Fortinet
NSE8_812 · Question #150
A data center for example.com hosts several separate web applications. Users authenticate with all of them by providing their Active Directory (AD) login credentials. You do not have access to…
The correct answer is C. Configure FortiWeb to query the AD server, and apply SSO for Web requests. Also configure it to scan FTPS and Web traffic, then forward allowed traffic to the Web servers. See the full explanation below for the reasoning.
Question
A data center for example.com hosts several separate web applications. Users authenticate with all of them by providing their Active Directory (AD) login credentials. You do not have access to example, inc.'s AD server. Your solution must do the following: - provide simple sign-on (SSO) for all protected Web applications - prevent login-brute-forcing - scan HTTPS connections to the Web servers for exploits - scan Webmail for OWASP Top 10 vulnerabilities such as session cookie hijacking, XSS, and SQL injection attacks Which solution meets these requirements?
Options
- AApply FortiGate deep inspection to FTPS. It must forward FTPS, HTTP, and HTTPS to FortiWeb. Configure FortiWeb to query the AD server, and apply SSO for Web requests. FortiWeb must forward FTPS directly to the Web servers without inspection, but proxy HTTP/HTTPS and block Web attacks.
- BDeploy FortiDDoS to block brute force attacks. Configure FortiGate to forward only FTPS, HTTP, and HTTPS to FortiWeb.
- CConfigure FortiWeb to query the AD server, and apply SSO for Web requests. Also configure it to scan FTPS and Web traffic, then forward allowed traffic to the Web servers.
- DConfigure FortiWeb to query the AD server, and apply SSO for Web requests. Also configure it to scan FTPS before forwarding, and to mitigate SYN floods. Configure FortiWeb to block Web attacks.
How the community answered
(28 responses)- A4% (1)
- B18% (5)
- C71% (20)
- D7% (2)
Community Discussion
No community discussion yet for this question.