{"id":21631,"date":"2026-09-25T06:36:38","date_gmt":"2026-09-25T06:36:38","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21631"},"modified":"2026-09-25T06:36:38","modified_gmt":"2026-09-25T06:36:38","slug":"fortinet-nse5_fwb_ad-8-0-practice-test-questions-and-exam-dumps-part-6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse5_fwb_ad-8-0-practice-test-questions-and-exam-dumps-part-6-q101-120\/","title":{"rendered":"Fortinet NSE5_FWB_AD-8.0 Practice Test Questions and Exam Dumps Part 6 Q101-120"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse5-fwb-ad-8-0-exam-dumps\"><b>Fortinet NSE5_FWB_AD-8.0 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 101. A FortiWeb administrator needs to protect an application hosted by several backend servers. The administrator wants FortiWeb to distribute incoming requests across those servers according to a configured balancing method. Which FortiWeb component should be configured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web vulnerability scanner<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL access control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus profile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Server pool<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A server pool defines the backend servers that FortiWeb can use to service requests for a protected application. After servers are added to a pool, FortiWeb can use its configured load-balancing behavior to distribute traffic among available members. Health checks can also determine whether a backend server is currently suitable for receiving requests. URL access control and antivirus inspection address application security rather than backend distribution. A vulnerability scanner is used to identify application weaknesses. When configuring a server pool, administrators should verify backend connectivity, appropriate health-check settings, and the selected balancing behavior so that traffic is distributed as intended.<\/span><\/p>\n<p><b>Question 102. An organization wants to ensure that sensitive cookies sent by its web application include security attributes that reduce exposure to client-side attacks. Which FortiWeb capability should the administrator investigate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cookie security<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health checks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geographic load balancing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Cookie security<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cookie security controls can help protect session-related cookies by enforcing or validating appropriate cookie attributes. Security attributes such as Secure and HttpOnly can reduce certain risks associated with transmitting or accessing sensitive cookies. Depending on the application and FortiWeb configuration, cookie-related protection can help strengthen session security without requiring changes to backend load balancing. Health checks determine whether servers are available, while HTTP caching controls how responses are stored and reused. Geographic load balancing concerns traffic distribution rather than cookie protection. Administrators should verify application compatibility before modifying cookie behavior because applications may depend on specific cookie names, paths, domains, or attributes.<\/span><\/p>\n<p><b>Question 103. A web application is vulnerable to users submitting malicious JavaScript through a comment field. Which attack should FortiWeb&#8217;s WAF primarily detect in this situation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> SQL injection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS poisoning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cross-site scripting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health-check failure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Cross-site scripting<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-site scripting, or XSS, occurs when an attacker causes malicious script content to be interpreted in a user&#8217;s browser through an application that does not properly validate or encode input. Comment fields are a common example because attackers may attempt to submit script content that is later displayed to other users. FortiWeb WAF protections can inspect requests for patterns associated with XSS attacks and take the configured enforcement action. SQL injection targets database query manipulation, while DNS poisoning and server health checks address different security or availability concerns. Administrators should also address the underlying application vulnerability through proper input validation and output encoding.<\/span><\/p>\n<p><b>Question 104. A company wants FortiWeb to reject requests to an application when the request URL contains paths that are not permitted by the application&#8217;s published structure. Which feature should be configured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server pool health check<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL access control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TLS certificate management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. URL access control<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">URL access control allows administrators to define which application URLs or paths should be permitted or denied. This can reduce unnecessary exposure by preventing clients from reaching resources that are not intended to be publicly accessible. It is particularly useful for restricting sensitive administrative paths, unused directories, or application areas with specific access requirements. Server health checks determine backend availability, TLS certificate management handles cryptographic credentials, and HTTP caching controls response reuse. Administrators should carefully define URL patterns so that legitimate application resources continue to work. Logs should be reviewed after deployment to identify unexpected legitimate requests that may have been affected by the access policy.<\/span><\/p>\n<p><b>Question 105. A FortiWeb administrator wants to protect a web application from clients that repeatedly send requests at a rate that could exhaust application resources. Which combination is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rate limiting and DoS protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Certificate renewal and URL rewriting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching and server health checks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery and geographic routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Rate limiting and DoS protection<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Rate limiting and denial-of-service protection can work together to reduce the impact of excessive request traffic. Rate limiting establishes thresholds for request activity, while DoS-oriented controls can detect and mitigate patterns associated with resource exhaustion or abnormal traffic volumes. These controls are particularly useful when an application must remain available during abusive or unusually high request rates. Certificate renewal addresses TLS credentials, URL rewriting modifies request paths, and health checks monitor backend availability. Administrators should establish thresholds based on normal traffic patterns because limits that are too restrictive can affect legitimate users during expected traffic spikes.<\/span><\/p>\n<p><b>Question 106. A protected application uses a virtual host name such as portal.example.com. Requests for another hostname are unexpectedly reaching the same application. What should the administrator verify first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus database update status<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual host and Host header matching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Backend file permissions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP cache expiration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Virtual host and Host header matching<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The HTTP Host header identifies the hostname requested by the client and can be used by FortiWeb to distinguish applications or virtual hosts. If an unexpected hostname reaches an application, the administrator should verify how the virtual server and server policy match incoming Host header values. Incorrect or overly broad matching can cause traffic intended for one hostname to be associated with another policy. Antivirus updates and backend file permissions do not normally determine which FortiWeb virtual host receives the request. Cache expiration affects response reuse rather than initial policy selection. Reviewing policy matching and relevant traffic logs can help confirm exactly how the request was processed.<\/span><\/p>\n<p><b>Question 107. A company terminates HTTPS connections on FortiWeb and wants FortiWeb to validate the certificate presented by backend HTTPS servers. Which configuration area is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Backend SSL\/TLS and trusted certificates<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP method restrictions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL rewriting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bot mitigation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Backend SSL\/TLS and trusted certificates<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When FortiWeb establishes HTTPS connections to backend servers, it may need to validate the backend server certificate according to the configured trust relationship. The administrator should therefore review backend SSL\/TLS settings and the certificates or certificate authorities trusted by FortiWeb. Proper certificate validation helps prevent FortiWeb from establishing secure connections to an unintended or untrusted backend. HTTP method restrictions control allowed request methods, URL rewriting changes URL behavior, and bot mitigation focuses on automated traffic. Administrators should also verify certificate validity, hostname expectations, expiration, and the appropriate trust chain when troubleshooting backend TLS connection failures.<\/span><\/p>\n<p><b>Question 108. A security team wants to inspect application traffic for known malicious patterns while minimizing the chance that legitimate requests are blocked because of overly broad rules. What should the administrator do when investigating a suspected false positive?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable every security profile permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review the matched rule and event details before tuning the policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove all backend servers from the pool<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable HTTPS for the application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Review the matched rule and event details before tuning the policy<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a legitimate request is blocked, the administrator should first identify the security mechanism that triggered the action. FortiWeb event and security logs can provide details about the matched rule, request characteristics, and enforcement action. Reviewing this evidence helps determine whether the request genuinely violates a protection rule or whether the rule needs more precise tuning. Permanently disabling security controls creates unnecessary exposure, while changing backend servers or disabling HTTPS does not address the underlying detection issue. After identifying the cause, administrators can make a narrowly scoped policy adjustment and test legitimate and malicious traffic to verify that protection remains effective.<\/span><\/p>\n<p><b>Question 109. An application requires only GET, POST, and PUT methods. The administrator wants all other HTTP methods rejected before reaching the backend. Which configuration should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP method restriction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web vulnerability scanner<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health check<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP response caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. HTTP method restriction<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HTTP method restrictions allow FortiWeb administrators to specify which request methods an application is allowed to use. In this scenario, GET, POST, and PUT can be permitted while other methods are rejected. Restricting unnecessary methods reduces the application&#8217;s exposed functionality and can help prevent unintended operations. A vulnerability scanner assesses weaknesses rather than enforcing runtime method restrictions. Health checks monitor backend availability, and HTTP caching manages responses. Before implementing the restriction, the administrator should verify the application&#8217;s complete method requirements, including methods used by APIs, browser interactions, health endpoints, and administrative functions, to avoid disrupting legitimate application behavior.<\/span><\/p>\n<p><b>Question 110. A FortiWeb administrator wants to prevent a client from repeatedly requesting the same expensive application endpoint at an excessive frequency. Which feature is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> TLS certificate import<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rate limiting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server pool creation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web vulnerability scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Rate limiting<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Rate limiting can restrict the frequency at which requests are accepted according to configured conditions. This is useful for protecting expensive application operations from excessive request activity while still allowing legitimate clients to access the service. The administrator can establish thresholds based on expected application behavior and monitor the resulting events to determine whether tuning is necessary. TLS certificate management provides cryptographic credentials, server pools define backend resources, and vulnerability scanning identifies weaknesses. Rate limiting should be configured carefully for endpoints with legitimate burst behavior, such as APIs, login services, or search functions, so normal traffic is not incorrectly treated as abusive.<\/span><\/p>\n<p><b>Question 111. A company wants FortiWeb to inspect an application&#8217;s incoming requests and block attempts to manipulate operating-system commands through user-controlled parameters. Which protection should be enabled?