NSE6_FWB-6.4 Exam Questions
65 real NSE6_FWB-6.4 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51Policy Configuration and Web Application Protection
What key factor must be considered when setting brute force rate limiting and blocking?
brute force rate limitingshared IPNATfalse positives - Question #52Deployment and Initial Configuration
Refer to the exhibits. FortiWeb is configured in reverse proxy mode and it is deployed downstream to FortiGate. Based on the configuration shown in the exhibits, which of the follo...
reverse proxyFortiGate integrationvirtual servernetwork topology - Question #53Deployment and Initial Configuration
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?
self-signed certificatePKIcertificate authorityActive Directory CA - Question #54Policy Configuration and Web Application Protection
In which scenario might you want to use the compression feature on FortiWeb?
HTTP compressionmobile usersbandwidth optimizationuse cases - Question #55Advanced Protection Features
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism. Which two functions does the first layer perform? (Choose two.)
machine learninganomaly detectionthreat modelingML phases - Question #56Deployment and Initial Configuration
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)
operation modespacket modificationtransparent proxyreverse proxy - Question #57Monitoring, Logging, and Reporting
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
X-Forwarded-ForXFF headerattack logsclient IP logging - Question #58Deployment and Initial Configuration
Which three statements about HTTPS on FortiWeb are true? (Choose three.)
TLS inspectionSSL re-encryptioncipher suitesHTTPS configuration - Question #59Policy Configuration and Web Application Protection
When user tracking is configured, how does FortiWeb identify which users to track?
user trackingauthenticated userssession managementuser identification - Question #60Advanced Protection Features
Which algorithm is used to build mathematical models for bot detection?
SVMbot detectionmachine learning algorithmmathematical model - Question #61Policy Configuration and Web Application Protection
A client is trying to start a session from a page that would normally be accessible only after the client has logged in. When a start page rule detects the invalid session access,...
start page rulessession managementHTTP response actionsaccess control - Question #62Advanced Protection Features
Refer to the exhibit. Many legitimate users are being identified as bots. FortiWeb bot detection has been configured with the settings shown in the exhibit. The FortiWeb administra...
bot detectionML modelbot confirmationfalse positives - Question #63Advanced Protection Features
What can an administrator do if a client has been incorrectly period blocked?
period blocktemporary blacklistIP blockingDoS protection - Question #65Policy Configuration and Web Application Protection
When FortiWeb triggers a redirect action, which two HTTP codes does it send to the client to inform the browser of the new URL? (Choose two.)
HTTP redirect301 redirect302 redirectstatus codes - Question #66Deployment and Initial Configuration
True transparent proxy mode is best suited for use in which type of environment?
true transparent proxydeployment modenetwork topologyIP addressing