
[Sep 23, 2021] NSE6_FWB-6.0 Ultimate Study Guide - Exam4Docs
Ultimate Guide to Prepare NSE6_FWB-6.0 Certification Exam for Fortinet Certification in 2021
NEW QUESTION 12
Which of the followingwould be a reason for implementing rewrites?
- A. Send connection to secure channel
- B. Replace vulnerable functions.
- C. Page has been moved to a new IP address
- D. Page has been moved to a new URL
Answer: D
NEW QUESTION 13
Which is true about HTTPS on FortiWeb? (Choose three.)
- A. In true transparent mode, the TLS session terminator is a protected web server.
- B. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.
- C. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.
- D. After enabling HSTS, redirects to HTTPS are no longer necessary.
- E. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.
Answer: A,B,E
NEW QUESTION 14
What capability can FortiWeb add to your Web App that your Web App may or may not already have?
- A. SSL Inspection
- B. Automatic backup and recovery
- C. High Availability
- D. HTTP/HTML Form Authentication
Answer: A
NEW QUESTION 15
- A. You must put the single web server into a server pool in order to use it with HTTP content routing.
- B. To achieve HTTP content routing, you must chain policies: the first policy accepts all traffic, and forwards requests for web app A to the virtual server for policy
- C. The server policy applies the same protection profile to all its protected web apps.
- D. Static or policy-based routes are not required.
- E. Policy A and Policy B apply their app-specific protection profiles, and then distribute that app's traffic among all members of the server farm.
- F. It also forwards requests for web app B to the virtual serverfor policy
Answer: B,E
NEW QUESTION 16
Which operationmode does not require additional configuration in order to allow FTP traffic to your web server?
- A. Transparent Inspection
- B. Offline Protection
- C. Reverse-Proxy
- D. True Transparent Proxy
Answer: A
NEW QUESTION 17
What role does FortiWeb play in ensuring PCI DSScompliance?
- A. Provide ability to securely process cash transactions
- B. Provides credit card processing capabilities
- C. PCI specifically requires a WAF
- D. Provides load balancing between multiple web servers
Answer: B
NEW QUESTION 18
A client is trying tostart a session from a page that should normally be accessible only after they have logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Allow the page access, but log the violation
- B. Automatically redirect the client to the login page
- C. Prompt the client to authenticate
- D. Display an access policy message, then allow the client to continue, redirecting them to their requested page
- E. Reply with a "403 Forbidden" HTTP error
Answer: A,B,E
NEW QUESTION 19
Which of the following is true about Local User Accounts?
- A. Must be assigned regardless of any other authentication
- B. Can be used for site publishing
- C. Best suited for large environments with many users
- D. Can be used for Single Sign On
Answer: A
NEW QUESTION 20
When generating a protection configuration from an auto learning report what critical step must you dobefore generating the final protection configuration?
- A. Drill down in the report to correct any false positives.
- B. Take the FortiWeb offline to apply the profile
- C. Restart the FortiWeb to clear the caches
- D. Activate the report to create t profile
Answer: A
NEW QUESTION 21
Under which circumstances does FortiWeb use its own certificates? (Choose Two)
- A. HTTPS to FortiGate
- B. Secondary HTTPS connection to server where FortiWeb acts as a client
- C. HTTPS access to GUI
- D. HTTPS to clients
Answer: B,C
NEW QUESTION 22
In Reverse proxy mode, how does FortiWeb handle traffic that does not match any defined policies?
- A. Non-matching traffic is Denied
- B. Non-matching traffic is rerouted to FortiGate
- C. Non-matching traffic is allowed
- D. non-Matching traffic is held in buffer
Answer: A
NEW QUESTION 23
What can an administrator do if a client has been incorrectly Period Blocked?
- A. Nothing, it is not possible to override a Period Block
- B. Manually release the IP from thetemporary Blacklist
- C. Force a new IP address to the client.
- D. Disconnect the client from the network
Answer: B
NEW QUESTION 24
......
Fortinet Certification Fundamentals-NSE6_FWB-6.0 Exam-Practice-Dumps: https://www.exam4docs.com/NSE6_FWB-6.0-study-questions.html

