[Q16-Q36] Ultimate Guide to Prepare NSE6_FWB-6.1 with Accurate PDF Questions [Nov 30, 2021]

Share

Ultimate Guide to Prepare NSE6_FWB-6.1 with Accurate PDF Questions [Nov 30, 2021]

Pass Fortinet With Prep4pass Exam Dumps

NEW QUESTION 16
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?

  • A. If you are an enterprise whose computers all trust your active directory or other CA server
  • B. If you are an enterprise whose resources do not need security
  • C. If you are a small business or home office
  • D. If you are an enterprise whose employees use only mobile devices

Answer: B

Explanation:
This can include SSL/TLS certificates, code signing certificates, and S/MIME certificates. The reason why they're considered different from traditional certificate-authority signed certificates is that they're created, issued, and signed by the company or developer who is responsible for the website or software being signed. This is why self-signed certificates are considered unsafe for public-facing websites and applications.

 

NEW QUESTION 17
Which regex expression is the correct format for redirecting the URL http://www.example.com?

  • A. www/.example/.com
  • B. www.example.com
  • C. www\example\com
  • D. www\.example\.com

Answer: B

Explanation:
\1://www.company.com/\2/\3

 

NEW QUESTION 18
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?

  • A. FortiWeb IP
  • B. FortiGate public IP
  • C. Client real IP
  • D. FortiGate local IP

Answer: C

Explanation:
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.

 

NEW QUESTION 19
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)

  • A. Transparent inspection
  • B. True transparent proxy
  • C. Offline protection
  • D. Reverse proxy

Answer: B,C

Explanation:
FortiWeb appliances operating in offline protection mode or either of the transparent modes

 

NEW QUESTION 20
What must you do with your FortiWeb logs to ensure PCI DSS compliance?

  • A. Compress them into a .zip file format
  • B. Erase them every two weeks
  • C. Store in an off-site location
  • D. Enable masking of sensitive data

Answer: D

 

NEW QUESTION 21
What key factor must be considered when setting brute force rate limiting and blocking?

  • A. Multiple clients from geographically diverse locations
  • B. A single client contacting multiple resources
  • C. Multiple clients connecting to multiple resources
  • D. Multiple clients sharing a single Internet connection

Answer: C

 

NEW QUESTION 22
What is one of the key benefits of the FortiGuard IP reputation feature?

  • A. It provides a document of IP addresses that are suspect, so that administrators can manually update their blacklists.
  • B. It is updated once per year.
  • C. It maintains a list of public IPs with a bad reputation for participating in attacks.
  • D. It maintains a list of private IP addresses.

Answer: C

Explanation:
FortiGuard IP Reputation service assigns a poor reputation, including virus-infected clients and malicious spiders/crawlers.

 

NEW QUESTION 23
What role does FortiWeb play in ensuring PCI DSS compliance?

  • A. It provides the ability to securely process cash transactions.
  • B. It provides the WAF required by PCI.
  • C. It provides the required SQL server protection.
  • D. It provides credit card processing capabilities.

Answer: D

Explanation:
FortiWeb protects against attacks that lead to sensitive data exposure such as SQL Injection and other injection types. Additionally, FortiWeb inspects all web server outgoing traffic for sensitive data such as Social Security numbers, credit card numbers and other predefined or custom based sensitive data.

 

NEW QUESTION 24
Which two statements about the anti-defacement feature on FortiWeb are true? (Choose two.)

  • A. Anti-defacement does not make a backup copy of your databases.
  • B. FortiWeb will only check to see if there are changes on the web server; it will not download the whole file each time.
  • C. Anti-defacement downloads a copy of your website to RAM, in order to restore a clean image, if it detects defacement.
  • D. Anti-defacement can redirect users to a backup web server, if it detects a change.

Answer: A,B

Explanation:
Anti-defacement backs up web pages only, not databases.
If it detects any file changes, the FortiWeb appliance will download a new backup revision.

 

NEW QUESTION 25
Refer to the exhibit.

Based on the configuration, what would happen if this FortiWeb were to lose power? (Choose two.)

  • A. Traffic that passes between port5 and port6 will be inspected.
  • B. Traffic will pass between port5 and port6 uninspected.
  • C. All traffic will be interrupted.
  • D. Traffic will be interrupted between port3 and port4.

Answer: B,D

 

NEW QUESTION 26
When FortiWeb triggers a redirect action, which two HTTP codes does it send to the client to inform the browser of the new URL? (Choose two.)

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B,C

 

NEW QUESTION 27
Refer to the exhibit.

FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)

  • A. Enable the Add X-Forwarded-For setting on FortiWeb.
  • B. No Special configuration is required; connectivity will be re-established after the set timeout.
  • C. Enable the Use X-Forwarded-For setting on FortiWeb.
  • D. Place FortiWeb in front of FortiADC.

Answer: A,C

Explanation:
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header

 

NEW QUESTION 28
......

Latest NSE6_FWB-6.1 Exam Dumps - Valid and Updated Dumps: https://www.prep4pass.com/NSE6_FWB-6.1_exam-braindumps.html