{"id":21637,"date":"2026-09-25T06:39:53","date_gmt":"2026-09-25T06:39:53","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21637"},"modified":"2026-09-25T06:39:53","modified_gmt":"2026-09-25T06:39:53","slug":"fortinet-nse5_fwb_ad-8-0-practice-test-questions-and-exam-dumps-part-9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse5_fwb_ad-8-0-practice-test-questions-and-exam-dumps-part-9-q161-180\/","title":{"rendered":"Fortinet NSE5_FWB_AD-8.0 Practice Test Questions and Exam Dumps Part 9 Q161-180"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse5-fwb-ad-8-0-exam-dumps\"><b>Fortinet NSE5_FWB_AD-8.0 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 161. A FortiWeb administrator wants to ensure that requests are distributed among backend servers while unavailable servers are automatically excluded from new connections. Which configuration should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL access control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server pool with health checks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Server pool with health checks<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A server pool defines the backend servers that can receive application traffic, while health checks allow FortiWeb to determine whether those servers are available. When a member fails its configured health check, FortiWeb can exclude that server from eligible traffic distribution according to the pool and health-check behavior. URL access control governs application paths, HTTP caching manages reusable responses, and API discovery provides visibility into APIs. Administrators should select an appropriate health-check method that verifies the actual service rather than only network reachability. Pool membership, health-check intervals, timeout values, and expected responses should be reviewed when troubleshooting backend availability.<\/span><\/p>\n<p><b>Question 162. A web application contains a login form that could be targeted by automated credential attacks. The organization wants to detect and mitigate suspicious automated clients. Which FortiWeb capability is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP response caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bot management and mitigation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Backend certificate validation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL rewriting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Bot management and mitigation<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bot management and mitigation helps identify and control automated traffic interacting with a web application. Login pages are frequent targets for automated credential attacks, password spraying, and other abusive activity. FortiWeb can apply bot-related detection and enforcement mechanisms according to the configured policy. Administrators should distinguish legitimate automation, such as approved monitoring systems or integrations, from suspicious automated behavior before applying restrictive controls. HTTP caching does not identify bots, certificate validation handles TLS trust, and URL rewriting changes request paths. Bot mitigation can also be combined with rate limiting, authentication controls, and logging to provide broader protection for sensitive application endpoints.<\/span><\/p>\n<p><b>Question 163. A FortiWeb administrator wants to restrict access to an application based on the country associated with the client&#8217;s source IP address. Which feature should be configured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geographic IP access control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP method restriction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server persistence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Response caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Geographic IP access control<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Geographic IP access control allows FortiWeb to make access decisions based on the geographic location associated with source IP addresses. This can be useful when an organization has business or security requirements that restrict application access from particular countries or regions. Geographic filtering should be considered one security layer rather than a replacement for authentication and application-level controls because IP geolocation can have limitations. HTTP method restriction controls permitted methods, server persistence maintains backend affinity, and caching manages responses. Administrators should validate legitimate user locations and monitor the policy after deployment to identify unexpected blocking of authorized users or business partners.<\/span><\/p>\n<p><b>Question 164. A company wants FortiWeb to prevent clients from sending HTTP methods that are not required by an application. Which configuration provides this control?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health monitoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP method restriction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. HTTP method restriction<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HTTP method restriction allows an administrator to specify which HTTP methods are permitted for a protected application. Methods that are not required can be denied before they reach the backend server. This can reduce unnecessary application functionality exposed to clients and help limit certain attack opportunities. API discovery identifies APIs, health monitoring evaluates backend availability, and antivirus scanning focuses on malicious file content. Before configuring the restriction, administrators should document all methods used by the application and its APIs. After deployment, logs should be monitored to identify legitimate requests that may have been rejected because an application component depends on an unexpected HTTP method.<\/span><\/p>\n<p><b>Question 165. A security team suspects that an attacker is attempting to manipulate database queries by inserting SQL syntax into URL parameters. Which FortiWeb protection should be investigated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SQL injection protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Session persistence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health checks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. SQL injection protection<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL injection protection is designed to detect malicious input intended to alter database queries through application-controlled parameters. Attackers can place SQL syntax into URLs, forms, cookies, or other request components in an attempt to access, modify, or manipulate backend database operations. FortiWeb WAF inspection can analyze such requests and apply the configured enforcement action. HTTP caching, session persistence, and server health checks address application delivery or availability rather than database attack detection. Administrators should review security events and matched rules when legitimate requests are blocked because valid application input may occasionally resemble SQL syntax.