Best Preparations of NSE6_FWB-6.0 Exam 2021 Fortinet Certification Unlimited 30 Questions
Focus on NSE6_FWB-6.0 All-in-One Exam Guide For Quick Preparation.
NEW QUESTION 12
Under which circumstances does FortiWeb use its own certificates? (Choose Two)
- A. HTTPS to FortiGate
- B. Secondary HTTPS connection to server where FortiWeb acts as a client
- C. HTTPS access to GUI
- D. HTTPS to clients
Answer: B,C
NEW QUESTION 13
A client is trying tostart a session from a page that should normally be accessible only after they have logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Allow the page access, but log the violation
- B. Automatically redirect the client to the login page
- C. Prompt the client to authenticate
- D. Display an access policy message, then allow the client to continue, redirecting them to their requested page
- E. Reply with a "403 Forbidden" HTTP error
Answer: A,B,E
NEW QUESTION 14
An e-commerce web app is used by small businesses. Clients often access it from offices behind a router, where clients are on an IPv4 privatenetwork LAN. You need to protect the web application from denial of service attacks that use request floods.
What FortiWeb feature should you configure?
- A. Configure FortiWeb to use "X-Forwarded-For:" headers to find each client's private network IP, and to block attacks using that.
- B. Enable "Shared IP" and configure the separate rate limits for requests from NATted source IPs.
- C. Enable SYN cookies.
- D. Configure a server policy that matches requests from shared Internet connections.
Answer: C
NEW QUESTION 15
You are configuring FortiAnalyzer to store logs from FortiWeb.
Which is true?
- A. You mustenable ADOMs on FortiAnalyzer.
- B. To store logs from FortiWeb6.0, on FortiAnalyzer, you must select "FrotiWeb 5.4".
- C. FortiAnalyzer will store antivirus and DLP archives from FortiWeb.
- D. FortiWeb will query FortiAnalyzer for reports, instead of generating them locally.
Answer: A
NEW QUESTION 16
What capability can FortiWeb add to your Web App that your Web App may or may not already have?
- A. SSL Inspection
- B. Automatic backup and recovery
- C. High Availability
- D. HTTP/HTML Form Authentication
Answer: A
NEW QUESTION 17
How does an ADOM differ from a VDOM?
- A. Allows you to have 1 administrator for multiple tenants
- B. ADOMs do not have virtual networking
- C. ADOMs only affect specific functions, and do not provide full separation like VDOMs do.
- D. ADOMs improve performance by offloading some functions.
Answer: A
NEW QUESTION 18
Which of the followingwould be a reason for implementing rewrites?
- A. Send connection to secure channel
- B. Replace vulnerable functions.
- C. Page has been moved to a new IP address
- D. Page has been moved to a new URL
Answer: D
NEW QUESTION 19
You are deploying FortiWeb6.0 in an Amazon Web Services cloud. Which 2 lines of this initial setup via CLI are incorrect? (Choose two.)
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B,C
NEW QUESTION 20
You've configured an authentication rule with delegation enabled on FortiWeb.
Whathappens when a user tries to access the web application?
- A. ForitWeb redirects the user tothe web app's authentication page
- B. FrotiWeb redirects users to a FortiAuthenticator page, then if the user authenticates successfully, FortiGate signals to FortiWeb to allow access to the web app
- C. FortiWeb replies with a HTTP challenge of behalf of the server, theif the user authenticates successfully, FortiWeb allows the request and also includes credentials in the request that it forwards to the web app
- D. FortiWeb forwards the HTTP challenge from the server to the client, then monitors the reply, allowing access if the user authenticates successfully
Answer: B
NEW QUESTION 21
What can an administrator do if a client has been incorrectly Period Blocked?
- A. Nothing, it is not possible to override a Period Block
- B. Manually release the IP from thetemporary Blacklist
- C. Force a new IP address to the client.
- D. Disconnect the client from the network
Answer: B
NEW QUESTION 22
When viewing the attack logs on your FortiWeb, which IP Address is shown for the client when using XFF Header rules?
- A. Client's real IP
- B. FortiGate's local IP
- C. FortiWeb's IP
- D. FortiGate's public IP
Answer: A
NEW QUESTION 23
Which operationmode does not require additional configuration in order to allow FTP traffic to your web server?
- A. Transparent Inspection
- B. Offline Protection
- C. Reverse-Proxy
- D. True Transparent Proxy
Answer: A
NEW QUESTION 24
......
Guaranteed Success with NSE6_FWB-6.0 Dumps: https://www.passexamdumps.com/NSE6_FWB-6.0-valid-exam-dumps.html
