nerdexam
Fortinet

FCP_FWB_AD-7.4 · Question #17

An administrator notices multiple IP addresses attempting to log in to an application frequently, within a short time period. They suspect attackers are attempting to guess user passwords for a…

The correct answer is B. Configure a brute force login custom policy. The best way to limit brute force login attacks on FortiWeb is to configure a brute force login custom policy. FortiWeb provides the ability to detect and mitigate brute force login attempts by automatically limiting the number of failed login attempts within a specific time…

Incidents and Remediation

Question

An administrator notices multiple IP addresses attempting to log in to an application frequently, within a short time period. They suspect attackers are attempting to guess user passwords for a secure application. What is the best way to limit this type of attack on FortiWeb, while still allowing legitimate traffic through?

Options

  • ABlocklist any suspected IPs.
  • BConfigure a brute force login custom policy.
  • CRate limit all connections from suspected IP addresses.
  • DBlock the IP address at the border router.

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    81% (30)
  • C
    11% (4)
  • D
    5% (2)

Explanation

The best way to limit brute force login attacks on FortiWeb is to configure a brute force login custom policy. FortiWeb provides the ability to detect and mitigate brute force login attempts by automatically limiting the number of failed login attempts within a specific time period. This approach allows you to block or rate limit suspicious IP addresses while still allowing legitimate users access, based on your configuration.

Topics

#brute force login#custom policy#attack mitigation#FortiWeb rate limiting

Community Discussion

No community discussion yet for this question.

Full FCP_FWB_AD-7.4 Practice