<\/span><\/p>\n<p><b>Question 166. A FortiWeb deployment terminates client HTTPS connections and then establishes HTTPS connections to backend servers. The administrator wants to ensure that the backend certificate is trusted. What should be configured or verified?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP method restrictions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bot mitigation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL access control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Backend TLS trust and certificate configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Backend TLS trust and certificate configuration<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When FortiWeb establishes an HTTPS connection to a backend server, appropriate certificate and trust configuration is required if FortiWeb is expected to validate the backend certificate. The administrator should verify the certificate chain, trusted certificate authorities, hostname expectations, validity period, and relevant TLS settings. HTTP method restrictions control request methods, bot mitigation addresses automated traffic, and URL access control governs application paths. Correct backend TLS configuration provides encrypted communication while allowing FortiWeb to continue acting as a reverse proxy. Certificate problems should be investigated separately from WAF policy issues because TLS validation failures can prevent the backend connection before application-layer inspection occurs.<\/span><\/p>\n<p><b>Question 167. A web application allows users to submit comments that are later displayed to other users. Security staff are concerned about malicious scripts being inserted into these comments. Which attack should FortiWeb help detect?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cross-site scripting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SQL injection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Load-balancing failure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS misconfiguration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Cross-site scripting<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-site scripting occurs when malicious script content is injected into application data and later executed in a user&#8217;s browser. User-submitted comments are a common area of concern because stored malicious content may be displayed to other users. FortiWeb WAF protections can inspect incoming requests for patterns associated with XSS attacks and enforce the configured action. SQL injection targets database queries, while load-balancing failures and DNS problems concern application delivery rather than malicious script injection. Administrators should also ensure that the application uses secure output encoding and input validation because WAF protection should complement, not replace, secure application development practices.<\/span><\/p>\n<p><b>Question 168. A FortiWeb administrator wants to identify APIs that are being accessed by clients but are not present in the organization&#8217;s documented API inventory. Which capability should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health checking<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cookie security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. API discovery<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">API discovery provides visibility into APIs observed in application traffic and can help administrators identify endpoints that are not included in an existing inventory. This is valuable in environments where applications evolve over time and development teams may introduce new API endpoints without updating security documentation. HTTP caching manages responses, health checking monitors backend availability, and cookie security focuses on session-related protections. After discovering APIs, administrators should validate their business purpose, expected request patterns, authentication requirements, and security controls. Discovery improves visibility but should be followed by appropriate API protection and governance rather than automatically blocking every previously unknown endpoint.<\/span><\/p>\n<p><b>Question 169. A protected application receives unusually high numbers of requests from individual clients, causing increased resource consumption. The administrator wants to limit request frequency without completely blocking normal users. Which feature is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Certificate management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL rewriting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rate limiting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web vulnerability scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Rate limiting<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Rate limiting controls how frequently requests can be accepted under defined conditions. It is useful when an administrator wants to reduce excessive request activity while continuing to permit legitimate traffic. This can help protect resource-intensive endpoints from abusive clients or unexpected request bursts. Certificate management handles TLS credentials, URL rewriting changes request paths, and vulnerability scanning assesses application weaknesses. Rate limits should be based on observed normal traffic and application requirements. Administrators should monitor logs and security events after deployment to determine whether legitimate clients are being throttled and adjust thresholds appropriately when necessary.<\/span><\/p>\n<p><b>Question 170. A FortiWeb administrator needs to protect a sensitive administrative URL so that only requests from a trusted management subnet can access it. Which configuration is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server load balancing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL access control combined with source IP restrictions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. URL access control combined with source IP restrictions<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">URL access control can identify the sensitive administrative resource, while source IP restrictions can limit access to the trusted management subnet. Combining these controls creates a targeted restriction without necessarily blocking the rest of the application. HTTP caching and load balancing address application delivery, while API discovery provides API visibility. Administrators should verify the exact administrative URL pattern and approved source networks before enforcing the rule. Logging denied requests is also useful for identifying unauthorized access attempts. If remote administrators require access through VPN or another controlled path, those legitimate source networks should be accounted for in the policy.