{"id":17679,"date":"2026-09-21T10:53:28","date_gmt":"2026-09-21T10:53:28","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17679"},"modified":"2026-09-21T10:53:28","modified_gmt":"2026-09-21T10:53:28","slug":"fortinet-nse5_sse_ad-7-6-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse5_sse_ad-7-6-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Fortinet NSE5_SSE_AD-7.6 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse5-sse-ad-7-6-exam-dumps\"><b>Fortinet NSE5_SSE_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Which SSE capability provides application-level access to private resources according to user identity and device context?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust Network Access provides controlled access to private applications based on identity and contextual information. A ZTNA policy can evaluate factors such as user identity, authentication status, device posture, and application requirements before access is granted. Instead of providing broad network connectivity, users can be limited to the specific applications authorized by policy. DLP protects sensitive information, CASB focuses on cloud applications, and Secure Web Gateway secures internet traffic. ZTNA is therefore the appropriate SSE capability for secure, application-specific access to private resources.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which feature allows administrators to apply security policies based on authenticated users or groups?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity-based policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity-based policies associate security controls with authenticated users, groups, roles, or other identity attributes. This provides more granular access control than relying only on IP addresses or network locations. Organizations can create different web and application policies for employees, contractors, administrators, or other groups. NAT performs address translation, DHCP provides network configuration, and static routing controls fixed traffic paths. Identity-based policy is therefore the appropriate feature when security decisions need to reflect the authenticated identity or group membership of a user.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>Which SSE service provides visibility and policy enforcement for cloud applications?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Access Security Broker provides visibility, governance, and security controls for cloud applications such as SaaS services. CASB can help administrators identify applications, monitor their usage, and apply policies based on users, applications, and activities. This is useful for managing cloud adoption and identifying unsanctioned services. Secure Web Gateway primarily protects general web traffic, DLP focuses on sensitive data, and ZTNA controls private application access. CASB is therefore the appropriate SSE service for cloud application visibility and policy enforcement.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which security capability is designed to detect sensitive information and control its transmission?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention identifies sensitive information and applies policies governing how that information can be transmitted. DLP can inspect supported traffic for configured patterns, classifications, or other sensitive-data indicators. When protected information is detected, actions can include blocking, logging, or generating an alert. Application Control identifies applications, DNS Security protects domain requests, and ZTNA provides private application access. DLP is therefore the security capability specifically designed to reduce unauthorized disclosure of confidential or regulated information.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>Which principle ensures that users receive only the access necessary for their assigned responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege requires that users receive only the permissions and resources necessary to complete authorized tasks. This reduces unnecessary exposure and limits the potential impact of compromised accounts or devices. In a Zero Trust architecture, least privilege can be implemented by allowing access to specific applications instead of providing unrestricted network connectivity. Full trust, open access, and implicit trust allow broader permissions and do not follow the same restrictive security model. Least privilege is therefore an important principle for minimizing unnecessary access while supporting legitimate business operations.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which authentication factor represents something the user possesses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PIN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fingerprint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware token<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware token is a possession factor because the user must possess the token to authenticate. Passwords and PINs are knowledge factors because the user knows them, while a fingerprint is a biometric factor representing something the user is. Possession factors can be combined with knowledge or biometric factors to provide multifactor authentication. This strengthens authentication because an attacker who obtains only a password may still be unable to authenticate without the additional possession factor. Hardware tokens are therefore a common example of possession-based authentication.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>Which capability identifies applications in network traffic and allows administrators to enforce application-specific policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control identifies applications within network traffic and allows administrators to apply policies based on the detected application. This provides more granular visibility and control than relying only on IP addresses or ports. Organizations can use Application Control to permit, block, monitor, or restrict services such as streaming, messaging, file sharing, and other applications. DNS Security protects domain requests, DHCP provides network configuration, and NTP synchronizes system time. Application Control is therefore the appropriate capability for application-aware traffic identification and security policy enforcement.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which service can block access to domains associated with malware or phishing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS Security evaluates domain-name requests and applies security policies using threat intelligence, reputation information, or configured rules. If a requested domain is associated with malware, phishing, command-and-control activity, or another prohibited category, the request can be blocked or redirected. This can prevent users from reaching harmful destinations before a complete connection is established. CASB focuses on cloud applications, DLP protects sensitive information, and ZTNA controls private application access. DNS Security is therefore the appropriate service for blocking malicious domains at the DNS layer.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>Which feature can restrict website access according to predefined security categories?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">URL Filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">URL Filtering allows administrators to control website access using categories, specific URLs, reputation, and other configured policy conditions. Organizations can use it to block websites associated with malware, phishing, inappropriate content, or other restricted categories. URL Filtering is commonly provided through Secure Web Gateway functionality and can be centrally managed for users across different locations. DHCP provides network configuration, NAT performs address translation, and NTP synchronizes system clocks. URL Filtering is therefore the appropriate feature for applying category-based website access policies.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which capability can evaluate an endpoint&#8217;s security condition before granting access to a protected application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">URL filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device posture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device posture represents the security and compliance state of an endpoint. A Zero Trust policy can evaluate posture information together with user identity and other contextual factors before granting access to a protected application. Depending on the integration, posture can include endpoint security status, operating system conditions, compliance information, or other security attributes. URL filtering controls websites, DNS caching stores domain-resolution information, and traffic shaping manages bandwidth. Device posture is therefore the capability most directly associated with evaluating endpoint security during an access decision.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which architecture combines cloud-delivered security services for web access, private applications, cloud applications, and data protection?