Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Fortinet FCP_FWB_AD-7.4 Practice Exam with Questions & Answers

Questions 1

In SAML deployments, which server contains user authentication credentials (username/password)?

Options:
A.

Identity provider

B.

Service provider

C.

User database

D.

Authentication client

Fortinet FCP_FWB_AD-7.4 Premium Access
Questions 2

Refer to the exhibit.

FCP_FWB_AD-7.4 Question 2

Which statement is true?

Options:
A.

FortiWeb cannot perform content inspection on the traffic because it is encrypted.

B.

FortiWeb is decrypting and re-encrypting the traffic.

C.

The server is not performing any cryptography on the traffic.

D.

The server is encrypting traffic being sent to the client.

Questions 3

What are two possible impacts of a DoS attack on your web server? (Choose two.)

Options:
A.

The web application starts accepting unencrypted traffic.

B.

The web application is unable to accept any more connections because of network socket exhaustion.

C.

The web application server is unable to accept new client sessions due to memory exhaustion.

D.

The web application server database is compromised with data theft.

Questions 4

A customer wants to be able to index your websites for search and advertisement purposes.

What is the easiest way to allow this on a FortiWeb?

Options:
A.

Add the indexer IP address to the trusted IP list on the FortiWeb.

B.

Add the indexer IP address tothe FortiGuard "Known Search Engines" category.

C.

Create a firewall rule to bypass the FortiWeb entirely for the indexer IP address.

D.

Do not allow any external sites to index your websites.

Questions 5

Under which two circumstances does FortiWeb use its own certificates? (Choose two.)

Options:
A.

Connecting to browser clients using SSL

B.

Making a secondary HTTPS connection to a server where FortiWeb acts as a client

C.

Routing an HTTPS connection to a FortiGate

D.

An administrator session connecting to the GUI using HTTPS

Questions 6

Refer to the exhibit.

FCP_FWB_AD-7.4 Question 6

A FortiWeb device is deployed upstream of a device performing source network address translation (SNAT) or load balancing.

What configuration must you perform on FortiWeb to preserve the original IP address of the client?

Options:
A.

Enable and configure the Preserve Client IP setting.

B.

Use a transparent operatingmode on FortiWeb.

C.

Enable and configure the Add X-Forwarded-For setting.

D.

Turn off NAT on the FortiWeb.

Questions 7

An administrator notices multiple IP addresses attempting to log in to an application frequently, within a short time period. They suspect attackers are attempting to guess user passwords for a secure application.

What is the best way to limit this type of attack on FortiWeb, while still allowing legitimate traffic through?

Options:
A.

Blocklist any suspected IPs.

B.

Configure a brute force login custom policy.

C.

Rate limit all connections from suspected IP addresses.

D.

Block the IP address at the border router.

Questions 8

Refer to the exhibits.

FCP_FWB_AD-7.4 Question 8

FCP_FWB_AD-7.4 Question 8

What will happen when a client attempts a mousedown cross-site scripting (XSS) attack against the sitehttp://my.blog.org/userl1/blog.php and FortiWeb is enforcing the highlighted signature?

Options:
A.

The connection will be stripped of the mousedown JavaScript code.

B.

The connection will be blocked as an XSS attack.

C.

FortiWeb will report the new mousedown attack to FortiGuard.

D.

The connection will be allowed.

Questions 9

In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)

Options:
A.

True transparent proxy

B.

Virtual proxy

C.

Transparent inspection

D.

Reverse proxy

Questions 10

Which three stages are part of creating a machine learning (ML) bot detection algorithm? (Choose three.)

Options:
A.

Model building

B.

Model running

C.

Model verification

D.

Sample collecting

E.

Model Bayesian analysis