View Full Fortinet FCP_FWF_AD-7.4 Exam Dumps and Practice Test Dumps
Question 281.
A FortiWeb administrator wants to reduce the chance that unauthorized personnel can change production policies. Which control is MOST appropriate?
- Role-based administrative permissions with individual accounts
- One shared administrator account for the entire team
- Disabled audit logging
- Management access from all networks
Correct Answer: 1. Role-based administrative permissions with individual accounts
Explanation:
Role-based access allows each administrator to receive only the privileges required for assigned duties. Individual accounts provide accountability because management actions can be tied to a specific person. This supports least privilege and separation of duties while reducing the risk of accidental or unauthorized changes. Shared accounts weaken traceability, and unrestricted management access increases exposure. Audit logging should remain enabled so changes can be investigated later. Secure FortiWeb administration therefore combines individual identities, appropriate role assignments, strong authentication, trusted management networks, and retained audit information.
Question 282.
A security manager wants to determine which administrator changed a server policy at 2:15 PM. Which source should be checked first?
- Backend application logs
- FortiWeb administrative audit logs
- IP reputation data
- Load-balancing statistics
Correct Answer: 2. FortiWeb administrative audit logs
Explanation:
Administrative audit logs are designed to record management activity, including policy and configuration changes. They can help identify which administrator made a change and when it occurred. This is valuable for troubleshooting, compliance, and incident investigation. Individual administrator accounts make the audit trail more meaningful because actions can be attributed accurately. Backend application logs and traffic statistics may show the effects of a policy change, but they do not directly identify the administrator who modified FortiWeb configuration.
Question 283.
Which configuration BEST protects the FortiWeb management plane from unnecessary exposure?
- Enable access from every interface
- Disable administrator authentication
- Limit management access to trusted interfaces and source networks
- Use public application addresses for management
Correct Answer: 3. Limit management access to trusted interfaces and source networks
Explanation:
The management plane contains sensitive configuration and should be exposed only where administration is required. Limiting access to dedicated management interfaces or trusted source networks reduces the number of systems that can attempt authentication or target administrative services. This should be combined with individual administrator accounts, role-based permissions, strong authentication, and audit logging. Management restrictions are separate from protected application policies and should be treated as a fundamental infrastructure hardening control.
Question 284.
An administrator is preparing to replace several FortiWeb policies during a maintenance window. What should be done before the change?
- Remove existing certificates
- Delete historical logs
- Disable health checks
- Create and securely store a current configuration backup**
Correct Answer: 4. Create and securely store a current configuration backup
Explanation:
A current backup provides a recovery point if the planned policy changes cause an outage, unexpected blocking, or configuration error. Backups should be stored securely because they can contain sensitive network, server, security, and certificate-related information. Administrators should also document the planned changes and establish validation steps. Backups do not replace proper testing, but they can significantly reduce recovery time. Removing certificates or health checks would create additional risk rather than preparing the environment safely for maintenance.
Question 285.
What is the BEST reason to maintain multiple recent FortiWeb configuration backups?
- They provide recovery options from different points in the configuration lifecycle
- They increase signature detection accuracy
- They improve session persistence
- They automatically renew certificates
Correct Answer: 1. They provide recovery options from different points in the configuration lifecycle
Explanation:
Keeping multiple recent backups can be useful when a problem is not discovered immediately after a configuration change. If the newest backup already contains the unwanted change, an earlier recovery point may be needed. Retention should be balanced with secure storage and organizational requirements. Administrators should also document major changes so they can identify which backup represents a known-good state. Configuration backups are an operational recovery mechanism rather than an application security detection feature.
Question 286.
Before performing a FortiWeb firmware upgrade, which task is MOST important?
- Disable all web protection
- Confirm the supported upgrade path and create a current backup
- Remove every backend server
- Delete all certificates
Correct Answer: 2. Confirm the supported upgrade path and create a current backup
Explanation:
Firmware upgrades should follow a supported upgrade path to reduce the risk of configuration migration problems or unsupported transitions. Administrators should review release notes, compatibility considerations, and known issues, then create a current backup before proceeding. A maintenance window and post-upgrade validation plan should also be prepared. In high-availability environments, the upgrade sequence may need additional consideration. Deleting certificates or disabling protection does not make the upgrade safer and could cause unnecessary service disruption.
Question 287.
After a firmware upgrade, attack logs show different behavior for an existing signature. What should the administrator investigate first?
- Printer configuration
- Physical cabling
- Release notes, signature behavior changes, and the affected policy settings
- Desktop wallpaper
Correct Answer: 3. Release notes, signature behavior changes, and the affected policy settings
Explanation:
Firmware upgrades can include changes to attack detection logic, signature processing, feature defaults, or configuration interpretation. Administrators should review release documentation and compare the current behavior with the existing protection profile. Logs can show exactly which requests now match or no longer match. Understanding the cause before modifying policy helps avoid unnecessary weakening of security. Unrelated physical or endpoint settings do not explain changes in signature behavior after a FortiWeb software upgrade.
