
FCP_FWB_AD-7.4 PDF Dumps 2024 Exam Questions with Practice Test
Dumps for Free FCP_FWB_AD-7.4 Practice Exam Questions
NEW QUESTION # 25
When FortiWeb triggers a redirect action, which two HTTP codes does it send to the client to inform the browser of the new URL? (Choose two.)
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A,D
NEW QUESTION # 26
When configuring HTTP content routing, which factors should be considered for routing decisions?
(Select all that apply)
- A. Source IP address
- B. Destination port number
- C. User-agent header
- D. HTTP request method
Answer: C,D
NEW QUESTION # 27
In which operation mode must you direct all HTTP requests to the web server and not a virtual IP?
- A. True transparent proxy
- B. Reverse proxy
- C. Routed proxy
- D. Virtual proxy
Answer: A
NEW QUESTION # 28
Which of the following are common reasons for configuring HTTP redirection in application delivery?
(Select all that apply)
- A. Redirecting users to a different website
- B. Load balancing traffic
- C. Blocking specific IP addresses
- D. Enforcing HTTPS for secure communication
Answer: A,D
NEW QUESTION # 29
When configuring API protection, what security measure is commonly used to verify the identity of clients making API requests?
- A. HTTP referrer headers
- B. IP whitelisting
- C. OAuth 2.0 tokens
- D. Session cookies
Answer: C
NEW QUESTION # 30
What is a common technique to mitigate Cross-Site Scripting (XSS) attacks in web applications?
- A. Captcha verification for login forms
- B. Encryption of user passwords
- C. Input validation and escaping
- D. SSL/TLS encryption
Answer: C
NEW QUESTION # 31
Which of the following is a key component of web application security that helps protect against common threats like SQL injection and cross-site scripting (XSS)?
- A. Intrusion Detection System (IDS)
- B. CAPTCHA
- C. Content Delivery Network (CDN)
- D. Web Application Firewall (WAF)
Answer: D
NEW QUESTION # 32
Which of the following is a common attack vector that API protection aims to mitigate?
- A. Distributed Denial of Service (DDoS) attacks
- B. Unauthorized access to APIs
- C. SQL injection attacks
- D. Cross-site scripting (XSS) attacks
Answer: B
NEW QUESTION # 33
Which two FortiWeb operation modes support machine learning? (Choose two.)
- A. True transparent proxy
- B. Transparent proxy
- C. Offline protection
- D. Reverse proxy
Answer: A,D
NEW QUESTION # 34
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
- A. FortiGate local IP
- B. FortiGate public IP
- C. Client real IP
- D. FortiWeb IP
Answer: C
NEW QUESTION # 35
Part of the location service registration process is to link FortiAPs in FortiPresence.
Which two management services can configure the discovered AP registration information from the FortiPresence cloud? (Choose two.)
- A. AP Manager
- B. FortiAP Cloud
- C. FortiSwitch
- D. FortiGate
Answer: B,D
NEW QUESTION # 36
In which operation mode does FortiWeb offer both the ability to offload SSL as well as re-encrypt SSL?
- A. Offline protection
- B. Transparent inspection
- C. Reverse proxy
- D. True transparent proxy
Answer: C
NEW QUESTION # 37
When configuring a wireless network for dynamic VLAN allocation, which three IETF attributes must be supplied by the radius server? (Choose three.)
- A. 83 Tunnel-Preference
- B. 65 Tunnel-Medium-Type
- C. 64 Tunnel-Type
- D. 81 Tunnel-Private-Group-ID
- E. 58 Egress-VLAN-Name
Answer: B,C,D
NEW QUESTION # 38
How can you troubleshoot encryption-related issues in a web application? (Select all that apply)
- A. Testing SSL connections from different devices
- B. Checking SSL certificate expiration
- C. Disabling all encryption protocols
- D. Reviewing SSL/TLS handshake logs
Answer: A,B,D
NEW QUESTION # 39
When configuring machine learning for web application security, what is the primary role of machine learning algorithms?
- A. Authenticating user credentials
- B. Encrypting sensitive data during transmission
- C. Identifying patterns and anomalies in web traffic
- D. Filtering unwanted spam emails
Answer: C
NEW QUESTION # 40
Which is true about HTTPS on FortiWeb? (Choose three.)
- A. In transparent inspection mode, you select which certificate that FortiWeb will present in the server pool, not in the server policy.
- B. For SNI, you select the certificate that FortiWeb will present in the server pool, not in the server policy.
- C. After enabling HSTS, redirects to HTTPS are no longer necessary.
- D. In true transparent mode, the TLS session terminator is a protected web server.
- E. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to only offer TLS 1.2.
Answer: A,B,D
NEW QUESTION # 41
Which compliance standards often require encryption and secure authentication for web applications?
(Select all that apply)
- A. HIPAA (Health Insurance Portability and Accountability Act)
- B. PCI DSS (Payment Card Industry Data Security Standard)
- C. GDPR (General Data Protection Regulation)
- D. ISO 9001 (Quality Management System)
Answer: A,B,C
NEW QUESTION # 42
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- A. Store in an off-site location
- B. Erase them every two weeks
- C. Compress them into a .zip file format
- D. Enable masking of sensitive data
Answer: D
NEW QUESTION # 43
......
Check your preparation for Fortinet FCP_FWB_AD-7.4 On-Demand Exam: https://testking.prep4sureexam.com/FCP_FWB_AD-7.4-dumps-torrent.html