Fortinet Certified Professional - FortiWeb 7.4 Administrator Free Sample Questions

20 free sample questions207 in the full practice test Other version: NSE6_FWB-6.4(98)

Try simulator

FCP-FWB-AD-7-4 Sample Questions

  1. Question 1

    A financial institution is using FortiWeb's Machine Learning (ML) feature to protect its online banking portal. During a routine review, an administrator observes that the ML model has incorrectly flagged several legitimate, complex user transactions as anomalies. The goal is to reduce these false positives without significantly weakening security. Which action should the administrator take?

    Answer and explanation

    Correct answer: B

    The most appropriate action is to create exceptions for the specific, legitimate traffic that is being misidentified. FortiWeb's ML allows administrators to review detected anomalies and mark them as false positives, effectively training the model to ignore similar legitimate patterns in the future. This refines the model's accuracy without disabling it or lowering its overall sensitivity, which would expose the application to other threats.

  2. Question 2

    Multiple answers

    A retail company has a public-facing web application with a separate single-page application (SPA) front end hosted on https://shop.example.com and a back-end API on https://api.example.com. The front end needs to make POST requests with a custom X-Auth-Token header to the API. Which two FortiWeb configurations are required to enable this functionality securely while preventing Cross-Origin Resource Sharing (CORS) attacks? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    The primary step in configuring CORS is to explicitly whitelist the origin from which the cross-domain requests are allowed. In this case, the front-end application's domain must be added to the 'Allowed Origins' list.

    Because the request includes a custom header (X-Auth-Token), this header must be explicitly listed in the 'Allowed Headers' section of the CORS rule. Without this, the browser's preflight OPTIONS request will fail, blocking the actual POST request.

  3. Question 3

    A DevOps team is deploying a new microservices-based application protected by FortiWeb. The API endpoints and parameters are constantly changing as part of their CI/CD pipeline. The security team does not have a static OpenAPI schema but needs to protect the APIs from malicious payloads and structural attacks. Which FortiWeb feature is specifically designed to address this challenge?

    Answer and explanation

    Correct answer: C

    ML-based API Protection with continuous learning is the ideal solution for dynamic API environments. It analyzes live traffic to automatically discover and model the API structure, including endpoints and parameters. The continuous adjustment feature (new in 7.4) allows the model to adapt to frequent changes from a CI/CD pipeline without manual intervention, providing protection even without a static schema.

  4. Question 4

    True or False: When FortiWeb is deployed in True Transparent Proxy mode, it can perform Layer 7 content rewriting, such as modifying HTTP headers.

    Answer and explanation

    Correct answer: B

    This statement is false. Layer 7 content rewriting, such as modifying HTTP headers or rewriting content in the body, requires FortiWeb to act as a full proxy that terminates the connection. This functionality is available in Reverse Proxy mode, typically with SSL offloading, but not in True Transparent Proxy mode, which operates at a lower level to inspect traffic without terminating the session.

  5. Question 5

    An e-commerce platform is experiencing a sophisticated bot attack that mimics human behavior, making it difficult for signature-based and threshold-based detection methods to identify. The attacks are causing inventory exhaustion and application slowdowns. Which FortiWeb feature is most effective at mitigating this type of attack?

    Answer and explanation

    Correct answer: B

    ML-based Bot Detection using biometric modeling is specifically designed to counter sophisticated bots that mimic human behavior. It analyzes subtle patterns like mouse movements, typing speed, and mobile device orientation (part of the 13 behavioral dimensions) to create a model of genuine human interaction. This allows it to distinguish advanced bots from real users, which simpler methods like rate limiting or signature matching cannot do.

  6. Question 6

    A security administrator needs to ensure that all administrative changes made to a FortiWeb appliance are logged and that the integrity of these logs is maintained to meet PCI DSS Requirement 10. Which FortiWeb configuration provides the strongest assurance of log integrity?

    Answer and explanation

    Correct answer: C

    PCI DSS requires logs to be stored securely and their integrity to be protected. Forwarding logs to a remote, centralized logging server like FortiAnalyzer prevents an attacker from altering logs on the local FortiWeb device. Enabling log file hashing (or digital signing) on the FortiAnalyzer provides a cryptographic mechanism to verify that the logs have not been tampered with, directly addressing the log integrity requirement.

  7. Question 7

    During the setup of a new web server policy on a FortiWeb appliance in Reverse Proxy mode, the administrator notices that the source IP addresses in the web server logs are all from the FortiWeb's own interface. This is causing issues for the analytics team. How can the administrator ensure the original client IP address is passed to the back-end web servers?

    Answer and explanation

    Correct answer: B

    In Reverse Proxy mode, FortiWeb terminates the client connection and initiates a new one to the back-end server, which causes the source IP to be that of the FortiWeb. The standard method to preserve the original client IP is to enable the 'Add X-Forwarded-For Header' (or similar headers like X-Real-IP). This inserts an HTTP header containing the original client's IP address into the request sent to the back-end server. The web server must then be configured to log this header value.

  8. Question 8

    A new administrator is protecting a GraphQL API endpoint with FortiWeb 7.4.1. They are concerned about denial-of-service attacks that exploit deeply nested or complex queries. Which specific FortiWeb feature should be configured to mitigate this threat?

    Answer and explanation

    Correct answer: C

    FortiWeb 7.4.1 introduced specific protections for GraphQL, including query complexity analysis. This feature allows administrators to set limits on factors like query depth and the number of aliases. By enforcing these limits, FortiWeb can block overly complex queries designed to overwhelm the server, effectively mitigating this type of denial-of-service attack vector unique to GraphQL.

  9. Question 9

    A hospital needs to protect its patient portal, which is hosted behind a FortiWeb appliance. To comply with data privacy regulations, all traffic between the client and the FortiWeb, as well as between the FortiWeb and the back-end web servers, must be encrypted. The FortiWeb must also inspect the traffic for attacks. Which SSL/TLS configuration fulfills these requirements?

    Answer and explanation

    Correct answer: C

    This scenario requires end-to-end encryption with inspection in the middle. This is achieved through SSL Offloading where FortiWeb terminates the client's SSL connection, inspects the decrypted traffic, and then re-encrypts it before sending it to the back-end server. Setting the 'SSL/TLS mode' to 'HTTPS' in the server pool configuration ensures that the connection from FortiWeb to the back-end servers is also encrypted.

  10. Question 10

    An administrator is configuring a FortiWeb High Availability (HA) cluster in Active-Passive mode. What is the primary function of the HA heartbeat interface?

    Answer and explanation

    Correct answer: C

    The HA heartbeat interface is a dedicated link used by the cluster members to send keep-alive packets to each other. Its primary purpose is to monitor the status and health of the other device in the cluster. If the active unit stops receiving heartbeat packets from the passive unit (or vice-versa), it assumes the peer is down and triggers a failover process to maintain service availability.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 305 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon