NSE6_FWB-6.1 Dumps 2022 - New Fortinet NSE6_FWB-6.1 Exam Questions
Free NSE6_FWB-6.1 braindumps download (NSE6_FWB-6.1 exam dumps Free Updated)
NEW QUESTION 15
Which would be a reason to implement HTTP rewriting?
- A. The original page has moved to a new IP address
- B. The original page has moved to a new URL
- C. To replace a vulnerable function in the requested URL
- D. To send the request to secure channel
Answer: B
Explanation:
Create a new URL rewriting rule.
NEW QUESTION 16
Refer to the exhibit.
Many legitimate users are being identified as bots. FortiWeb bot detection has been configured with the settings shown in the exhibit. The FortiWeb administrator has already verified that the current model is accurate.
What can the administrator do to fix this problem, making sure that real bots are not allowed through FortiWeb?
- A. Change Action under Action Settings to Alert
- B. Disable Dynamically Update Model
- C. Change Model Type to Strict
- D. Enable Bot Confirmation
Answer: D
Explanation:
Bot Confirmation
If the number of anomalies from a user has reached the Anomaly Count, the system executes Bot Confirmation before taking actions.
The Bot Confirmation is to confirm if the user is indeed a bot. The system sends RBE (Real Browser Enforcement) JavaScript or CAPTCHA to the client to double check if it's a real bot.
NEW QUESTION 17
What role does FortiWeb play in ensuring PCI DSS compliance?
- A. It provides credit card processing capabilities.
- B. It provides the required SQL server protection.
- C. It provides the ability to securely process cash transactions.
- D. It provides the WAF required by PCI.
Answer: A
Explanation:
FortiWeb protects against attacks that lead to sensitive data exposure such as SQL Injection and other injection types. Additionally, FortiWeb inspects all web server outgoing traffic for sensitive data such as Social Security numbers, credit card numbers and other predefined or custom based sensitive data.
NEW QUESTION 18
Refer to the exhibit.
There is only one administrator account configured on FortiWeb. What must an administrator do to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?
- A. Delete the built-in administrator user and create a new one.
- B. Configure IPv4 Trusted Host # 3 with a specific IP address.
- C. The configuration changes must be made on the upstream device.
- D. Change the Access Profile to Read_Only.
Answer: A
NEW QUESTION 19
FortiWeb offers the same load balancing algorithms as FortiGate.
Which two Layer 7 switch methods does FortiWeb also offer? (Choose two.)
- A. HTTP content routes
- B. HTTP user-based round robin
- C. Round robin
- D. HTTP session-based round robin
Answer: A,C
Explanation:
Reference:
http://fortinet.globalgate.com.ar/pdfs/FortiWeb/FortiWeb_DS.pdf
NEW QUESTION 20
What is one of the key benefits of the FortiGuard IP reputation feature?
- A. It maintains a list of public IPs with a bad reputation for participating in attacks.
- B. It is updated once per year.
- C. It provides a document of IP addresses that are suspect, so that administrators can manually update their blacklists.
- D. It maintains a list of private IP addresses.
Answer: A
Explanation:
FortiGuard IP Reputation service assigns a poor reputation, including virus-infected clients and malicious spiders/crawlers.
NEW QUESTION 21
Which three statements about HTTPS on FortiWeb are true? (Choose three.)
- A. In transparent inspection mode, you select the certificate that FortiWeb presents in the server pool, not in the server policy.
- B. In true transparent mode, the TLS session terminator is a protected web server.
- C. After enabling HSTS, redirects to HTTPS are never needed.
- D. For SNI, you select the certificate that FortiWeb presents in the server pool, not in the server policy.
- E. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to offer only TLS 1.2.
Answer: A,B,D
NEW QUESTION 22
What can an administrator do if a client has been incorrectly period blocked?
- A. Force a new IP address to the client.
- B. Manually release the ID address from the temporary blacklist.
- C. Nothing, it is not possible to override a period block.
- D. Disconnect the client from the network.
Answer: B
Explanation:
Block Period
Enter the number of seconds that you want to block the requests. The valid range is 1-3,600 seconds. The default value is 60 seconds.
This option only takes effect when you choose Period Block in Action.
Note: That's a temporary blacklist so you can manually release them from the blacklist.
NEW QUESTION 23
What key factor must be considered when setting brute force rate limiting and blocking?
- A. Multiple clients from geographically diverse locations
- B. A single client contacting multiple resources
- C. Multiple clients sharing a single Internet connection
- D. Multiple clients connecting to multiple resources
Answer: D
NEW QUESTION 24
In which scenario might you want to use the compression feature on FortiWeb?
- A. When you want to reduce buffering of video streams
- B. When you are offering a music streaming service
- C. When you are serving many corporate road warriors using 4G tablets and phones
- D. Never, since most traffic today is already highly compressed
Answer: D
Explanation:
FortiWeb might expend resources compressing responses that have already been compressed by the server.
NEW QUESTION 25
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
- A. Client real IP
- B. FortiGate local IP
- C. FortiWeb IP
- D. FortiGate public IP
Answer: A
Explanation:
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.
NEW QUESTION 26
Which statement about local user accounts is true?
- A. They are best suited for large environments with many users.
- B. They cannot be used for site publishing.
- C. They must be assigned, regardless of any other authentication.
- D. They can be used for SSO.
Answer: D
Explanation:
You can configure the Remedy Single Sign-On server to authenticate TrueSight Capacity Optimization users as local users.
NEW QUESTION 27
......
Verified NSE6_FWB-6.1 dumps Q&As - Pass Guarantee Exam Dumps Test Engine: https://www.vce4plus.com/Fortinet/NSE6_FWB-6.1-valid-vce-dumps.html