Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Fortinet Public Cloud Security FCP_FWB_AD-7.4 Questions and answers with ValidTests

Exam FCP_FWB_AD-7.4 All Questions
Exam FCP_FWB_AD-7.4 Premium Access

View all detail and faqs for the FCP_FWB_AD-7.4 exam

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

What are two possible impacts of a DoS attack on your web server? (Choose two.)

Options:

A.

The web application starts accepting unencrypted traffic.

B.

The web application is unable to accept any more connections because of network socket exhaustion.

C.

The web application server is unable to accept new client sessions due to memory exhaustion.

D.

The web application server database is compromised with data theft.

Expert Solution
Questions # 2:

Review the following configuration:

Question # 2

Which result would you expect from this configuration setting?

Options:

A.

When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.

B.

When ML is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.

C.

When ML is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.

D.

When ML is in its collecting phase, FortiWeb will not accept any samples from any IP addresses.

Expert Solution
Questions # 3:

What is the difference between an API gateway protection schema and a machine learning (ML) API protection schema?

Options:

A.

An API gateway protection schema does not allow authentication.

B.

An API gateway protection schema handles response bodies.

C.

An API gateway protection schema supports data types other than string.

D.

An API gateway protection schema cannot change without administrator intervention.

Expert Solution
Questions # 4:

What are two results of enabling monitor mode on FortiWeb? (Choose two.)

Options:

A.

It does not affect denial-of-service (DoS) protection profile actions to rate limit traffic.

B.

It uses the default action for all profiles and, depending on the configuration, blocks or allows traffic.

C.

It does not affect any HTML rewriting or redirection actions in web protection profiles.

D.

It overrides all usual profile actions. FortiWeb accepts all requests and generates alert email or log messages only for violations.

Expert Solution
Questions # 5:

Refer to the exhibit.

Question # 5

A FortiWeb device is deployed upstream of a device performing source network address translation (SNAT) or load balancing.

What configuration must you perform on FortiWeb to preserve the original IP address of the client?

Options:

A.

Enable and configure the Preserve Client IP setting.

B.

Use a transparent operatingmode on FortiWeb.

C.

Enable and configure the Add X-Forwarded-For setting.

D.

Turn off NAT on the FortiWeb.

Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

Which statement is true?

Options:

A.

FortiWeb cannot perform content inspection on the traffic because it is encrypted.

B.

FortiWeb is decrypting and re-encrypting the traffic.

C.

The server is not performing any cryptography on the traffic.

D.

The server is encrypting traffic being sent to the client.

Expert Solution
Questions # 7:

An attacker attempts to send an SQL injection attack containing the known attack string 'root'; -- through an API call.

Which FortiWeb inspection feature will be able to detect this attack the quickest?

Options:

A.

API gateway rule

B.

Known signatures

C.

Machine learning(ML)-based API protection—anomaly detection

D.

ML-based API protection—threat detection

Expert Solution
Questions # 8:

When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?

Options:

A.

If you are an enterprise whose employees use only mobile devices

B.

If you are a small business or home office

C.

If you are an enterprise whose computers all trust the active directory or CA server that signed the certificate

D.

If you are an enterprise whose resources do not need security or https connections

Expert Solution
Questions # 9:

A customer wants to be able to index your websites for search and advertisement purposes.

What is the easiest way to allow this on a FortiWeb?

Options:

A.

Add the indexer IP address to the trusted IP list on the FortiWeb.

B.

Add the indexer IP address tothe FortiGuard "Known Search Engines" category.

C.

Create a firewall rule to bypass the FortiWeb entirely for the indexer IP address.

D.

Do not allow any external sites to index your websites.

Expert Solution
Questions # 10:

What can a FortiWeb administrator do if a client has been incorrectly period blocked?

Options:

A.

Allow the period block to expire on its own, you cannot override it.

B.

Manually release the IP address from the blocklist.

C.

Disable and re-enable the server policy.

D.

Force a new IP address to the client.

Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions