NSE6_FWB-6.1 Pre-Exam Practice Tests (Updated 30 Questions) [Q10-Q29]

Share

NSE6_FWB-6.1 Pre-Exam Practice Tests | (Updated 30 Questions)

Valid NSE6_FWB-6.1 Exam Q&A PDF - One Year Free Update

NEW QUESTION 10
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.
Which two functions does the first layer perform? (Choose two.)

  • A. Determines whether traffic is an anomaly, based on observed application traffic over time
  • B. Builds a threat model behind every parameter and HTTP method
  • C. Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored
  • D. Determines if a detected threat is a false-positive or not

Answer: A,B

Explanation:
The first layer uses the Hidden Markov Model (HMM) and monitors access to the application and collects data to build a mathematical model behind every parameter and HTTP method.

 

NEW QUESTION 11
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?

  • A. FortiGate public IP
  • B. Client real IP
  • C. FortiGate local IP
  • D. FortiWeb IP

Answer: B

Explanation:
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.

 

NEW QUESTION 12
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)

  • A. Display an access policy message, then allow the client to continue
  • B. Prompt the client to authenticate
  • C. Redirect the client to the login page
  • D. Reply with a 403 Forbidden HTTP error
  • E. Allow the page access, but log the violation

Answer: C,D,E

 

NEW QUESTION 13
Refer to the exhibit.

FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)

  • A. Place FortiWeb in front of FortiADC.
  • B. Enable the Use X-Forwarded-For setting on FortiWeb.
  • C. Enable the Add X-Forwarded-For setting on FortiWeb.
  • D. No Special configuration is required; connectivity will be re-established after the set timeout.

Answer: B,C

Explanation:
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header

 

NEW QUESTION 14
In which scenario might you want to use the compression feature on FortiWeb?

  • A. Never, since most traffic today is already highly compressed
  • B. When you are serving many corporate road warriors using 4G tablets and phones
  • C. When you want to reduce buffering of video streams
  • D. When you are offering a music streaming service

Answer: A

Explanation:
FortiWeb might expend resources compressing responses that have already been compressed by the server.

 

NEW QUESTION 15
Which algorithm is used to build mathematical models for bot detection?

  • A. SVM
  • B. HMM
  • C. SVN
  • D. HCM

Answer: A

Explanation:
FortiWeb uses SVM (Support Vector Machine) algorithm to build up the bot detection model

 

NEW QUESTION 16
What key factor must be considered when setting brute force rate limiting and blocking?

  • A. A single client contacting multiple resources
  • B. Multiple clients sharing a single Internet connection
  • C. Multiple clients from geographically diverse locations
  • D. Multiple clients connecting to multiple resources

Answer: D

 

NEW QUESTION 17
Which would be a reason to implement HTTP rewriting?

  • A. The original page has moved to a new URL
  • B. To replace a vulnerable function in the requested URL
  • C. To send the request to secure channel
  • D. The original page has moved to a new IP address

Answer: A

Explanation:
Create a new URL rewriting rule.

 

NEW QUESTION 18
Which regex expression is the correct format for redirecting the URL http://www.example.com?

  • A. www\.example\.com
  • B. www.example.com
  • C. www/.example/.com
  • D. www\example\com

Answer: B

Explanation:
\1://www.company.com/\2/\3

 

NEW QUESTION 19
Which statement about local user accounts is true?

  • A. They are best suited for large environments with many users.
  • B. They can be used for SSO.
  • C. They must be assigned, regardless of any other authentication.
  • D. They cannot be used for site publishing.

Answer: B

Explanation:
You can configure the Remedy Single Sign-On server to authenticate TrueSight Capacity Optimization users as local users.

 

NEW QUESTION 20
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?

  • A. If you are an enterprise whose computers all trust your active directory or other CA server
  • B. If you are a small business or home office
  • C. If you are an enterprise whose resources do not need security
  • D. If you are an enterprise whose employees use only mobile devices

Answer: C

Explanation:
This can include SSL/TLS certificates, code signing certificates, and S/MIME certificates. The reason why they're considered different from traditional certificate-authority signed certificates is that they're created, issued, and signed by the company or developer who is responsible for the website or software being signed. This is why self-signed certificates are considered unsafe for public-facing websites and applications.

 

NEW QUESTION 21
Which two statements about running a vulnerability scan are true? (Choose two.)

  • A. You should run the vulnerability scan in a test environment.
  • B. You should run the vulnerability scan during a maintenance window.
  • C. You should run the vulnerability scan on a live website to get accurate results.
  • D. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.

Answer: A,B

Explanation:
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
Reference:
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/vulnerability_scans.htm

 

NEW QUESTION 22
......

Fortinet NSE 6 - FortiWeb 6.1 Free Update Certification Sample Questions: https://testking.itexamsimulator.com/NSE6_FWB-6.1-brain-dumps.html