Pre-Winter Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

NSE5_FWB_AD-8.0 Fortinet NSE 5 - FortiWeb 8.0 Administrator Questions and Answers

Questions 4

FortiWeb is blocking groups of users behind your load balancer. In the logs, all users show the same source IP address.

Which action should you take to restore proper client identification?

Options:

A.

Add a bot detection rule in the protection profile.

B.

Update the signature engine.

C.

Reconfigure the load balancer to insert the original client IP address in an HTTP header.

D.

Enable caching for HTTPS traffic.

Buy Now
Questions 5

You need to monitor and respond to repeated suspicious activity from individual users who are accessing your web application.

Your goal is to evaluate each action the user takes and apply a response when their behavior becomes risky.

What can you configure on FortiWeb to track user behavior and respond automatically when risky activity continues?

Options:

A.

Configure rate limiting on the IP reputation blocklist.

B.

Add a custom signature to block suspicious URLs immediately.

C.

Enable automatic cookie security under the server policy.

D.

Set up scoring in the protection profile to track request behavior over time.

Buy Now
Questions 6

You recently deployed two FortiWeb devices in an active-active (A-A) high availability (HA) cluster.

During routine maintenance, you want to confirm that the cluster is synchronizing the correct configuration areas and that both FortiWeb devices behave consistently in production.

As the FortiWeb administrator, which two configuration areas should you examine to verify that HA synchronization is functioning correctly? (Choose two.)

Options:

A.

Check the network configuration on both FortiWeb devices—such as interfaces and static routes—to ensure they are aligned.

B.

Review policy configurations, including server policies and protection profiles, to confirm they match across the cluster.

C.

Review inspection and mitigation log files to determine if they are being replicated across both FortiWeb devices.

D.

Verify whether firmware images and upgrade history are synchronized between the FortiWeb devices.

Buy Now
Questions 7

A FortiWeb administrator sees the following request:

GET /api/v1/data HTTP/1.1

Host: example.com

Authorization: ApiKey abc123def456

The API key belongs to a user in group B who is authorized to access only /api/v1/reports.

What should the administrator do to prevent this unauthorized access?

Options:

A.

Restrict access to /api/v1/data using user group–based access control.

B.

Block /api/v1/data for all user groups to avoid policy confusion.

C.

Move the user to group A so they can access both endpoints.

D.

Allow all valid API keys to access any API endpoint.

Buy Now
Questions 8

Refer to the exhibit.

A FortiWeb administrator tests a new form input value after training the machine learning (ML) anomaly detection system.

The hidden Markov model (HMM) flags the input as abnormal, while the support vector machine (SVM) model classifies it as normal. FortiWeb allows the request.

What does this result indicate about the FortiWeb ML anomaly detection behavior?

Options:

A.

The anomaly detection thresholds are too low and must be increased.

B.

One of the ML models should be disabled to avoid inconsistent results.

C.

FortiWeb is correctly allowing an unusual but non-malicious input based on combined HMM and SVM evaluation.

D.

FortiWeb failed to detect an attack and should have blocked the request.

Buy Now
Questions 9

You have configured parameter validation, file security, and machine learning (ML) anomaly detection for a web form, but some server-side request forgery tests are still succeeding. You need to advise the team on what to prioritize next to improve SSRF protection without compromising other parts of the application.

Which recommendation would best strengthen FortiWeb’s ability to block remaining SSRF attempts?

Options:

A.

Disable ML anomaly detection and rely solely on parameter inspection.

B.

Review and refine input validation logic, as SSRF may be exploiting backend behavior or bypassing weak filters.

C.

Offload all server-side request forgery (SSRF) protection to FortiGate and remove FortiWeb from the API flow.

D.

Apply HTTPS inspection at the transport layer, which FortiWeb does not use to block SSRF.

Buy Now
Questions 10

Refer to the exhibit.

You are configuring SSL offloading on FortiWeb to protect a public-facing application. Clients connect using HTTPS, while FortiWeb forwards requests to the back-end server using HTTP.

You are reviewing certificate deployment and need to decide where to install the private key for the certificate used in client connections.

In this SSL offloading setup, which device is responsible for using the private key associated with the web server certificate?

Options:

A.

FortiWeb, because it terminates the HTTPS session and decrypts traffic.

B.

None. SSL offloading does not require a private key because FortiWeb only forwards traffic.

C.

The server, because it always handles certificates regardless of SSL mode.

D.

The client, because it initiates the TLS handshake and verifies the certificate.

Buy Now
Exam Code: NSE5_FWB_AD-8.0
Exam Name: Fortinet NSE 5 - FortiWeb 8.0 Administrator
Last Update: Sep 17, 2026
Questions: 36
NSE5_FWB_AD-8.0 pdf

NSE5_FWB_AD-8.0 PDF

$25.5  $84.99
NSE5_FWB_AD-8.0 Engine

NSE5_FWB_AD-8.0 Testing Engine

$30  $99.99
NSE5_FWB_AD-8.0 PDF + Engine

NSE5_FWB_AD-8.0 PDF + Testing Engine

$40.5  $134.99