Pass the Fortinet Public Cloud Security FCP_FWB_AD-7.4 Questions and answers with CertsForce

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

What is true about this FortiWeb device? (Choose two.)

Options:

A.

It has 41% of the disk available for logging.


B.

It was upgraded to a different version after initial installation.


C.

It is currently running version 6.4.0.


D.

It is currently running version 6.4.1.


Expert Solution
Questions # 2:

Review the following configuration:

Question # 2

What are two routing behaviors that you can expect on FortiWeb after this configuration change? (Choose two.)

Options:

A.

Non-HTTP traffic routed through the FortiWeb is allowed.


B.

IPv6 routing is enabled.


C.

Non-HTTP traffic destined to the FortiWeb virtual server IP address is dropped.


D.

Only ICMP traffic is allowed. All other traffic is dropped.


Expert Solution
Questions # 3:

Under which two circumstances does FortiWeb use its own certificates? (Choose two.)

Options:

A.

Connecting to browser clients using SSL


B.

Making a secondary HTTPS connection to a server where FortiWeb acts as a client


C.

Routing an HTTPS connection to a FortiGate


D.

An administrator session connecting to the GUI using HTTPS


Expert Solution
Questions # 4:

An administrator notices multiple IP addresses attempting to log in to an application frequently, within a short time period. They suspect attackers are attempting to guess user passwords for a secure application.

What is the best way to limit this type of attack on FortiWeb, while still allowing legitimate traffic through?

Options:

A.

Blocklist any suspected IPs.


B.

Configure a brute force login custom policy.


C.

Rate limit all connections from suspected IP addresses.


D.

Block the IP address at the border router.


Expert Solution
Questions # 5:

Which two functions does the first layer of the FortiWeb anomaly machine learning (ML) analysis mechanism perform? (Choose two.)

Options:

A.

Determines whether an anomaly is a real attack or just a harmless anomaly that should be ignored


B.

Determines a probability model behind every parameter and HTTP method passing through FortiWeb


C.

Determines whether traffic is an anomaly, based on observable features overtime


D.

Determines if a detected threat is a false-positive or not


Expert Solution
Questions # 6:

What are two possible impacts of a DoS attack on your web server? (Choose two.)

Options:

A.

The web application starts accepting unencrypted traffic.


B.

The web application is unable to accept any more connections because of network socket exhaustion.


C.

The web application server is unable to accept new client sessions due to memory exhaustion.


D.

The web application server database is compromised with data theft.


Expert Solution
Questions # 7:

An attacker attempts to send an SQL injection attack containing the known attack string 'root'; -- through an API call.

Which FortiWeb inspection feature will be able to detect this attack the quickest?

Options:

A.

API gateway rule


B.

Known signatures


C.

Machine learning(ML)-based API protection—anomaly detection


D.

ML-based API protection—threat detection


Expert Solution
Questions # 8:

How are bot machine learning (ML) models different from API or anomaly detection models?

Options:

A.

Bot ML models analyze multiple connections overtime instead analyzing each connection as a single unit.


B.

Bot ML models detect only anomalies and not actual threats.


C.

Bot ML models inspect more types of connection properties.


D.

Bot ML models do not update models periodically from new data.


Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

FortiADC is applying SNAT to all inbound traffic going to the servers.

When an attack occurs, FortiWeb blocks traffic based on the192.0.2.1source IP address, which belongs to FortiADC. This setup is breaking all connectivity and genuine clients are not able to access the servers.

What can the administrator do to avoid this problem? (Choose two.)

Options:

A.

Enable and configure the Preserve Client IP setting on the client.


B.

No special configuration is required; connectivity will be re-established for all clients after the set timeout.


C.

Place FortiWeb in front of FortiADC.


D.

Enable and configure the Use X-Forwarded-For setting on FortiWeb.


Expert Solution
Questions # 10:

Which Layer 7 routing method does FortiWeb support?

Options:

A.

URL policy routing


B.

OSPF


C.

BGP


D.

HTTPcontent routing


Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions