Fortinet NSE 5 - FortiWeb 8.0 Administrator - NSE5_FWB_AD-8.0 Exam Practice Test

Which statement best describes the purpose of FortiWeb's "combination access control" rules?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
You have configured parameter validation, file security, and machine learning (ML) anomaly detection for a web form, but some server-side request forgery tests are still succeeding. You need to advise the team on what to prioritize next to improve SSRF protection without compromising other parts of the application. Which recommendation would best strengthen FortiWeb's ability to block remaining SSRF attempts?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which action must a FortiWeb administrator take to enable FortiAppSec Cloud Advanced Bot Protection (ABP) service in a cloud deployment?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A customer wants FortiWeb to prevent sensitive data such as credit card numbers from leaving the network in HTTP responses. Which feature addresses this requirement?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
You are reviewing a report from your FortiWeb logs and notice a JavaScript payload like
<script>document.cookie</script> submitted through a product review form. The page doesn't filter the script, and users who view the review have their session cookies exposed. Which type of attack does this scenario represent?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which feature allows FortiWeb to inspect and enforce policy on API traffic that uses JSON or XML payloads, including schema validation?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which certificate deployment method allows FortiWeb to present different SSL certificates depending on the hostname requested by the client during the TLS handshake?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
0
0
0
0