[Sep 23, 2021] NSE6_FWB-6.0 Ultimate Study Guide - Exam4Docs [Q12-Q34]

Share

[Sep 23, 2021] NSE6_FWB-6.0 Ultimate Study Guide -  Exam4Docs

Ultimate Guide to Prepare NSE6_FWB-6.0 Certification Exam for Fortinet Certification in 2021

NEW QUESTION 12
Which of the followingwould be a reason for implementing rewrites?

  • A. Send connection to secure channel
  • B. Replace vulnerable functions.
  • C. Page has been moved to a new IP address
  • D. Page has been moved to a new URL

Answer: D

 

NEW QUESTION 13
Which is true about HTTPS on FortiWeb? (Choose three.)

  • A. In true transparent mode, the TLS session terminator is a protected web server.
  • B. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.
  • C. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.
  • D. After enabling HSTS, redirects to HTTPS are no longer necessary.
  • E. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.

Answer: A,B,E

 

NEW QUESTION 14
What capability can FortiWeb add to your Web App that your Web App may or may not already have?

  • A. SSL Inspection
  • B. Automatic backup and recovery
  • C. High Availability
  • D. HTTP/HTML Form Authentication

Answer: A

 

NEW QUESTION 15

  • A. You must put the single web server into a server pool in order to use it with HTTP content routing.
  • B. To achieve HTTP content routing, you must chain policies: the first policy accepts all traffic, and forwards requests for web app A to the virtual server for policy
  • C. The server policy applies the same protection profile to all its protected web apps.
  • D. Static or policy-based routes are not required.
  • E. Policy A and Policy B apply their app-specific protection profiles, and then distribute that app's traffic among all members of the server farm.
  • F. It also forwards requests for web app B to the virtual serverfor policy

Answer: B,E

 

NEW QUESTION 16
Which operationmode does not require additional configuration in order to allow FTP traffic to your web server?

  • A. Transparent Inspection
  • B. Offline Protection
  • C. Reverse-Proxy
  • D. True Transparent Proxy

Answer: A

 

NEW QUESTION 17
What role does FortiWeb play in ensuring PCI DSScompliance?

  • A. Provide ability to securely process cash transactions
  • B. Provides credit card processing capabilities
  • C. PCI specifically requires a WAF
  • D. Provides load balancing between multiple web servers

Answer: B

 

NEW QUESTION 18
A client is trying tostart a session from a page that should normally be accessible only after they have logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)

  • A. Allow the page access, but log the violation
  • B. Automatically redirect the client to the login page
  • C. Prompt the client to authenticate
  • D. Display an access policy message, then allow the client to continue, redirecting them to their requested page
  • E. Reply with a "403 Forbidden" HTTP error

Answer: A,B,E

 

NEW QUESTION 19
Which of the following is true about Local User Accounts?

  • A. Must be assigned regardless of any other authentication
  • B. Can be used for site publishing
  • C. Best suited for large environments with many users
  • D. Can be used for Single Sign On

Answer: A

 

NEW QUESTION 20
When generating a protection configuration from an auto learning report what critical step must you dobefore generating the final protection configuration?

  • A. Drill down in the report to correct any false positives.
  • B. Take the FortiWeb offline to apply the profile
  • C. Restart the FortiWeb to clear the caches
  • D. Activate the report to create t profile

Answer: A

 

NEW QUESTION 21
Under which circumstances does FortiWeb use its own certificates? (Choose Two)

  • A. HTTPS to FortiGate
  • B. Secondary HTTPS connection to server where FortiWeb acts as a client
  • C. HTTPS access to GUI
  • D. HTTPS to clients

Answer: B,C

 

NEW QUESTION 22
In Reverse proxy mode, how does FortiWeb handle traffic that does not match any defined policies?

  • A. Non-matching traffic is Denied
  • B. Non-matching traffic is rerouted to FortiGate
  • C. Non-matching traffic is allowed
  • D. non-Matching traffic is held in buffer

Answer: A

 

NEW QUESTION 23
What can an administrator do if a client has been incorrectly Period Blocked?

  • A. Nothing, it is not possible to override a Period Block
  • B. Manually release the IP from thetemporary Blacklist
  • C. Force a new IP address to the client.
  • D. Disconnect the client from the network

Answer: B

 

NEW QUESTION 24
......

Fortinet Certification Fundamentals-NSE6_FWB-6.0 Exam-Practice-Dumps: https://www.exam4docs.com/NSE6_FWB-6.0-study-questions.html