Vcehome > Fortinet > NSE 6 Network Security Specialist > NSE6_FWB-6.0 > NSE6_FWB-6.0 Online Practice Questions and Answers

NSE6_FWB-6.0 Online Practice Questions and Answers

Questions 4

What can an administrator do if a client has been incorrectly Period Blocked?

A. Disconnect the client from the network

B. Manually release the IP from the temporary Blacklist

C. Nothing, it is not possible to override a Period Block

D. Force a new IP address to the client.

Browse 30 Q&As
Questions 5

When generating a protection configuration from an auto learning report what critical step must you do before generating the final protection configuration?

A. Restart the FortiWeb to clear the caches

B. Drill down in the report to correct any false positives.

C. Activate the report to create t profile

D. Take the FortiWeb offline to apply the profile

Browse 30 Q&As
Questions 6

You are configuring FortiAnalyzer to store logs from FortiWeb. Which is true?

A. FortiAnalyzer will store antivirus and DLP archives from FortiWeb.

B. You must enable ADOMs on FortiAnalyzer.

C. To store logs from FortiWeb 6.0, on FortiAnalyzer, you must select "FrotiWeb 5.4".

D. FortiWeb will query FortiAnalyzer for reports, instead of generating them locally.

Browse 30 Q&As
Questions 7

A client is trying to start a session from a page that should normally be accessible only after they have

logged in.

When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)

A. Reply with a "403 Forbidden" HTTP error

B. Allow the page access, but log the violation

C. Automatically redirect the client to the login page

D. Display an access policy message, then allow the client to continue, redirecting them to their requested page

E. Prompt the client to authenticate

Browse 30 Q&As
Questions 8

Which is true about HTTPS on FortiWeb? (Choose three.)

A. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.

B. After enabling HSTS, redirects to HTTPS are no longer necessary.

C. In true transparent mode, the TLS session terminator is a protected web server.

D. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.

E. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.

Browse 30 Q&As
Questions 9

When the FortiWeb is configured in Reverse Proxy mode and the FortiGate is configured as an SNAT device, what IP address will the FortiGate's Real Server configuration point at?

A. Virtual Server IP on the FortiGate

B. Server's real IP

C. FortiWeb's real IP

D. IP Address of the Virtual Server on the FortiWeb

Browse 30 Q&As
Questions 10

What role does FortiWeb play in ensuring PCI DSS compliance?

A. PCI specifically requires a WAF

B. Provides credit card processing capabilities

C. Provide ability to securely process cash transactions

D. Provides load balancing between multiple web servers

Browse 30 Q&As
Questions 11

Which operation mode does not require additional configuration in order to allow FTP traffic to your web server?

A. Offline Protection

B. Transparent Inspection

C. True Transparent Proxy

D. Reverse-Proxy

Browse 30 Q&As
Questions 12

Which implementation is best suited for a deployment that must meet compliance criteria?

A. SSL Inspection with FortiWeb in Transparency mode

B. SSL Offloading with FortiWeb in reverse proxy mode

C. SSL Inspection with FrotiWeb in Reverse Proxy mode

D. SSL Offloading with FortiWeb in Transparency Mode

Browse 30 Q&As
Questions 13

An e-commerce web app is used by small businesses. Clients often access it from offices behind a router,

where clients are on an IPv4 private network LAN. You need to protect the web application from denial of

service attacks that use request floods.

What FortiWeb feature should you configure?

A. Enable "Shared IP" and configure the separate rate limits for requests from NATted source IPs.

B. Configure FortiWeb to use "X-Forwarded-For:" headers to find each client's private network IP, and to block attacks using that.

C. Enable SYN cookies.

D. Configure a server policy that matches requests from shared Internet connections.

Browse 30 Q&As
Exam Code: NSE6_FWB-6.0
Exam Name: Fortinet NSE 6 - FortiWeb 6.0
Last Update: May 06, 2024
Questions: 30 Q&As

PDF

$49.99

VCE

$59.99

PDF + VCE

$67.99