Fortinet FCP_FWF_AD-7.4 Practice Test Questions and Exam Dumps Part20 Q381-400

View Full Fortinet FCP_FWF_AD-7.4 Exam Dumps and Practice Test Dumps

 

Question 381.

A FortiWeb administrator wants different administrators to have different management privileges. Which configuration is MOST appropriate?

  1. Role-based administrator permissions
  2. One shared administrator account
  3. Disabled audit logging
  4. Public management access

Correct Answer: 1. Role-based administrator permissions

Explanation:

Role-based administrative permissions allow FortiWeb access to be aligned with job responsibilities. For example, one administrator may require full configuration access while another only needs to review logs and dashboards. This supports least privilege and reduces the potential impact of an accidental or unauthorized change. Individual administrator accounts should also be used so management actions can be traced to specific users. Shared credentials and unrestricted privileges weaken accountability and make change investigations more difficult.

Question 382.

An application outage begins immediately after a configuration change. Which FortiWeb information should be reviewed to identify who made the change?

  1. Attack signature statistics
  2. Administrative audit logs
  3. Backend persistence data
  4. IP reputation records

Correct Answer: 2. Administrative audit logs

Explanation:

Administrative audit logs provide visibility into management actions performed on FortiWeb. They can help determine which administrator changed a setting and when the modification occurred. This is particularly useful when an outage begins shortly after a policy, certificate, routing, or server pool change. Individual administrator accounts improve the value of the audit trail by providing clear attribution. Application traffic logs may show the effect of the change, but audit logs are the primary source for identifying who altered the configuration.

Question 383.

Which practice BEST reduces exposure of the FortiWeb management plane?

  1. Permit management from all public networks
  2. Disable administrator authentication
  3. Restrict management access to trusted interfaces and source networks
  4. Share administrator credentials among staff

Correct Answer: 3. Restrict management access to trusted interfaces and source networks

Explanation:

Management services should be reachable only from systems that require administrative access. Restricting connectivity to trusted interfaces and source networks reduces the number of hosts capable of targeting the management plane. Strong authentication, individual accounts, role-based privileges, and audit logging should be used in addition to network restrictions. Public management exposure increases the attack surface unnecessarily. Protecting the FortiWeb management plane is separate from securing the web applications it processes.

Question 384.

Before implementing a major FortiWeb configuration change, which action provides the BEST recovery option?

  1. Delete historical logs
  2. Disable all health checks
  3. Remove current certificates
  4. Create and verify a current configuration backup**

Correct Answer: 4. Create and verify a current configuration backup

Explanation:

A verified backup provides a known recovery point if the planned change causes an outage, unexpected traffic handling, or security problems. The backup should be current, securely stored, and available to authorized administrators. Major policy, network, certificate, server pool, and firmware changes should also include validation and recovery procedures. Backups do not prevent configuration errors, but they can significantly reduce recovery time when changes do not behave as expected.

Question 385.

Why should several recent FortiWeb configuration backups be retained when possible?

  1. A problem may be discovered after the newest backup already contains the unwanted change
  2. More backups improve signature detection
  3. Backups increase HTTP throughput
  4. Backups replace event logging

Correct Answer: 1. A problem may be discovered after the newest backup already contains the unwanted change

Explanation:

Configuration issues are not always detected immediately. If the newest backup already includes the problematic configuration, an earlier known-good state may be needed for recovery. Retaining several appropriate backup versions provides greater flexibility during restoration. Backups should be stored securely because they may contain sensitive network, server, security, and certificate-related information. Backup retention should follow organizational policy and should complement, rather than replace, change documentation and log retention.

Question 386.

A FortiWeb administrator is preparing for a firmware upgrade. Which action is MOST appropriate?

  1. Disable all security features
  2. Review the supported upgrade path, release notes, and create a current backup
  3. Remove every server pool
  4. Delete all existing logs

Correct Answer: 2. Review the supported upgrade path, release notes, and create a current backup

Explanation:

Firmware upgrades should follow vendor-supported upgrade paths and documented guidance. Release notes can identify behavior changes, new features, resolved issues, known limitations, and compatibility considerations. Administrators should create a current backup and prepare a maintenance and validation plan before beginning. In high-availability environments, the upgrade sequence may require additional planning. These steps make recovery and troubleshooting easier if unexpected behavior appears after the upgrade.

Question 387.

After a FortiWeb upgrade, a backend HTTPS connection begins failing certificate validation. What should the administrator review FIRST?

  1. Desktop configuration
  2. Printer settings
  3. Certificate trust, hostname validation, TLS settings, logs, and upgrade notes
  4. Bot mitigation thresholds

Correct Answer: 3. Certificate trust, hostname validation, TLS settings, logs, and upgrade notes

Explanation:

A certificate validation failure can result from an incomplete trust chain, hostname mismatch, expired certificate, changed TLS behavior, or configuration migration issue. Administrators should review FortiWeb logs and compare the backend certificate and trust configuration with the previously working state. Upgrade documentation may also describe changes affecting TLS validation. Disabling certificate verification without understanding the cause would weaken security. The correct approach is to identify and correct the trust or compatibility issue.

