Fortinet FCP_FWF_AD-7.4 Practice Test Questions and Exam Dumps Part14 Q261-280

View Full Fortinet FCP_FWF_AD-7.4 Exam Dumps and Practice Test Dumps

 

Question 261.

A FortiWeb administrator wants to make sure configuration changes can be attributed to a specific person. Which approach is BEST?

  1. Use individual administrator accounts with audit logging
  2. Share one administrator account
  3. Disable management logs
  4. Allow anonymous administrative access

Correct Answer: 1. Use individual administrator accounts with audit logging

Explanation:

Individual administrator accounts provide clear accountability because FortiWeb can associate management actions with a specific user. Audit logs can then show who made a configuration change and when it occurred. Shared accounts weaken traceability because multiple people appear under the same identity. Individual accounts also support role-based permissions so administrators receive only the access required for their responsibilities. Management activity should remain logged and protected just like application traffic. Strong authentication, restricted management networks, and periodic review of administrative access further improve the security of the FortiWeb management plane.

Question 262.

Which FortiWeb security practice BEST supports separation of duties among administrators?

  1. Give every administrator full control
  2. Assign role-based permissions according to job responsibilities
  3. Use one shared root account
  4. Disable audit logging

Correct Answer: 2. Assign role-based permissions according to job responsibilities

Explanation:

Role-based administrative permissions allow different administrators to perform only the tasks required by their job roles. For example, a monitoring user may need access to logs and dashboards without permission to change policies, while a senior administrator may require configuration rights. This reduces the chance of accidental or unauthorized changes and supports separation of duties. Shared accounts and unrestricted privileges make accountability and least privilege harder to enforce. Role-based access should be combined with individual accounts, strong authentication, and appropriate management network restrictions.

Question 263.

An administrator wants FortiWeb management traffic to be reachable only from a dedicated operations network. What should be configured?

  1. More backend server pools
  2. Broader URL access rules for applications
  3. Restricted management access from trusted source networks or interfaces
  4. Session persistence

Correct Answer: 3. Restricted management access from trusted source networks or interfaces

Explanation:

The FortiWeb management plane should be exposed only to systems that require administrative access. Restricting management connections to a trusted operations network reduces the number of hosts that can attempt authentication or target administrative services. This control should be combined with strong credentials, role-based administrator rights, secure management protocols, and audit logging. Application features such as session persistence and backend pools do not secure the management interface. Limiting management exposure is a basic infrastructure security measure.

Question 264.

A FortiWeb administrator is about to make a major routing and policy change. Which action should be performed first?

  1. Disable all attack signatures
  2. Delete old logs
  3. Remove server pools
  4. Create a current configuration backup**

Correct Answer: 4. Create a current configuration backup

Explanation:

A current configuration backup gives the administrator a recovery point if the planned change causes unexpected behavior or an outage. This is especially important before modifications to routing, protected services, server pools, web protection profiles, certificates, or firmware. Backups should be stored securely because they may contain sensitive infrastructure and security information. A backup does not prevent configuration errors, but it can significantly reduce recovery time. Deleting logs or removing services before the change would increase risk rather than improve change safety.

Question 265.

Why should FortiWeb configuration backups be tested periodically?

  1. To verify that they are current, accessible, and usable for recovery
  2. To improve attack signature accuracy
  3. To increase backend server performance
  4. To disable management authentication

Correct Answer: 1. To verify that they are current, accessible, and usable for recovery

Explanation:

A backup is valuable only if it can actually be restored when needed. Periodic validation helps confirm that the backup process is working, the files are recent enough, and administrators know where recovery copies are stored. Backup handling should also account for software versions and significant configuration changes. Secure storage is essential because backups may reveal protected server details, policy information, and certificate-related configuration. Backup verification is part of operational resilience and should be included in routine FortiWeb administration.

Question 266.

Before upgrading FortiWeb firmware, what information should the administrator review?

  1. Printer inventory
  2. Supported upgrade path, release notes, compatibility, and known issues
  3. User desktop settings
  4. Public DNS records only

Correct Answer: 2. Supported upgrade path, release notes, compatibility, and known issues

Explanation:

Firmware upgrades should be planned using the vendor’s supported upgrade path and release documentation. Administrators should understand new features, behavior changes, resolved defects, known issues, and compatibility considerations before upgrading production systems. A current configuration backup should also be created, and high-availability behavior should be considered where applicable. Testing in a nonproduction environment can further reduce risk. Upgrade planning helps prevent avoidable service disruption and makes post-upgrade troubleshooting more predictable.

Question 267.

After a firmware upgrade, one FortiWeb policy begins behaving differently. What should the administrator investigate FIRST?

  1. Printer status
  2. Rack temperature
  3. Upgrade documentation, configuration state, and relevant logs
  4. User desktop theme

Correct Answer: 3. Upgrade documentation, configuration state, and relevant logs

Explanation:

A firmware upgrade may change detection logic, defaults, feature behavior, or configuration interpretation. Administrators should first review the release and upgrade notes for relevant changes, confirm that the policy migrated correctly, and inspect FortiWeb logs to understand the new behavior. This evidence can help determine whether the difference is expected, caused by a configuration issue, or related to updated security detection. Broad policy changes should not be made until the cause is understood. Structured post-upgrade analysis reduces the risk of weakening security unnecessarily.

