NSE 6 Network Security Specialist NSE6_FWB-6.1 Real Exam Questions and Answers FREE Updated on Sep 18, 2021
NSE6_FWB-6.1 Ultimate Study Guide - Test4Engine
NEW QUESTION 14
Review the following configuration:
What is the expected result of this configuration setting?
- A. When machine learning (ML) is in its collecting phase, FortiWeb will not accept any samples from any source IP addresses.
- B. When machine learning (ML) is in its running phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- C. When machine learning (ML) is in its collecting phase, FortiWeb will accept an unlimited number of samples from the same source IP address.
- D. When machine learning (ML) is in its running phase, FortiWeb will accept a set number of samples from the same source IP address.
Answer: C
NEW QUESTION 15
True transparent proxy mode is best suited for use in which type of environment?
- A. Flexible environments where you can easily change the IP addressing scheme
- B. New networks where infrastructure is not yet defined
- C. Environments where you cannot change the IP addressing scheme
- D. Small office to home office environments
Answer: C
Explanation:
Does not require changes to the IP address scheme of the network. Requests are destined for a web server and not the FortiWeb appliance. This operation mode supports the same feature set as True Transparent Proxy mode.
NEW QUESTION 16
In which scenario might you want to use the compression feature on FortiWeb?
- A. When you are serving many corporate road warriors using 4G tablets and phones
- B. Never, since most traffic today is already highly compressed
- C. When you want to reduce buffering of video streams
- D. When you are offering a music streaming service
Answer: B
Explanation:
FortiWeb might expend resources compressing responses that have already been compressed by the server.
NEW QUESTION 17
A client is trying to start a session from a page that would normally be accessible only after the client has logged in.
When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
- A. Allow the page access, but log the violation
- B. Display an access policy message, then allow the client to continue
- C. Reply with a 403 Forbidden HTTP error
- D. Redirect the client to the login page
- E. Prompt the client to authenticate
Answer: A,C,D
NEW QUESTION 18
Which three statements about HTTPS on FortiWeb are true? (Choose three.)
- A. In true transparent mode, the TLS session terminator is a protected web server.
- B. In transparent inspection mode, you select the certificate that FortiWeb presents in the server pool, not in the server policy.
- C. For SNI, you select the certificate that FortiWeb presents in the server pool, not in the server policy.
- D. After enabling HSTS, redirects to HTTPS are never needed.
- E. Enabling RC4 protects against the BEAST attack, but is not recommended if you configure FortiWeb to offer only TLS 1.2.
Answer: A,B,C
NEW QUESTION 19
You are using HTTP content routing on FortiWeb. You want requests for web application A to be forwarded to a cluster of web servers, which all host the same web application. You want requests for web application B to be forwarded to a different, single web server.
Which statement about this solution is true?
- A. The server policy applies the same protection profile to all of its protected web applications.
- B. Static or policy-based routes are not required.
- C. You must put the single web server in to a server pool, in order to use it with HTTP content routing.
- D. You must chain policies so that requests for web application A go to the virtual server for policy A, and requests for web application B go to the virtual server for policy B.
Answer: B
NEW QUESTION 20
In which two operating modes can FortiWeb modify HTTP packets? (Choose two.)
- A. True transparent proxy
- B. Transparent inspection
- C. Offline protection
- D. Reverse proxy
Answer: A,C
Explanation:
FortiWeb appliances operating in offline protection mode or either of the transparent modes
NEW QUESTION 21
When viewing the attack logs on FortiWeb, which client IP address is shown when you are using XFF header rules?
- A. FortiGate public IP
- B. Client real IP
- C. FortiWeb IP
- D. FortiGate local IP
Answer: B
Explanation:
When an XFF header reaches Alteon from a client, Alteon removes all the content from the header and injects the client IP address. Alteon then forwards the header to the server.
NEW QUESTION 22
What can an administrator do if a client has been incorrectly period blocked?
- A. Nothing, it is not possible to override a period block.
- B. Manually release the ID address from the temporary blacklist.
- C. Force a new IP address to the client.
- D. Disconnect the client from the network.
Answer: B
Explanation:
Block Period
Enter the number of seconds that you want to block the requests. The valid range is 1-3,600 seconds. The default value is 60 seconds.
This option only takes effect when you choose Period Block in Action.
Note: That's a temporary blacklist so you can manually release them from the blacklist.
NEW QUESTION 23
Which regex expression is the correct format for redirecting the URL http://www.example.com?
- A. www\.example\.com
- B. www.example.com
- C. www/.example/.com
- D. www\example\com
Answer: B
Explanation:
\1://www.company.com/\2/\3
NEW QUESTION 24
What must you do with your FortiWeb logs to ensure PCI DSS compliance?
- A. Compress them into a .zip file format
- B. Erase them every two weeks
- C. Store in an off-site location
- D. Enable masking of sensitive data
Answer: D
NEW QUESTION 25
Which would be a reason to implement HTTP rewriting?
- A. The original page has moved to a new IP address
- B. To replace a vulnerable function in the requested URL
- C. The original page has moved to a new URL
- D. To send the request to secure channel
Answer: C
Explanation:
Create a new URL rewriting rule.
NEW QUESTION 26
......
Ultimate Guide to Prepare NSE6_FWB-6.1 Certification Exam for NSE 6 Network Security Specialist: https://www.test4engine.com/NSE6_FWB-6.1_exam-latest-braindumps.html