[Dec 29, 2021] NSE6_FWB-6.1 Exam Dumps - Try Best NSE6_FWB-6.1 Exam Questions - DumpsTests
Verified NSE6_FWB-6.1 exam dumps Q&As with Correct 30 Questions and Answers
NEW QUESTION 11
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)
- A. Transparent inspection
- B. Reverse proxy
- C. True transparent proxy
- D. Offline protection
Answer: C,D
Explanation:
FortiWeb appliances operating in offline protection mode or either of the transparent modes
NEW QUESTION 12
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- A. Erase them every two weeks
- B. Compress them into a .zip file format
- C. Enable masking of sensitive data
- D. Store in an off-site location
Answer: C
NEW QUESTION 13
Review the following configuration:
What is the expected result of this configuration setting?
- A. When machine learning (ML) is in its collecting phase, FortiWeb will not accept any samples from any source IP addresses.
- B. When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.
- C. When machine learning (ML) is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- D. When machine learning (ML) is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
Answer: D
NEW QUESTION 14
Which algorithm is used to build mathematical models for bot detection?
- A. HMM
- B. HCM
- C. SVM
- D. SVN
Answer: C
Explanation:
FortiWeb uses SVM (Support Vector Machine) algorithm to build up the bot detection model
NEW QUESTION 15
Which two statements about running a vulnerability scan are true? (Choose two.)
- A. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
- B. You should run the vulnerability scan on a live website to get accurate results.
- C. You should run the vulnerability scan in a test environment.
- D. You should run the vulnerability scan during a maintenance window.
Answer: C,D
Explanation:
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
Reference:
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/vulnerability_scans.htm
NEW QUESTION 16
Refer to the exhibit.
FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)
- A. No Special configuration is required; connectivity will be re-established after the set timeout.
- B. Enable the Use X-Forwarded-For setting on FortiWeb.
- C. Enable the Add X-Forwarded-For setting on FortiWeb.
- D. Place FortiWeb in front of FortiADC.
Answer: B,C
Explanation:
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header
NEW QUESTION 17
FortiWeb offers the same load balancing algorithms as FortiGate.
Which two Layer 7 switch methods does FortiWeb also offer? (Choose two.)
- A. HTTP content routes
- B. HTTP user-based round robin
- C. Round robin
- D. HTTP session-based round robin
Answer: A,C
Explanation:
Reference:
http://fortinet.globalgate.com.ar/pdfs/FortiWeb/FortiWeb_DS.pdf
NEW QUESTION 18
Which three statements about HTTPS on FortiWeb are true? (Choose three.)
- A. In transparent inspection mode, you select the certificate that FortiWeb presents in the server pool, not in the server policy.
- B. In true transparent mode, the TLS session terminator is a protected web server.
- C. After enabling HSTS, redirects to HTTPS are never needed.
- D. For SNI, you select the certificate that FortiWeb presents in the server pool, not in the server policy.
- E. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to offer only TLS 1.2.
Answer: A,B,D
NEW QUESTION 19
True transparent proxy mode is best suited for use in which type of environment?
- A. New networks where infrastructure is not yet defined
- B. Environments where you cannot change the IP addressing scheme
- C. Flexible environments where you can easily change the IP addressing scheme
- D. Small office to home office environments
Answer: B
Explanation:
Does not require changes to the IP address scheme of the network. Requests are destined for a web server and not the FortiWeb appliance. This operation mode supports the same feature set as True Transparent Proxy mode.
NEW QUESTION 20
Refer to the exhibit.
There is only one administrator account configured on FortiWeb. What must an administrator do to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?
- A. Delete the built-in administrator user and create a new one.
- B. Configure IPv4 Trusted Host # 3 with a specific IP address.
- C. The configuration changes must be made on the upstream device.
- D. Change the Access Profile to Read_Only.
Answer: A
NEW QUESTION 21
Which two statements about the anti-defacement feature on FortiWeb are true? (Choose two.)
- A. Anti-defacement downloads a copy of your website to RAM, in order to restore a clean image, if it detects defacement.
- B. FortiWeb will only check to see if there are changes on the web server; it will not download the whole file each time.
- C. Anti-defacement can redirect users to a backup web server, if it detects a change.
- D. Anti-defacement does not make a backup copy of your databases.
Answer: B,D
Explanation:
Anti-defacement backs up web pages only, not databases.
If it detects any file changes, the FortiWeb appliance will download a new backup revision.
NEW QUESTION 22
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?
- A. The server policy applies the same protection profile to all of its protected web applications.
- B. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
- C. Static or policy-based routes are not required.
- D. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
Answer: C
NEW QUESTION 23
......
Fortinet NSE6_FWB-6.1 Test Engine PDF - All Free Dumps: https://www.dumpstests.com/NSE6_FWB-6.1-latest-test-dumps.html
Get New NSE6_FWB-6.1 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1k6EFNEPRrNb6a7MHppP46F6IixFEOfTZ