Achieve the NSE6_FWB-6.4 Exam Best Results with Help from Fortinet Certified Experts
Provide NSE6_FWB-6.4 Practice Test Engine for Preparation
NEW QUESTION # 28
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.
Which two functions does the first layer perform? (Choose two.)
- A. Determines if a detected threat is a false-positive or not
- B. Builds a threat model behind every parameter and HTTP method
- C. Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored
- D. Determines whether traffic is an anomaly, based on observed application traffic over time
Answer: B,D
Explanation:
Explanation
The first layer uses the Hidden Markov Model (HMM) and monitors access to the application and collects data to build a mathematical model behind every parameter and HTTP method.
NEW QUESTION # 29
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?
- A. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
- B. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
- C. Static or policy-based routes are not required.
- D. The server policy applies the same protection profile to all of its protected web applications.
Answer: C
NEW QUESTION # 30
You are using HTTP content routing on FortiWeb. Requests for web app A should be forwarded to a cluster of web servers which all host the same web app. Requests for web app B should be forwarded to a different, single web server.
Which is true about the solution?
- A. To achieve HTTP content routing, you must chain policies: the first policy accepts all traffic, and forwards requests for web app A to the virtual server for policy A. It also forwards requests for web app B to the virtual server for policy B. Policy A and Policy B apply their app-specific protection profiles, and then distribute that app's traffic among all members of the server farm.
- B. You must put the single web server into a server pool in order to use it with HTTP content routing.
- C. Static or policy-based routes are not required.
- D. The server policy applies the same protection profile to all its protected web apps.
Answer: A
NEW QUESTION # 31
Which algorithm is used to build mathematical models for bot detection?
- A. HMM
- B. SVN
- C. HCM
- D. SVM
Answer: D
Explanation:
Explanation
FortiWeb uses SVM (Support Vector Machine) algorithm to build up the bot detection model
NEW QUESTION # 32
Under what circumstances would you want to use the temporary uncompress feature of FortiWeb?
- A. In the case of the file being a .MP3 music file
- B. In the case of the file being an .MP4 video
- C. In the case of compression being done on the web server, to inspect the content of the compressed file.
- D. In the case of compression being done on the FortiWeb, to inspect the content of the compressed file
Answer: C
NEW QUESTION # 33
What key factor must be considered when setting brute force rate limiting and blocking?
- A. Multiple clients sharing a single Internet connection
- B. Multiple clients from geographically diverse locations
- C. Multiple clients connecting to multiple resources
- D. A single client contacting multiple resources
Answer: A
Explanation:
Explanation
https://training.fortinet.com/course/view.php?id=3363 What is one key factor that you must consider when setting brute force rate limiting and blocking? Multiple clients sharing a single Internet connection
NEW QUESTION # 34
What other consideration must you take into account when configuring Defacement protection
- A. Use FortiWeb to block SQL Injections and keep regular backups of the Database
- B. None. FortiWeb completely secures the site against defacement attacks
- C. Configure the FortiGate to perform Anti-Defacement as well
- D. Also incorporate a FortiADC into your network
Answer: A
NEW QUESTION # 35
Which implementation is best suited for a deployment that must meet compliance criteria?
- A. SSL Offloading with FortiWeb in reverse proxy mode
- B. SSL Inspection with FrotiWeb in Reverse Proxy mode
- C. SSL Inspection with FortiWeb in Transparency mode
- D. SSL Offloading with FortiWeb in Transparency Mode
Answer: B
NEW QUESTION # 36
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- A. Store in an off-site location
- B. Compress them into a .zip file format
- C. Erase them every two weeks
- D. Enable masking of sensitive data
Answer: D
NEW QUESTION # 37
Refer to the exhibit.
FortiWeb is configured to block traffic from Japan to your web application server. However, in the logs, the administrator is seeing traffic allowed from one particular IP address which is geo-located in Japan.