Question 388.

Which upgrade strategy BEST protects production availability?

  1. Upgrade immediately during peak usage
  2. Disable monitoring during the change
  3. Remove all recovery backups
  4. Use a planned maintenance process with testing, validation, and recovery steps**

Correct Answer: 4. Use a planned maintenance process with testing, validation, and recovery steps

Explanation:

A controlled upgrade process should include a supported upgrade path, current backup, suitable maintenance period, validation checklist, and recovery procedures. After the upgrade, administrators should verify management access, protected applications, TLS connections, security policies, server pools, health checks, and logging. High availability can reduce disruption but does not eliminate the need for careful planning. Production upgrades are safer when both technical validation and operational recovery options are defined in advance.

Question 389.

A security operations center wants to correlate FortiWeb events with firewall, identity, and endpoint data. What should be configured?

  1. Centralized log forwarding to a SIEM
  2. Session persistence only
  3. Backend load-balancing weights
  4. Disabled security logging

Correct Answer: 1. Centralized log forwarding to a SIEM

Explanation:

A SIEM can combine FortiWeb attack and administrative events with information from firewalls, identity systems, endpoints, servers, and other security technologies. This allows analysts to determine whether application-layer activity is part of a wider incident. Centralized logging also supports alerting, dashboards, historical search, and retention. FortiWeb continues enforcing its own policies while the SIEM provides broader context and correlation. Load balancing and persistence do not provide this cross-platform visibility.

Question 390.

Why should FortiWeb synchronize its clock with reliable time sources?

  1. To increase load-balancing capacity
  2. To ensure accurate event correlation and incident timelines
  3. To eliminate certificate renewal
  4. To improve upload throughput

Correct Answer: 2. To ensure accurate event correlation and incident timelines

Explanation:

Accurate timestamps are essential when administrators need to compare FortiWeb events with logs from backend servers, firewalls, identity platforms, and SIEM tools. If system clocks differ, the sequence of events can appear misleading and complicate investigation. Reliable time synchronization also supports certificate-related checks and scheduled operations. Using approved time sources helps make FortiWeb logs dependable for incident response, troubleshooting, compliance, and reporting.

Question 391.

A security team wants only critical FortiWeb events to generate immediate notifications. Which configuration is BEST?

  1. Severity-based alert thresholds and notification rules
  2. Session persistence
  3. Server pool weighting
  4. Health checking

Correct Answer: 1. Severity-based alert thresholds and notification rules

Explanation:

Severity-based alerting helps security teams focus on events that require immediate attention while retaining lower-priority information in logs. This reduces alert fatigue and improves the likelihood that critical attacks are investigated promptly. Administrators should periodically review alert criteria to ensure they still reflect business risk and current attack patterns. Detailed security logging should remain enabled even when only selected events generate real-time notifications.

Question 392.

A trusted monitoring service is repeatedly classified as an unwanted bot. What should the administrator do?

  1. Disable bot protection globally
  2. Validate the service and create a narrowly scoped policy adjustment
  3. Stop collecting logs
  4. Permit every automated client

Correct Answer: 2. Validate the service and create a narrowly scoped policy adjustment

Explanation:

Legitimate monitoring systems and automated services can sometimes resemble malicious bots. The administrator should verify the service’s identity and behavior and then make the smallest appropriate adjustment to the bot policy. Broadly disabling bot protection would weaken security for unrelated traffic. After tuning, logs should be reviewed to confirm that the trusted service operates correctly while suspicious automated clients continue to be controlled.

Question 393.

One member of a FortiWeb server pool receives much more traffic than the others. Which settings should be reviewed FIRST?

  1. DLP patterns
  2. Administrator privileges
  3. Load-balancing method, member weights, persistence, and health status
  4. Signature severity levels

Correct Answer: 3. Load-balancing method, member weights, persistence, and health status

Explanation:

Uneven backend traffic may result from the selected load-balancing algorithm, configured server weights, session persistence, or unhealthy pool members. A high-capacity server may intentionally receive more traffic, while persistence can keep large groups of clients attached to one system. Failed members can also shift load toward the remaining servers. Reviewing these application-delivery settings and statistics is the most direct troubleshooting approach. DLP and signature settings normally do not control traffic distribution among healthy backends.

Question 394.

A backend health check fails after the application changes its status endpoint. What should the administrator do?

  1. Disable all web protection
  2. Remove the backend permanently
  3. Ignore health status
  4. Update the health check to use the new endpoint and correct expected response**

Correct Answer: 4. Update the health check to use the new endpoint and correct expected response

Explanation:

Health checks must remain aligned with actual application behavior. If the application status page moves to a new URL, the old check may return an error or unexpected response even though the server itself is healthy. Administrators should validate the new endpoint and update the health-check configuration accordingly. Accurate monitoring is important because false failures can reduce available capacity and affect load balancing. The goal is to use a stable endpoint that reliably represents application health.

