NSE6_FWB-6.4 Free Study Guide! with New Update 58 Exam Questions
Get up-to-date Real Exam Questions for NSE6_FWB-6.4 UPDATED [2023]
Fortinet NSE6_FWB-6.4 certification exam is designed for individuals seeking to validate their knowledge and skills in deploying, configuring, and maintaining Fortinet FortiWeb 6.4. Fortinet NSE 6 - FortiWeb 6.4 certification is ideal for security professionals who are responsible for protecting web applications from a range of cyber threats and attacks. NSE6_FWB-6.4 exam covers various topics such as FortiWeb deployment, security policies, SSL/TLS inspection, web application firewall, and more. Passing NSE6_FWB-6.4 exam demonstrates that the candidate has the necessary expertise to manage FortiWeb appliances effectively and protect web applications against various cyber threats.
NEW QUESTION # 23
How does an ADOM differ from a VDOM?
- A. Allows you to have 1 administrator for multiple tenants
- B. ADOMs do not have virtual networking
- C. ADOMs improve performance by offloading some functions.
- D. ADOMs only affect specific functions, and do not provide full separation like VDOMs do.
Answer: B
NEW QUESTION # 24
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?
- A. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
- B. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
- C. Static or policy-based routes are not required.
- D. The server policy applies the same protection profile to all of its protected web applications.
Answer: C
NEW QUESTION # 25
Refer to the exhibit.
FortiWeb is configured to block traffic from Japan to your web application server. However, in the logs, the administrator is seeing traffic allowed from one particular IP address which is geo-located in Japan.
What can the administrator do to solve this problem? (Choose two.)
- A. Configure the IP address as a blacklisted IP address.
- B. Manually update the geo-location IP addresses for Japan.
- C. If the IP address is configured as a geo reputation exception, remove it.
- D. If the IP address is configured as an IP reputation exception, remove it.
Answer: A,C
NEW QUESTION # 26
In Reverse proxy mode, how does FortiWeb handle traffic that does not match any defined policies?
- A. Non-matching traffic is Denied
- B. Non-matching traffic is allowed
- C. Non-matching traffic is rerouted to FortiGate
- D. non-Matching traffic is held in buffer
Answer: A
NEW QUESTION # 27
FortiWeb offers the same load balancing algorithms as FortiGate.
Which two Layer 7 switch methods does FortiWeb also offer? (Choose two.)
- A. HTTP user-based round robin
- B. HTTP content routes
- C. Round robin
- D. HTTP session-based round robin
Answer: B,C
NEW QUESTION # 28
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Allow the page access, but log the violation
- B. Redirect the client to the login page
- C. Prompt the client to authenticate
- D. Display an access policy message, then allow the client to continue
- E. Reply with a 403 Forbidden HTTP error
Answer: A,B,E
NEW QUESTION # 29
What other consideration must you take into account when configuring Defacement protection
- A. None. FortiWeb completely secures the site against defacement attacks
- B. Use FortiWeb to block SQL Injections and keep regular backups of the Database
- C. Configure the FortiGate to perform Anti-Defacement as well
- D. Also incorporate a FortiADC into your network
Answer: B
NEW QUESTION # 30
Refer to the exhibit.
FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)
- A. No Special configuration is required; connectivity will be re-established after the set timeout.
- B. Enable the Add X-Forwarded-For setting on FortiWeb.
- C. Enable the Use X-Forwarded-For setting on FortiWeb.
- D. Place FortiWeb in front of FortiADC.
Answer: C,D
Explanation:
Explanation
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header
NEW QUESTION # 31
An e-commerce web app is used by small businesses. Clients often access it from offices behind a router, where clients are on an IPv4 private network LAN. You need to protect the web application from denial of service attacks that use request floods.
What FortiWeb feature should you configure?
- A. Enable SYN cookies.
- B. Configure FortiWeb to use "X-Forwarded-For:" headers to find each client's private network IP, and to block attacks using that.
- C. Enable "Shared IP" and configure the separate rate limits for requests from NATted source IPs.
- D. Configure a server policy that matches requests from shared Internet connections.
Answer: A
NEW QUESTION # 32
What can an administrator do if a client has been incorrectly period blocked?
- A. Force a new IP address to the client.
- B. Manually release the ID address from the temporary blacklist.
- C. Disconnect the client from the network.
- D. Nothing, it is not possible to override a period block.
