Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet NSE5_FWB_AD-8.0 Fortinet NSE 5 - FortiWeb 8.0 Administrator Exam Practice Test

Demo: 10 questions
Total 36 questions

Fortinet NSE 5 - FortiWeb 8.0 Administrator Questions and Answers

Question 1

Refer to the exhibit.

There is only one administrator account configured on FortiWeb and IPv6 is not configured on any interface.

Which action should an administrator take to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?

Options:

A.

Make configuration changes on the upstream device.

B.

Replace 0.0.0.0/0 with a specific IP address.

C.

Delete the built-in administrator user and create a new one.

D.

Change the setting in the Access Profile field to Read_Only .

Question 2

A FortiWeb administrator sees the following request:

GET /api/v1/data HTTP/1.1

Host: example.com

Authorization: ApiKey abc123def456

The API key belongs to a user in group B who is authorized to access only /api/v1/reports.

What should the administrator do to prevent this unauthorized access?

Options:

A.

Restrict access to /api/v1/data using user group–based access control.

B.

Block /api/v1/data for all user groups to avoid policy confusion.

C.

Move the user to group A so they can access both endpoints.

D.

Allow all valid API keys to access any API endpoint.

Question 3

You are reviewing the FortiWeb integration with the Advanced Bot Protection (ABP) service.

Match each step in the ABP flow with its description.

Options:

Question 4

Refer to the exhibit.

You have deployed FortiWeb behind a FortiGate that is configured as a reverse proxy and inserts the X-Forwarded-For HTTP header when forwarding HTTP and HTTPS traffic.

FortiWeb is using a custom inline protection profile, and logging is enabled, as shown in the exhibit.

You notice that FortiWeb is blocking legitimate users, and all requests in the attack logs appear to come from the FortiGate IP address, not the original client IP address.

Which action should you take to fix this issue?

Options:

A.

Replace the current deployment mode with a one-arm proxy to expose source IP addresses.

B.

Disable IP-based detection features on FortiWeb to avoid IP-related blocking.

C.

Recreate the server policy using the predefined profile instead of a custom one.

D.

Modify the protection profile to use the X-Forwarded-For header for client IP address detection.

Question 5

Refer to the exhibit.

You are a FortiWeb administrator reviewing the biometrics-based detection rule shown in the exhibit. Your goal is to configure a rule that detects bots that avoid typical human interactions like using a mouse or clicking. You also want to log the detection event and apply a high-severity alert.

Based on the current configuration, which settings should you change to meet this goal?

Options:

A.

Select Screen Touch and Page Focus , set the severity to Low , and keep action as Deny (no log) .

B.

Select Keyboard and Scroll , change the action to Alert , and set the severity to High .

C.

Select Mouse Movement and Click , change the action to Alert , and set the severity to High .

D.

Do not select any client events to monitor, enable Bot Trait Checking , keep the current severity, and keep the action as Deny (no log) .

Question 6

A FortiWeb administrator wants to stop coordinated scraping traffic coming from several IP addresses, each making only a few requests so thresholds never trigger.

Which tactic should the administrator deploy to identify botnets using shared behavioral signals instead of volume?

Options:

A.

A DoS protection profile with extremely low request limits for the entire site.

B.

A static blocklist for all IP addresses seen in logs, even if most appear only once.

C.

Bot mitigation with device fingerprinting to correlate clients by behavior, headers, and JavaScript challenges instead of IP address volume.

D.

A web application firewall (WAF) rule that blocks every user agent that is not on a manually created allowlist.

Question 7

You are hosting multiple secure web applications behind a single public IP address on FortiWeb.

When a client connects to a service, FortiWeb needs to:

    Identify the correct SSL certificate.

    Decrypt the request.

    Route the request to the correct back-end server.

Match each FortiWeb function to the request handling step that performs the function.

Options:

Question 8

A FortiWeb administrator is deciding between using SAML SSO or HTML authentication. They want to minimize the number of credential prompts users receive across multiple Fortinet services.

Which statement accurately describes which option is best, and why?

Options:

A.

SAML SSO, because it supports identity authentication on Fortinet devices.

B.

SAML, because it blocks users from accessing anything not approved in FortiWeb policy.

C.

HTML form authentication, because it’s faster and doesn’t need external systems.

D.

HTML form, because it provides token-based access to remote services.

Question 9

Refer to the exhibit.

A FortiWeb administrator tests a new form input value after training the machine learning (ML) anomaly detection system.

The hidden Markov model (HMM) flags the input as abnormal, while the support vector machine (SVM) model classifies it as normal. FortiWeb allows the request.

What does this result indicate about the FortiWeb ML anomaly detection behavior?

Options:

A.

The anomaly detection thresholds are too low and must be increased.

B.

One of the ML models should be disabled to avoid inconsistent results.

C.

FortiWeb is correctly allowing an unusual but non-malicious input based on combined HMM and SVM evaluation.

D.

FortiWeb failed to detect an attack and should have blocked the request.

Question 10

You recently deployed two FortiWeb devices in an active-active (A-A) high availability (HA) cluster.

During routine maintenance, you want to confirm that the cluster is synchronizing the correct configuration areas and that both FortiWeb devices behave consistently in production.

As the FortiWeb administrator, which two configuration areas should you examine to verify that HA synchronization is functioning correctly? (Choose two.)

Options:

A.

Check the network configuration on both FortiWeb devices—such as interfaces and static routes—to ensure they are aligned.

B.

Review policy configurations, including server policies and protection profiles, to confirm they match across the cluster.

C.

Review inspection and mitigation log files to determine if they are being replicated across both FortiWeb devices.

D.

Verify whether firmware images and upgrade history are synchronized between the FortiWeb devices.

Demo: 10 questions
Total 36 questions