[2023] Use Valid New NSE6_FWB-6.4 Questions - Top choice Help You Gain Success [Q32-Q54]

Share

[2023] Use Valid New NSE6_FWB-6.4 Questions - Top choice Help You Gain Success

NSE6_FWB-6.4 Exam Practice Materials Collection


Fortinet NSE6_FWB-6.4 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Troubleshoot threat detection and mitigation related issues
  • Identify FortiWeb deployment requirements
Topic 2
  • Troublehsoot application delivery related issues
  • Configure various threat mitigation features
Topic 3
  • Encryption, Authentication, and Compliance
  • Mitigate web application vulnerabilities
Topic 4
  • Configure various access control and tracking methods
  • Troubleshoot deployment and system related issues
Topic 5
  • Configure machine learning and bot detection
  • Configure SSL inspection and offloading
Topic 6
  • Configure API protection and bot mitigation
  • Configure caching and compression

 

NEW QUESTION 32
Which operation mode does not require additional configuration in order to allow FTP traffic to your web server?

  • A. Transparent Inspection
  • B. Offline Protection
  • C. Reverse-Proxy
  • D. True Transparent Proxy

Answer: A

 

NEW QUESTION 33
When generating a protection configuration from an auto learning report what critical step must you do before generating the final protection configuration?

  • A. Activate the report to create t profile
  • B. Drill down in the report to correct any false positives.
  • C. Restart the FortiWeb to clear the caches
  • D. Take the FortiWeb offline to apply the profile

Answer: B

 

NEW QUESTION 34
You are deploying FortiWeb 6.4 in an Amazon Web Services cloud. Which 2 lines of this initial setup via CLI are incorrect? (Choose two.)

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B,C

 

NEW QUESTION 35
What other consideration must you take into account when configuring Defacement protection

  • A. Use FortiWeb to block SQL Injections and keep regular backups of the Database
  • B. Configure the FortiGate to perform Anti-Defacement as well
  • C. None. FortiWeb completely secures the site against defacement attacks
  • D. Also incorporate a FortiADC into your network

Answer: A

 

NEW QUESTION 36
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?

  • A. If you are an enterprise whose resources do not need security
  • B. If you are an enterprise whose employees use only mobile devices
  • C. If you are a small business or home office
  • D. If you are an enterprise whose computers all trust your active directory or other CA server

Answer: D

 

NEW QUESTION 37
Which statement about local user accounts is true?

  • A. They are best suited for large environments with many users.
  • B. They must be assigned, regardless of any other authentication.
  • C. They can be used for SSO.
  • D. They cannot be used for site publishing.

Answer: D

 

NEW QUESTION 38
When FortiWeb triggers a redirect action, which two HTTP codes does it send to the client to inform the browser of the new URL? (Choose two.)

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A,C

 

NEW QUESTION 39
Which of the following would be a reason for implementing rewrites?

  • A. Page has been moved to a new URL
  • B. Send connection to secure channel
  • C. Page has been moved to a new IP address
  • D. Replace vulnerable functions.

Answer: D

 

NEW QUESTION 40
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)

  • A. Display an access policy message, then allow the client to continue
  • B. Allow the page access, but log the violation
  • C. Redirect the client to the login page
  • D. Reply with a 403 Forbidden HTTP error
  • E. Prompt the client to authenticate

Answer: B,C,D

 

NEW QUESTION 41
Refer to the exhibit.

There is only one administrator account configured on FortiWeb. What must an administrator do to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?

  • A. Configure IPv4 Trusted Host # 3 with a specific IP address.
  • B. Delete the built-in administrator user and create a new one.
  • C. Change the Access Profile to Read_Only.
  • D. The configuration changes must be made on the upstream device.

Answer: A

 

NEW QUESTION 42
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?

  • A. FortiWeb IP
  • B. Client real IP
  • C. FortiGate local IP
  • D. FortiGate public IP

Answer: B

Explanation:
Explanation
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.

 

NEW QUESTION 43
What capability can FortiWeb add to your Web App that your Web App may or may not already have?

  • A. High Availability
  • B. Automatic backup and recovery
  • C. HTTP/HTML Form Authentication
  • D. SSL Inspection

Answer: C

 

NEW QUESTION 44
You are configuring FortiAnalyzer to store logs from FortiWeb.
Which is true?

  • A. FortiWeb will query FortiAnalyzer for reports, instead of generating them locally.
  • B. To store logs from FortiWeb 6.4, on FortiAnalyzer, you must select "FrotiWeb 6.1".
  • C. You must enable ADOMs on FortiAnalyzer.
  • D. FortiAnalyzer will store antivirus and DLP archives from FortiWeb.

Answer: C

 

NEW QUESTION 45
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?

  • A. Static or policy-based routes are not required.
  • B. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
  • C. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
  • D. The server policy applies the same protection profile to all of its protected web applications.

Answer: A

 

NEW QUESTION 46
Refer to the exhibits.