What can the administrator do to solve this problem? (Choose two.)
- A. Configure the IP address as a blacklisted IP address.
- B. If the IP address is configured as a geo reputation exception, remove it.
- C. Manually update the geo-location IP addresses for Japan.
- D. If the IP address is configured as an IP reputation exception, remove it.
Answer: A,B
NEW QUESTION # 38
Which of the following FortiWeb features is part of the mitigation tools against OWASP A4 threats?
- A. Session Management
- B. Brute Force blocking
- C. Sensitive info masking
- D. Poison Cookie detection
Answer: A
NEW QUESTION # 39
Review the following configuration:
What is the expected result of this configuration setting?
- A. When machine learning (ML) is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- B. When machine learning (ML) is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- C. When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.
- D. When machine learning (ML) is in its collecting phase, FortiWeb will not accept any samples from any source IP addresses.
Answer: B
NEW QUESTION # 40
In which operation mode(s) can FortiWeb modify HTTP packets? (Choose two.)
- A. True transparent proxy
- B. Reverse proxy
- C. Transparent Inspection
- D. Offline protection
Answer: A,B
NEW QUESTION # 41
Which two statements about running a vulnerability scan are true? (Choose two.)
- A. You should run the vulnerability scan during a maintenance window.
- B. You should run the vulnerability scan in a test environment.
- C. You should run the vulnerability scan on a live website to get accurate results.
- D. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
Answer: A,B
Explanation:
Explanation
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
NEW QUESTION # 42
Which
regex expression is the correct format for redirecting the URL http://www.example.com?
- A. www.example.com
- B. www\.example\.com
- C. www/.example/.com
- D. www\example\com
Answer: A
Explanation:
Explanation
\1://www.company.com/\2/\3
NEW QUESTION # 43
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
- A. FortiGate public IP
- B. Client real IP
- C. FortiGate local IP
- D. FortiWeb IP
Answer: B
Explanation:
Explanation
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.
NEW QUESTION # 44
How does an ADOM differ from a VDOM?
- A. Allows you to have 1 administrator for multiple tenants
- B. ADOMs improve performance by offloading some functions.
- C. ADOMs do not have virtual networking
- D. ADOMs only affect specific functions, and do not provide full separation like VDOMs do.
Answer: C
NEW QUESTION # 45
A client is trying to start a session from a page that should normally be accessible only after they have logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Reply with a "403 Forbidden" HTTP error
- B. Display an access policy message, then allow the client to continue, redirecting them to their requested page
- C. Prompt the client to authenticate
- D. Automatically redirect the client to the login page
- E. Allow the page access, but log the violation
Answer: A,D,E
NEW QUESTION # 46
What role does FortiWeb play in ensuring PCI DSS compliance?
- A. It provides the WAF required by PCI.
- B. It provides the ability to securely process cash transactions.
- C. It provides the required SQL server protection.
- D. It provides credit card processing capabilities.
Answer: A
NEW QUESTION # 47
What can an administrator do if a client has been incorrectly period blocked?
- A. Nothing, it is not possible to override a period block.
- B. Force a new IP address to the client.
- C. Manually release the ID address from the temporary blacklist.
- D. Disconnect the client from the network.
Answer: C
Explanation:
Explanation
Block Period
Enter the number of seconds that you want to block the requests. The valid range is 1-3,600 seconds. The default value is 60 seconds.
This option only takes effect when you choose Period Block in Action.
Note: That's a temporary blacklist so you can manually release them from the blacklist.
NEW QUESTION # 48
......
Detailed New NSE6_FWB-6.4 Exam Questions for Concept Clearance: https://www.validdumps.top/NSE6_FWB-6.4-exam-torrent.html
NSE6_FWB-6.4 Exam Preparation Material with New NSE6_FWB-6.4 Dumps Questions.: https://drive.google.com/open?id=1TVWEeiPRRKF23sGAvXM0LN5HZvo860tx