View Full Fortinet FCP_FWF_AD-7.4 Exam Dumps and Practice Test Dumps
Question 321.
A FortiWeb administrator wants to limit the risk of a compromised administrator account changing every production policy. Which design is BEST?
- Use role-based administrative permissions and least privilege
- Give every administrator full access
- Disable management logging
- Use a shared administrator credential
Correct Answer: 1. Use role-based administrative permissions and least privilege
Explanation:
Role-based administration limits what each administrator can do according to job responsibilities. If one account is compromised, the attacker’s capabilities are reduced compared with an environment where every account has unrestricted control. Individual administrator identities also support accountability and auditing. Permissions should be reviewed periodically so users do not retain unnecessary access after role changes. Shared credentials and disabled logging weaken traceability. Least privilege on the management plane is therefore an important complement to FortiWeb’s application security functions.
Question 322.
An administrator wants to identify who changed a certificate configuration yesterday. Which FortiWeb data should be reviewed?
- Server pool statistics
- Administrative audit logs
- Bot mitigation events
- Session persistence records
Correct Answer: 2. Administrative audit logs
Explanation:
Administrative audit logs are the appropriate source for determining who performed management actions and when. They can help identify configuration changes involving certificates, policies, networking, server pools, and other FortiWeb settings. Individual administrator accounts make the audit trail more useful because actions can be attributed to specific people. Traffic or bot logs may show the operational effects of a change, but they do not directly identify who modified the configuration. Auditability is a core part of secure FortiWeb administration.
Question 323.
What is the BEST way to reduce exposure of the FortiWeb management interface?
- Allow management from all public interfaces
- Disable administrator authentication
- Restrict management access to trusted interfaces and source networks
- Use the same address as every public application
Correct Answer: 3. Restrict management access to trusted interfaces and source networks
Explanation:
Restricting management access reduces the number of systems that can attempt authentication or target the administrative interface. Ideally, FortiWeb management should be reachable only from dedicated management networks or explicitly trusted sources. This should be combined with secure protocols, strong authentication, role-based permissions, and audit logging. Public exposure of the management plane creates unnecessary risk. Application traffic and administrative traffic should be treated as separate security concerns.
Question 324.
Before applying a large configuration change to a production FortiWeb, which action is MOST important?
- Delete historical logs
- Disable health checks
- Remove TLS certificates
- Create a current, verified configuration backup**
Correct Answer: 4. Create a current, verified configuration backup
Explanation:
A current backup provides a recovery point if the planned change causes an outage, unexpected blocking, or other configuration problems. The backup should be verified, stored securely, and accessible to authorized administrators. Major policy, network, certificate, server pool, and upgrade changes all benefit from a defined rollback or recovery path. Disabling health checks or deleting logs reduces operational visibility and does not make the change safer. Good change management combines backups with validation and recovery procedures.
Question 325.
Why should FortiWeb configuration backups be retained according to a defined policy?
- They provide recovery points if problems are discovered after later changes
- They automatically improve attack signatures
- They increase HTTP throughput
- They replace administrator accounts
Correct Answer: 1. They provide recovery points if problems are discovered after later changes
Explanation:
Some configuration problems are not detected immediately. If only the newest backup is retained and it already contains the unwanted change, administrators may have no known-good recovery point. Maintaining an appropriate backup history provides flexibility when rolling back to an earlier state. Retention should be balanced against storage, security, and organizational requirements. Because configuration files may contain sensitive information, access to them should remain tightly controlled.
Question 326.
A FortiWeb administrator is planning a firmware upgrade. Which preparation is MOST appropriate?
- Remove all server pools
- Review the supported upgrade path, release notes, and create a backup
- Disable all protections permanently
- Delete all logs
Correct Answer: 2. Review the supported upgrade path, release notes, and create a backup
Explanation:
Firmware upgrades should follow the supported path and vendor guidance. Administrators should review release notes for known issues, changes in behavior, feature updates, and compatibility considerations. A current configuration backup should be created before the upgrade, and a maintenance and validation plan should be prepared. High-availability environments may require additional sequencing considerations. Proper preparation makes troubleshooting and recovery easier if unexpected behavior appears after the upgrade.
Question 327.
After an upgrade, FortiWeb no longer accepts a previously working backend TLS connection. What should the administrator investigate FIRST?
- Printer settings
- User desktop configuration
- TLS protocol, cipher, certificate, trust, and upgrade-related changes
- IP reputation categories
Correct Answer: 3. TLS protocol, cipher, certificate, trust, and upgrade-related changes
Explanation:
An upgrade can affect supported TLS behavior, certificate validation, defaults, or compatibility with backend servers. Administrators should review relevant logs and release notes and compare the backend TLS configuration with the previous working state. The failure could involve protocol versions, cipher compatibility, certificate trust, hostname validation, or another encrypted-connection setting. Disabling validation without understanding the cause can weaken security. Structured TLS troubleshooting is the safer approach.
