NSE6_FWB-6.4 Exam Questions
65 real NSE6_FWB-6.4 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Advanced Protection Features
Review the following configuration: What is the expected result of this configuration setting?
machine learningcollecting phasesample limitsML configuration - Question #2Policy Configuration and Web Application Protection
Which three statements about HTTPS on FortiWeb are true? (Choose three.)
HTTPSSNIHSTSTLS modes - Question #3Advanced Protection Features
What is one of the key benefits of the FortiGuard IP reputation feature?
IP reputationFortiGuardthreat intelligenceblocklist - Question #4Advanced Protection Features
How does FortiWeb protect against defacement attacks?
defacement protectionfile hashingintegrity monitoringweb server - Question #5Load Balancing and High Availability
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You wa...
HTTP content routingserver poolvirtual serverpolicy routing - Question #6Policy Configuration and Web Application Protection
When generating a protection configuration from an auto learning report what critical step must you do before generating the final protection configuration?
auto learningprotection profilefalse positivesreport generation - Question #7Deployment and Initial Configuration
How does an ADOM differ from a VDOM?
ADOMVDOMvirtual domainsmulti-tenancy - Question #8Monitoring, Logging, and Reporting
You are configuring FortiAnalyzer to store logs from FortiWeb. Which is true?
FortiAnalyzerADOMlog storageFortiWeb integration - Question #9Policy Configuration and Web Application Protection
Which of the following would be a reason for implementing rewrites?
URL rewritingredirectscontent routingHTTP manipulation - Question #10Advanced Protection Features
A client is trying to start a session from a page that should normally be accessible only after they have logged in. When a start page rule detects the invalid session access, what...
start page rulesession validationinvalid sessionaccess control - Question #11Policy Configuration and Web Application Protection
Which is true about HTTPS on FortiWeb? (Choose three.)
HTTPSSNItransparent modeRC4 - Question #12Policy Configuration and Web Application Protection
Which of the following is true about Local User Accounts?
local user accountsauthenticationsite publishingSSO - Question #13Deployment and Initial Configuration
In which operation mode(s) can FortiWeb modify HTTP packets? (Choose two.)
operation modesreverse proxytrue transparent proxypacket modification - Question #14Advanced Protection Features
What other consideration must you take into account when configuring Defacement protection
defacement protectionSQL injectiondatabase backuplayered security - Question #15Policy Configuration and Web Application Protection
Under what circumstances would you want to use the temporary uncompress feature of FortiWeb?
HTTP decompressioncontent inspectioncompression offloadtransparent inspection - Question #16Deployment and Initial Configuration
You are deploying FortiWeb 6.4 in an Amazon Web Services cloud. Which 2 lines of this initial setup via CLI are incorrect? (Choose two.)
AWS deploymentcloud setupCLI configurationinitial setup - Question #17Load Balancing and High Availability
How does offloading compression to FortiWeb benefit your network?
compression offloadingweb server resourcesperformancereverse proxy - Question #18Deployment and Initial Configuration
When the FortiWeb is configured in Reverse Proxy mode and the FortiGate is configured as an SNAT device, what IP address will the FortiGate's Real Server configuration point at?
reverse proxySNATreal server IPnetwork topology - Question #19Deployment and Initial Configuration
How does your FortiWeb configuration differ if the FortiWeb is upstream of the SNAT device instead of downstream of the SNAT device?
X-Forwarded-ForSNATupstream configurationsource IP - Question #20Load Balancing and High Availability
You are using HTTP content routing on FortiWeb. Requests for web app A should be forwarded to a cluster of web servers which all host the same web app. Requests for web app B shoul...
HTTP content routingpolicy chainingserver poolvirtual server - Question #21Deployment and Initial Configuration
In Reverse proxy mode, how does FortiWeb handle traffic that does not match any defined policies?
reverse proxy modedefault denytraffic policyunmatched traffic - Question #22Policy Configuration and Web Application Protection
You've configured an authentication rule with delegation enabled on FortiWeb. What happens when a user tries to access the web application?
authentication delegationFortiAuthenticatorHTTP challengeSSO - Question #23Monitoring, Logging, and Reporting
When integrating FortiWeb and FortiAnalyzer, why is the selection for FortiWeb Version critical? (Choose two)
FortiAnalyzer integrationlog file formatdatabase schemalogging configuration - Question #24Policy Configuration and Web Application Protection
What role does FortiWeb play in ensuring PCI DSS compliance?
PCI DSS complianceWAF requirementregulatory complianceweb application firewall - Question #25Deployment and Initial Configuration
Which operation mode does not require additional configuration in order to allow FTP traffic to your web server?
operation modesFTP traffictransparent inspectionnon-HTTP protocols - Question #26Deployment and Initial Configuration
Which implementation is best suited for a deployment that must meet compliance criteria?