FortiWeb is configured in reverse proxy mode and it is deployed downstream to FortiGate. Based on the configuration shown in the exhibits, which of the following statements is true?

  • A. The configuration is incorrect. FortiWeb should always be located upstream to FortiGate.
  • B. FortiGate should forward web traffic to virtual server IP address.
  • C. FortiGate should forward web traffic to the server pool IP addresses.
  • D. You must disable the Preserve Client IP setting on FotriGate for this configuration to work.

Answer: B

 

NEW QUESTION 47
You've configured an authentication rule with delegation enabled on FortiWeb.
What happens when a user tries to access the web application?

  • A. FortiWeb forwards the HTTP challenge from the server to the client, then monitors the reply, allowing access if the user authenticates successfully
  • B. ForitWeb redirects the user to the web app's authentication page
  • C. FrotiWeb redirects users to a FortiAuthenticator page, then if the user authenticates successfully, FortiGate signals to FortiWeb to allow access to the web app
  • D. FortiWeb replies with a HTTP challenge of behalf of the server, the if the user authenticates successfully, FortiWeb allows the request and also includes credentials in the request that it forwards to the web app

Answer: C

 

NEW QUESTION 48
Which implementation is best suited for a deployment that must meet compliance criteria?

  • A. SSL Inspection with FortiWeb in Transparency mode
  • B. SSL Inspection with FrotiWeb in Reverse Proxy mode
  • C. SSL Offloading with FortiWeb in Transparency Mode
  • D. SSL Offloading with FortiWeb in reverse proxy mode

Answer: B

 

NEW QUESTION 49
What can an administrator do if a client has been incorrectly period blocked?

  • A. Force a new IP address to the client.
  • B. Manually release the ID address from the temporary blacklist.
  • C. Nothing, it is not possible to override a period block.
  • D. Disconnect the client from the network.

Answer: B

Explanation:
Explanation
Block Period
Enter the number of seconds that you want to block the requests. The valid range is 1-3,600 seconds. The default value is 60 seconds.
This option only takes effect when you choose Period Block in Action.
Note: That's a temporary blacklist so you can manually release them from the blacklist.

 

NEW QUESTION 50
Which two statements about the anti-defacement feature on FortiWeb are true? (Choose two.)

  • A. Anti-defacement does not make a backup copy of your databases.
  • B. Anti-defacement can redirect users to a backup web server, if it detects a change.
  • C. FortiWeb will only check to see if there are changes on the web server; it will not download the whole file each time.
  • D. Anti-defacement downloads a copy of your website to RAM, in order to restore a clean image, if it detects defacement.

Answer: A,C

Explanation:
Explanation
Anti-defacement backs up web pages only, not databases.
If it detects any file changes, the FortiWeb appliance will download a new backup revision.

 

NEW QUESTION 51
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.
Which two functions does the first layer perform? (Choose two.)

  • A. Builds a threat model behind every parameter and HTTP method
  • B. Determines whether traffic is an anomaly, based on observed application traffic over time
  • C. Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored
  • D. Determines if a detected threat is a false-positive or not

Answer: A,B

Explanation:
Explanation
The first layer uses the Hidden Markov Model (HMM) and monitors access to the application and collects data to build a mathematical model behind every parameter and HTTP method.

 

NEW QUESTION 52
Refer to the exhibit.

FortiWeb is configured to block traffic from Japan to your web application server. However, in the logs, the administrator is seeing traffic allowed from one particular IP address which is geo-located in Japan.
What can the administrator do to solve this problem? (Choose two.)

  • A. If the IP address is configured as a geo reputation exception, remove it.
  • B. If the IP address is configured as an IP reputation exception, remove it.
  • C. Configure the IP address as a blacklisted IP address.
  • D. Manually update the geo-location IP addresses for Japan.

Answer: A,C

 

NEW QUESTION 53
You are using HTTP content routing on FortiWeb. Requests for web app A should be forwarded to a cluster of web servers which all host the same web app. Requests for web app B should be forwarded to a different, single web server.
Which is true about the solution?

  • A. Static or policy-based routes are not required.
  • B. To achieve HTTP content routing, you must chain policies: the first policy accepts all traffic, and forwards requests for web app A to the virtual server for policy A. It also forwards requests for web app B to the virtual server for policy B. Policy A and Policy B apply their app-specific protection profiles, and then distribute that app's traffic among all members of the server farm.
  • C. You must put the single web server into a server pool in order to use it with HTTP content routing.
  • D. The server policy applies the same protection profile to all its protected web apps.

Answer: B

 

NEW QUESTION 54
......

Maximum Grades By Making ready With NSE6_FWB-6.4 Dumps: https://www.exam4labs.com/NSE6_FWB-6.4-practice-torrent.html

Get Latest and 100% Accurate NSE6_FWB-6.4 Exam Questions: https://drive.google.com/open?id=1AGI8ek6g20_-Xnai-a75SdScCqwUYLFB