FCP_FWB_AD-7.4 Exam Questions
75 real FCP_FWB_AD-7.4 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
Refer to the exhibit. A FortiWeb device is deployed upstream of a device performing source network address translation (SNAT) or load balancing. What configuration must you perform...
- Question #2
Refer to the exhibit. Attack ID 20000010 is brute force logins. Which statement is accurate about the potential attack?
- Question #3
Which three stages are part of creating a machine learning (ML) bot detection algorithm? (Choose three.)
- Question #4
Under which two circumstances does FortiWeb use its own certificates? (Choose two.)
- Question #5
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You wa...
- Question #6
What can a FortiWeb administrator do if a client has been incorrectly period blocked?
- Question #7
Which two functions does the first layer of the FortiWeb anomaly machine learning (ML) analysis mechanism perform? (Choose two.)
- Question #9
Which Layer 7 routing method does FortiWeb support?
- Question #10
Which command will enable debugging for the FortiWeb user tracking feature?
- Question #11
Refer to the exhibit. What is true about this FortiWeb device? (Choose two.)
- Question #12
Which high availability (HA) mode uses gratuitous Address Resolution Protocol (ARP) to advertise a failover event to neighboring network devices?
- Question #13
In SAML deployments, which server contains user authentication credentials (username/password)?
- Question #14
What are two possible impacts of a DoS attack on your web server? (Choose two.)
- Question #15
Which two items can be defined in a FortiWeb XML Protection Rule? (Choose two.)
- Question #16
Which two statements about running a vulnerability scan are true? (Choose two.)
- Question #17
An administrator notices multiple IP addresses attempting to log in to an application frequently, within a short time period. They suspect attackers are attempting to guess user pa...
- Question #18
Review the following configuration: Which result would you expect from this configuration setting?
- Question #19
Refer to the exhibit. What can you conclude from this support vector machine (SVM) plot of a potential bot connection?
- Question #20
What are two results of enabling monitor mode on FortiWeb? (Choose two.)
- Question #21
Which two objects are required to configure a server policy in reverse proxy mode without content routing? (Choose two.)
- Question #22
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?
- Question #23
Refer to the exhibit. Which statement is true?
- Question #24
How are bot machine learning (ML) models different from API or anomaly detection models?
- Question #25
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)
- Question #26
Which three security features must you configure on FortiWeb to protect API connections? (Choose three.)
- Question #27
Refer to the exhibit. FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address...
- Question #28
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?
- Question #29
In which scenario might you want to use the compression feature on FortiWeb?
- Question #30
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism. Which two functions does the first layer perform? (Choose two.)
- Question #31
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)
- Question #32
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
- Question #33
Which three statements about HTTPS on FortiWeb are true? (Choose three.)
- Question #34
When user tracking is configured, how does FortiWeb identify which users to track?
- Question #35
Which algorithm is used to build mathematical models for bot detection?
- Question #36
A client is trying to start a session from a page that would normally be accessible only after the client has logged in. When a start page rule detects the invalid session access,...
- Question #37
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- Question #38
What role does FortiWeb play in ensuring PCI DSS compliance?
- Question #39
In which operation mode does FortiWeb offer both the ability to offload SSL as well as re-encrypt SSL?
- Question #40
What are two advantages of using the URL rewriting and redirecting feature on FortiWeb? (Choose two.)
- Question #41
Which two statements about the anti-defacement feature on FortiWeb are true? (Choose two.)
- Question #42
Which implementation is most suited for a deployment that must meet PCI DSS compliance criteria?
- Question #43
Review the following configuration: What are two routing behaviors that you can expect on FortiWeb after this configuration change? (Choose two.)
- Question #44
An attacker attempts to send an SQL injection attack containing the known attack string 'root'; -- through an API call. Which FortiWeb inspection feature will be able to detect thi...
- Question #45
Refer to the exhibit. What are two additional configuration elements that you must be configure for this API gateway? (Choose two.)
- Question #46
Which would be a reason to implement HTTP rewriting?
- Question #47
What is the difference between an API gateway protection schema and a machine learning (ML) API protection schema?
- Question #48
Refer to the exhibits. What will happen when a client attempts a mousedown cross-site scripting highlighted signature?
- Question #49
Which high availability mode is commonly used to integrate with a traffic distributer like FortiADC?
- Question #50
A customer wants to be able to index your websites for search and advertisement purposes. What is the easiest way to allow this on a FortiWeb?
- Question #51
You can configure FortiWeb to send traffic to third-party IPS/IDS devices through network interfaces for traffic monitoring. Which two operation modes support this feature? (Choose...