2024 Latest FCP_FWB_AD-7.4 dumps - Instant Download PDF
Updated Verified FCP_FWB_AD-7.4 Downloadable Printable Exam Dumps
NEW QUESTION # 41
Which operation mode requires additional configuration in order to allow FTP traffic into your web server?
- A. Transparent inspection
- B. Reverse proxy
- C. True transparent proxy
- D. Offline protection
Answer: B
NEW QUESTION # 42
How does your FortiWeb configuration differ if the FortiWeb is upstream of the SNAT device instead of downstream of the SNAT device?
- A. You must enable "Add" X-Forwarded-For: instead of the "Use" X-Forwarded-For: option.
- B. You must enable the "Use" X-Forwarded-For: option.
- C. FortiWeb must be set for Transparent Mode
- D. No special configuration required
Answer: A
NEW QUESTION # 43
What must you configure on FortiWeb to prevent cross-origin resource sharing (CORS) attacks?
- A. Configure an allowed origin domain.
- B. Blocklist client IP addresses.
- C. Disable CORS in the web protection profile.
- D. Configure a CORS parameter in DNS.
Answer: A
NEW QUESTION # 44
What is the purpose of using Web Application Firewalls (WAFs) in the context of web application security? (Select all that apply)
- A. Optimizing website performance
- B. Protecting against DDoS attacks
- C. Preventing SQL injection attacks
- D. Enforcing secure authentication
Answer: B,C,D
NEW QUESTION # 45
Which of the following is a critical system setting that should be configured during FortiWeb deployment?
- A. Email notifications
- B. DNS server settings
- C. Default web filtering policies
- D. System time synchronization
Answer: D
NEW QUESTION # 46
Review the following configuration:
config waf machine-learning-policy
edit 1
set sample-limit-by-ip 0
next
end
What is the expected result of this configuration setting?
- A. When machine learning (ML) is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- B. When machine learning (ML) is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- C. When machine learning (ML) is in its collecting phase, FortiWeb will not accept any samples from any source IP addresses.
- D. When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.
Answer: B
NEW QUESTION # 47
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
- A. FortiGate local IP
- B. Client real IP
- C. FortiWeb IP
- D. FortiGate public IP
Answer: B
NEW QUESTION # 48
Which two statements about running a vulnerability scan are true? (Choose two.)
- A. You should run the vulnerability scan during a maintenance window.
- B. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
- C. You should run the vulnerability scan on a live website to get accurate results.
- D. You should run the vulnerability scan in a test environment.
Answer: A,D
NEW QUESTION # 49
A client is trying to start a session from a page that should normally be accessible only after they have logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Automatically redirect the client to the login page
- B. Display an access policy message, then allow the client to continue, redirecting them to their requested page
- C. Prompt the client to authenticate
- D. Allow the page access, but log the violation
- E. Reply with a "403 Forbidden" HTTP error
Answer: A,D,E
NEW QUESTION # 50
Refer to the exhibit.
If rule 1 matches http://bwapp.fortinet.demo, rule 2 matches http://dvwa.fortinet.demo, and the default web protection profile is the inline protection profile, which protection profile will be applied to a connection to http://petstore.fortinet.demo?
- A. policy1
- B. dwva
- C. bwapp
- D. Inline protection profile
Answer: C
NEW QUESTION # 51
When configuring access control methods for web application users, which options should be considered for tracking and auditing user actions? (Select all that apply)
- A. Session logs
- B. Web server logs
- C. Authentication logs
- D. Error logs
Answer: A,B,C
NEW QUESTION # 52
Which of the following is a common threat mitigation technique to protect against SQL injection attacks?
- A. Server load balancing
- B. Input validation and sanitization
- C. Cross-site scripting (XSS) prevention
- D. Data encryption at rest
Answer: B
NEW QUESTION # 53
What other consideration must you take into account when configuring Defacement protection?
- A. None. FortiWeb completely secures the site against defacement attacks
- B. Also incorporate a FortiADC into your network
- C. Configure the FortiGate to perform Anti-Defacement as well
- D. Use FortiWeb to block SQL Injections and keep regular backups of the Database
Answer: D
NEW QUESTION # 54
In Reverse proxy mode, how does FortiWeb handle traffic that does not match any defined policies?
- A. non-Matching traffic is held in buffer
- B. Non-matching traffic is allowed
- C. Non-matching traffic is Denied
- D. Non-matching traffic is rerouted to FortiGate
Answer: C
NEW QUESTION # 55
Which of the following is a common challenge when implementing bot mitigation techniques?
- A. Increased server response times
- B. Lack of support for mobile devices
- C. Difficulty in distinguishing between legitimate and malicious bots
- D. Incompatibility with web browsers
Answer: C
NEW QUESTION # 56
Which of the following FortiWeb features is part of the mitigation tools against OWASP A4 threats?
- A. Session Management
- B. Sensitive info masking
- C. Poison Cookie detection
- D. Brute Force blocking
Answer: A
NEW QUESTION # 57
Refer to the exhibits.

FortiWeb is configured in reverse proxy mode and it is deployed downstream to FortiGate. Based on the configuration shown in the exhibits, which of the following statements is true?
- A. You must disable the Preserve Client IP setting on FotriGate for this configuration to work.
- B. FortiGate should forward web traffic to virtual server IP address.
- C. The configuration is incorrect. FortiWeb should always be located upstream to FortiGate.
- D. FortiGate should forward web traffic to the server pool IP addresses.
Answer: B
NEW QUESTION # 58
Which of the following are common SSL/TLS encryption-related issues that can be encountered during web application deployment? (Select all that apply)
- A. Weak encryption ciphers
- B. Mixed content warnings
- C. Expired SSL certificates
- D. Insecure session management
Answer: A,B,C
NEW QUESTION # 59
......
The Ultimate Fortinet FCP_FWB_AD-7.4 Dumps PDF Review: https://examboost.validdumps.top/FCP_FWB_AD-7.4-exam-torrent.html