Special Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet FCP_FWB_AD-7.4 FCP - FortiWeb 7.4 Administrator Exam Practice Test

Demo: 10 questions
Total 36 questions

FCP - FortiWeb 7.4 Administrator Questions and Answers

Question 1

Which high availability (HA) mode uses gratuitous Address Resolution Protocol (ARP) to advertise a failover event to neighboring network devices?

Options:

A.

Passive-Passive

B.

Active-Passive

C.

Active-Active

D.

Passive-Active

Question 2

In SAML deployments, which server contains user authentication credentials (username/password)?

Options:

A.

Identity provider

B.

Service provider

C.

User database

D.

Authentication client

Question 3

Refer to the exhibit.

A FortiWeb device is deployed upstream of a device performing source network address translation (SNAT) or load balancing.

What configuration must you perform on FortiWeb to preserve the original IP address of the client?

Options:

A.

Enable and configure the Preserve Client IP setting.

B.

Use a transparent operatingmode on FortiWeb.

C.

Enable and configure the Add X-Forwarded-For setting.

D.

Turn off NAT on the FortiWeb.

Question 4

When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?

Options:

A.

If you are an enterprise whose employees use only mobile devices

B.

If you are a small business or home office

C.

If you are an enterprise whose computers all trust the active directory or CA server that signed the certificate

D.

If you are an enterprise whose resources do not need security or https connections

Question 5

Which would be a reason to implement HTTP rewriting?

Options:

A.

To redirect HTTP to HTTPS.

B.

To implement load balancing.

C.

To replace a vulnerable element in a requested URL.

D.

The original page has moved to a new URL.

Question 6

An administrator notices multiple IP addresses attempting to log in to an application frequently, within a short time period. They suspect attackers are attempting to guess user passwords for a secure application.

What is the best way to limit this type of attack on FortiWeb, while still allowing legitimate traffic through?

Options:

A.

Blocklist any suspected IPs.

B.

Configure a brute force login custom policy.

C.

Rate limit all connections from suspected IP addresses.

D.

Block the IP address at the border router.

Question 7

Refer to the exhibit.

FortiADC is applying SNAT to all inbound traffic going to the servers.

When an attack occurs, FortiWeb blocks traffic based on the192.0.2.1source IP address, which belongs to FortiADC. This setup is breaking all connectivity and genuine clients are not able to access the servers.

What can the administrator do to avoid this problem? (Choose two.)

Options:

A.

Enable and configure the Preserve Client IP setting on the client.

B.

No special configuration is required; connectivity will be re-established for all clients after the set timeout.

C.

Place FortiWeb in front of FortiADC.

D.

Enable and configure the Use X-Forwarded-For setting on FortiWeb.

Question 8

Which is an example of a cross-site scripting (XSS) attack?

Options:

A.

SELECT username FROM accounts WHERE username='admin';-- ' AND password='password';

B.

C.

SELECT username FROM accounts WHERE username='XSS' ' AND password='alert("http://badurl.com")';

D.

Question 9

Under which two circumstances does FortiWeb use its own certificates? (Choose two.)

Options:

A.

Connecting to browser clients using SSL

B.

Making a secondary HTTPS connection to a server where FortiWeb acts as a client

C.

Routing an HTTPS connection to a FortiGate

D.

An administrator session connecting to the GUI using HTTPS

Question 10

Review the following configuration:

Which result would you expect from this configuration setting?

Options:

A.

When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.

B.

When ML is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.

C.

When ML is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.

D.

When ML is in its collecting phase, FortiWeb will not accept any samples from any IP addresses.

Demo: 10 questions
Total 36 questions