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traditional LAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standalone DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security Service Edge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Basic routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security Service Edge integrates multiple cloud-delivered security capabilities for distributed users and resources. Depending on the deployment, SSE can include Secure Web Gateway for internet security, ZTNA for private application access, CASB for cloud application security, and DLP for sensitive-data protection. This architecture is useful for remote workers, branch locations, and mobile users because security policies can be centrally managed through cloud infrastructure. Traditional LANs, DHCP, and basic routing provide networking functions but do not represent the integrated cloud security architecture described.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>Which capability can identify unsanctioned SaaS applications being used by employees?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CASB provides visibility into cloud application usage and can help organizations identify unapproved or unsanctioned SaaS services. This can reveal shadow IT and allow security teams to evaluate security, privacy, and compliance risks. Once applications are identified, administrators can establish policies to monitor, permit, restrict, or block them according to organizational requirements. DLP focuses on sensitive information, DNS Security protects domain requests, and ZTNA controls private application access. CASB is therefore the appropriate capability for discovering and managing unsanctioned cloud applications.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which security capability can generate an alert when sensitive information is detected in monitored traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DLP can inspect supported traffic for sensitive information using configured patterns, classifications, dictionaries, or other rules. When protected information is detected, DLP policies can generate alerts, create logs, block transfers, or take other configured actions. This helps security teams identify possible data leakage and investigate policy violations involving confidential information. Application Control identifies applications, DNS Security protects domain requests, and ZTNA controls private application access. DLP is therefore the capability most directly associated with detecting sensitive information and generating policy-based alerts.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>Which service provides centralized security inspection and control for internet-bound web traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Web Gateway provides centralized security inspection and policy enforcement for users accessing internet resources. It can support URL filtering, web category controls, malware protection, and application-aware policies. This allows organizations to apply consistent web security controls to users regardless of their physical location. DLP protects sensitive data, CASB focuses on cloud applications, and ZTNA controls private application access. Secure Web Gateway is therefore the service most directly responsible for securing and controlling users&#8217; general internet web traffic.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>Which authentication method requires two or more independent authentication factors?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password-only authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guest access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication requires two or more authentication factors, generally from different categories such as knowledge, possession, and inherence. A password combined with a hardware token or biometric factor is a common example. MFA strengthens authentication because compromising one factor alone may not be sufficient to gain access. Password-only authentication uses a single factor, while guest and anonymous access do not provide equivalent identity assurance. Multifactor authentication is therefore the appropriate method when multiple independent authentication factors are required.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>Which capability allows security policies to be associated with authenticated users or groups?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity-based policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity-based policies allow security controls to be associated with authenticated users, groups, roles, or other identity attributes. This enables organizations to apply different access rules according to user responsibilities and group membership. For example, employees, contractors, and administrators can receive different web or application policies. NAT translates addresses, DHCP provides network configuration, and static routing determines fixed traffic paths. Identity-based policy is therefore the appropriate capability for enforcing security decisions according to authenticated user identity and group membership.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which SSE component provides controlled access to private applications without giving users broad network connectivity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust Network Access provides application-level access to private resources rather than unrestricted network connectivity. A ZTNA policy can evaluate identity, authentication status, device posture, and other contextual conditions before allowing access to a specific application. This supports least privilege and limits exposure of unrelated internal systems. CASB manages cloud applications, Secure Web Gateway protects internet traffic, and DLP protects sensitive information. ZTNA is therefore the appropriate SSE component for controlled access to private applications while minimizing unnecessary network exposure.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>Which capability can prevent sensitive information from being uploaded to an unauthorized cloud destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DLP can inspect supported traffic for sensitive information and enforce policies governing how protected content is transferred. If a user attempts to upload confidential information to an unauthorized cloud destination, DLP can identify the sensitive content and take an action such as blocking, logging, or generating an alert. DNS Security protects domain requests, Application Control identifies applications, and DHCP provides network configuration. DLP is therefore the most appropriate capability for preventing sensitive information from being transferred to unauthorized cloud destinations.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>Which capability can use endpoint security information as part of a Zero Trust access decision?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device posture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">URL Filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device posture provides information about the security and compliance status of an endpoint. Zero Trust policies can evaluate this information together with identity and other contextual factors before granting access to protected applications. Depending on the integration, posture information can include endpoint security status, operating system conditions, compliance state, or other security attributes. URL Filtering controls website access, DNS Caching stores domain-resolution information, and Traffic Shaping manages bandwidth. Device Posture is therefore the appropriate capability for including endpoint security state in access decisions.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>Which SSE capability provides centralized web security policies for users accessing internet resources from remote locations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Web Gateway provides centralized security controls for users accessing internet resources, including remote and mobile users. Through cloud-delivered SSE, administrators can enforce URL filtering, web category policies, malware protection, and application controls regardless of the user&#8217;s physical location. CASB focuses on cloud applications, ZTNA manages private application access, and DLP protects sensitive information. Secure Web Gateway is therefore the appropriate SSE capability for centrally securing web access for distributed and remote users.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 Which SSE capability provides application-level access to private resources according to user identity and device context? DLP CASB ZTNA Secure Web Gateway Correct Answer: 3 Explanation Zero Trust Network Access provides controlled access to private applications based on identity and contextual information. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17679"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17679"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17679\/revisions"}],"predecessor-version":[{"id":17680,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17679\/revisions\/17680"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}