Refer to the exhibit.You are a FortiWeb administrator. FortiWeb is deployed between a FortiGate and two back-end web servers, as shown in the diagram. No server policies are currently configured on FortiWeb.While testing, you notice that a student system in the 100.64.0.0/24 network is still able to access the back-end servers in 10.1.1.0/24, even though FortiWeb is not logging or inspecting the traffic.Which action should you take to ensure FortiWeb blocks or inspects all traffic before it reaches the back-end servers?
Answer(s): D
Disabling ip-forward prevents FortiWeb from acting as a simple Layer 3 forwarding device when no matching server policy exists. This ensures traffic cannot bypass FortiWeb inspection and will be blocked unless it matches a configured policy that allows FortiWeb to inspect or process it before reaching the back-end servers.
Which URL should you rewrite to reduce security risk?
Answer(s): A
The URL exposes a specific application version in the path. Rewriting it reduces information disclosure, making it harder for attackers to identify the application version and target known vulnerabilities.
You are setting up a FortiWeb policy to protect a customer login portal. Users connect to https:// login.training.lab, and you want FortiWeb to forward those requests to a load-balanced pool of back-end servers.Which three components must you configure to complete the server policy?
Answer(s): C
A FortiWeb server policy needs a virtual server to receive client traffic, a server pool to define the load-balanced back-end servers, and service/port settings so FortiWeb knows which traffic the policy should handle.
Refer to the exhibit.A FortiWeb administrator notices an alert triggered under the Threshold Based Detection category, with the message: Threshold Based Content Scraping Detection (Bot Detection) violation.Based on the log details, what is the most likely cause of this alert?
Threshold Based Content Scraping Detection indicates FortiWeb detected behavior consistent with automated content harvesting. This usually occurs when a client repeatedly or systematically accesses web pages in a pattern that exceeds configured thresholds, which is typical of a bot or scraping script attempting to extract site content.
Your e-commerce platform is experiencing frequent SQL injection attempts. You need FortiWeb to actively inspect, enforce, and block attacks inline before traffic reaches the web servers.The deployment must support the full FortiWeb security feature set without operational limitations, including protocol validation, attack detection, and policy enforcement.Which FortiWeb operation mode should you configure to proactively intercept and block threats such as SQL injection attempts?
Reverse proxy mode places FortiWeb inline as the termination point for client connections and allows it to fully inspect, validate, enforce policies, and block malicious requests before they reach the protected web servers. This mode provides the most complete FortiWeb security capability for proactively stopping SQL injection and other application-layer attacks.
Refer to the exhibit.A FortiWeb administrator tests a new form input value after training the machine learning (ML) anomaly detection system.The hidden Markov model (HMM) flags the input as abnormal, while the support vector machine (SVM) model classifies it as normal. FortiWeb allows the request.What does this result indicate about the FortiWeb ML anomaly detection behavior?
FortiWeb ML anomaly detection uses multiple models to evaluate whether input is truly malicious or simply unusual. In this case, the input appears abnormal to the HMM pattern model, but the SVM classification considers it acceptable, so FortiWeb treats it as normal and allows the request.
A third-party penetration test reveals that users can bypass login controls through a mobile API. Your current FortiWeb configuration includes zero trust network access (ZTNA) profiles and cookie security, but API protection and client management are not enabled. The security team asks you to recommend the most effective way to close this gap.Which FortiWeb adjustment would best prevent future unauthorized API access?
Answer(s): B
API protection and client management are designed to control and validate access to API endpoints, including mobile API traffic. Enabling them allows FortiWeb to apply identity-aware checks, manage API clients, and prevent unauthorized access paths that are not adequately protected by cookie security alone.
Which statement best describes the difference between SAML authentication and HTML authentication in FortiWeb site publishing?
SAML authentication relies on an external identity provider to authenticate the user and return an assertion to FortiWeb. HTML authentication uses a FortiWeb-hosted login page or form-based authentication process where FortiWeb directly handles the user login workflow for the published site.
Share your comments for Fortinet NSE5_FWB_AD-8.0 exam with other users:
for question 4, the righr answer is :recover automatically from failures
question number 4s answer is 3, option c. i
very good questions
i am confused about the answers to the questions. are the answers correct?
very usefull
need certification.
great exam prep
i require dump
good morning, could you please upload this exam again,
hi can you please upload the dumps for sap contingent module. thanks
good questions
looking forward to the real exam
good ones for exam preparation
this is a good experience
hi everyone
waiting for the dump. please upload.
upload cks exam questions
awesome training material
where is dump
q. 289 - the correct answer should be b not d, since the question asks for the most secure way to provide access to a s3 bucket (a single one), and by principle of the least privilege you should not be giving access to all buckets.
please i need if possible h12-831,
good collection of questions and solution for pl500 certification
i would like to appear the exam.
i am very happy as i cleared my comptia a+ 220-1101 exam. i studied from as it has all exam dumps and mock tests available. i got 91% on the test.
need this dump
its really good to eventuate knowledge before appearing for the actual exam.
this is great
please i want the questions to pass the exam
i need to pass exam
great, i appreciate it.
please could you upload (isc)2 certified in cybersecurity (cc) exam questions
good questions, wrong answers
im preparing for exams
question no: 42 isnt azure vm an iaas solution? so, shouldnt the answer be "no"?