Question 395.

A FortiWeb exception created during testing is no longer needed in production. What should the administrator do?

  1. Validate the application and remove the obsolete exception
  2. Expand the exception
  3. Disable the associated protection globally
  4. Keep the exception indefinitely

Correct Answer: 1. Validate the application and remove the obsolete exception

Explanation:

Security exceptions should remain only while a legitimate requirement exists. If the testing condition has disappeared, administrators should verify that normal application traffic works without the exception and then remove it. This restores the full protection of the underlying control and reduces configuration complexity. Temporary exceptions that are never revisited can become long-term security gaps. Regular policy review should therefore include confirmation that each exception still has a valid purpose.

Question 396.

An organization needs to investigate FortiWeb attacks that occurred many months earlier. Which practice is MOST important?

  1. Review current sessions only
  2. Maintain adequate log retention or centralized archival
  3. Delete logs frequently
  4. Disable external log forwarding

Correct Answer: 2. Maintain adequate log retention or centralized archival

Explanation:

Historical incident investigations depend on preserved event data. Retained logs can show source addresses, attack types, targeted URLs, policy actions, timestamps, and administrative changes long after an event occurs. Centralized storage can provide greater retention capacity and more powerful searching and correlation. Retention periods should be aligned with organizational policies, compliance requirements, and incident-response needs. Without historical records, important evidence may be unavailable when an attack is discovered late.

Question 397.

A broad signature exception resolves one false positive but weakens protection for unrelated requests. What should the administrator do?

  1. Replace it with a narrowly scoped exception for the exact legitimate condition
  2. Leave the broad exception unchanged
  3. Disable all signatures
  4. Stop monitoring the affected application

Correct Answer: 1. Replace it with a narrowly scoped exception for the exact legitimate condition

Explanation:

Exceptions should reduce protection only where absolutely necessary. If a broad exception affects unrelated requests, attackers may be able to exploit the resulting gap. The administrator should identify the exact URL, parameter, signature, or request condition responsible for the false positive and restrict the exception to that context. Afterward, both legitimate and malicious test cases should be reviewed. Narrow exceptions preserve security elsewhere and are easier to manage and remove later.

Question 398.

A new version of an application changes valid API paths, methods, and payload formats. What should the FortiWeb administrator do?

  1. Assume the existing WAF configuration will always remain correct
  2. Review and update relevant access, protocol, signature, and behavioral policies
  3. Disable FortiWeb for the new application version
  4. Delete historical logs

Correct Answer: 2. Review and update relevant access, protocol, signature, and behavioral policies

Explanation:

Application changes can affect what FortiWeb considers legitimate traffic. New API paths may require updated URL access rules, changed methods may affect protocol constraints, and new payload structures can alter signature and behavioral detection. Administrators should coordinate with application teams and monitor deployment traffic carefully. A WAF policy that remains unchanged while the application evolves can either block legitimate traffic or fail to protect new functionality appropriately.

Question 399.

A highly restrictive FortiWeb protection profile is ready for a mission-critical application. Which rollout approach is BEST?

  1. Test with representative traffic, review logs, tune the profile, and then expand enforcement
  2. Enable maximum blocking immediately
  3. Disable logs during deployment
  4. Remove backend health checks first

Correct Answer: 1. Test with representative traffic, review logs, tune the profile, and then expand enforcement

Explanation:

A staged rollout helps reduce the risk of false positives causing production disruption. Administrators should test normal user workflows, APIs, authentication, uploads, administrative functions, and unusual but legitimate requests. FortiWeb logs provide evidence about which controls trigger and where tuning is required. Once the policy behaves correctly with representative traffic, stronger enforcement can be expanded. Immediate maximum blocking can turn a minor tuning issue into a widespread outage.

Question 400.

Which statement BEST describes mature FortiWeb administration and security operations?

  1. Configure the WAF once and never revisit it
  2. Use only attack signatures
  3. Keep temporary exceptions permanently
  4. Combine secure administration, backups, planned upgrades, centralized logging, reliable health monitoring, application-aware tuning, and continuous policy review**

Correct Answer: 4. Combine secure administration, backups, planned upgrades, centralized logging, reliable health monitoring, application-aware tuning, and continuous policy review

Explanation:

A mature FortiWeb program combines web application security with disciplined operations. Management access should be restricted, auditable, and based on least privilege. Reliable backups support recovery, while firmware upgrades should follow tested change procedures. Centralized logging improves monitoring and investigation, and accurate health checks support application availability. Protection profiles, behavioral models, bot controls, protocol constraints, and exceptions should be reviewed as applications evolve. Continuous lifecycle management keeps FortiWeb aligned with current business requirements and changing threats.