Question 268.

Which upgrade practice BEST protects application availability?

  1. Upgrade without testing
  2. Disable health checks permanently
  3. Delete configuration backups
  4. Use a controlled maintenance plan with validation and recovery steps**

Correct Answer: 4. Use a controlled maintenance plan with validation and recovery steps

Explanation:

A controlled upgrade process should include a configuration backup, supported firmware path, maintenance window, validation checklist, and recovery options. Critical applications should be tested after the upgrade to confirm TLS, policies, backend pools, health checks, logs, and traffic flow are functioning correctly. High-availability deployments may reduce downtime but still require careful planning. An unstructured upgrade increases the chance that a minor issue becomes a prolonged application outage. Change management and verification are essential parts of reliable FortiWeb operations.

Question 269.

What is the PRIMARY advantage of forwarding FortiWeb logs to a centralized SIEM?

  1. Events can be correlated with activity from other security systems
  2. FortiWeb no longer needs security policies
  3. Backend servers become faster
  4. Certificates renew automatically

Correct Answer: 1. Events can be correlated with activity from other security systems

Explanation:

A SIEM can combine FortiWeb attack and administrative events with data from firewalls, endpoints, identity systems, servers, and other technologies. This broader context helps analysts understand whether a web attack is part of a larger incident. Centralized logging also supports alerting, dashboards, reporting, and longer-term retention. FortiWeb continues to perform web application protection even when logs are forwarded externally. The main benefit of SIEM integration is improved visibility and correlation across the security environment.

Question 270.

Why should FortiWeb synchronize its clock with a reliable time source?

  1. To increase load-balancing capacity
  2. To maintain accurate timestamps for logging, correlation, and troubleshooting
  3. To disable web attack signatures
  4. To eliminate TLS certificates

Correct Answer: 2. To maintain accurate timestamps for logging, correlation, and troubleshooting

Explanation:

Accurate time is essential when administrators need to correlate FortiWeb events with backend server logs, firewall activity, authentication records, or SIEM alerts. Incorrect system time can make incident timelines difficult to reconstruct and can complicate troubleshooting. Accurate time also supports certificate validation and scheduled operations. FortiWeb should therefore synchronize with reliable time sources according to organizational standards. This is a foundational operational control that improves the quality of security evidence and system administration.

Question 271.

A security operations team wants immediate notification of critical FortiWeb attack events. What should be configured?

  1. Event alerting or SIEM-based notifications for high-severity events
  2. Session persistence
  3. Load balancing only
  4. Server health checking only

Correct Answer: 1. Event alerting or SIEM-based notifications for high-severity events

Explanation:

Critical attack events should be surfaced promptly so analysts can investigate them before additional damage occurs. FortiWeb can generate or forward security events that can be used by notification systems or SIEM platforms. Alerts should contain useful context, such as the application, source, attack type, severity, and enforcement action. Administrators should tune notifications carefully to avoid alert fatigue. Routine low-value events can remain in logs without requiring immediate notification, while high-risk events should receive faster attention.

Question 272.

A FortiWeb administrator receives thousands of repetitive informational alerts. What should be done?

  1. Disable all logs permanently
  2. Tune notification thresholds and severity criteria
  3. Remove all signatures
  4. Disable web protection

Correct Answer: 2. Tune notification thresholds and severity criteria

Explanation:

Excessive alert volume can make important security events harder to notice. Administrators should determine which events require immediate action and adjust thresholds, severity levels, and notification rules accordingly. Detailed logs can still be retained for investigation without generating a notification for every low-priority event. The goal is to create an actionable alert stream while preserving underlying evidence. Disabling logging or web protection would reduce visibility and security rather than solve the alert-management problem.

Question 273.

FortiWeb shows that one backend server is receiving significantly more traffic than its peers. What should be reviewed FIRST?

  1. Data leak prevention rules
  2. Attack signature database
  3. Load-balancing method, server weights, and session persistence
  4. Administrator password policy

Correct Answer: 3. Load-balancing method, server weights, and session persistence

Explanation:

Uneven server utilization can result from the selected load-balancing algorithm, configured weights, session persistence, or member health. If persistence keeps many active users attached to one member, that server may legitimately receive more traffic. Similarly, weighted balancing may intentionally favor a higher-capacity server. Administrators should review server pool statistics and configuration before concluding that there is a fault. Security settings such as DLP and attack signatures do not directly determine how normal requests are distributed among backend systems.

Question 274.

A backend server is marked unhealthy by FortiWeb even though users can browse to it directly. What should be examined FIRST?

