 4

Explanation

Zero Trust Network Access is designed to provide secure, application-specific access based on identity and contextual security information. A ZTNA policy can evaluate the user’s identity, authentication status, device posture, and other conditions before allowing access to a private application. This is different from traditional network access methods that may provide broad connectivity after authentication. DNS Security protects domain requests, Secure Web Gateway secures web traffic, and CASB provides cloud application security. ZTNA is therefore the most appropriate SSE capability for controlled access to private applications based on identity and device context.

Question 122

Which security service is primarily responsible for applying web filtering and URL-based access policies?

  1. CASB
  2. Secure Web Gateway
  3. DLP
  4. ZTNA

Correct Answer: 2

Explanation

Secure Web Gateway provides centralized inspection and control of users’ web traffic. It can enforce URL filtering, web categories, malware protection, and other web access policies according to organizational requirements. Administrators can use SWG policies to block malicious, inappropriate, or unauthorized websites. CASB focuses on cloud applications, DLP focuses on sensitive information, and ZTNA provides access to private applications. Therefore, Secure Web Gateway is the service most directly responsible for web filtering and URL-based access control in an SSE architecture.

Question 123

Which capability can detect sensitive information in traffic and apply a policy such as blocking or logging the transfer?

  1. DLP
  2. DHCP
  3. NAT
  4. NTP

Correct Answer: 1

Explanation

Data Loss Prevention can inspect supported traffic for sensitive information using configured patterns, rules, dictionaries, or classifications. When a match is detected, DLP policies can specify actions such as allowing the transfer, blocking it, logging the event, or generating an alert. This helps organizations protect confidential business information, personal data, and other sensitive content. DHCP provides network configuration, NAT translates addresses, and NTP synchronizes system time. DLP is therefore the capability designed to identify sensitive information and enforce policies around its transmission.

Question 124

Which technology provides visibility and policy enforcement for cloud applications such as SaaS services?

  1. DNS Security
  2. ZTNA
  3. CASB
  4. DHCP

Correct Answer: 3

Explanation

Cloud Access Security Broker provides visibility, governance, and security controls for cloud applications. CASB can help organizations identify cloud services in use, monitor activity, and apply policies based on users, applications, and other supported conditions. This is especially valuable when employees rely on multiple SaaS platforms from different locations. DNS Security handles domain-level protection, ZTNA controls private application access, and DHCP provides network configuration. CASB is therefore the appropriate technology for improving visibility and policy enforcement across cloud applications.

Question 125

What does the principle of least privilege require in a Zero Trust environment?

  1. Every authenticated user receives full network access
  2. Users receive only the access required for their tasks
  3. Internal users are automatically trusted
  4. All applications are exposed to the internet

Correct Answer: 2

Explanation

Least privilege means granting a user only the permissions and application access necessary to perform authorized tasks. This principle reduces unnecessary exposure and limits the potential impact of compromised accounts or devices. In Zero Trust environments, access can be limited to specific applications rather than providing broad network connectivity. Automatically trusting internal users or granting full network access conflicts with the least-privilege approach. Exposing applications to the internet also does not represent least privilege. Restricting permissions according to actual business requirements is therefore the core principle.

Question 126

Which capability can identify the applications being used so administrators can create application-specific security policies?

  1. DNS Filtering
  2. DLP
  3. ZTNA
  4. Application Control

Correct Answer: 4

Explanation

Application Control identifies applications in network traffic and enables administrators to apply policies based on those applications. This can provide more precise control than using only IP addresses or network ports. Administrators can use application control to monitor, allow, restrict, or block applications according to security and acceptable-use requirements. DNS Filtering is focused on domain requests, DLP protects sensitive information, and ZTNA controls private application access. Application Control is therefore the appropriate capability for application-aware traffic identification and policy enforcement.

Question 127

Which factor can be evaluated to determine whether an endpoint meets security requirements before access is granted?

  1. Device posture
  2. Screen size
  3. Keyboard type
  4. Monitor resolution

Correct Answer: 1

Explanation

Device posture represents the security and compliance state of an endpoint. A Zero Trust policy can use posture information to determine whether the endpoint satisfies organizational requirements before allowing access to protected resources. Depending on the integration, posture can include operating system state, endpoint protection status, compliance information, or other security attributes. Screen size, keyboard type, and monitor resolution do not normally provide useful security information. Device posture is therefore the relevant factor for evaluating endpoint security as part of an access decision.

