[2023] Free NSE6_FWB-6.4 Exam Dumps to Pass Exam Easily
NSE6_FWB-6.4 Exam Dumps, NSE6_FWB-6.4 Practice Test Questions
Fortinet NSE6_FWB-6.4 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION 18
Which implementation is best suited for a deployment that must meet compliance criteria?
- A. SSL Inspection with FortiWeb in Transparency mode
- B. SSL Inspection with FrotiWeb in Reverse Proxy mode
- C. SSL Offloading with FortiWeb in Transparency Mode
- D. SSL Offloading with FortiWeb in reverse proxy mode
Answer: B
NEW QUESTION 19
You are configuring FortiAnalyzer to store logs from FortiWeb.
Which is true?
- A. To store logs from FortiWeb 6.4, on FortiAnalyzer, you must select "FrotiWeb 6.1".
- B. FortiWeb will query FortiAnalyzer for reports, instead of generating them locally.
- C. You must enable ADOMs on FortiAnalyzer.
- D. FortiAnalyzer will store antivirus and DLP archives from FortiWeb.
Answer: C
NEW QUESTION 20
Which three statements about HTTPS on FortiWeb are true? (Choose three.)
- A. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.
- B. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.
- C. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.
- D. In true transparent mode, the TLS session terminator is a protected web server.
- E. After enabling HSTS, redirects to HTTPS are no longer necessary.
Answer: A,C,D
NEW QUESTION 21
Which would be a reason to implement HTTP rewriting?
- A. The original page has moved to a new URL
- B. To send the request to secure channel
- C. To replace a vulnerable function in the requested URL
- D. The original page has moved to a new IP address
Answer: C
Explanation:
Explanation
Create a new URL rewriting rule.
NEW QUESTION 22
In which operation mode(s) can FortiWeb modify HTTP packets? (Choose two.)
- A. Offline protection
- B. Reverse proxy
- C. Transparent Inspection
- D. True transparent proxy
Answer: B,D
NEW QUESTION 23
An e-commerce web app is used by small businesses. Clients often access it from offices behind a router, where clients are on an IPv4 private network LAN. You need to protect the web application from denial of service attacks that use request floods.
What FortiWeb feature should you configure?
- A. Enable SYN cookies.
- B. Enable "Shared IP" and configure the separate rate limits for requests from NATted source IPs.
- C. Configure FortiWeb to use "X-Forwarded-For:" headers to find each client's private network IP, and to block attacks using that.
- D. Configure a server policy that matches requests from shared Internet connections.
Answer: A
NEW QUESTION 24
When generating a protection configuration from an auto learning report what critical step must you do before generating the final protection configuration?
- A. Take the FortiWeb offline to apply the profile
- B. Activate the report to create t profile
- C. Drill down in the report to correct any false positives.
- D. Restart the FortiWeb to clear the caches
Answer: C
NEW QUESTION 25
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- A. Enable masking of sensitive data
- B. Compress them into a .zip file format
- C. Erase them every two weeks
- D. Store in an off-site location
Answer: A
NEW QUESTION 26
Which of the following would be a reason for implementing rewrites?
- A. Page has been moved to a new IP address
- B. Send connection to secure channel
- C. Page has been moved to a new URL
- D. Replace vulnerable functions.
Answer: D
NEW QUESTION 27
Refer to the exhibit.
FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)
- A. No Special configuration is required; connectivity will be re-established after the set timeout.
- B. Enable the Use X-Forwarded-For setting on FortiWeb.
- C. Enable the Add X-Forwarded-For setting on FortiWeb.
- D. Place FortiWeb in front of FortiADC.
Answer: B,D
Explanation:
Explanation
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header
NEW QUESTION 28
Which is true about HTTPS on FortiWeb? (Choose three.)
- A. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.
- B. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.
- C. In true transparent mode, the TLS session terminator is a protected web server.
- D. After enabling HSTS, redirects to HTTPS are no longer necessary.
- E. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.
Answer: A,B,C
NEW QUESTION 29
What role does FortiWeb play in ensuring PCI DSS compliance?
- A. Provides load balancing between multiple web servers
- B. PCI specifically requires a WAF
- C. Provide ability to securely process cash transactions
- D. Provides credit card processing capabilities
Answer: B
Explanation:
Explanation
FortiWeb helps you meet all PCI requirements, but PCI now specifically recommends using a WAF, and developing remediations against the top 10 vulnerabilities, according to OWASP.
NEW QUESTION 30
How does FortiWeb protect against defacement attacks?
- A. It keeps full copies of all files and directories.
- B. It keeps a live duplicate of the database.
- C. It keeps hashes of files and periodically compares them to the server.
- D. It keeps a complete backup of all files and the database.
Answer: C
Explanation:
Explanation
The anti-defacement feature examines a web site's files for changes at specified time intervals. If it detects a change that could indicate a defacement attack, the FortiWeb appliance can notify you and quickly react by automatically restoring the web site contents to the previous backup.
NEW QUESTION 31
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Display an access policy message, then allow the client to continue
- B. Prompt the client to authenticate
- C. Reply with a 403 Forbidden HTTP error
- D. Redirect the client to the login page
- E. Allow the page access, but log the violation
Answer: C,D,E
NEW QUESTION 32
Which two statements about the anti-defacement feature on FortiWeb are true? (Choose two.)
- A. Anti-defacement downloads a copy of your website to RAM, in order to restore a clean image, if it detects defacement.
- B. Anti-defacement can redirect users to a backup web server, if it detects a change.
- C. Anti-defacement does not make a backup copy of your databases.
- D. FortiWeb will only check to see if there are changes on the web server; it will not download the whole file each time.
Answer: C,D
Explanation:
Explanation
Anti-defacement backs up web pages only, not databases.
If it detects any file changes, the FortiWeb appliance will download a new backup revision.
NEW QUESTION 33
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?
- A. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
- B. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
- C. Static or policy-based routes are not required.
- D. The server policy applies the same protection profile to all of its protected web applications.
Answer: C
NEW QUESTION 34
In Reverse proxy mode, how does FortiWeb handle traffic that does not match any defined policies?
- A. non-Matching traffic is held in buffer
- B. Non-matching traffic is rerouted to FortiGate
- C. Non-matching traffic is allowed
- D. Non-matching traffic is Denied
Answer: D
NEW QUESTION 35
When the FortiWeb is configured in Reverse Proxy mode and the FortiGate is configured as an SNAT device, what IP address will the FortiGate's Real Server configuration point at?
- A. Virtual Server IP on the FortiGate
- B. IP Address of the Virtual Server on the FortiWeb
- C. Server's real IP
- D. FortiWeb's real IP
Answer: A
NEW QUESTION 36
......
NSE6_FWB-6.4 Exam Dumps, NSE6_FWB-6.4 Practice Test Questions: https://www.topexamcollection.com/NSE6_FWB-6.4-vce-collection.html
Free NSE6_FWB-6.4 Study Guides Exam Questions and Answer: https://drive.google.com/open?id=14I2J3BwzV98eaECfTn1BbSDhTD6h4nlO

