100% Real NSE6_FWB-6.4 dumps - Brilliant NSE6_FWB-6.4 Exam Questions PDF [Q13-Q29]

Share

100% Real NSE6_FWB-6.4 dumps  - Brilliant NSE6_FWB-6.4 Exam Questions PDF

NSE6_FWB-6.4 Exam PDF [2022] Tests Free Updated Today with Correct 58 Questions

NEW QUESTION 13
Which two statements about the anti-defacement feature on FortiWeb are true? (Choose two.)

  • A. Anti-defacement does not make a backup copy of your databases.
  • B. Anti-defacement downloads a copy of your website to RAM, in order to restore a clean image, if it detects defacement.
  • C. FortiWeb will only check to see if there are changes on the web server; it will not download the whole file each time.
  • D. Anti-defacement can redirect users to a backup web server, if it detects a change.

Answer: A,C

Explanation:
Explanation
Anti-defacement backs up web pages only, not databases.
If it detects any file changes, the FortiWeb appliance will download a new backup revision.

 

NEW QUESTION 14
Refer to the exhibit.

There is only one administrator account configured on FortiWeb. What must an administrator do to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?

  • A. Configure IPv4 Trusted Host # 3 with a specific IP address.
  • B. Change the Access Profile to Read_Only.
  • C. The configuration changes must be made on the upstream device.
  • D. Delete the built-in administrator user and create a new one.

Answer: A

 

NEW QUESTION 15
Which of the following would be a reason for implementing rewrites?

  • A. Page has been moved to a new URL
  • B. Replace vulnerable functions.
  • C. Send connection to secure channel
  • D. Page has been moved to a new IP address

Answer: B

 

NEW QUESTION 16
Review the following configuration:

What is the expected result of this configuration setting?

  • A. When machine learning (ML) is in its collecting phase, FortiWeb will not accept any samples from any source IP addresses.
  • B. When machine learning (ML) is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
  • C. When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.
  • D. When machine learning (ML) is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.

Answer: D

 

NEW QUESTION 17
Which algorithm is used to build mathematical models for bot detection?

  • A. SVN
  • B. SVM
  • C. HCM
  • D. HMM

Answer: B

Explanation:
Explanation
FortiWeb uses SVM (Support Vector Machine) algorithm to build up the bot detection model

 

NEW QUESTION 18
Which
regex expression is the correct format for redirecting the URL http://www.example.com?

  • A. www\example\com
  • B. www\.example\.com
  • C. www/.example/.com
  • D. www.example.com

Answer: D

Explanation:
Explanation
\1://www.company.com/\2/\3

 

NEW QUESTION 19
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)

  • A. Display an access policy message, then allow the client to continue
  • B. Prompt the client to authenticate
  • C. Reply with a 403 Forbidden HTTP error
  • D. Redirect the client to the login page
  • E. Allow the page access, but log the violation

Answer: C,D,E

 

NEW QUESTION 20
Under what circumstances would you want to use the temporary uncompress feature of FortiWeb?

  • A. In the case of compression being done on the FortiWeb, to inspect the content of the compressed file
  • B. In the case of compression being done on the web server, to inspect the content of the compressed file.
  • C. In the case of the file being a .MP3 music file
  • D. In the case of the file being an .MP4 video

Answer: B

 

NEW QUESTION 21
Which three statements about HTTPS on FortiWeb are true? (Choose three.)

  • A. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.
  • B. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.
  • C. After enabling HSTS, redirects to HTTPS are no longer necessary.
  • D. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.
  • E. In true transparent mode, the TLS session terminator is a protected web server.

Answer: B,D,E

 

NEW QUESTION 22
Refer to the exhibits.


FortiWeb is configured in reverse proxy mode and it is deployed downstream to FortiGate. Based on the configuration shown in the exhibits, which of the following statements is true?

  • A. The configuration is incorrect. FortiWeb should always be located upstream to FortiGate.
  • B. FortiGate should forward web traffic to virtual server IP address.
  • C. You must disable the Preserve Client IP setting on FotriGate for this configuration to work.
  • D. FortiGate should forward web traffic to the server pool IP addresses.

Answer: B

 

NEW QUESTION 23
You are using HTTP content routing on FortiWeb. Requests for web app A should be forwarded to a cluster of web servers which all host the same web app. Requests for web app B should be forwarded to a different, single web server.
Which is true about the solution?

  • A. You must put the single web server into a server pool in order to use it with HTTP content routing.
  • B. Static or policy-based routes are not required.
  • C. The server policy applies the same protection profile to all its protected web apps.
  • D. To achieve HTTP content routing, you must chain policies: the first policy accepts all traffic, and forwards requests for web app A to the virtual server for policy A. It also forwards requests for web app B to the virtual server for policy B. Policy A and Policy B apply their app-specific protection profiles, and then distribute that app's traffic among all members of the server farm.

Answer: D

 

NEW QUESTION 24
What role does FortiWeb play in ensuring PCI DSS compliance?

  • A. It provides the required SQL server protection.
  • B. It provides credit card processing capabilities.
  • C. It provides the WAF required by PCI.
  • D. It provides the ability to securely process cash transactions.

Answer: C

 

NEW QUESTION 25
What benefit does Auto Learning provide?

  • A. Automatically builds rules sets
  • B. FortiWeb scans all traffic without taking action and makes recommendations on rules
  • C. Automatically blocks all detected threats
  • D. Automatically identifies and blocks suspicious IPs

Answer: A

 

NEW QUESTION 26
Which two statements about running a vulnerability scan are true? (Choose two.)

  • A. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
  • B. You should run the vulnerability scan on a live website to get accurate results.
  • C. You should run the vulnerability scan in a test environment.
  • D. You should run the vulnerability scan during a maintenance window.

Answer: C,D

Explanation:
Explanation
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.

 

NEW QUESTION 27
In which scenario might you want to use the compression feature on FortiWeb?

  • A. When you are offering a music streaming service
  • B. When you want to reduce buffering of video streams
  • C. Never, since most traffic today is already highly compressed
  • D. When you are serving many corporate road warriors using 4G tablets and phones

Answer: D

Explanation:
Explanation
https://training.fortinet.com/course/view.php?id=3363
When might you want to use the compression feature on FortiWeb? When you are serving many road warriors who are using 4G tablets and phones

 

NEW QUESTION 28
In which operation mode(s) can FortiWeb modify HTTP packets? (Choose two.)

  • A. Transparent Inspection
  • B. True transparent proxy
  • C. Offline protection
  • D. Reverse proxy

Answer: B,D

 

NEW QUESTION 29
......

Verified & Correct NSE6_FWB-6.4 Practice Test Reliable Source Sep 07, 2022 Updated: https://www.passleadervce.com/NSE-6-Network-Security-Specialist/reliable-NSE6_FWB-6.4-exam-learning-guide.html

Fortinet NSE6_FWB-6.4 Exam Preparation Guide and PDF Download: https://drive.google.com/open?id=1RQ0T8iVD2BAq1tU8UKF2t3VkGV_AgKU_