<\/span><\/p>\n<p><b>Question 171. A FortiWeb administrator notices that legitimate API requests are being blocked. The administrator wants to identify whether a WAF signature or another security control caused the block. What should be examined first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security event and matched-rule details<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Browser bookmarks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Backend disk fragmentation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS cache expiration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Security event and matched-rule details<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security event details provide the most direct evidence about why FortiWeb rejected a request. Depending on the configured logging, the event can identify the matched security rule, request characteristics, action, and other information needed for troubleshooting. Reviewing this information first allows the administrator to determine whether a WAF signature, access rule, method restriction, or another control caused the block. Browser bookmarks and backend disk conditions do not identify FortiWeb enforcement decisions. DNS information can be relevant to connectivity but does not normally explain why an already received request was blocked by a security policy.<\/span><\/p>\n<p><b>Question 172. A web application accepts documents uploaded by customers. The security team wants to inspect those files for malicious content before they reach the backend server. Which capability should be enabled?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Session persistence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antivirus scanning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geographic access control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL rewriting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Antivirus scanning<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Antivirus scanning can inspect uploaded files for known malicious content before the files are passed to the protected application, depending on the configured FortiWeb inspection capabilities and policy. This is particularly useful for applications that accept documents, images, archives, or other user-supplied files. Session persistence controls backend affinity, geographic access control restricts traffic by location, and URL rewriting changes request paths. Administrators should consider file-size limits, supported file types, inspection performance, and legitimate business requirements when configuring file inspection. Backend applications should also securely handle uploaded files because antivirus scanning alone cannot eliminate every risk associated with user-controlled content.<\/span><\/p>\n<p><b>Question 173. A company wants to maintain service if one FortiWeb appliance fails. Which FortiWeb capability should the administrator investigate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL rewriting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> High availability<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. High availability<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">High availability allows multiple FortiWeb appliances to participate in a resilient deployment so that service can continue when an appliance becomes unavailable, according to the configured HA design. Administrators should review synchronization, heartbeat interfaces, failover behavior, network topology, and configuration consistency when implementing HA. URL rewriting changes application URLs, HTTP caching manages responses, and API discovery provides visibility into APIs. HA should be tested in a controlled environment to confirm that failover works as expected and that protected applications remain reachable. Administrators should also understand which configuration elements synchronize between HA members and which operational conditions can trigger a failover.<\/span><\/p>\n<p><b>Question 174. A security team wants FortiWeb to identify requests attempting to execute operating-system commands through application parameters. Which WAF protection is designed for this threat?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Command injection protection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health checking<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Session persistence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Command injection protection<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Command injection protection addresses attempts to manipulate application input so that unintended operating-system commands can be executed. Attackers may place command syntax in URL parameters, form fields, headers, or other user-controlled data. FortiWeb can inspect these requests using WAF security controls and apply the configured action. HTTP caching does not inspect malicious command syntax, health checking evaluates backend availability, and session persistence controls backend affinity. Administrators should review security events when this protection blocks traffic because legitimate applications can sometimes process characters that resemble command syntax. Application-side input validation and secure coding practices should also be maintained.<\/span><\/p>\n<p><b>Question 175. A FortiWeb administrator wants to send security events to a centralized platform so that they can be correlated with firewall and endpoint events. Which configuration should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP method restriction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URL rewriting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Centralized log forwarding<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server pool persistence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Centralized log forwarding<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Centralized log forwarding allows FortiWeb security and operational events to be transmitted to an external logging or SIEM platform. Centralizing events makes it easier to correlate web application activity with events from firewalls, endpoints, servers, and other infrastructure. Administrators should configure the appropriate destination, transport, event categories, and severity levels. HTTP method restrictions govern request methods, URL rewriting changes request paths, and server persistence affects backend selection. After configuring forwarding, administrators should verify that expected events arrive at the central platform with useful timestamps and event details. Log retention and access controls should also be considered as part of the organization&#8217;s security monitoring design.<\/span><\/p>\n<p><b>Question 176. A web application requires only GET and POST requests. The administrator wants FortiWeb to reject requests using methods such as TRACE, DELETE, and CONNECT. Which setting should be configured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP method restriction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web vulnerability scanning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server health check<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. HTTP method restriction<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HTTP method restriction allows FortiWeb to specify the methods that an application is permitted to receive. In this scenario, GET and POST can be allowed while TRACE, DELETE, CONNECT, and other unnecessary methods are denied. This reduces the application&#8217;s exposed functionality and can help prevent unintended operations from reaching backend servers. API discovery identifies APIs, vulnerability scanning assesses application weaknesses, and health checks monitor backend availability. Administrators should confirm that all application components and APIs truly require only the approved methods before enforcing the rule. Security logs should be reviewed after deployment to identify legitimate traffic using an unexpected method.