Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: discactive

Fortinet NSE5_FWB_AD-8.0 Fortinet NSE 5 - FortiWeb 8.0 Administrator Exam Practice Test

Fortinet NSE 5 - FortiWeb 8.0 Administrator Questions and Answers

Question 1

Refer to the exhibit.

Question # 1

There is only one administrator account configured on FortiWeb and IPv6 is not configured on any interface.

Which action should an administrator take to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?

Options:

A.

Make configuration changes on the upstream device.

B.

Replace 0.0.0.0/0 with a specific IP address.

C.

Delete the built-in administrator user and create a new one.

D.

Change the setting in the Access Profile field to Read_Only .

Question 2

A FortiWeb administrator needs to allow a known web indexer to scan the website for search engine visibility.

What is the easiest way to allow this on FortiWeb?

Options:

A.

Add the web indexer IP address to the trusted IP address list.

B.

Add the web indexer IP address to an IP exception list inside the inline protection profile.

C.

Add the web indexer IP address to the FortiGuard Known Search Engines category.

D.

Add the web indexer user-agent string to a custom signature exception rule.

Question 3

FortiWeb is blocking groups of users behind your load balancer. In the logs, all users show the same source IP address.

Which action should you take to restore proper client identification?

Options:

A.

Add a bot detection rule in the protection profile.

B.

Update the signature engine.

C.

Reconfigure the load balancer to insert the original client IP address in an HTTP header.

D.

Enable caching for HTTPS traffic.

Question 4

Refer to the exhibit.

Question # 4

Question # 4

A FortiWeb administrator tests a new form input value after training the machine learning (ML) anomaly detection system.

The hidden Markov model (HMM) flags the input as abnormal, while the support vector machine (SVM) model classifies it as normal. FortiWeb allows the request.

What does this result indicate about the FortiWeb ML anomaly detection behavior?

Options:

A.

The anomaly detection thresholds are too low and must be increased.

B.

One of the ML models should be disabled to avoid inconsistent results.

C.

FortiWeb is correctly allowing an unusual but non-malicious input based on combined HMM and SVM evaluation.

D.

FortiWeb failed to detect an attack and should have blocked the request.

Question 5

You are hosting multiple secure web applications behind a single public IP address on FortiWeb.

When a client connects to a service, FortiWeb needs to:

    Identify the correct SSL certificate.

    Decrypt the request.

    Route the request to the correct back-end server.

Match each FortiWeb function to the request handling step that performs the function.

Question # 5

Options:

Question 6

Refer to the exhibit.

Question # 6

You are a FortiWeb administrator reviewing how FortiAI protects sensitive data when interacting with a large language model (LLM).

Drag each label to the corresponding step in the FortiAI data privacy workflow.

Question # 6

Options:

Question 7

How should a FortiWeb administrator configure behavior-based bot detection to identify traffic from nonhuman users?

Options:

A.

Set request rate limits and enable mouse movement tracking.

B.

Block all traffic that doesn’t come from known devices.

C.

Disable JavaScript execution for anonymous users.

D.

Create IP blocklists based on login failures.

Question 8

A FortiWeb administrator sees the following request:

GET /api/v1/data HTTP/1.1

Host: example.com

Authorization: ApiKey abc123def456

The API key belongs to a user in group B who is authorized to access only /api/v1/reports.

What should the administrator do to prevent this unauthorized access?

Options:

A.

Restrict access to /api/v1/data using user group–based access control.

B.

Block /api/v1/data for all user groups to avoid policy confusion.

C.

Move the user to group A so they can access both endpoints.

D.

Allow all valid API keys to access any API endpoint.

Question 9

A FortiWeb administrator is hardening a customer checkout website.

The site contains sensitive links such as Login, Payment, and Admin, which are embedded in the HTML content of several pages.

A vulnerability scan shows that automated bots can crawl the web pages and easily enumerate these links by parsing the HTML source, even though users access them normally, through the site navigation.

Which FortiWeb feature should the administrator enable to prevent automated scanners from discovering these links?

Options:

A.

Link cloaking

B.

URL rewriting

C.

URL encryption

D.

Deep packet inspection