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Command injection protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Session persistence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health checking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Command injection protection<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Command injection protection is designed to detect attempts to manipulate application input so that unintended operating-system commands may be executed. Attackers may place command syntax into URL parameters, form fields, headers, or other user-controlled data. FortiWeb can inspect application traffic and apply WAF security controls against such patterns. HTTP caching does not analyze command syntax, session persistence controls backend affinity, and health checking determines server availability. Administrators should review application behavior and security events when tuning this protection because legitimate applications may sometimes accept characters or strings that resemble command syntax. The objective is to maintain protection without unnecessarily blocking valid requests.<\/span><\/p>\n<p><b>Question 112. A FortiWeb administrator wants to ensure that only authenticated users can access a protected web application. Which security function should be investigated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP response caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web application authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health checking<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL rewriting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Web application authentication<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web application authentication allows FortiWeb to enforce authentication requirements for protected application resources, depending on the configured authentication architecture. This can prevent unauthenticated clients from reaching sensitive application content. Authentication requirements should be designed according to the application&#8217;s identity system and user workflow. HTTP caching controls response handling, health checks monitor backend availability, and URL rewriting changes request paths or destinations. Administrators should verify how authentication interacts with sessions, cookies, redirects, and protected URLs. Testing both successful and unsuccessful authentication flows is important to ensure that authorized users can access required resources while unauthenticated requests are handled according to the intended policy.<\/span><\/p>\n<p><b>Question 113. A FortiWeb deployment uses multiple backend servers. One server repeatedly fails health checks while the others remain healthy. What should the administrator expect if the server pool is configured to honor health-check results?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The failed server should be removed from eligible traffic distribution<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All healthy servers should automatically be disabled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The WAF should stop inspecting every request<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The FortiWeb management interface should become unavailable<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The failed server should be removed from eligible traffic distribution<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Health checks allow FortiWeb to determine whether backend servers are responding according to configured criteria. When a server fails the health check and the server pool is configured to use those results, FortiWeb can stop sending new traffic to that unhealthy member while continuing to use healthy members. This prevents repeated requests from being directed toward a backend that is not functioning correctly. The failure of one backend does not normally disable healthy servers or stop WAF inspection for the entire application. Administrators should investigate the failed server separately and review health-check logs, connectivity, service status, and configuration to determine why the server is failing.<\/span><\/p>\n<p><b>Question 114. An administrator needs to force users who access an insecure URL to use the secure equivalent without changing the backend application&#8217;s URL structure. Which feature should be considered?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server pool load balancing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL redirection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus scanning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. URL redirection<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">URL redirection can instruct a client to request a different URL, such as redirecting an HTTP address to its HTTPS equivalent. This allows FortiWeb to enforce secure access patterns without requiring the backend application to generate the initial redirect itself. The administrator should configure the redirect carefully so that the correct hostname, path, and protocol are preserved. Load balancing determines which backend server handles a request, antivirus scanning examines files, and API discovery provides visibility into API endpoints. When enforcing HTTPS, the administrator should also ensure that the destination HTTPS virtual server has a valid certificate and appropriate TLS configuration.<\/span><\/p>\n<p><b>Question 115. A security administrator wants FortiWeb to identify application programming interfaces that are being used but were not formally documented by the application team. Which feature is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health checks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cookie persistence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. API discovery<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">API discovery provides visibility into APIs that are exposed or observed in application traffic. This can help organizations identify undocumented endpoints, understand API usage, and improve their API security inventory. Once discovered, APIs can be reviewed and protected according to their expected behavior and security requirements. HTTP caching affects response delivery, server health checks monitor backend availability, and cookie persistence concerns session behavior. API discovery is particularly useful in environments where development teams have introduced services over time and security teams need an accurate picture of the application&#8217;s current API exposure. Administrators should validate discovered endpoints against business and application requirements before applying restrictive controls.<\/span><\/p>\n<p><b>Question 116. A FortiWeb administrator wants to prevent users from accessing a sensitive administrative path except from the organization&#8217;s management network. Which policy design is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow all source IPs and rely only on caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Combine URL-specific access control with an approved source IP restriction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable TLS on the administrative path<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove the application from the server pool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Combine URL-specific access control with an approved source IP restriction<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A sensitive administrative path can be protected by combining a URL-specific rule with source IP restrictions. The URL condition identifies the protected resource, while the IP restriction limits access to trusted management networks. This creates a more targeted control than applying a broad restriction to the entire application. Caching does not provide authorization, disabling TLS would reduce security, and removing a server from the pool does not control client access to a specific path. Administrators should verify the organization&#8217;s approved management ranges and account for legitimate remote administration requirements before enforcing the restriction. Logging denied requests can also help identify unexpected access attempts.