NSE6_FWB-6.4 Exam Dumps - PDF Questions and Testing Engine
NSE6_FWB-6.4 Dumps - The Sure Way To Pass Exam
NEW QUESTION # 32
Which
regex expression is the correct format for redirecting the URL http://www.example.com?
- A. www/.example/.com
- B. www.example.com
- C. www\example\com
- D. www\.example\.com
Answer: B
Explanation:
Explanation
\1://www.company.com/\2/\3
NEW QUESTION # 33
Under which circumstances does FortiWeb use its own certificates? (Choose Two)
- A. HTTPS access to GUI
- B. HTTPS to FortiGate
- C. HTTPS to clients
- D. Secondary HTTPS connection to server where FortiWeb acts as a client
Answer: A,D
NEW QUESTION # 34
Refer to the exhibit.
There is only one administrator account configured on FortiWeb. What must an administrator do to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?
- A. Configure IPv4 Trusted Host # 3 with a specific IP address.
- B. The configuration changes must be made on the upstream device.
- C. Change the Access Profile to Read_Only.
- D. Delete the built-in administrator user and create a new one.
Answer: A
NEW QUESTION # 35
Under what circumstances would you want to use the temporary uncompress feature of FortiWeb?
- A. In the case of compression being done on the web server, to inspect the content of the compressed file.
- B. In the case of the file being a .MP3 music file
- C. In the case of the file being an .MP4 video
- D. In the case of compression being done on the FortiWeb, to inspect the content of the compressed file
Answer: A
NEW QUESTION # 36
Refer to the exhibit.
Many legitimate users are being identified as bots. FortiWeb bot detection has been configured with the settings shown in the exhibit. The FortiWeb administrator has already verified that the current model is accurate.
What can the administrator do to fix this problem, making sure that real bots are not allowed through FortiWeb?
- A. Change Model Type to Strict
- B. Change Action under Action Settings to Alert
- C. Enable Bot Confirmation
- D. Disable Dynamically Update Model
Answer: C
Explanation:
Explanation
Bot Confirmation
If the number of anomalies from a user has reached the Anomaly Count, the system executes Bot Confirmation before taking actions.
The Bot Confirmation is to confirm if the user is indeed a bot. The system sends RBE (Real Browser Enforcement) JavaScript or CAPTCHA to the client to double check if it's a real bot.
NEW QUESTION # 37
Which two statements about the anti-defacement feature on FortiWeb are true? (Choose two.)
- A. Anti-defacement can redirect users to a backup web server, if it detects a change.
- B. Anti-defacement downloads a copy of your website to RAM, in order to restore a clean image, if it detects defacement.
- C. Anti-defacement does not make a backup copy of your databases.
- D. FortiWeb will only check to see if there are changes on the web server; it will not download the whole file each time.
Answer: C,D
Explanation:
Explanation
Anti-defacement backs up web pages only, not databases.
If it detects any file changes, the FortiWeb appliance will download a new backup revision.
NEW QUESTION # 38
Refer to the exhibits.

FortiWeb is configured in reverse proxy mode and it is deployed downstream to FortiGate. Based on the configuration shown in the exhibits, which of the following statements is true?
- A. You must disable the Preserve Client IP setting on FotriGate for this configuration to work.
- B. FortiGate should forward web traffic to the server pool IP addresses.
- C. The configuration is incorrect. FortiWeb should always be located upstream to FortiGate.
- D. FortiGate should forward web traffic to virtual server IP address.
Answer: D
NEW QUESTION # 39
What role does FortiWeb play in ensuring PCI DSS compliance?
- A. It provides the required SQL server protection.
- B. It provides the WAF required by PCI.
- C. It provides credit card processing capabilities.
- D. It provides the ability to securely process cash transactions.
Answer: B
NEW QUESTION # 40
When the FortiWeb is configured in Reverse Proxy mode and the FortiGate is configured as an SNAT device, what IP address will the FortiGate's Real Server configuration point at?
- A. Virtual Server IP on the FortiGate
- B. FortiWeb's real IP
- C. IP Address of the Virtual Server on the FortiWeb
- D. Server's real IP
Answer: A
NEW QUESTION # 41
Which would be a reason to implement HTTP rewriting?
