[Dec 03, 2021] Prepare For The NSE6_FWB-6.1 Question Papers In Advance
NSE6_FWB-6.1 PDF Dumps Real 2021 Recently Updated Questions
NEW QUESTION 11
Refer to the exhibit.
FortiWeb is configured to block traffic from Japan to your web application server. However, in the logs, the administrator is seeing traffic allowed from one particular IP address which is geo-located in Japan.
What can the administrator do to solve this problem? (Choose two.)
- A. If the IP address is configured as a geo reputation exception, remove it.
- B. Configure the IP address as a blacklisted IP address.
- C. Manually update the geo-location IP addresses for Japan.
- D. If the IP address is configured as an IP reputation exception, remove it.
Answer: B,C
Explanation:
IP reputation leverages many techniques for accurate, early, and frequently updated identification of compromised and malicious clients so you can block attackers before they target your servers.
IP blacklisting is a method used to filter out illegitimate or malicious IP addresses from accessing your networks. Blacklists are lists containing ranges of or individual IP addresses that you want to block.
Reference:
https://www.imperva.com/learn/application-security/ip-blacklist/
NEW QUESTION 12
Which regex expression is the correct format for redirecting the URL http://www.example.com?
- A. www.example.com
- B. www/.example/.com
- C. www\example\com
- D. www\.example\.com
Answer: A
Explanation:
\1://www.company.com/\2/\3
NEW QUESTION 13
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Allow the page access, but log the violation
- B. Reply with a 403 Forbidden HTTP error
- C. Prompt the client to authenticate
- D. Display an access policy message, then allow the client to continue
- E. Redirect the client to the login page
Answer: A,B,E
NEW QUESTION 14
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.
Which two functions does the first layer perform? (Choose two.)
- A. Builds a threat model behind every parameter and HTTP method
- B. Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored
- C. Determines if a detected threat is a false-positive or not
- D. Determines whether traffic is an anomaly, based on observed application traffic over time
Answer: A,D
Explanation:
The first layer uses the Hidden Markov Model (HMM) and monitors access to the application and collects data to build a mathematical model behind every parameter and HTTP method.
NEW QUESTION 15
Refer to the exhibit.
FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)
- A. Enable the Use X-Forwarded-For setting on FortiWeb.
- B. No Special configuration is required; connectivity will be re-established after the set timeout.
- C. Place FortiWeb in front of FortiADC.
- D. Enable the Add X-Forwarded-For setting on FortiWeb.
Answer: A,D
Explanation:
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header
NEW QUESTION 16
Which two statements about running a vulnerability scan are true? (Choose two.)
- A. You should run the vulnerability scan in a test environment.
- B. You should run the vulnerability scan on a live website to get accurate results.
- C. You should run the vulnerability scan during a maintenance window.
- D. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
Answer: A,C
Explanation:
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
Reference:
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/vulnerability_scans.htm
NEW QUESTION 17
Which algorithm is used to build mathematical models for bot detection?
- A. SVM
- B. HCM
- C. HMM
- D. SVN
Answer: A
Explanation:
FortiWeb uses SVM (Support Vector Machine) algorithm to build up the bot detection model
NEW QUESTION 18
Refer to the exhibit.
Based on the configuration, what would happen if this FortiWeb were to lose power? (Choose two.)
- A. Traffic that passes between port5 and port6 will be inspected.
- B. Traffic will be interrupted between port3 and port4.
- C. Traffic will pass between port5 and port6 uninspected.
- D. All traffic will be interrupted.
Answer: B,C
NEW QUESTION 19
How does FortiWeb protect against defacement attacks?
- A. It keeps full copies of all files and directories.
- B. It keeps a live duplicate of the database.
- C. It keeps a complete backup of all files and the database.
- D. It keeps hashes of files and periodically compares them to the server.
Answer: D
Explanation:
The anti-defacement feature examines a web site's files for changes at specified time intervals. If it detects a change that could indicate a defacement attack, the FortiWeb appliance can notify you and quickly react by automatically restoring the web site contents to the previous backup.
NEW QUESTION 20
In which scenario might you want to use the compression feature on FortiWeb?
- A. Never, since most traffic today is already highly compressed
- B. When you are serving many corporate road warriors using 4G tablets and phones
- C. When you want to reduce buffering of video streams
- D. When you are offering a music streaming service
Answer: A
Explanation:
FortiWeb might expend resources compressing responses that have already been compressed by the server.
NEW QUESTION 21
Refer to the exhibits.

FortiWeb is configured in reverse proxy mode and it is deployed downstream to FortiGate. Based on the configuration shown in the exhibits, which of the following statements is true?
- A. FortiGate should forward web traffic to the server pool IP addresses.
- B. FortiGate should forward web traffic to virtual server IP address.
- C. You must disable the Preserve Client IP setting on FotriGate for this configuration to work.
- D. The configuration is incorrect. FortiWeb should always be located upstream to FortiGate.
Answer: B
NEW QUESTION 22
True transparent proxy mode is best suited for use in which type of environment?
- A. Flexible environments where you can easily change the IP addressing scheme
- B. New networks where infrastructure is not yet defined
- C. Small office to home office environments
- D. Environments where you cannot change the IP addressing scheme
Answer: D
Explanation:
Does not require changes to the IP address scheme of the network. Requests are destined for a web server and not the FortiWeb appliance. This operation mode supports the same feature set as True Transparent Proxy mode.
NEW QUESTION 23
......
NSE6_FWB-6.1 Dumps and Practice Test (30 Exam Questions): https://www.prep4pass.com/NSE6_FWB-6.1_exam-braindumps.html
