[Dec 13, 2021] Updates Up to 365 days On Valid NSE6_FWB-6.1 Braindumps [Q12-Q27]

Share

[Dec 13, 2021] Updates Up to 365 days On Valid NSE6_FWB-6.1 Braindumps

Best QualityNSE6_FWB-6.1 Exam Questions  Fortinet Test To Gain Brilliante Result

NEW QUESTION 12
Refer to the exhibit.

FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers.
What must the administrator do to avoid this problem? (Choose two.)

  • A. No Special configuration is required; connectivity will be re-established after the set timeout.
  • B. Enable the Use X-Forwarded-For setting on FortiWeb.
  • C. Enable the Add X-Forwarded-For setting on FortiWeb.
  • D. Place FortiWeb in front of FortiADC.

Answer: B,C

Explanation:
Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X-header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header

 

NEW QUESTION 13
What role does FortiWeb play in ensuring PCI DSS compliance?

  • A. It provides credit card processing capabilities.
  • B. It provides the required SQL server protection.
  • C. It provides the ability to securely process cash transactions.
  • D. It provides the WAF required by PCI.

Answer: A

Explanation:
FortiWeb protects against attacks that lead to sensitive data exposure such as SQL Injection and other injection types. Additionally, FortiWeb inspects all web server outgoing traffic for sensitive data such as Social Security numbers, credit card numbers and other predefined or custom based sensitive data.

 

NEW QUESTION 14
What key factor must be considered when setting brute force rate limiting and blocking?

  • A. Multiple clients from geographically diverse locations
  • B. A single client contacting multiple resources
  • C. Multiple clients sharing a single Internet connection
  • D. Multiple clients connecting to multiple resources

Answer: D

 

NEW QUESTION 15
Which would be a reason to implement HTTP rewriting?

  • A. The original page has moved to a new IP address
  • B. The original page has moved to a new URL
  • C. To replace a vulnerable function in the requested URL
  • D. To send the request to secure channel

Answer: B

Explanation:
Create a new URL rewriting rule.

 

NEW QUESTION 16
FortiWeb offers the same load balancing algorithms as FortiGate.
Which two Layer 7 switch methods does FortiWeb also offer? (Choose two.)

  • A. HTTP content routes
  • B. HTTP user-based round robin
  • C. Round robin
  • D. HTTP session-based round robin

Answer: A,C

Explanation:
Reference:
http://fortinet.globalgate.com.ar/pdfs/FortiWeb/FortiWeb_DS.pdf

 

NEW QUESTION 17
Refer to the exhibit.

Based on the configuration, what would happen if this FortiWeb were to lose power? (Choose two.)

  • A. Traffic will pass between port5 and port6 uninspected.
  • B. Traffic that passes between port5 and port6 will be inspected.
  • C. All traffic will be interrupted.
  • D. Traffic will be interrupted between port3 and port4.

Answer: A,D

 

NEW QUESTION 18
The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.
Which two functions does the first layer perform? (Choose two.)

  • A. Determines whether traffic is an anomaly, based on observed application traffic over time
  • B. Determines if a detected threat is a false-positive or not
  • C. Builds a threat model behind every parameter and HTTP method
  • D. Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored

Answer: A,C

Explanation:
The first layer uses the Hidden Markov Model (HMM) and monitors access to the application and collects data to build a mathematical model behind every parameter and HTTP method.

 

NEW QUESTION 19
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?

  • A. If you are an enterprise whose computers all trust your active directory or other CA server
  • B. If you are a small business or home office
  • C. If you are an enterprise whose resources do not need security
  • D. If you are an enterprise whose employees use only mobile devices

Answer: C

Explanation:
This can include SSL/TLS certificates, code signing certificates, and S/MIME certificates. The reason why they're considered different from traditional certificate-authority signed certificates is that they're created, issued, and signed by the company or developer who is responsible for the website or software being signed. This is why self-signed certificates are considered unsafe for public-facing websites and applications.

 

NEW QUESTION 20
Which regex expression is the correct format for redirecting the URL http://www.example.com?

  • A. www\example\com
  • B. www\.example\.com
  • C. www/.example/.com
  • D. www.example.com

Answer: D

Explanation:
\1://www.company.com/\2/\3

 

NEW QUESTION 21
Which statement about local user accounts is true?

  • A. They are best suited for large environments with many users.
  • B. They cannot be used for site publishing.
  • C. They must be assigned, regardless of any other authentication.
  • D. They can be used for SSO.

Answer: D

Explanation:
You can configure the Remedy Single Sign-On server to authenticate TrueSight Capacity Optimization users as local users.

 

NEW QUESTION 22
What must you do with your FortiWeb logs to ensure PCI DSS compliance?

  • A. Erase them every two weeks
  • B. Compress them into a .zip file format
  • C. Enable masking of sensitive data
  • D. Store in an off-site location

Answer: C

 

NEW QUESTION 23
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?

  • A. The server policy applies the same protection profile to all of its protected web applications.
  • B. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
  • C. Static or policy-based routes are not required.
  • D. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.

Answer: C

 

NEW QUESTION 24
......

Focus on NSE6_FWB-6.1 All-in-One Exam Guide For Quick Preparation: https://www.practicetorrent.com/NSE6_FWB-6.1-practice-exam-torrent.html