Question 288.
Which strategy BEST reduces application downtime risk during a FortiWeb upgrade?
- Upgrade during peak business hours
- Disable server health checks permanently
- Delete all backups before starting
- Use a planned maintenance process with validation and recovery procedures**
Correct Answer: 4. Use a planned maintenance process with validation and recovery procedures
Explanation:
A controlled maintenance process should include a supported upgrade path, backup, maintenance timing, validation checklist, and recovery options. Critical protected applications should be tested after the upgrade to confirm that TLS, policies, health checks, load balancing, logging, and backend connectivity work correctly. High availability may reduce disruption but does not eliminate the need for planning. A documented recovery procedure is especially important if unexpected behavior prevents the appliance from handling production traffic correctly.
Question 289.
A SOC wants to correlate FortiWeb attack events with endpoint and firewall alerts. What should be configured?
- Forward FortiWeb logs to a centralized SIEM or log platform
- Increase server pool weights
- Enable session persistence only
- Disable attack logging
Correct Answer: 1. Forward FortiWeb logs to a centralized SIEM or log platform
Explanation:
Centralized logging allows a SOC to correlate FortiWeb attack activity with alerts from other security systems. For example, a web attack from one source can be compared with firewall, endpoint, identity, and server events to determine whether it is part of a broader campaign. A SIEM can also provide dashboards, alerting, reporting, and retention. Log forwarding complements local FortiWeb logging and does not replace WAF enforcement. Application delivery features such as load balancing are unrelated to cross-platform event correlation.
Question 290.
Why should FortiWeb use reliable time synchronization?
- To improve load balancing
- To ensure event timestamps are accurate for correlation and troubleshooting
- To increase upload limits
- To disable certificate validation
Correct Answer: 2. To ensure event timestamps are accurate for correlation and troubleshooting
Explanation:
Accurate timestamps are essential when administrators reconstruct incidents across multiple systems. FortiWeb events may need to be correlated with firewall, authentication, backend application, and endpoint logs. If system clocks differ significantly, event sequences can become misleading. Reliable time also supports certificate validation and scheduled operations. Administrators should therefore synchronize FortiWeb with approved time sources according to organizational policy. Time accuracy is a foundational operational requirement rather than an optional convenience.
Question 291.
A security team wants immediate notification when FortiWeb detects critical attacks against a payment application. Which approach is BEST?
- Configure high-severity event alerting or SIEM notifications
- Disable detailed logging
- Increase server pool size
- Enable session persistence
Correct Answer: 1. Configure high-severity event alerting or SIEM notifications
Explanation:
Critical application attacks should generate timely notifications so security personnel can investigate quickly. Alerts may be generated directly or through a SIEM receiving FortiWeb logs. The notification criteria should focus on high-risk events and include useful context such as the protected application, attack type, source, and action taken. Administrators should avoid generating immediate alerts for every low-value event because excessive noise can cause alert fatigue. Detailed logs should still be retained for deeper analysis.
Question 292.
The SOC is receiving too many FortiWeb alerts to investigate efficiently. What should be done first?
- Disable all logging
- Tune alert criteria, thresholds, and severity levels
- Turn off all web security profiles
- Remove attack signatures
Correct Answer: 2. Tune alert criteria, thresholds, and severity levels
Explanation:
Alert fatigue reduces the likelihood that analysts will notice important events. Administrators should identify which events truly require immediate attention and refine thresholds, severity levels, and notification rules accordingly. Lower-priority events can remain available in logs without generating real-time notifications. This preserves visibility while making the alert stream more actionable. Disabling logging or protection would reduce security and remove valuable evidence rather than solving the operational problem.
Question 293.
One server pool member is receiving much more traffic than expected. Which configuration should be reviewed first?
- Data leak prevention rules
- Signature database version
- Load-balancing algorithm, weights, and persistence settings
- Administrator password age
Correct Answer: 3. Load-balancing algorithm, weights, and persistence settings
Explanation:
Backend traffic distribution depends on the selected load-balancing method, configured server weights, health status, and session persistence. If one server is carrying significantly more traffic, it may have a higher configured weight or a large number of persistent sessions. A failed pool member can also shift traffic toward remaining systems. Administrators should review server pool statistics together with these settings before assuming a backend performance problem. Security inspection features do not directly control normal backend request distribution.
Question 294.
FortiWeb marks a server pool member unhealthy even though its web page opens in a browser. What is the BEST next step?