- A. The original page has moved to a new URL
- B. The original page has moved to a new IP address
- C. To send the request to secure channel
- D. To replace a vulnerable function in the requested URL
Answer: D
Explanation:
Explanation
Create a new URL rewriting rule.
NEW QUESTION # 42
A client is trying to start a session from a page that should normally be accessible only after they have logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Reply with a "403 Forbidden" HTTP error
- B. Prompt the client to authenticate
- C. Allow the page access, but log the violation
- D. Automatically redirect the client to the login page
- E. Display an access policy message, then allow the client to continue, redirecting them to their requested page
Answer: A,C,D
NEW QUESTION # 43
How does FortiWeb protect against defacement attacks?
- A. It keeps a live duplicate of the database.
- B. It keeps hashes of files and periodically compares them to the server.
- C. It keeps a complete backup of all files and the database.
- D. It keeps full copies of all files and directories.
Answer: B
Explanation:
Explanation
The anti-defacement feature examines a web site's files for changes at specified time intervals. If it detects a change that could indicate a defacement attack, the FortiWeb appliance can notify you and quickly react by automatically restoring the web site contents to the previous backup.
NEW QUESTION # 44
You've configured an authentication rule with delegation enabled on FortiWeb.
What happens when a user tries to access the web application?
- A. FortiWeb forwards the HTTP challenge from the server to the client, then monitors the reply, allowing access if the user authenticates successfully
- B. FortiWeb replies with a HTTP challenge of behalf of the server, the if the user authenticates successfully, FortiWeb allows the request and also includes credentials in the request that it forwards to the web app
- C. ForitWeb redirects the user to the web app's authentication page
- D. FrotiWeb redirects users to a FortiAuthenticator page, then if the user authenticates successfully, FortiGate signals to FortiWeb to allow access to the web app
Answer: D
NEW QUESTION # 45
Which of the following would be a reason for implementing rewrites?
- A. Replace vulnerable functions.
- B. Page has been moved to a new URL
- C. Page has been moved to a new IP address
- D. Send connection to secure channel
Answer: A
NEW QUESTION # 46
Which operation mode does not require additional configuration in order to allow FTP traffic to your web server?
- A. Reverse-Proxy
- B. True Transparent Proxy
- C. Offline Protection
- D. Transparent Inspection
Answer: D
NEW QUESTION # 47
What other consideration must you take into account when configuring Defacement protection
- A. Use FortiWeb to block SQL Injections and keep regular backups of the Database
- B. Configure the FortiGate to perform Anti-Defacement as well
- C. None. FortiWeb completely secures the site against defacement attacks
- D. Also incorporate a FortiADC into your network
Answer: A
NEW QUESTION # 48
Which statement about local user accounts is true?
- A. They cannot be used for site publishing.
- B. They are best suited for large environments with many users.
- C. They can be used for SSO.
- D. They must be assigned, regardless of any other authentication.
Answer: A
NEW QUESTION # 49
You are using HTTP content routing on FortiWeb. Requests for web app A should be forwarded to a cluster of web servers which all host the same web app. Requests for web app B should be forwarded to a different, single web server.
Which is true about the solution?
- A. Static or policy-based routes are not required.
- B. The server policy applies the same protection profile to all its protected web apps.
- C. To achieve HTTP content routing, you must chain policies: the first policy accepts all traffic, and forwards requests for web app A to the virtual server for policy A. It also forwards requests for web app B to the virtual server for policy B. Policy A and Policy B apply their app-specific protection profiles, and then distribute that app's traffic among all members of the server farm.
- D. You must put the single web server into a server pool in order to use it with HTTP content routing.
Answer: C
NEW QUESTION # 50
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- A. Store in an off-site location
- B. Enable masking of sensitive data
- C. Erase them every two weeks
- D. Compress them into a .zip file format
Answer: B
NEW QUESTION # 51
......
Pass Fortinet NSE6_FWB-6.4 Exam Quickly With BraindumpQuiz: https://interfacett.braindumpquiz.com/NSE6_FWB-6.4-exam-material.html