Question 328.
Which approach BEST protects availability during a FortiWeb production upgrade?
- Upgrade during the busiest period
- Disable monitoring
- Remove backups
- Use a planned maintenance process with testing, validation, and recovery steps**
Correct Answer: 4. Use a planned maintenance process with testing, validation, and recovery steps
Explanation:
A controlled maintenance process reduces operational risk. Administrators should use a supported upgrade path, schedule an appropriate maintenance window, create a backup, and define post-upgrade validation. Critical applications should be tested for TLS, traffic flow, security policy, backend health, and logging. Recovery options should be understood before changes begin. High availability may reduce service interruption but does not remove the need for careful planning and validation.
Question 329.
A SOC wants to correlate FortiWeb attack activity with authentication failures recorded elsewhere. What should be configured?
- Centralized log forwarding to a SIEM
- Session persistence only
- Server pool weighting
- Disabled event logging
Correct Answer: 1. Centralized log forwarding to a SIEM
Explanation:
A SIEM allows FortiWeb attack events to be correlated with authentication, endpoint, server, firewall, and other security data. This can reveal whether a web attack is part of a larger incident or whether successful application access followed repeated malicious activity. Centralized logs also support dashboards, alerting, search, and longer retention. FortiWeb continues to enforce its own policies; SIEM integration enhances visibility and investigation rather than replacing the WAF.
Question 330.
What is the MAIN reason accurate time synchronization is important for FortiWeb?
- It increases server pool capacity
- It makes event correlation and incident timelines reliable
- It eliminates TLS certificates
- It improves file upload speed
Correct Answer: 2. It makes event correlation and incident timelines reliable
Explanation:
Security investigations often involve multiple systems. If FortiWeb, backend servers, identity platforms, and the SIEM use different times, reconstructing the sequence of events becomes difficult. Accurate synchronization ensures timestamps can be compared reliably and also supports scheduled operations and certificate-related checks. Administrators should configure trusted time sources according to organizational standards. Reliable time is a foundational operational requirement for meaningful logging and troubleshooting.
Question 331.
A FortiWeb administrator wants only high-severity attacks to generate immediate notifications. Which configuration is MOST appropriate?
- Severity-based alert thresholds
- Session persistence
- Health-check intervals
- Backend load-balancing weights
Correct Answer: 1. Severity-based alert thresholds
Explanation:
Severity-based alerting allows administrators to distinguish events that require immediate action from those that can remain in logs for later analysis. This reduces alert fatigue while preserving detailed security records. Thresholds and notification criteria should be reviewed periodically so they reflect current risks and operational priorities. Disabling low-value notifications does not mean deleting the underlying events. Proper alert tuning helps security teams focus on actionable attacks without losing broader visibility.
Question 332.
A legitimate monitoring service is repeatedly classified as an unwanted bot. What is the BEST response?
- Disable all bot protection
- Validate the service and create a narrowly scoped adjustment or exception
- Disable logging
- Block all automated traffic
Correct Answer: 2. Validate the service and create a narrowly scoped adjustment or exception
Explanation:
Legitimate monitoring tools, search engines, and integrations may generate automated traffic that resembles bots. The administrator should first validate that the service is trusted and then tune the bot policy or create the smallest appropriate exception. Broadly disabling bot protection would reduce security for unrelated traffic. Logs should continue to be monitored after the adjustment to confirm that the legitimate service functions correctly without opening an unnecessary bypass for other automated clients.
Question 333.
A backend server is receiving much more traffic than other members in the same pool. What should be reviewed FIRST?
- Data leak prevention
- Attack signature severity
- Load-balancing algorithm, member weights, persistence, and health state
- Administrator role assignments
Correct Answer: 3. Load-balancing algorithm, member weights, persistence, and health state
Explanation:
Uneven backend distribution can be caused by the selected load-balancing algorithm, configured weights, persistent sessions, or unavailable pool members. A higher-capacity server may intentionally have a larger weight, while session persistence can cause large numbers of clients to remain attached to one member. If another server is unhealthy, traffic may shift naturally. Reviewing pool statistics and these settings is the most direct troubleshooting approach. Security policies generally do not determine ordinary load distribution.
Question 334.
FortiWeb reports a backend server as unhealthy because the configured health-check page now requires authentication. What should the administrator do?
