[Dec 06, 2021] New Updated NSE6_FWB-6.1 Exam Questions 2021 [Q18-Q33]

Share

[Dec 06, 2021] New Updated NSE6_FWB-6.1 Exam Questions 2021

Updated Free Fortinet NSE6_FWB-6.1 Test Engine Questions with 30 Q&As

NEW QUESTION 18
What can an administrator do if a client has been incorrectly period blocked?

  • A. Manually release the ID address from the temporary blacklist.
  • B. Nothing, it is not possible to override a period block.
  • C. Force a new IP address to the client.
  • D. Disconnect the client from the network.

Answer: A

Explanation:
Block Period
Enter the number of seconds that you want to block the requests. The valid range is 1-3,600 seconds. The default value is 60 seconds.
This option only takes effect when you choose Period Block in Action.
Note: That's a temporary blacklist so you can manually release them from the blacklist.

 

NEW QUESTION 19
Which two statements about running a vulnerability scan are true? (Choose two.)

  • A. You should run the vulnerability scan in a test environment.
  • B. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
  • C. You should run the vulnerability scan on a live website to get accurate results.
  • D. You should run the vulnerability scan during a maintenance window.

Answer: A,D

Explanation:
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
Reference:
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/vulnerability_scans.htm

 

NEW QUESTION 20
What is one of the key benefits of the FortiGuard IP reputation feature?

  • A. It maintains a list of public IPs with a bad reputation for participating in attacks.
  • B. It maintains a list of private IP addresses.
  • C. It is updated once per year.
  • D. It provides a document of IP addresses that are suspect, so that administrators can manually update their blacklists.

Answer: A

Explanation:
FortiGuard IP Reputation service assigns a poor reputation, including virus-infected clients and malicious spiders/crawlers.

 

NEW QUESTION 21
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)

  • A. Transparent inspection
  • B. Offline protection
  • C. Reverse proxy
  • D. True transparent proxy

Answer: B,D

Explanation:
FortiWeb appliances operating in offline protection mode or either of the transparent modes

 

NEW QUESTION 22
Refer to the exhibit.

Many legitimate users are being identified as bots. FortiWeb bot detection has been configured with the settings shown in the exhibit. The FortiWeb administrator has already verified that the current model is accurate.
What can the administrator do to fix this problem, making sure that real bots are not allowed through FortiWeb?

  • A. Enable Bot Confirmation
  • B. Change Model Type to Strict
  • C. Change Action under Action Settings to Alert
  • D. Disable Dynamically Update Model

Answer: A

Explanation:
Bot Confirmation
If the number of anomalies from a user has reached the Anomaly Count, the system executes Bot Confirmation before taking actions.
The Bot Confirmation is to confirm if the user is indeed a bot. The system sends RBE (Real Browser Enforcement) JavaScript or CAPTCHA to the client to double check if it's a real bot.

 

NEW QUESTION 23
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?

  • A. If you are an enterprise whose computers all trust your active directory or other CA server
  • B. If you are an enterprise whose resources do not need security
  • C. If you are a small business or home office
  • D. If you are an enterprise whose employees use only mobile devices

Answer: B

Explanation:
This can include SSL/TLS certificates, code signing certificates, and S/MIME certificates. The reason why they're considered different from traditional certificate-authority signed certificates is that they're created, issued, and signed by the company or developer who is responsible for the website or software being signed. This is why self-signed certificates are considered unsafe for public-facing websites and applications.

 

NEW QUESTION 24
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?

  • A. Static or policy-based routes are not required.
  • B. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
  • C. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
  • D. The server policy applies the same protection profile to all of its protected web applications.

Answer: A

 

NEW QUESTION 25
Refer to the exhibit.

FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)

  • A. No Special configuration is required; connectivity will be re-established after the set timeout.
  • B. Place FortiWeb in front of FortiADC.
  • C. Enable the Use X-Forwarded-For setting on FortiWeb.
  • D. Enable the Add X-Forwarded-For setting on FortiWeb.

Answer: C,D

Explanation:
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header

 

NEW QUESTION 26
True transparent proxy mode is best suited for use in which type of environment?

  • A. Small office to home office environments
  • B. Flexible environments where you can easily change the IP addressing scheme
  • C. New networks where infrastructure is not yet defined
  • D. Environments where you cannot change the IP addressing scheme

Answer: D

Explanation:
Does not require changes to the IP address scheme of the network. Requests are destined for a web server and not the FortiWeb appliance. This operation mode supports the same feature set as True Transparent Proxy mode.

 

NEW QUESTION 27
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.
Which two functions does the first layer perform? (Choose two.)

  • A. Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored
  • B. Builds a threat model behind every parameter and HTTP method
  • C. Determines if a detected threat is a false-positive or not
  • D. Determines whether traffic is an anomaly, based on observed application traffic over time

Answer: B,D

Explanation:
The first layer uses the Hidden Markov Model (HMM) and monitors access to the application and collects data to build a mathematical model behind every parameter and HTTP method.

 

NEW QUESTION 28
Refer to the exhibits.


FortiWeb is configured in reverse proxy mode and it is deployed downstream to FortiGate. Based on the configuration shown in the exhibits, which of the following statements is true?

  • A. You must disable the Preserve Client IP setting on FotriGate for this configuration to work.
  • B. FortiGate should forward web traffic to the server pool IP addresses.
  • C. The configuration is incorrect. FortiWeb should always be located upstream to FortiGate.
  • D. FortiGate should forward web traffic to virtual server IP address.

Answer: D

 

NEW QUESTION 29
What role does FortiWeb play in ensuring PCI DSS compliance?

  • A. It provides credit card processing capabilities.
  • B. It provides the required SQL server protection.
  • C. It provides the ability to securely process cash transactions.
  • D. It provides the WAF required by PCI.

Answer: A

Explanation:
FortiWeb protects against attacks that lead to sensitive data exposure such as SQL Injection and other injection types. Additionally, FortiWeb inspects all web server outgoing traffic for sensitive data such as Social Security numbers, credit card numbers and other predefined or custom based sensitive data.

 

NEW QUESTION 30
......

Try 100% Updated NSE6_FWB-6.1 Exam Questions [2021]: https://testking.itexamsimulator.com/NSE6_FWB-6.1-brain-dumps.html