View Full Fortinet FCP_FWF_AD-7.4 Exam Dumps and Practice Test Dumps
Question 361.
A FortiWeb administrator wants to protect management access by ensuring only approved staff can make configuration changes. Which combination is BEST?
- Individual administrator accounts, least privilege, and trusted management access
- One shared administrator account
- Public management access from all interfaces
- Disabled administrative logging
Correct Answer: 1. Individual administrator accounts, least privilege, and trusted management access
Explanation:
Secure management depends on several complementary controls. Individual administrator accounts provide accountability, least-privilege roles limit what each person can modify, and restricting management access to trusted networks reduces exposure. Audit logging should remain enabled so actions can be reviewed later. Shared credentials weaken attribution, while public management access increases the attack surface. Combining identity, authorization, network restriction, and logging provides stronger protection for the FortiWeb management plane than relying on any single control.
Question 362.
A manager asks who changed a protected server configuration last week. Which FortiWeb information should be reviewed first?
- Attack signature statistics
- Administrative audit logs
- IP reputation records
- Session persistence information
Correct Answer: 2. Administrative audit logs
Explanation:
Administrative audit logs are intended to record management actions and help identify which administrator performed a change and when it occurred. They are particularly useful when investigating modifications to server policies, certificates, backend pools, or other settings. Individual accounts make these logs more meaningful because actions can be linked to specific users. Traffic logs may show the effect of a change, but audit records are the most direct source for determining who altered the configuration.
Question 363.
What is the BEST way to reduce attack surface on the FortiWeb management interface?
- Allow management from every public IP
- Disable administrator authentication
- Restrict access to trusted management networks and secure protocols
- Reuse the same credentials across administrators
Correct Answer: 3. Restrict access to trusted management networks and secure protocols
Explanation:
Management access should be limited to networks and systems that genuinely require administrative connectivity. Restricting source networks and using secure protocols reduces exposure to brute-force attacks and exploitation attempts. Strong authentication, individual accounts, role-based privileges, and audit logging should also be used. Publicly exposing administrative services without need creates unnecessary risk. Management-plane hardening should be treated separately from application-facing security policies.
Question 364.
Before replacing several FortiWeb security policies, which action provides the BEST recovery option?
- Delete historical logs
- Disable backend health checks
- Remove certificates
- Create and verify a current configuration backup**
Correct Answer: 4. Create and verify a current configuration backup
Explanation:
A current backup provides a known recovery point if the new policies cause unexpected blocking, routing problems, or service disruption. The backup should be verified, securely stored, and accessible to authorized personnel. Administrators should also document the intended changes and define validation and recovery steps. Backups are especially important before large policy changes, firmware upgrades, network changes, or certificate updates. Removing logs or other controls would make troubleshooting more difficult.
Question 365.
Why is it useful to retain more than one FortiWeb configuration backup?
- An older known-good state may be needed if a problem is discovered later
- Multiple backups increase attack signature coverage
- Backups improve TLS performance
- Backups replace SIEM logging
Correct Answer: 1. An older known-good state may be needed if a problem is discovered later
Explanation:
Not all configuration problems are detected immediately. If the most recent backup already contains an unwanted change, an earlier recovery point may be required. Keeping several recent, securely stored backups gives administrators more flexibility during restoration. Backup retention should follow organizational policy and available storage. Because backups may contain sensitive policy, network, and certificate information, access should be carefully controlled.
Question 366.
A FortiWeb firmware upgrade is planned. Which action should occur before installation?
- Disable all security policies
- Review release notes, verify the supported upgrade path, and create a backup
- Remove all backend members
- Delete all logs
Correct Answer: 2. Review release notes, verify the supported upgrade path, and create a backup
Explanation:
A firmware upgrade should be planned carefully. Administrators should review release documentation for supported upgrade sequences, known issues, changed behavior, and compatibility considerations. A current configuration backup should be created before changes begin. It is also good practice to prepare a maintenance window, post-upgrade validation checklist, and recovery plan. These steps reduce risk and make troubleshooting easier if unexpected behavior appears after the upgrade.
Question 367.
After upgrading FortiWeb, one HTTPS backend connection fails while others continue working. What should be investigated FIRST?
- Desktop wallpaper
- Printer drivers
- Backend certificate trust, TLS compatibility, logs, and upgrade changes
- Session persistence settings
Correct Answer: 3. Backend certificate trust, TLS compatibility, logs, and upgrade changes
Explanation:
A post-upgrade HTTPS failure may result from changed TLS behavior, protocol compatibility, cipher support, certificate trust, or validation rules. Administrators should review FortiWeb logs and release notes and compare the failed backend’s TLS configuration with the previous working state. Because only one backend is affected, its certificate chain and server-side TLS settings deserve particular attention. Disabling validation without understanding the root cause could weaken security unnecessarily.