SSL inspectionSSL offloadingcompliancereverse proxy mode - Question #27Policy Configuration and Web Application Protection
Which of the following FortiWeb features is part of the mitigation tools against OWASP A4 threats?
OWASP A4session managementbroken authenticationweb app protection - Question #28Policy Configuration and Web Application Protection
What capability can FortiWeb add to your Web App that your Web App may or may not already have?
HTTP form authenticationweb app capabilitiesauthentication offloadsite publishing - Question #29Advanced Protection Features
An e-commerce web app is used by small businesses. Clients often access it from offices behind a router, where clients are on an IPv4 private network LAN. You need to protect the w...
DoS protectionSYN cookiesrequest floodshared IP NAT - Question #30Deployment and Initial Configuration
Under which circumstances does FortiWeb use its own certificates? (Choose Two)
SSL certificatesHTTPScertificate managementGUI access - Question #31Advanced Protection Features
What benefit does Auto Learning provide?
auto learningrule generationtraffic profilingpolicy recommendations - Question #32Advanced Protection Features
Which two FortiWeb operation modes support machine learning? (Choose two.)
machine learningoperation modestrue transparent proxyreverse proxy - Question #33Deployment and Initial Configuration
In order for FortiWeb to provide the best possible protection for servers, how should you deploy it?
deployment topologyreverse proxy modeinline deploymentFortiGate integration - Question #34Deployment and Initial Configuration
In which two ways does FortiWeb handle traffic that does not match any defined policies? (Choose two.)
unmatched trafficreverse proxytransparent modedefault behavior - Question #35Deployment and Initial Configuration
Which operation mode requires additional configuration in order to allow FTP traffic into your web server?
operation modesFTP trafficreverse proxyadditional configuration - Question #36Monitoring, Logging, and Reporting
Which two statements about running a vulnerability scan are true? (Choose two.)
vulnerability scanningmaintenance windowtest environmentbest practices - Question #37Load Balancing and High Availability
FortiWeb offers the same load balancing algorithms as FortiGate. Which two Layer 7 switch methods does FortiWeb also offer? (Choose two.)
load balancingLayer 7 switchinground robinHTTP content routes - Question #38Policy Configuration and Web Application Protection
Which would be a reason to implement HTTP rewriting?
HTTP rewritingURL manipulationvirtual patchingrequest modification - Question #39Advanced Protection Features
Refer to the exhibit. FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address...
X-Forwarded-ForSNATsource IP trackingFortiADC integration - Question #40Policy Configuration and Web Application Protection
Which statement about local user accounts is true?
local user accountssite publishingSSOauthentication methods - Question #41Deployment and Initial Configuration
Refer to the exhibit. Based on the configuration, what would happen if this FortiWeb were to lose power? (Choose two.)
hardware bypassfail-openport pairspower failure - Question #42Policy Configuration and Web Application Protection
Refer to the exhibit. FortiWeb is configured to block traffic from Japan to your web application server. However, in the logs, the administrator is seeing traffic allowed from one...
geo-blockingIP reputationexception listsblacklist - Question #43Policy Configuration and Web Application Protection
Under which circumstance would you not use compression on FortiWeb?
HTTP compressionbufferingperformance optimizationoffloading - Question #44Deployment and Initial Configuration
In which operation mode does FortiWeb offer both the ability to offload SSL as well as re-encrypt SSL?
SSL offloadingSSL re-encryptionoperation modesreverse proxy - Question #45Policy Configuration and Web Application Protection
What are two advantages of using the URL rewriting and redirecting feature on FortiWeb? (Choose two.)
URL rewritingURL redirecttechnology disclosureman-in-the-middle - Question #46Monitoring, Logging, and Reporting
Which command allows you to temporarily terminate a process that is consuming excessive amounts of resources?
CLI commandsprocess managementdiagnosetroubleshooting - Question #47Advanced Protection Features
Which two statements about the anti-defacement feature on FortiWeb are true? (Choose two.)
anti-defacementchange detectionwebsite backupdatabase protection - Question #48Monitoring, Logging, and Reporting
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
PCI DSSlog maskingsensitive datacompliance - Question #49Monitoring, Logging, and Reporting
What role does FortiWeb play in ensuring PCI DSS compliance?
PCI DSSWAF complianceregulatory requirementsweb application firewall - Question #50Deployment and Initial Configuration
Refer to the exhibit. There is only one administrator account configured on FortiWeb. What must an administrator do to restrict any brute force attacks that attempt to gain access...
trusted hostsadmin access controlbrute force protectionmanagement GUI