Answer: B
Explanation:
Explanation
Block Period
Enter the number of seconds that you want to block the requests. The valid range is 1-3,600 seconds. The default value is 60 seconds.
This option only takes effect when you choose Period Block in Action.
Note: That's a temporary blacklist so you can manually release them from the blacklist.
NEW QUESTION # 33
Which two statements about running a vulnerability scan are true? (Choose two.)
- A. You should run the vulnerability scan during a maintenance window.
- B. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
- C. You should run the vulnerability scan on a live website to get accurate results.
- D. You should run the vulnerability scan in a test environment.
Answer: A,D
Explanation:
Explanation
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
NEW QUESTION # 34
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)
- A. True transparent proxy
- B. Reverse proxy
- C. Transparent inspection
- D. Offline protection
Answer: A,B
NEW QUESTION # 35
Which three statements about HTTPS on FortiWeb are true? (Choose three.)
- A. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.
- B. In true transparent mode, the TLS session terminator is a protected web server.
- C. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.
- D. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.
- E. After enabling HSTS, redirects to HTTPS are no longer necessary.
Answer: B,C,D
NEW QUESTION # 36
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.
Which two functions does the first layer perform? (Choose two.)
- A. Builds a threat model behind every parameter and HTTP method
- B. Determines whether traffic is an anomaly, based on observed application traffic over time
- C. Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored
- D. Determines if a detected threat is a false-positive or not
Answer: A,B
Explanation:
Explanation
The first layer uses the Hidden Markov Model (HMM) and monitors access to the application and collects data to build a mathematical model behind every parameter and HTTP method.
NEW QUESTION # 37
When integrating FortiWeb and FortiAnalyzer, why is the selection for FortiWeb Version critical? (Choose two)
- A. Defines Database Schema
- B. Defines Log file format
- C. Defines Log storage location
- D. Defines communication protocol
Answer: B,C
NEW QUESTION # 38
How does your FortiWeb configuration differ if the FortiWeb is upstream of the SNAT device instead of downstream of the SNAT device?
- A. You must enable the "Use" X-Forwarded-For: option.
- B. FortiWeb must be set for Transparent Mode
- C. No special configuration required
- D. You must enable "Add" X-Forwarded-For: instead of the "Use" X-Forwarded-For: option.
Answer: D
NEW QUESTION # 39
True transparent proxy mode is best suited for use in which type of environment?
- A. Flexible environments where you can easily change the IP addressing scheme
- B. Small office to home office environments
- C. New networks where infrastructure is not yet defined
- D. Environments where you cannot change the IP addressing scheme
Answer: A
Explanation:
Explanation
"Because blocking is not guaranteed to succeed in offline mode, this mode is best used during the evaluation and planning phase, early in implementation. Reverse proxy is the most popular operating mode. It can rewrite URLs, offload TLS, load balance, and apply NAT. For very large MSSP, true transparent mode has a significant advantage. You can drop it in without changing any schemes of limited IPv4 space-in transparent mode, you don't need to give IP addresses to the network interfaces on FortiWeb."
NEW QUESTION # 40
When generating a protection configuration from an auto learning report what critical step must you do before generating the final protection configuration?
- A. Drill down in the report to correct any false positives.
- B. Take the FortiWeb offline to apply the profile
- C. Restart the FortiWeb to clear the caches
- D. Activate the report to create t profile
Answer: A
NEW QUESTION # 41
Under which circumstances does FortiWeb use its own certificates? (Choose Two)
- A. HTTPS access to GUI
- B. HTTPS to FortiGate
- C. HTTPS to clients
- D. Secondary HTTPS connection to server where FortiWeb acts as a client
Answer: A,D
NEW QUESTION # 42
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- A. Store in an off-site location
- B. Erase them every two weeks
- C. Enable masking of sensitive data
- D. Compress them into a .zip file format
Answer: C
NEW QUESTION # 43
What capability can FortiWeb add to your Web App that your Web App may or may not already have?
- A. SSL Inspection
- B. High Availability
- C. HTTP/HTML Form Authentication
- D. Automatic backup and recovery
Answer: C
NEW QUESTION # 44
When FortiWeb triggers a redirect action, which two HTTP codes does it send to the client to inform the browser of the new URL? (Choose two.)
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B,C
NEW QUESTION # 45
......
Pass Fortinet NSE6_FWB-6.4 Exam in First Attempt Guaranteed: https://www.dumpsactual.com/NSE6_FWB-6.4-actualtests-dumps.html