Question 368.
Which upgrade approach BEST reduces the chance of a prolonged production outage?
- Upgrade without a recovery plan
- Disable monitoring during the upgrade
- Remove backups before starting
- Use a controlled maintenance process with testing, validation, and rollback options**
Correct Answer: 4. Use a controlled maintenance process with testing, validation, and rollback options
Explanation:
Production upgrades should be performed as controlled changes. Administrators should use a supported upgrade path, create a current backup, schedule an appropriate maintenance period, and define validation and recovery procedures. Critical applications should be tested after the upgrade to verify traffic flow, TLS, policies, health checks, logging, and management access. High availability may reduce disruption but does not eliminate the need for careful planning and post-upgrade verification.
Question 369.
A SOC wants to investigate whether FortiWeb attacks are related to suspicious endpoint activity. Which configuration is MOST useful?
- Forward FortiWeb logs to a SIEM
- Increase backend weights
- Enable persistence only
- Disable security logging
Correct Answer: 1. Forward FortiWeb logs to a SIEM
Explanation:
A SIEM can correlate FortiWeb attack events with endpoint, firewall, identity, server, and other security data. This broader context can reveal whether a web attack is part of a larger incident. Centralized logging also supports alerting, dashboards, historical searches, and reporting. FortiWeb continues to enforce its own security policies while the SIEM improves visibility and investigation capability across the environment.
Question 370.
Why should FortiWeb use the same reliable time source as other security systems?
- To increase backend server capacity
- To ensure event timelines and correlations are accurate
- To disable expired certificates
- To improve file upload throughput
Correct Answer: 2. To ensure event timelines and correlations are accurate
Explanation:
Security investigations often require events from several systems to be placed in the correct chronological order. If FortiWeb, firewalls, servers, and the SIEM have different clocks, the sequence can appear misleading. Accurate time synchronization improves incident response, troubleshooting, reporting, and correlation. It can also support certificate validation and scheduled operations. Using approved reliable time sources is therefore an important operational practice.
Question 371.
A security team wants immediate alerts only for critical attacks against a customer portal. Which configuration is BEST?
- Severity-based alerting and notification thresholds
- Session persistence
- Server health checks
- Load-balancing weights
Correct Answer: 1. Severity-based alerting and notification thresholds
Explanation:
Alerting should focus on events that require prompt investigation. Severity-based notification rules allow critical attacks to generate immediate alerts while lower-priority events remain in logs for later review. This reduces alert fatigue and makes important activity easier to notice. The underlying detailed logs should still be retained. Alert criteria should be reviewed periodically as business priorities and attack patterns change.
Question 372.
A legitimate automated vulnerability scanner operated by the company is being treated as an unwanted bot. What should the administrator do?
- Disable all bot controls
- Verify the scanner and create a narrowly scoped adjustment
- Disable logging
- Permit all automated clients
Correct Answer: 2. Verify the scanner and create a narrowly scoped adjustment
Explanation:
Authorized scanners, monitoring systems, and automated integrations can resemble malicious bots. The administrator should first confirm the scanner is legitimate and then create the smallest appropriate adjustment or exception. Broadly disabling bot protection would weaken defenses against unrelated automated attacks. After tuning, logs should be reviewed to verify that the authorized scanner works correctly while unwanted automation remains controlled.
Question 373.
A FortiWeb server pool shows one member handling much more traffic than the others. What should the administrator review FIRST?
- DLP patterns
- Administrator roles
- Load-balancing algorithm, member weights, persistence, and health status
- Web attack signature severity
Correct Answer: 3. Load-balancing algorithm, member weights, persistence, and health status
Explanation:
Uneven backend utilization can be caused by intentional weighting, the selected balancing algorithm, session persistence, or the health state of other members. A server with a larger weight may receive more traffic by design, and persistent sessions can keep many users attached to one member. If another backend is unhealthy, the remaining members will also receive more load. Reviewing server pool statistics and these settings is the most direct troubleshooting path.
Question 374.
A health check begins failing after the application’s status page is moved to a different URL. What should the administrator do?
- Disable all security profiles
- Remove the backend permanently
- Ignore health status
- Update the health check to the correct application endpoint and expected response**
Correct Answer: 4. Update the health check to the correct application endpoint and expected response
Explanation:
Health checks must reflect current application behavior. If the monitored resource moves, the old URL may return an error or redirect and cause FortiWeb to mark a healthy server down. Administrators should verify the new application endpoint and update the check so it accurately indicates service availability. Reliable health checks are important because false failures can unnecessarily reduce backend capacity or cause application availability problems.