Question 128

Which security service can block access to a domain associated with phishing or malware?

  1. CASB
  2. DLP
  3. DNS Security
  4. Application Control

Correct Answer: 3

Explanation

DNS Security can inspect domain requests and compare destinations against security intelligence and configured policies. When a domain is associated with phishing, malware, command-and-control activity, or another prohibited category, the request can be blocked or redirected. This provides an early security control because the malicious destination can be prevented before the user establishes a complete connection. CASB protects cloud applications, DLP protects sensitive information, and Application Control identifies applications. DNS Security is therefore the appropriate service for blocking known malicious or prohibited domains.

Question 129

What is a major benefit of cloud-delivered SSE services for remote users?

  1. Security policies can be applied without requiring all traffic to return to a central data center
  2. Users no longer require authentication
  3. All applications must be installed locally
  4. Internet access is disabled

Correct Answer: 4

Explanation

Cloud-delivered SSE services allow organizations to apply security controls through cloud infrastructure rather than requiring every remote user’s traffic to be sent through a central corporate data center. This can simplify security enforcement for distributed users and provide protection closer to where users connect. Authentication remains important, and applications do not need to be installed locally. Internet access also does not need to be disabled. The main architectural benefit is that security services can be delivered through cloud points of presence while maintaining centralized policy control.

Question 130

Which authentication method represents something the user is?

  1. Fingerprint
  2. Password
  3. Security token
  4. PIN

Correct Answer: 1

Explanation

A fingerprint is a biometric authentication factor and represents something the user is. Authentication factors are commonly divided into knowledge, possession, and inherence categories. Passwords and PINs are knowledge factors because the user knows them, while a security token represents a possession factor because the user has it. Biometrics such as fingerprints provide an inherence factor based on a physical characteristic. Combining a biometric factor with another authentication factor can provide multifactor authentication and improve protection against stolen credentials.

Question 131

Which feature allows different web access rules to be assigned to different authenticated user groups?

  1. NAT
  2. Identity-based policy
  3. Static routing
  4. DHCP

Correct Answer: 2

Explanation

Identity-based policies allow administrators to associate security controls with authenticated users or groups. This makes it possible to apply different web access rules according to organizational roles, responsibilities, or group membership. For example, employees, contractors, and administrators may receive different website access policies. NAT performs address translation, static routing defines fixed paths, and DHCP provides network configuration. Identity-based policy is therefore the appropriate feature when web security rules need to be applied according to the authenticated user’s identity or group.

Question 132

Which SSE component can help identify unsanctioned SaaS applications used within an organization?

  1. Secure Web Gateway
  2. ZTNA
  3. CASB
  4. DLP

Correct Answer: 3

Explanation

CASB provides visibility into cloud application usage and can help organizations discover unsanctioned SaaS services. These applications may create security, privacy, or compliance concerns if they have not been evaluated or approved. CASB capabilities can help administrators identify cloud applications and then apply appropriate policies, such as monitoring, restricting, or blocking specific services. Secure Web Gateway focuses on web traffic, ZTNA provides private application access, and DLP protects sensitive information. CASB is therefore the appropriate SSE component for identifying and managing unauthorized cloud application usage.

Question 133

Which principle prevents a user from automatically receiving access to every internal resource after authentication?

  1. Least privilege
  2. Open access
  3. Implicit trust
  4. Full network access

Correct Answer: 1

Explanation

Least privilege ensures that authentication does not automatically result in unrestricted access. Instead, users receive only the permissions necessary for their authorized tasks. In Zero Trust environments, this can mean allowing access to specific private applications while denying access to unrelated resources. Open access and full network access provide broader permissions, while implicit trust assumes that authentication alone is sufficient for access. Least privilege therefore helps limit lateral movement and reduce exposure if a user’s credentials or endpoint become compromised.

Question 134

Which security service can inspect internet traffic and apply policies to websites and web applications?

  1. CASB
  2. DLP
  3. DNS Security
  4. Secure Web Gateway

Correct Answer: 4

Explanation

Secure Web Gateway is designed to inspect and control internet-bound web traffic. It can apply URL filtering, web category policies, malware protection, application controls, and other security measures according to the organization’s configuration. This provides centralized protection for users accessing internet resources from different locations. CASB focuses on cloud applications, DLP protects sensitive information, and DNS Security primarily evaluates domain requests. Secure Web Gateway is therefore the most appropriate SSE service for inspecting websites and web applications and enforcing internet access policies.

