PDF (New 2021) Actual Fortinet NSE6_FWB-6.1 Exam Questions [Q18-Q37]

Share

PDF (New 2021) Actual Fortinet NSE6_FWB-6.1 Exam Questions

Dumps Moneyack Guarantee - NSE6_FWB-6.1 Dumps UpTo 90% Off

NEW QUESTION 18
Which would be a reason to implement HTTP rewriting?

  • A. To send the request to secure channel
  • B. The original page has moved to a new IP address
  • C. To replace a vulnerable function in the requested URL
  • D. The original page has moved to a new URL

Answer: D

Explanation:
Create a new URL rewriting rule.

 

NEW QUESTION 19
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)

  • A. Redirect the client to the login page
  • B. Reply with a 403 Forbidden HTTP error
  • C. Display an access policy message, then allow the client to continue
  • D. Prompt the client to authenticate
  • E. Allow the page access, but log the violation

Answer: A,B,E

 

NEW QUESTION 20
Which three statements about HTTPS on FortiWeb are true? (Choose three.)

  • A. After enabling HSTS, redirects to HTTPS are never needed.
  • B. For SNI, you select the certificate that FortiWeb presents in the server pool, not in the server policy.
  • C. In true transparent mode, the TLS session terminator is a protected web server.
  • D. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to offer only TLS 1.2.
  • E. In transparent inspection mode, you select the certificate that FortiWeb presents in the server pool, not in the server policy.

Answer: B,C,E

 

NEW QUESTION 21
What must you do with your FortiWeb logs to ensure PCI DSS compliance?

  • A. Compress them into a .zip file format
  • B. Erase them every two weeks
  • C. Store in an off-site location
  • D. Enable masking of sensitive data

Answer: D

 

NEW QUESTION 22
Refer to the exhibit.

FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)

  • A. Enable the Add X-Forwarded-For setting on FortiWeb.
  • B. No Special configuration is required; connectivity will be re-established after the set timeout.
  • C. Enable the Use X-Forwarded-For setting on FortiWeb.
  • D. Place FortiWeb in front of FortiADC.

Answer: A,C

Explanation:
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header

 

NEW QUESTION 23
Refer to the exhibit.

Many legitimate users are being identified as bots. FortiWeb bot detection has been configured with the settings shown in the exhibit. The FortiWeb administrator has already verified that the current model is accurate.
What can the administrator do to fix this problem, making sure that real bots are not allowed through FortiWeb?

  • A. Change Model Type to Strict
  • B. Change Action under Action Settings to Alert
  • C. Enable Bot Confirmation
  • D. Disable Dynamically Update Model

Answer: C

Explanation:
Bot Confirmation
If the number of anomalies from a user has reached the Anomaly Count, the system executes Bot Confirmation before taking actions.
The Bot Confirmation is to confirm if the user is indeed a bot. The system sends RBE (Real Browser Enforcement) JavaScript or CAPTCHA to the client to double check if it's a real bot.

 

NEW QUESTION 24
Which algorithm is used to build mathematical models for bot detection?

  • A. SVM
  • B. HMM
  • C. HCM
  • D. SVN

Answer: A

Explanation:
FortiWeb uses SVM (Support Vector Machine) algorithm to build up the bot detection model

 

NEW QUESTION 25
What key factor must be considered when setting brute force rate limiting and blocking?

  • A. Multiple clients from geographically diverse locations
  • B. A single client contacting multiple resources
  • C. Multiple clients connecting to multiple resources
  • D. Multiple clients sharing a single Internet connection

Answer: C

 

NEW QUESTION 26
Which two statements about running a vulnerability scan are true? (Choose two.)

  • A. You should run the vulnerability scan on a live website to get accurate results.
  • B. You should run the vulnerability scan during a maintenance window.
  • C. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
  • D. You should run the vulnerability scan in a test environment.

Answer: B,D

Explanation:
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
Reference:
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/vulnerability_scans.htm

 

NEW QUESTION 27
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.
Which two functions does the first layer perform? (Choose two.)

  • A. Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored
  • B. Builds a threat model behind every parameter and HTTP method
  • C. Determines whether traffic is an anomaly, based on observed application traffic over time
  • D. Determines if a detected threat is a false-positive or not

Answer: B,C

Explanation:
The first layer uses the Hidden Markov Model (HMM) and monitors access to the application and collects data to build a mathematical model behind every parameter and HTTP method.

 

NEW QUESTION 28
What is one of the key benefits of the FortiGuard IP reputation feature?

  • A. It provides a document of IP addresses that are suspect, so that administrators can manually update their blacklists.
  • B. It is updated once per year.
  • C. It maintains a list of public IPs with a bad reputation for participating in attacks.
  • D. It maintains a list of private IP addresses.

Answer: C

Explanation:
FortiGuard IP Reputation service assigns a poor reputation, including virus-infected clients and malicious spiders/crawlers.

 

NEW QUESTION 29
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?

  • A. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
  • B. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
  • C. The server policy applies the same protection profile to all of its protected web applications.
  • D. Static or policy-based routes are not required.

Answer: D

 

NEW QUESTION 30
......

Updated Dec-2021 Pass NSE6_FWB-6.1 Exam - Real Practice Test Questions: https://www.easy4engine.com/NSE6_FWB-6.1-test-engine.html

Pass Your Exam With 100% Verified NSE6_FWB-6.1 Exam Questions: https://drive.google.com/open?id=1_k8_lUKeWDn3hi0ZP3OBvACJ4jzkktRt