Question 375.
A temporary signature exception was created during an application migration. The migration is complete and the original traffic pattern no longer exists. What should be done?
- Validate normal behavior and remove the exception if it is no longer required
- Broaden the exception
- Disable the associated signature globally
- Keep the exception permanently
Correct Answer: 1. Validate normal behavior and remove the exception if it is no longer required
Explanation:
Exceptions should remain only while their business or technical justification exists. Once the migration is complete, the administrator should test normal application traffic without the exception. If the exception is no longer necessary, removing it restores the original security coverage and simplifies policy management. Temporary exceptions can become persistent security gaps if they are never revisited. Regular review is therefore an important part of WAF governance.
Question 376.
An organization wants FortiWeb logs available for incident investigations up to one year later. Which practice is MOST appropriate?
- Keep only current active sessions
- Configure adequate log retention or centralized archival
- Delete logs every month
- Disable external logging
Correct Answer: 2. Configure adequate log retention or centralized archival
Explanation:
Long-term investigations require historical event data. Adequate retention allows analysts to review attack sources, targeted URLs, matched signatures, administrative changes, and policy actions months after the original activity occurred. Centralized logging platforms often provide additional storage, search, reporting, and correlation capabilities. Retention should be aligned with organizational policy, compliance requirements, and storage capacity. Without historical logs, important evidence may be unavailable when needed.
Question 377.
A false-positive exception unintentionally applies to several unrelated request parameters. What should the administrator do?
- Narrow the exception to the exact validated parameter and condition
- Leave it unchanged
- Disable the full web protection profile
- Stop reviewing logs
Correct Answer: 1. Narrow the exception to the exact validated parameter and condition
Explanation:
Exceptions should weaken protection only where necessary. If a broad rule covers unrelated parameters, attackers may gain opportunities to bypass inspection in areas that never required an exception. The administrator should use logs and testing to identify the exact legitimate condition and scope the exception accordingly. After the change, legitimate traffic should be retested while suspicious variations are confirmed to remain blocked. Narrow exceptions are safer and easier to manage.
Question 378.
A new application release changes URL paths, supported methods, and JSON payload structures. What should the FortiWeb administrator do?
- Assume no policy changes are necessary
- Review and update access, protocol, signature, and behavioral policies as needed
- Disable FortiWeb permanently
- Delete previous security events
Correct Answer: 2. Review and update access, protocol, signature, and behavioral policies as needed
Explanation:
Application releases can significantly change what legitimate traffic looks like. New URLs may require updated access rules, changed HTTP methods can affect protocol controls, and new payload structures can influence signature and behavioral detection. Administrators should coordinate with application teams and monitor the rollout so false positives and protection gaps are identified quickly. FortiWeb policies should evolve with the applications they protect rather than remain static.
Question 379.
A strict FortiWeb policy is ready for a mission-critical application. What is the BEST rollout strategy?
- Test with representative traffic, review logs, tune the policy, and then expand enforcement
- Enable maximum blocking immediately
- Disable event logging during rollout
- Remove backend health checks first
Correct Answer: 1. Test with representative traffic, review logs, tune the policy, and then expand enforcement
Explanation:
A staged rollout reduces the chance that a false positive or overly restrictive limit will disrupt production users. Administrators should test authentication flows, APIs, uploads, common pages, administrative functions, and unusual but valid traffic. Logs provide the evidence needed to tune the policy before broad enforcement. Once behavior is validated, stronger blocking can be expanded confidently. Immediate maximum enforcement creates unnecessary outage risk.
Question 380.
Which statement BEST describes mature FortiWeb lifecycle management?
- Depend only on signatures
- Use shared administrator accounts
- Keep every temporary exception forever
- Combine secure administration, backups, controlled upgrades, centralized monitoring, reliable backend health checks, application-aware tuning, and recurring policy review**
Correct Answer: 4. Combine secure administration, backups, controlled upgrades, centralized monitoring, reliable backend health checks, application-aware tuning, and recurring policy review
Explanation:
Mature FortiWeb operations require continuous attention to both security and availability. Management access should be restricted and auditable, reliable backups should support recovery, and upgrades should follow controlled procedures. Centralized logging improves monitoring and incident response, while accurate health checks support backend availability. Protection profiles, behavioral models, bot policies, access rules, and exceptions should be reviewed as applications evolve. Ongoing lifecycle management helps FortiWeb remain effective as infrastructure, applications, and threats change.