Question 135

Which capability can control access to cloud applications based on user activity and organizational policy?

  1. DHCP
  2. DNS Security
  3. CASB
  4. NAT

Correct Answer: 3

Explanation

CASB provides cloud application security and can support policy enforcement based on application usage and user activity. Organizations can use CASB to gain visibility into SaaS usage and establish controls that align with security or compliance requirements. This can help manage activities involving sanctioned and unsanctioned cloud services. DHCP assigns network parameters, DNS Security protects domain requests, and NAT translates addresses. CASB is therefore the capability most closely associated with monitoring and controlling cloud application activity according to organizational policy.

Question 136

What is the purpose of multifactor authentication?

  1. Allow anonymous access
  2. Require multiple authentication factors
  3. Eliminate authorization policies
  4. Provide unrestricted network access

Correct Answer: 2

Explanation

Multifactor authentication requires users to provide two or more authentication factors, typically from different categories such as knowledge, possession, and inherence. For example, a password can be combined with a security token or biometric factor. MFA improves security because an attacker who obtains one credential may still be unable to authenticate without the additional factor. MFA does not provide anonymous access, eliminate authorization policies, or grant unrestricted network access. Its purpose is to strengthen identity verification by requiring multiple independent authentication factors.

Question 137

Which FortiSASE function can enforce policies according to the actual application identified in network traffic?

  1. DHCP
  2. DNS Security
  3. DLP
  4. Application Control

Correct Answer: 4

Explanation

Application Control identifies applications in network traffic and allows administrators to apply policies based on the detected application. This is useful when organizations need to control specific services such as streaming, file sharing, messaging, or other applications. Application-based policies can provide more precise security controls than relying only on ports or IP addresses. DHCP provides network configuration, DNS Security protects domain requests, and DLP focuses on sensitive information. Application Control is therefore the appropriate FortiSASE function for application-aware security policy enforcement.

Question 138

Which capability helps determine whether an endpoint is compliant before it can access a protected application?

  1. Device posture
  2. URL filtering
  3. DNS caching
  4. Traffic shaping

Correct Answer: 1

Explanation

Device posture provides information about an endpoint’s security and compliance status. In a Zero Trust architecture, this information can be used to evaluate whether a device should be permitted to access a protected application. Organizations may define requirements related to endpoint protection, operating system condition, or other compliance attributes. If the endpoint fails the required checks, access can be restricted or denied. URL filtering controls websites, DNS caching stores domain-resolution information, and traffic shaping manages bandwidth. Device posture is therefore the appropriate capability for evaluating endpoint compliance.

Question 139

Which service is specifically designed to protect sensitive data from unauthorized transfer?

  1. Secure Web Gateway
  2. CASB
  3. DLP
  4. ZTNA

Correct Answer: 3

Explanation

Data Loss Prevention is specifically designed to identify and protect sensitive information from unauthorized transmission. DLP policies can inspect supported traffic for configured data patterns and take actions such as blocking, logging, or alerting when sensitive information is detected. This can help protect confidential documents, personal information, intellectual property, and other regulated data. Secure Web Gateway protects web traffic, CASB manages cloud application security, and ZTNA controls private application access. DLP is therefore the service most directly associated with preventing unauthorized transfer of sensitive data.

Question 140

Which SSE capability can provide security enforcement for users working from branch offices, homes, or other remote locations?

  1. Local-only firewall
  2. Standalone DHCP
  3. Traditional LAN switching
  4. Cloud-delivered SSE

Correct Answer: 4

Explanation

Cloud-delivered SSE provides security services through cloud infrastructure and can enforce policies for users regardless of their physical location. This is particularly useful for organizations with remote workers, branch offices, and mobile users. Security controls such as web filtering, Zero Trust access, cloud application protection, and data protection can be centrally managed and delivered through cloud security points of presence. Local-only firewalls and traditional LAN switching are more dependent on a specific network location, while DHCP provides addressing rather than comprehensive security. Cloud-delivered SSE therefore supports consistent security enforcement for distributed users.