<\/span><\/p>\n<p><b>Question 117. An organization wants FortiWeb to record security events and make them available to a central SIEM system. Which configuration should be reviewed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Centralized logging and log forwarding<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP method restriction only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server pool persistence only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL rewriting only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Centralized logging and log forwarding<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized logging and log forwarding allow FortiWeb events to be sent to an external logging or SIEM platform for centralized analysis. Security teams can use these events to correlate FortiWeb activity with information from firewalls, endpoints, servers, and other security systems. The administrator should verify the destination, transport settings, event categories, and severity levels being forwarded. HTTP method restrictions control request methods, server persistence affects backend selection, and URL rewriting modifies URL behavior. Centralized logging should be tested after configuration to confirm that the expected FortiWeb events are arriving at the SIEM and that timestamps and event details are available for investigation.<\/span><\/p>\n<p><b>Question 118. A web application receives file uploads from customers. The organization wants to reduce the risk of malicious files reaching the backend server. Which FortiWeb security capability should be considered?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP response caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus scanning for uploaded content<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geographic load balancing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL redirection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Antivirus scanning for uploaded content<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Antivirus scanning can inspect uploaded files for malicious content before the files are passed to backend application servers. This is particularly valuable for applications that accept documents or other user-supplied files. The administrator should configure appropriate inspection settings and consider file types, size limits, and legitimate business requirements. HTTP response caching does not provide malware inspection, geographic load balancing distributes traffic, and URL redirection changes the destination requested by the client. File scanning should complement, rather than replace, secure application design. Administrators should also ensure that uploaded files are handled safely by the backend application and are not automatically executed or served in an unsafe manner.<\/span><\/p>\n<p><b>Question 119. A FortiWeb administrator notices that a protected application is receiving traffic from a large number of automated clients. Some are legitimate monitoring systems, while others appear abusive. What should the administrator do when configuring bot mitigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Block every automated client without exception<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all WAF inspection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identify legitimate automation and tune bot controls to distinguish it from unwanted traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove all backend servers from the application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Identify legitimate automation and tune bot controls to distinguish it from unwanted traffic<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bot mitigation should account for legitimate automated clients as well as potentially abusive automation. Monitoring services, trusted integrations, API clients, and other business processes may legitimately generate automated requests. Blocking all automation could therefore disrupt valid functionality. The administrator should identify known legitimate clients and configure appropriate detection or exceptions while applying stronger controls to suspicious or abusive traffic. Disabling WAF protection or removing backend servers does not solve the automation problem and could create additional availability or security issues. Reviewing bot-related events and traffic patterns can help administrators refine the policy while preserving required business automation.<\/span><\/p>\n<p><b>Question 120. A FortiWeb administrator is troubleshooting an application that intermittently returns errors. Backend servers appear healthy, but some requests are rejected by FortiWeb. What should be examined to determine whether a security rule is causing the failures?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the client browser&#8217;s bookmarks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security events, matched rules, request details, and policy configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the physical power supply of the backend servers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the HTTP cache duration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Security events, matched rules, request details, and policy configuration<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When FortiWeb rejects some requests while backend servers remain healthy, security events and policy details should be examined to determine whether a WAF or other security control is responsible. Event records can identify the matched rule, request characteristics, and enforcement action. Comparing those details with the configured server policy and security profiles helps determine whether the behavior is intentional or represents a false positive. Backend power status and cache duration do not directly explain a FortiWeb security rejection. A structured investigation should preserve evidence, identify the triggering control, test representative requests, and make narrowly scoped policy adjustments only after confirming the cause.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE5_FWB_AD-8.0 Exam Dumps and Practice Test Dumps &nbsp; Question 101. A FortiWeb administrator needs to protect an application hosted by several backend servers. The administrator wants FortiWeb to distribute incoming requests across those servers according to a configured balancing method. Which FortiWeb component should be configured? Web vulnerability scanner Server pool URL [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21631"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21631"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21631\/revisions"}],"predecessor-version":[{"id":21632,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21631\/revisions\/21632"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21631"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21631"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21631"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}