- Disable all security policies
- Increase attack signature sensitivity
- Replace the appliance
- Compare the configured health-check request with the actual server response**
Correct Answer: 4. Compare the configured health-check request with the actual server response
Explanation:
A backend server can appear functional in a browser but fail the specific check FortiWeb performs. The health-check URL may have changed, a redirect may occur, authentication may now be required, or the expected response content may no longer match. The administrator should verify the health-check protocol, port, path, and success criteria against actual application behavior. Correcting the check may restore the server to service without changing the backend application. Accurate health monitoring is essential for reliable load balancing.
Question 295.
A signature exception was created for a short-term compatibility problem that has now been fixed in the application. What should the administrator do?
- Remove the obsolete exception after validation
- Expand the exception to more URLs
- Keep it permanently
- Disable the associated signature globally
Correct Answer: 1. Remove the obsolete exception after validation
Explanation:
Exceptions should exist only while there is a legitimate reason for them. If the application change that caused the false positive has been corrected, the administrator should test the application without the exception and remove it if it is no longer necessary. This restores the full protection of the underlying signature and reduces policy complexity. Long-lived exceptions can become unnoticed security gaps, especially as staff and applications change. Periodic exception review is therefore an important part of FortiWeb policy governance.
Question 296.
Which practice BEST supports long-term analysis of attacks against a protected application?
- Review only current active sessions
- Maintain appropriate historical log retention
- Delete logs after every incident
- Disable centralized logging
Correct Answer: 2. Maintain appropriate historical log retention
Explanation:
Historical logs allow administrators to compare attack volume, targeted URLs, signatures, source patterns, and severity over weeks or months. This can reveal recurring campaigns, seasonal trends, or changes in attacker behavior. Centralized retention also supports incident investigations and compliance requirements. The appropriate retention period depends on organizational policy and available storage. Relying only on current sessions provides little context about long-term security activity and can cause important trends to be missed.
Question 297.
A broad URL exception resolves one false positive but weakens protection for several other parameters. What should the administrator do?
- Replace the broad exception with a more narrowly scoped rule
- Leave it unchanged
- Disable all signatures
- Stop reviewing attack logs
Correct Answer: 1. Replace the broad exception with a more narrowly scoped rule
Explanation:
The goal of a security exception is to resolve a specific legitimate compatibility issue while preserving protection everywhere else. If the exception weakens security for unrelated parameters or request conditions, it is too broad. Administrators should identify the exact condition causing the false positive and limit the exception to that context. Logs can then be reviewed to verify that legitimate traffic succeeds while suspicious activity continues to be detected. Narrow exceptions reduce unintended attack surface and are easier to manage over time.
Question 298.
A new application version introduces a new REST API and additional HTTP methods. What should the FortiWeb administrator do?
- Assume the existing policy will always be correct
- Review and update the relevant URL, method, signature, and behavioral controls
- Disable FortiWeb for the new API
- Delete all logs before deployment
Correct Answer: 2. Review and update the relevant URL, method, signature, and behavioral controls
Explanation:
New APIs change the application’s external behavior and may require policy updates. Administrators should review new paths, allowed HTTP methods, authentication requirements, request structures, rate limits, signatures, and behavioral models. Existing protocol constraints may block legitimate new traffic, while new endpoints may need additional security controls. Coordinating with the application team before release helps reduce false positives and protection gaps. FortiWeb policy should evolve with the application instead of remaining static.
Question 299.
How should a highly restrictive FortiWeb policy be introduced to a critical production application?
- Test with representative traffic and logs before expanding blocking
- Enable maximum blocking immediately without monitoring
- Disable logging during rollout
- Remove all health checks first
Correct Answer: 1. Test with representative traffic and logs before expanding blocking
Explanation:
A staged rollout allows administrators to evaluate how the restrictive policy handles real application behavior before it affects every user. Testing should include authentication, uploads, APIs, administrative workflows, common requests, and uncommon but legitimate operations. Logs provide the evidence needed to identify false positives and tune the policy. Once the configuration behaves correctly, enforcement can be expanded. Immediate broad blocking increases the likelihood of an avoidable outage and makes troubleshooting more difficult.
Question 300.
Which statement BEST describes a mature FortiWeb administration and security lifecycle?
- Configure policies once and never change them
- Use shared administrator accounts for convenience
- Disable audit logs to reduce storage
- Maintain secure administration, backups, upgrades, centralized monitoring, health checks, application-aware tuning, and regular exception review**
Correct Answer: 4. Maintain secure administration, backups, upgrades, centralized monitoring, health checks, application-aware tuning, and regular exception review
Explanation:
A mature FortiWeb environment requires continuous security and operational management. Administrative access should be controlled and auditable, backups should support recovery, and firmware upgrades should follow a planned process. Centralized monitoring improves visibility into attacks, while health checks and server pool statistics support application availability. Protection profiles, machine-learning models, URL rules, upload controls, and exceptions should be reviewed whenever applications change. Regular lifecycle management keeps FortiWeb aligned with current business traffic and threat conditions while reducing both security gaps and unnecessary blocking.