  1. Administrator role permissions
  2. IP reputation configuration
  3. Bot mitigation thresholds
  4. The health-check request and expected response**

Correct Answer: 4. The health-check request and expected response

Explanation:

A health check can fail even when the server appears reachable if the configured request no longer matches actual application behavior. The requested URL may have changed, the server may redirect the request, authentication may now be required, or the expected response content may be different. Administrators should compare the FortiWeb health-check configuration with the actual backend response before making changes to the server pool. Accurate health checks are important because a misconfigured check can unnecessarily remove a healthy server from service.

Question 275.

Why should FortiWeb policy exceptions be reviewed periodically?

  1. To remove obsolete exceptions and reduce unnecessary security gaps
  2. To increase session persistence
  3. To improve server hardware performance
  4. To prevent log forwarding

Correct Answer: 1. To remove obsolete exceptions and reduce unnecessary security gaps

Explanation:

Exceptions weaken or alter normal security enforcement, so they should exist only as long as the legitimate need remains. An application update may eliminate the false positive that originally required an exception, or a broad exception may be narrowed after additional testing. Periodic review ensures that old workarounds do not become permanent attack paths. Each exception should have a clear reason and appropriate scope. Removing unnecessary exceptions restores protection and simplifies long-term FortiWeb policy management.

Question 276.

A company wants to analyze FortiWeb attack trends over the previous six months. Which practice is MOST important?

  1. Review only current sessions
  2. Maintain sufficient log retention and centralized reporting
  3. Delete old events weekly
  4. Disable attack logging

Correct Answer: 2. Maintain sufficient log retention and centralized reporting

Explanation:

Historical analysis requires enough retained data to compare attack frequency, severity, targeted applications, source patterns, and policy actions over time. Centralized reporting or a SIEM can help aggregate and search large volumes of FortiWeb logs. Retention periods should reflect organizational requirements and available storage. Deleting logs too quickly makes long-term trend analysis impossible and can also hinder incident investigations. Consistent retention supports security operations, compliance, and capacity planning.

Question 277.

A policy exception fixes a false positive but also allows suspicious requests to another application path. What is the BEST response?

  1. Narrow the exception to the exact legitimate condition
  2. Leave the broad exception unchanged
  3. Disable all signatures
  4. Stop collecting logs

Correct Answer: 1. Narrow the exception to the exact legitimate condition

Explanation:

An exception should solve the operational problem without unnecessarily weakening protection elsewhere. If suspicious requests are now allowed on another path, the exception is too broad. Administrators should review event logs, identify the precise URL, parameter, or request characteristic that needs exclusion, and limit the exception accordingly. This preserves normal enforcement across the rest of the application. Exceptions should always be tested for unintended consequences because broad allowances can create long-lived security gaps.

Question 278.

A new web application release introduces additional URLs, methods, and request parameters. What should the FortiWeb administrator do?

  1. Ignore the release because WAF policies never change
  2. Review and update relevant access, protocol, signature, and behavioral controls
  3. Disable FortiWeb for the new version
  4. Remove all logs

Correct Answer: 2. Review and update relevant access, protocol, signature, and behavioral controls

Explanation:

Application changes can affect how FortiWeb interprets legitimate traffic. New URLs may require access policies, new HTTP methods may need to be permitted, new request structures may affect protocol constraints, and behavioral models may need retraining. Administrators should coordinate with the application team and monitor logs during deployment. A WAF policy that never changes while the application evolves can create either false positives or protection gaps. Security configuration should therefore be part of the application release lifecycle.

Question 279.

What is the BEST way to introduce a highly restrictive FortiWeb policy to a critical production application?

  1. Validate it with representative traffic and logs before broad blocking
  2. Enable maximum enforcement immediately
  3. Disable logging during rollout
  4. Remove backend health checks

Correct Answer: 1. Validate it with representative traffic and logs before broad blocking

Explanation:

Representative testing allows administrators to see how the new policy interacts with real application workflows before all production users are affected. Testing should include authentication, APIs, uploads, administrative tasks, common user actions, and less frequent legitimate requests. Logs provide evidence about false positives or overly restrictive settings. Once the policy behaves correctly, enforcement can be expanded gradually. Immediate global blocking creates avoidable outage risk, while disabling logs removes the information needed to tune and troubleshoot the configuration.

Question 280.

Which statement BEST describes mature FortiWeb operations?

  1. Use shared administrator accounts and minimal logging
  2. Keep every exception permanently
  3. Upgrade without backups to save time
  4. Combine secure management, auditable changes, backups, controlled upgrades, centralized monitoring, backend health review, and continuous policy tuning**

Correct Answer: 4. Combine secure management, auditable changes, backups, controlled upgrades, centralized monitoring, backend health review, and continuous policy tuning

Explanation:

Mature FortiWeb operations combine strong application security with disciplined administration. Management access should be restricted and role based, while individual accounts and audit logs provide accountability. Reliable backups support recovery, and firmware upgrades should follow a tested change process. Centralized monitoring improves visibility into attacks and operational issues. Backend health, certificates, application changes, behavioral models, and policy exceptions should all be reviewed continuously. Treating FortiWeb as a living security platform rather than a static appliance helps maintain both protection and application availability over time.