[Q21-Q40] Updated Mar-2023 Exam Engine or PDF for the NSE6_FWB-6.4 Tests Free Updated Today!

Share

Updated Mar-2023 Exam Engine or PDF for the NSE6_FWB-6.4 Tests Free Updated Today!

Ultimate Guide to Prepare NSE6_FWB-6.4 with Accurate PDF Questions

NEW QUESTION 21
Refer to the exhibit.

There is only one administrator account configured on FortiWeb. What must an administrator do to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?

  • A. The configuration changes must be made on the upstream device.
  • B. Change the Access Profile to Read_Only.
  • C. Delete the built-in administrator user and create a new one.
  • D. Configure IPv4 Trusted Host # 3 with a specific IP address.

Answer: D

 

NEW QUESTION 22
In which scenario might you want to use the compression feature on FortiWeb?

  • A. Never, since most traffic today is already highly compressed
  • B. When you want to reduce buffering of video streams
  • C. When you are offering a music streaming service
  • D. When you are serving many corporate road warriors using 4G tablets and phones

Answer: D

Explanation:
Explanation
https://training.fortinet.com/course/view.php?id=3363
When might you want to use the compression feature on FortiWeb? When you are serving many road warriors who are using 4G tablets and phones

 

NEW QUESTION 23
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)

  • A. Prompt the client to authenticate
  • B. Redirect the client to the login page
  • C. Display an access policy message, then allow the client to continue
  • D. Allow the page access, but log the violation
  • E. Reply with a 403 Forbidden HTTP error

Answer: B,D,E

 

NEW QUESTION 24
Which operation mode does not require additional configuration in order to allow FTP traffic to your web server?

  • A. Transparent Inspection
  • B. Reverse-Proxy
  • C. Offline Protection
  • D. True Transparent Proxy

Answer: A

 

NEW QUESTION 25
Which of the following would be a reason for implementing rewrites?

  • A. Replace vulnerable functions.
  • B. Send connection to secure channel
  • C. Page has been moved to a new IP address
  • D. Page has been moved to a new URL

Answer: A

 

NEW QUESTION 26
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?

  • A. Static or policy-based routes are not required.
  • B. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
  • C. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
  • D. The server policy applies the same protection profile to all of its protected web applications.

Answer: A

 

NEW QUESTION 27
Which would be a reason to implement HTTP rewriting?

  • A. To send the request to secure channel
  • B. The original page has moved to a new URL
  • C. The original page has moved to a new IP address
  • D. To replace a vulnerable function in the requested URL

Answer: D

Explanation:
Explanation
Create a new URL rewriting rule.

 

NEW QUESTION 28
Review the following configuration:

What is the expected result of this configuration setting?

  • A. When machine learning (ML) is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
  • B. When machine learning (ML) is in its collecting phase, FortiWeb will not accept any samples from any source IP addresses.
  • C. When machine learning (ML) is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
  • D. When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.

Answer: A

 

NEW QUESTION 29
You are deploying FortiWeb 6.4 in an Amazon Web Services cloud. Which 2 lines of this initial setup via CLI are incorrect? (Choose two.)

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B,C

 

NEW QUESTION 30
Which algorithm is used to build mathematical models for bot detection?

  • A. HMM
  • B. HCM
  • C. SVN
  • D. SVM

Answer: D

Explanation:
Explanation
FortiWeb uses SVM (Support Vector Machine) algorithm to build up the bot detection model

 

NEW QUESTION 31
Under what circumstances would you want to use the temporary uncompress feature of FortiWeb?

  • A. In the case of compression being done on the web server, to inspect the content of the compressed file.
  • B. In the case of the file being an .MP4 video
  • C. In the case of compression being done on the FortiWeb, to inspect the content of the compressed file
  • D. In the case of the file being a .MP3 music file

Answer: A

 

NEW QUESTION 32
Which is true about HTTPS on FortiWeb? (Choose three.)

  • A. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.
  • B. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.
  • C. In true transparent mode, the TLS session terminator is a protected web server.
  • D. After enabling HSTS, redirects to HTTPS are no longer necessary.
  • E. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.

Answer: A,C,E

 

NEW QUESTION 33
When FortiWeb triggers a redirect action, which two HTTP codes does it send to the client to inform the browser of the new URL? (Choose two.)

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A,B

 

NEW QUESTION 34
How does an ADOM differ from a VDOM?

  • A. ADOMs improve performance by offloading some functions.
  • B. Allows you to have 1 administrator for multiple tenants
  • C. ADOMs only affect specific functions, and do not provide full separation like VDOMs do.
  • D. ADOMs do not have virtual networking

Answer: D

 

NEW QUESTION 35
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?

  • A. Client real IP
  • B. FortiGate public IP
  • C. FortiWeb IP
  • D. FortiGate local IP

Answer: A

Explanation:
Explanation
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.

 

NEW QUESTION 36
What benefit does Auto Learning provide?

  • A. FortiWeb scans all traffic without taking action and makes recommendations on rules
  • B. Automatically identifies and blocks suspicious IPs
  • C. Automatically builds rules sets
  • D. Automatically blocks all detected threats

Answer: C

 

NEW QUESTION 37
What capability can FortiWeb add to your Web App that your Web App may or may not already have?

  • A. Automatic backup and recovery
  • B. HTTP/HTML Form Authentication
  • C. High Availability
  • D. SSL Inspection

Answer: B

 

NEW QUESTION 38
Which three statements about HTTPS on FortiWeb are true? (Choose three.)

  • A. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.
  • B. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.
  • C. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.
  • D. In true transparent mode, the TLS session terminator is a protected web server.
  • E. After enabling HSTS, redirects to HTTPS are no longer necessary.

Answer: A,B,D

 

NEW QUESTION 39
You are configuring FortiAnalyzer to store logs from FortiWeb.
Which is true?

  • A. FortiWeb will query FortiAnalyzer for reports, instead of generating them locally.
  • B. You must enable ADOMs on FortiAnalyzer.
  • C. FortiAnalyzer will store antivirus and DLP archives from FortiWeb.
  • D. To store logs from FortiWeb 6.4, on FortiAnalyzer, you must select "FrotiWeb 6.1".

Answer: B

 

NEW QUESTION 40
......


Fortinet NSE6_FWB-6.4 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Troubleshoot threat detection and mitigation related issues
  • Identify FortiWeb deployment requirements
Topic 2
  • Troublehsoot application delivery related issues
  • Configure various threat mitigation features
Topic 3
  • Configure machine learning and bot detection
  • Configure SSL inspection and offloading
Topic 4
  • Configure HTTP content routing, rewriting, and redirection
  • Mitigate attacks on authentication
Topic 5
  • Configure API protection and bot mitigation
  • Configure caching and compression

 

Pass Fortinet With PassReview Exam Dumps: https://www.passreview.com/NSE6_FWB-6.4_exam-braindumps.html

Fully Updated NSE6_FWB-6.4 Dumps - 100% Same Q&A In Your Real Exam: https://drive.google.com/open?id=1RBVFHAgRx4G2gxMfmOT6GRFwya6xMj7A