[2022] NSE6_FWB-6.1 Answers NSE6_FWB-6.1 Free Demo Are Based On The Real Exam
NSE6_FWB-6.1 [Mar-2022 Newly Released] Exam Questions For You To Pass
NEW QUESTION 13
Refer to the exhibit.
FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)
- A. Place FortiWeb in front of FortiADC.
- B. Enable the Use X-Forwarded-For setting on FortiWeb.
- C. Enable the Add X-Forwarded-For setting on FortiWeb.
- D. No Special configuration is required; connectivity will be re-established after the set timeout.
Answer: B,C
Explanation:
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header
NEW QUESTION 14
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
- A. FortiGate public IP
- B. Client real IP
- C. FortiGate local IP
- D. FortiWeb IP
Answer: B
Explanation:
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.
NEW QUESTION 15
Review the following configuration:
What is the expected result of this configuration setting?
- A. When machine learning (ML) is in its collecting phase, FortiWeb will not accept any samples from any source IP addresses.
- B. When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.
- C. When machine learning (ML) is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- D. When machine learning (ML) is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
Answer: C
NEW QUESTION 16
Which three statements about HTTPS on FortiWeb are true? (Choose three.)
- A. For SNI, you select the certificate that FortiWeb presents in the server pool, not in the server policy.
- B. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to offer only TLS 1.2.
- C. In transparent inspection mode, you select the certificate that FortiWeb presents in the server pool, not in the server policy.
- D. After enabling HSTS, redirects to HTTPS are never needed.
- E. In true transparent mode, the TLS session terminator is a protected web server.
Answer: A,C,E
NEW QUESTION 17
Which two statements about running a vulnerability scan are true? (Choose two.)
- A. You should run the vulnerability scan in a test environment.
- B. You should run the vulnerability scan during a maintenance window.
- C. You should run the vulnerability scan on a live website to get accurate results.
- D. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
Answer: A,B
Explanation:
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
Reference:
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/vulnerability_scans.htm
NEW QUESTION 18
When FortiWeb triggers a redirect action, which two HTTP codes does it send to the client to inform the browser of the new URL? (Choose two.)
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A,C
NEW QUESTION 19
Refer to the exhibit.
FortiWeb is configured to block traffic from Japan to your web application server. However, in the logs, the administrator is seeing traffic allowed from one particular IP address which is geo-located in Japan.
What can the administrator do to solve this problem? (Choose two.)
- A. If the IP address is configured as an IP reputation exception, remove it.
- B. Configure the IP address as a blacklisted IP address.
- C. Manually update the geo-location IP addresses for Japan.
- D. If the IP address is configured as a geo reputation exception, remove it.
Answer: B,C
Explanation:
IP reputation leverages many techniques for accurate, early, and frequently updated identification of compromised and malicious clients so you can block attackers before they target your servers.
IP blacklisting is a method used to filter out illegitimate or malicious IP addresses from accessing your networks. Blacklists are lists containing ranges of or individual IP addresses that you want to block.
Reference:
https://www.imperva.com/learn/application-security/ip-blacklist/
NEW QUESTION 20
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)
- A. True transparent proxy
- B. Reverse proxy
- C. Transparent inspection
- D. Offline protection
Answer: A,D
Explanation:
FortiWeb appliances operating in offline protection mode or either of the transparent modes
NEW QUESTION 21
FortiWeb offers the same load balancing algorithms as FortiGate.
Which two Layer 7 switch methods does FortiWeb also offer? (Choose two.)
- A. Round robin
- B. HTTP user-based round robin
- C. HTTP session-based round robin
- D. HTTP content routes
Answer: A,D
Explanation:
Reference:
http://fortinet.globalgate.com.ar/pdfs/FortiWeb/FortiWeb_DS.pdf
NEW QUESTION 22
Which statement about local user accounts is true?
- A. They are best suited for large environments with many users.
- B. They can be used for SSO.
- C. They must be assigned, regardless of any other authentication.
- D. They cannot be used for site publishing.
Answer: B
Explanation:
You can configure the Remedy Single Sign-On server to authenticate TrueSight Capacity Optimization users as local users.
NEW QUESTION 23
How does FortiWeb protect against defacement attacks?
- A. It keeps hashes of files and periodically compares them to the server.
- B. It keeps full copies of all files and directories.
- C. It keeps a live duplicate of the database.
- D. It keeps a complete backup of all files and the database.
Answer: A
Explanation:
The anti-defacement feature examines a web site's files for changes at specified time intervals. If it detects a change that could indicate a defacement attack, the FortiWeb appliance can notify you and quickly react by automatically restoring the web site contents to the previous backup.
NEW QUESTION 24
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?
- A. If you are an enterprise whose computers all trust your active directory or other CA server
- B. If you are a small business or home office
- C. If you are an enterprise whose resources do not need security
- D. If you are an enterprise whose employees use only mobile devices
Answer: C
Explanation:
This can include SSL/TLS certificates, code signing certificates, and S/MIME certificates. The reason why they're considered different from traditional certificate-authority signed certificates is that they're created, issued, and signed by the company or developer who is responsible for the website or software being signed. This is why self-signed certificates are considered unsafe for public-facing websites and applications.
NEW QUESTION 25
......
New 2022 Realistic Free Fortinet NSE6_FWB-6.1 Exam Dump Questions and Answer: https://www.torrentexam.com/NSE6_FWB-6.1-exam-latest-torrent.html

