Summer Certification Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

NSE6_FWB-6.4 Fortinet NSE 6 - FortiWeb 6.4 Questions and Answers

Questions 4

You are deploying FortiWeb 6.4 in an Amazon Web Services cloud. Which 2 lines of this initial setup via CLI are incorrect? (Choose two.)

NSE6_FWB-6.4 Question 4

Options:

A.

6

B.

9

C.

3

D.

2

Buy Now
Questions 5

Refer to the exhibits.

NSE6_FWB-6.4 Question 5

NSE6_FWB-6.4 Question 5

FortiWeb is configured in reverse proxy mode and it is deployed downstream to FortiGate. Based on the configuration shown in the exhibits, which of the following statements is true?

Options:

A.

FortiGate should forward web traffic to the server pool IP addresses.

B.

The configuration is incorrect. FortiWeb should always be located upstream to FortiGate.

C.

You must disable the Preserve Client IP setting on FotriGate for this configuration to work.

D.

FortiGate should forward web traffic to virtual server IP address.

Buy Now
Questions 6

Which implementation is best suited for a deployment that must meet compliance criteria?

Options:

A.

SSL Inspection with FortiWeb in Transparency mode

B.

SSL Offloading with FortiWeb in reverse proxy mode

C.

SSL Inspection with FrotiWeb in Reverse Proxy mode

D.

SSL Offloading with FortiWeb in Transparency Mode

Buy Now
Questions 7

You are using HTTP content routing on FortiWeb. Requests for web app A should be forwarded to a cluster of web servers which all host the same web app. Requests for web app B should be forwarded to a different, single web server.

Which is true about the solution?

Options:

A.

Static or policy-based routes are not required.

B.

To achieve HTTP content routing, you must chain policies: the first policy accepts all traffic, and forwards requests for web app A to the virtual server for policy A. It also forwards requests for web app B to the virtual server for policy B. Policy A and Policy B apply their app-specific protection profiles, and then distribute that app’s traffic among all members of the server farm.

C.

You must put the single web server into a server pool in order to use it with HTTP content routing.

D.

The server policy applies the same protection profile to all its protected web apps.

Buy Now
Questions 8

Which three statements about HTTPS on FortiWeb are true? (Choose three.)

Options:

A.

For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.

B.

After enabling HSTS, redirects to HTTPS are no longer necessary.

C.

In true transparent mode, the TLS session terminator is a protected web server.

D.

Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.

E.

In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.

Buy Now
Questions 9

In which scenario might you want to use the compression feature on FortiWeb?

Options:

A.

When you are serving many corporate road warriors using 4G tablets and phones

B.

When you are offering a music streaming service

C.

When you want to reduce buffering of video streams

D.

Never, since most traffic today is already highly compressed

Buy Now
Questions 10

Which of the following is true about Local User Accounts?

Options:

A.

Must be assigned regardless of any other authentication

B.

Can be used for Single Sign On

C.

Can be used for site publishing

D.

Best suited for large environments with many users

Buy Now
Questions 11

The FortiWeb machine learning (ML) feature is a two-phase analysis mechanism.

Which two functions does the first layer perform? (Choose two.)

Options:

A.

Determines whether an anomaly is a real attack or just a benign anomaly that should be ignored

B.

Builds a threat model behind every parameter and HTTP method

C.

Determines if a detected threat is a false-positive or not

D.

Determines whether traffic is an anomaly, based on observed application traffic over time

Buy Now
Questions 12

A client is trying to start a session from a page that should normally be accessible only after they have logged in.

When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)

Options:

A.

Reply with a “403 Forbidden” HTTP error

B.

Allow the page access, but log the violation

C.

Automatically redirect the client to the login page

D.

Display an access policy message, then allow the client to continue, redirecting them to their requested page

E.

Prompt the client to authenticate

Buy Now
Questions 13

Refer to the exhibit.

NSE6_FWB-6.4 Question 13

FortiWeb is configured to block traffic from Japan to your web application server. However, in the logs, the administrator is seeing traffic allowed from one particular IP address which is geo-located in Japan.

What can the administrator do to solve this problem? (Choose two.)

Options:

A.

Manually update the geo-location IP addresses for Japan.

B.

If the IP address is configured as a geo reputation exception, remove it.

C.

Configure the IP address as a blacklisted IP address.

D.

If the IP address is configured as an IP reputation exception, remove it.

Buy Now
Questions 14

When generating a protection configuration from an auto learning report what critical step must you do before generating the final protection configuration?

Options:

A.

Restart the FortiWeb to clear the caches

B.

Drill down in the report to correct any false positives.

C.

Activate the report to create t profile

D.

Take the FortiWeb offline to apply the profile

Buy Now
Questions 15

Which two statements about the anti-defacement feature on FortiWeb are true? (Choose two.)

Options:

A.

Anti-defacement can redirect users to a backup web server, if it detects a change.

B.

Anti-defacement downloads a copy of your website to RAM, in order to restore a clean image, if it detects defacement.

C.

FortiWeb will only check to see if there are changes on the web server; it will not download the whole file each time.

D.

Anti-defacement does not make a backup copy of your databases.

Buy Now
Questions 16

How does your FortiWeb configuration differ if the FortiWeb is upstream of the SNAT device instead of downstream of the SNAT device?

Options:

A.

You must enable the “Use” X-Forwarded-For: option.

B.

FortiWeb must be set for Transparent Mode

C.

No special configuration required

D.

You must enable “Add” X-Forwarded-For: instead of the “Use” X-Forwarded-For: option.

Buy Now
Exam Code: NSE6_FWB-6.4
Exam Name: Fortinet NSE 6 - FortiWeb 6.4
Last Update: Jun 8, 2026
Questions: 56

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11