[Jul 18, 2021] NSE6_FWB-6.1 PDF Dumps is essential on your NSE6_FWB-6.1 Exam Questions Certain Success!
NSE6_FWB-6.1 PDF Questions - Perfect Prospect To Go With NSE6_FWB-6.1 Practice Exam
NEW QUESTION 15
What role does FortiWeb play in ensuring PCI DSS compliance?
- A. It provides the ability to securely process cash transactions.
- B. It provides the required SQL server protection.
- C. It provides credit card processing capabilities.
- D. It provides the WAF required by PCI.
Answer: C
Explanation:
FortiWeb protects against attacks that lead to sensitive data exposure such as SQL Injection and other injection types. Additionally, FortiWeb inspects all web server outgoing traffic for sensitive data such as Social Security numbers, credit card numbers and other predefined or custom based sensitive data.
NEW QUESTION 16
Which two statements about running a vulnerability scan are true? (Choose two.)
- A. Vulnerability scanning increases the load on FortiWeb, so it should be avoided.
- B. You should run the vulnerability scan during a maintenance window.
- C. You should run the vulnerability scan in a test environment.
- D. You should run the vulnerability scan on a live website to get accurate results.
Answer: B,C
Explanation:
Should the Vulnerability Scanner allow it, SVMS will set the scan schedule (or schedules) to run in a maintenance window. SVMS will advise Client of the scanner's ability to complete the scan(s) within the maintenance window.
Vulnerabilities on live web sites. Instead, duplicate the web site and its database in a test environment.
Reference:
https://help.fortinet.com/fweb/552/Content/FortiWeb/fortiweb-admin/vulnerability_scans.htm
NEW QUESTION 17
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.
Which two functions does the first layer perform? (Choose two.)
- A. Builds a threat model behind every parameter and HTTP method
- B. Determines if a detected threat is a false-positive or not
- C. Determines whether traffic is an anomaly, based on observed application traffic over time
- D. Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored
Answer: A,C
Explanation:
The first layer uses the Hidden Markov Model (HMM) and monitors access to the application and collects data to build a mathematical model behind every parameter and HTTP method.
NEW QUESTION 18
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)
- A. True transparent proxy
- B. Transparent inspection
- C. Offline protection
- D. Reverse proxy
Answer: A,C
Explanation:
FortiWeb appliances operating in offline protection mode or either of the transparent modes
NEW QUESTION 19
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- A. Compress them into a .zip file format
- B. Erase them every two weeks
- C. Store in an off-site location
- D. Enable masking of sensitive data
Answer: D
NEW QUESTION 20
Review the following configuration:
What is the expected result of this configuration setting?
- A. When machine learning (ML) is in its collecting phase, FortiWeb will not accept any samples from any source IP addresses.
- B. When machine learning (ML) is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- C. When machine learning (ML) is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- D. When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.
Answer: C
NEW QUESTION 21
True transparent proxy mode is best suited for use in which type of environment?
- A. Flexible environments where you can easily change the IP addressing scheme
- B. New networks where infrastructure is not yet defined
- C. Environments where you cannot change the IP addressing scheme
- D. Small office to home office environments
Answer: C
Explanation:
Does not require changes to the IP address scheme of the network. Requests are destined for a web server and not the FortiWeb appliance. This operation mode supports the same feature set as True Transparent Proxy mode.
NEW QUESTION 22
Which statement about local user accounts is true?
- A. They must be assigned, regardless of any other authentication.
- B. They are best suited for large environments with many users.
- C. They cannot be used for site publishing.
- D. They can be used for SSO.
Answer: D
Explanation:
You can configure the Remedy Single Sign-On server to authenticate TrueSight Capacity Optimization users as local users.
NEW QUESTION 23
What can an administrator do if a client has been incorrectly period blocked?
- A. Nothing, it is not possible to override a period block.
- B. Manually release the ID address from the temporary blacklist.
- C. Force a new IP address to the client.
- D. Disconnect the client from the network.
Answer: B
Explanation:
Block Period
Enter the number of seconds that you want to block the requests. The valid range is 1-3,600 seconds. The default value is 60 seconds.
This option only takes effect when you choose Period Block in Action.
Note: That's a temporary blacklist so you can manually release them from the blacklist.
NEW QUESTION 24
Which would be a reason to implement HTTP rewriting?
- A. The original page has moved to a new IP address
- B. To replace a vulnerable function in the requested URL
- C. The original page has moved to a new URL
- D. To send the request to secure channel
Answer: C
Explanation:
Create a new URL rewriting rule.
NEW QUESTION 25
Refer to the exhibit.
Many legitimate users are being identified as bots. FortiWeb bot detection has been configured with the settings shown in the exhibit. The FortiWeb administrator has already verified that the current model is accurate.
What can the administrator do to fix this problem, making sure that real bots are not allowed through FortiWeb?
- A. Change Model Type to Strict
- B. Enable Bot Confirmation
- C. Disable Dynamically Update Model
- D. Change Action under Action Settings to Alert
Answer: B
Explanation:
Bot Confirmation
If the number of anomalies from a user has reached the Anomaly Count, the system executes Bot Confirmation before taking actions.
The Bot Confirmation is to confirm if the user is indeed a bot. The system sends RBE (Real Browser Enforcement) JavaScript or CAPTCHA to the client to double check if it's a real bot.
NEW QUESTION 26
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?
- A. The server policy applies the same protection profile to all of its protected web applications.
- B. Static or policy-based routes are not required.
- C. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
- D. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
Answer: B
NEW QUESTION 27
......
NSE6_FWB-6.1 Exam with Accurate Fortinet NSE 6 - FortiWeb 6.1 PDF Questions: https://www.testvalid.com/NSE6_FWB-6.1-exam-collection.html