Pre-Winter Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Fortinet NSE 5 Network Security Analyst NSE5_FWB_AD-8.0 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam NSE5_FWB_AD-8.0 Premium Access

View all detail and faqs for the NSE5_FWB_AD-8.0 exam


0 Students Passed

0% Average Score

0% Same Questions
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibits.

Question # 11

Question # 11

You are configuring a FortiWeb device in reverse proxy mode, placed downstream from a FortiGate. The server pool includes two back-end web servers: 10.1.1.21 and 10.1.1.22, and you’ve defined a health check policy.

After completing the server policy configuration and applying it to a virtual server, you notice that FortiWeb is not forwarding traffic to the back-end servers. No errors or health check failures appear in the logs.

Based on the configuration shown in the exhibit, which change should you make to restore back-end traffic flow?

Options:

A.

Select the correct server pool in the FortiWeb server policy.

B.

Enable Client Real IP to ensure traffic goes to the back-end servers.

C.

Change the virtual server IP address to match one of the back-end servers.

D.

Configure FortiGate to forward traffic to the back-end IP addresses directly.

Questions # 12:

You recently deployed two FortiWeb devices in an active-active (A-A) high availability (HA) cluster.

During routine maintenance, you want to confirm that the cluster is synchronizing the correct configuration areas and that both FortiWeb devices behave consistently in production.

As the FortiWeb administrator, which two configuration areas should you examine to verify that HA synchronization is functioning correctly? (Choose two.)

Options:

A.

Check the network configuration on both FortiWeb devices—such as interfaces and static routes—to ensure they are aligned.

B.

Review policy configurations, including server policies and protection profiles, to confirm they match across the cluster.

C.

Review inspection and mitigation log files to determine if they are being replicated across both FortiWeb devices.

D.

Verify whether firmware images and upgrade history are synchronized between the FortiWeb devices.

Questions # 13:

While reviewing FortiWeb logs, you notice a suspicious login request that failed authentication. You suspect it may be part of an injection attack targeting the login form.

Which input pattern is an example of a typical SQL injection attempt that could bypass authentication checks?

Options:

A.

'||(SELECT password FROM users WHERE role='admin')||'

B.

< sql > select(ALL USERS); < /sql >

C.

< script > document.location='/steal?cookie='+document.cookie < /script >

D.

SELECT username FROM accounts WHERE username='admin';-- ' AND password='password';

Questions # 14:

A FortiWeb administrator wants to create a machine learning (ML)-based bot detection system.

Which three actions must the administrator take to build and activate this ML model? (Choose three.)

Options:

A.

Collect traffic samples for training.

B.

Verify the model manually on test data only.

C.

Apply Bayesian analysis to the model output.

D.

Build the detection model using collected data.

E.

Run the model in the live environment.

Questions # 15:

You are reviewing a report from your FortiWeb logs and notice a JavaScript payload like < script > document.cookie < /script > is submitted through a product review form. The page doesn’t filter the script, and when users view the review, their session cookies are exposed.

Why is this attack dangerous?

Options:

A.

It executes code in the victim’s browser.

B.

It leaks back-end database information.

C.

It bypasses login pages.

D.

It forces a victim to click malicious links.

Questions # 16:

Your team is spending too much time digging through FortiWeb logs to investigate threats.

How can FortiAI improve this workflow?

Options:

A.

It disables logging to improve performance.

B.

It blocks malicious IP addresses automatically.

C.

It replaces the need for FortiGuard updates.

D.

It explains recent events using natural language.

Questions # 17:

A FortiWeb administrator wants to stop coordinated scraping traffic coming from several IP addresses, each making only a few requests so thresholds never trigger.

Which tactic should the administrator deploy to identify botnets using shared behavioral signals instead of volume?

Options:

A.

A DoS protection profile with extremely low request limits for the entire site.

B.

A static blocklist for all IP addresses seen in logs, even if most appear only once.

C.

Bot mitigation with device fingerprinting to correlate clients by behavior, headers, and JavaScript challenges instead of IP address volume.

D.

A web application firewall (WAF) rule that blocks every user agent that is not on a manually created allowlist.

Questions # 18:

You have configured parameter validation, file security, and machine learning (ML) anomaly detection for a web form, but some server-side request forgery tests are still succeeding. You need to advise the team on what to prioritize next to improve SSRF protection without compromising other parts of the application.

Which recommendation would best strengthen FortiWeb’s ability to block remaining SSRF attempts?

Options:

A.

Disable ML anomaly detection and rely solely on parameter inspection.

B.

Review and refine input validation logic, as SSRF may be exploiting backend behavior or bypassing weak filters.

C.

Offload all server-side request forgery (SSRF) protection to FortiGate and remove FortiWeb from the API flow.

D.

Apply HTTPS inspection at the transport layer, which FortiWeb does not use to block SSRF.

Questions # 19:

Refer to the exhibit.

Question # 19

Question # 19

A FortiWeb administrator is trying to enable policy-based traffic logging on FortiWeb but doesn’t see the traffic log option available in the server policy settings.

What is the most likely reason this option is not visible?

Options:

A.

The FortiWeb administrator must first connect to FortiSIEM or FortiAnalyzer, and then enable policy logs from those devices.

B.

Server policy logging only becomes available when FortiWeb is deployed in reverse-proxy mode and transparent mode.

C.

The global traffic log setting must be enabled manually in the CLI for the option to appear.

D.

The FortiWeb administrator must get a license to use this feature with FortiAppSec Cloud.

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.