<\/span><\/p>\n<p><b>Question 177. A FortiWeb administrator wants to prevent oversized HTTP requests from reaching a backend application because the application accepts only small request bodies. Which control should be configured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Geographic access control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Session persistence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Request-size limitation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> API discovery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Request-size limitation<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Request-size limitations allow FortiWeb to reject HTTP requests whose bodies exceed a configured maximum. This can help prevent excessive resource consumption and reduce the application&#8217;s exposure to unusually large requests. The administrator should establish the limit according to the application&#8217;s documented requirements, especially if legitimate file uploads or API payloads are supported. Geographic access control limits traffic by location, session persistence manages backend affinity, and API discovery identifies APIs. After configuring the limit, administrators should test legitimate requests near the expected maximum size and monitor logs for rejected requests to ensure that the setting protects the application without unnecessarily disrupting valid functionality.<\/span><\/p>\n<p><b>Question 178. A FortiWeb administrator wants to identify why a particular request is being handled by an unexpected server policy. Which information should be examined?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Backend disk capacity only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Virtual server, Host header, destination, and policy-matching conditions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Browser cache only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP response compression only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Virtual server, Host header, destination, and policy-matching conditions<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">FortiWeb determines policy selection using request attributes and configured matching conditions. When traffic is handled by an unexpected policy, the administrator should compare the request&#8217;s destination, Host header, virtual server association, protocol, and other relevant attributes with the configured policies. This can reveal whether the request is matching a broader or different rule than intended. Backend disk capacity and browser cache do not normally determine FortiWeb policy selection. Traffic and security logs can provide additional evidence about which policy processed the request. Administrators should correct the specific matching condition rather than making unrelated configuration changes that could affect other protected applications.<\/span><\/p>\n<p><b>Question 179. A company wants to identify vulnerabilities in its web application before attackers exploit them. Which FortiWeb capability is specifically designed for security assessment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Session persistence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Server pool load balancing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> HTTP caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Web vulnerability scanning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Web vulnerability scanning<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web vulnerability scanning is intended to assess web applications for security weaknesses. It can help identify vulnerabilities in exposed resources and provide information that application and security teams can use for remediation. This differs from runtime WAF protection, which evaluates live requests and applies security policies as traffic is processed. Session persistence manages backend affinity, server pool load balancing distributes traffic, and HTTP caching improves response delivery. Administrators should perform scans according to organizational testing procedures and carefully review findings because scanner results may require validation. Discovered vulnerabilities should be addressed through appropriate application remediation and security controls.<\/span><\/p>\n<p><b>Question 180. A FortiWeb administrator observes intermittent application failures even though all backend servers appear reachable. Some requests are being rejected before reaching the servers. What should be reviewed to determine whether FortiWeb security controls are responsible?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only backend CPU utilization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only DNS records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security events, matched rules, request details, and server policy configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only browser cache settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Security events, matched rules, request details, and server policy configuration<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If requests are being rejected before reaching healthy backend servers, the administrator should investigate FortiWeb&#8217;s security events and policy processing. Event details can identify the matched rule, security mechanism, request characteristics, and enforcement action. Comparing this information with the server policy and configured security profiles helps determine whether the rejection is intentional or a false positive. Backend CPU utilization and DNS records may be relevant to other troubleshooting scenarios but do not normally explain a FortiWeb security rejection. A structured investigation should identify the exact triggering control before any policy adjustment is made, and changes should be narrowly scoped and tested afterward.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE5_FWB_AD-8.0 Exam Dumps and Practice Test Dumps &nbsp; Question 161. A FortiWeb administrator wants to ensure that requests are distributed among backend servers while unavailable servers are automatically excluded from new connections. Which configuration should be used? URL access control HTTP caching API discovery Server pool with health checks Correct Answer: 4. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21637"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21637"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21637\/revisions"}],"predecessor-version":[{"id":21638,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21637\/revisions\/21638"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21637"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21637"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21637"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}