- Disable all web security
- Delete the server pool
- Ignore the failure permanently
- Update the health check to use a suitable endpoint and expected response**
Correct Answer: 4. Update the health check to use a suitable endpoint and expected response
Explanation:
Health checks must reflect actual application behavior. If the monitored page changes and now requires authentication, the existing test may fail even though the server is healthy. Administrators should select an endpoint that reliably indicates application availability and configure the expected response appropriately. A good health check should be stable, lightweight, and representative of the service. Accurate health monitoring prevents healthy servers from being unnecessarily removed from the active pool.
Question 335.
A FortiWeb exception was created for an issue that no longer exists. What should the administrator do?
- Validate normal operation and remove the obsolete exception
- Expand it to the full application
- Keep it permanently
- Disable the underlying protection globally
Correct Answer: 1. Validate normal operation and remove the obsolete exception
Explanation:
Security exceptions weaken normal enforcement and should remain only while they are necessary. If the underlying application issue has been fixed, administrators should test the application without the exception and remove it if legitimate traffic continues to function. This restores the full protection of the original control and reduces policy complexity. Exceptions should be documented, narrowly scoped, and periodically reviewed so temporary fixes do not become permanent security gaps.
Question 336.
A company wants to investigate FortiWeb attacks that occurred six months earlier. Which practice is MOST important?
- Review only current sessions
- Maintain sufficient historical log retention
- Delete logs frequently
- Disable centralized logging
Correct Answer: 2. Maintain sufficient historical log retention
Explanation:
Historical incident investigation depends on preserved event data. Logs can reveal source addresses, targeted URLs, attack types, policy actions, and timing long after the original event occurred. Centralized storage is often useful for retaining larger volumes of information and supporting search and correlation. Retention periods should be aligned with organizational, regulatory, and incident-response requirements. Without retained logs, important evidence may be unavailable when an incident is discovered late.
Question 337.
A false-positive exception is allowing more traffic than intended. What should the administrator do?
- Narrow the exception to the exact legitimate condition
- Disable the entire protection profile
- Leave the exception unchanged
- Stop monitoring it
Correct Answer: 1. Narrow the exception to the exact legitimate condition
Explanation:
Exceptions should remove only the minimum amount of protection required to support legitimate application behavior. If an exception applies to an entire URL or application when only one parameter requires special treatment, it can allow unrelated malicious traffic to bypass inspection. Administrators should use logs and testing to identify the precise condition and restrict the exception accordingly. Narrow exceptions reduce attack surface and make future review and removal easier.
Question 338.
A new application release introduces different API paths, methods, and payload structures. What should the FortiWeb administrator do?
- Assume existing policy requires no review
- Reassess relevant URL, protocol, signature, and behavioral protections
- Disable the WAF permanently
- Delete historical logs
Correct Answer: 2. Reassess relevant URL, protocol, signature, and behavioral protections
Explanation:
Changes to application behavior can affect both security enforcement and false-positive risk. New API paths may need access rules, new methods may require protocol policy updates, and different payload structures may affect signature or behavioral detection. Administrators should work with the application team, review expected traffic, and monitor rollout logs. WAF policy should evolve with application changes rather than remaining static, because outdated security assumptions can cause either disruption or protection gaps.
Question 339.
A strict FortiWeb protection profile is ready for a critical production application. Which rollout approach is BEST?
- Test with representative traffic, monitor logs, tune the profile, and then expand blocking
- Enable maximum enforcement immediately
- Disable logging during deployment
- Remove backend monitoring first
Correct Answer: 1. Test with representative traffic, monitor logs, tune the profile, and then expand blocking
Explanation:
Representative testing reduces the risk that false positives or incorrect assumptions cause an outage. The traffic sample should include normal user requests, APIs, authentication, uploads, administrative functions, and less common legitimate activity. FortiWeb logs can then show which rules trigger and where tuning is needed. Once the profile has been validated, enforcement can be expanded. Immediate maximum blocking may turn a small tuning issue into widespread service disruption.
Question 340.
Which statement BEST describes mature FortiWeb security operations?
- Use only signatures and ignore operational controls
- Keep all exceptions indefinitely
- Use shared administrator credentials
- Combine secure management, backups, planned upgrades, centralized logging, accurate health monitoring, application-aware tuning, and continuous policy review**
Correct Answer: 4. Combine secure management, backups, planned upgrades, centralized logging, accurate health monitoring, application-aware tuning, and continuous policy review
Explanation:
A mature FortiWeb environment combines strong web application protection with disciplined operations. Administrative access should be restricted and auditable, configuration backups should support recovery, and upgrades should follow a controlled change process. Centralized logging improves incident visibility, while accurate health checks and server pool monitoring support application availability. Protection profiles, behavioral models, bot controls, protocol constraints, and exceptions should be reviewed as applications change. Continuous lifecycle management helps preserve both security and reliable application delivery.