Fortinet NSE5_FWB_AD-8.0 - Fortinet NSE 5 - FortiWeb 8.0 Administrator Exam

Question #11 (Topic: Exam A)
You have configured parameter validation, file security, and machine learning (ML) anomaly detection for a web form, but some server-side request forgery tests are still succeeding. You need to advise the team on what to prioritize next to improve SSRF protection without compromising other parts of the application.
Which recommendation would best strengthen FortiWeb's ability to block remaining SSRF attempts?
A. Disable ML anomaly detection and rely solely on parameter inspection. B. Apply HTTPS inspection at the transport layer, which FortiWeb does not use to block SSRF. C. Offload all server-side request forgery (SSRF) protection to FortiGate and remove FortiWeb from the API flow. D. Review and refine input validation logic, as SSRF may be exploiting backend behavior or bypassing weak filters.
Answer: D
Question #12 (Topic: Exam A)
While reviewing FortiWeb logs, you notice a suspicious login request that failed authentication. You suspect it may be part of an injection attack targeting the login form.
Which input pattern is an example of a typical SQL injection attempt that could bypass authentication checks?
A. <script>document.location='/steal?cookie='+document.cookie</script> B. SELECT username FROM accounts WHERE username='admin';-- ' AND password='password'; C. '||(SELECT password FROM users WHERE role='admin')||' D. <sql>select(ALL USERS);</sql>
Answer: B
Question #13 (Topic: Exam A)
Refer to the exhibit.

You have deployed FortiWeb behind a FortiGate that is configured as a reverse proxy and inserts the X-Forwarded-For HTTP header when forwarding HTTP and HTTPS traffic.
FortiWeb is using a custom inline protection profile, and logging is enabled, as shown in the exhibit.
You notice that FortiWeb is blocking legitimate users, and all requests in the attack logs appear to come from the FortiGate IP address, not the original client IP addresses.
Which action should you take to fix this issue?
A. Modify the protection profile to use the X-Forwarded-For header for client IP address detection. B. Replace the current deployment mode with a one-arm proxy to expose source IP addresses. C. Recreate the server policy using the predefined profile instead of a custom one. D. Disable IP-based detection features on FortiWeb to avoid IP-related blocking.
Answer: A
Question #14 (Topic: Exam A)
Refer to the exhibit.

There is only one administrator account configured on FortiWeb and IPv6 is not configured on any interface.
Which action should an administrator take to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?
A. Replace 0.0.0.0/0 with a specific IP address. B. Make configuration changes on the upstream device. C. Change the setting in the Access Profile field to Read_Only. D. Delete the built-in administrator user and create a new one.
Answer: A
Question #15 (Topic: Exam A)
A FortiWeb administrator needs to protect new API endpoints that a development team is publishing.
To secure these API endpoints, which three configuration actions should the administrator perform on FortiWeb? (Choose three.)
A. Configure Active Directory (AD) single sign-on (SSO) for the web portal. B. Apply API schema validation to incoming requests. C. Enable machine learning (ML)-based API protection. D. Enforce API user key requirements in the API policy. E. Activate SAML authentication for general user access.
Answer: BCD
Download Exam
Page: 3 / 10
Total 50 questions