Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

NSE5_FWB_AD-8.0 Fortinet NSE 5 - FortiWeb 8.0 Administrator Questions and Answers

Questions 4

Your team is spending too much time digging through FortiWeb logs to investigate threats.

How can FortiAI improve this workflow?

Options:

A.

It disables logging to improve performance.

B.

It blocks malicious IP addresses automatically.

C.

It replaces the need for FortiGuard updates.

D.

It explains recent events using natural language.

Buy Now
Questions 5

A FortiWeb administrator wants to stop coordinated scraping traffic coming from several IP addresses, each making only a few requests so thresholds never trigger.

Which tactic should the administrator deploy to identify botnets using shared behavioral signals instead of volume?

Options:

A.

A DoS protection profile with extremely low request limits for the entire site.

B.

A static blocklist for all IP addresses seen in logs, even if most appear only once.

C.

Bot mitigation with device fingerprinting to correlate clients by behavior, headers, and JavaScript challenges instead of IP address volume.

D.

A web application firewall (WAF) rule that blocks every user agent that is not on a manually created allowlist.

Buy Now
Questions 6

You have configured parameter validation, file security, and machine learning (ML) anomaly detection for a web form, but some server-side request forgery tests are still succeeding. You need to advise the team on what to prioritize next to improve SSRF protection without compromising other parts of the application.

Which recommendation would best strengthen FortiWeb’s ability to block remaining SSRF attempts?

Options:

A.

Disable ML anomaly detection and rely solely on parameter inspection.

B.

Review and refine input validation logic, as SSRF may be exploiting backend behavior or bypassing weak filters.

C.

Offload all server-side request forgery (SSRF) protection to FortiGate and remove FortiWeb from the API flow.

D.

Apply HTTPS inspection at the transport layer, which FortiWeb does not use to block SSRF.

Buy Now
Questions 7

Refer to the exhibits.

You are configuring a FortiWeb device in reverse proxy mode, placed downstream from a FortiGate. The server pool includes two back-end web servers: 10.1.1.21 and 10.1.1.22, and you’ve defined a health check policy.

After completing the server policy configuration and applying it to a virtual server, you notice that FortiWeb is not forwarding traffic to the back-end servers. No errors or health check failures appear in the logs.

Based on the configuration shown in the exhibit, which change should you make to restore back-end traffic flow?

Options:

A.

Select the correct server pool in the FortiWeb server policy.

B.

Enable Client Real IP to ensure traffic goes to the back-end servers.

C.

Change the virtual server IP address to match one of the back-end servers.

D.

Configure FortiGate to forward traffic to the back-end IP addresses directly.

Buy Now
Questions 8

You are setting up a FortiWeb policy to protect a customer login portal. Users connect to https://login.training.lab, and you want FortiWeb to forward those requests to a load-balanced pool of back-end servers.

Which three components must you configure to complete the server policy?

Options:

A.

Virtual server, server pool, and port settings (service).

B.

Web application firewall (WAF) profile, DoS policy, and server name indication (SNI)-based certificate.

C.

DNS resolver, URL rewrite rule, and HTTP health check.

D.

Real server, IPsec tunnel, and static route.

Buy Now
Questions 9

FortiWeb is blocking groups of users behind your load balancer. In the logs, all users show the same source IP address.

Which action should you take to restore proper client identification?

Options:

A.

Add a bot detection rule in the protection profile.

B.

Update the signature engine.

C.

Reconfigure the load balancer to insert the original client IP address in an HTTP header.

D.

Enable caching for HTTPS traffic.

Buy Now
Questions 10

A third-party penetration test reveals that users can bypass login controls through a mobile API. Your current FortiWeb configuration includes zero trust network access (ZTNA) profiles and cookie security, but API protection and client management are not enabled. The security team asks you to recommend the most effective way to close this gap.

Which FortiWeb adjustment would best prevent future unauthorized API access?

Options:

A.

Switch to a reverse-proxy mode to bypass cookie-based controls.

B.

Enable API protection and client management to enforce identity checks on mobile API traffic.

C.

Replace ZTNA with bot protection to reduce false positives.

D.

Log only API traffic and rely on FortiAnalyzer for future alerts.

Buy Now
Exam Code: NSE5_FWB_AD-8.0
Exam Name: Fortinet NSE 5 - FortiWeb 8.0 Administrator
Last Update: Jul 24, 2026
Questions: 0
NSE5_FWB_AD-8.0 pdf

NSE5_FWB_AD-8.0 PDF

$25.5  $84.99
NSE5_FWB_AD-8.0 Engine

NSE5_FWB_AD-8.0 Testing Engine

$30  $99.99
NSE5_FWB_AD-8.0 PDF + Engine

NSE5_FWB_AD-8.0 PDF + Testing Engine

$255  $850