
Fortinet NSE 5 - FortiWeb 8.0 Administrator - NSE5_FWB_AD-8.0 Exam Questions
QUESTION NO: 1
Your e-commerce platform is experiencing frequent SQL injection attempts. You need FortiWeb to actively inspect, enforce, and block attacks inline before traffic reaches the web servers.
The deployment must support the full FortiWeb security feature set without operational limitations, including protocol validation, attack detection, and policy enforcement.
Which FortiWeb operation mode should you configure to proactively intercept and block threats such as SQL injection attempts?
Your e-commerce platform is experiencing frequent SQL injection attempts. You need FortiWeb to actively inspect, enforce, and block attacks inline before traffic reaches the web servers.
The deployment must support the full FortiWeb security feature set without operational limitations, including protocol validation, attack detection, and policy enforcement.
Which FortiWeb operation mode should you configure to proactively intercept and block threats such as SQL injection attempts?
Correct Answer: A
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 2
An administrator is troubleshooting why FortiWeb is not decrypting HTTPS traffic for inspection in reverse proxy mode. What is the most likely missing configuration?
An administrator is troubleshooting why FortiWeb is not decrypting HTTPS traffic for inspection in reverse proxy mode. What is the most likely missing configuration?
Correct Answer: A
QUESTION NO: 3
Which statement about FortiWeb's "Auto Learning" (or "Auto-learn") profile is correct?
Which statement about FortiWeb's "Auto Learning" (or "Auto-learn") profile is correct?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 4
You are setting up a FortiWeb policy to protect a customer login portal. Users connect to
https://login.training.lab, and you want FortiWeb to forward those requests to a load-balanced pool of back-end servers. Which three components must you configure to complete the server policy?
You are setting up a FortiWeb policy to protect a customer login portal. Users connect to
https://login.training.lab, and you want FortiWeb to forward those requests to a load-balanced pool of back-end servers. Which three components must you configure to complete the server policy?
Correct Answer: B
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 5
Drag and Drop Question
A FortiWeb administrator is reviewing protection effectiveness after a surge in malicious traffic exposed design flaws and misconfigurations in several web applications.
For each Open Web Application Security Project (OWASP) risk listed, choose the FortiWeb feature that offers the most strategic protection, considering both coverage depth and operational effectiveness.
Match the most appropriate FortiWeb feature to each OWASP issue.
Select each FortiWeb feature in the left column, hold and drag it to the blank space next to the OWASP issue in the column on the right. Once you match a FortiWeb feature to the OWASP issue, you can move it again if you want to change your answer by clicking on the FortiWeb feature. You need to match five FortiWeb features to the OWASP issue in the work area.

Drag and Drop Question
A FortiWeb administrator is reviewing protection effectiveness after a surge in malicious traffic exposed design flaws and misconfigurations in several web applications.
For each Open Web Application Security Project (OWASP) risk listed, choose the FortiWeb feature that offers the most strategic protection, considering both coverage depth and operational effectiveness.
Match the most appropriate FortiWeb feature to each OWASP issue.
Select each FortiWeb feature in the left column, hold and drag it to the blank space next to the OWASP issue in the column on the right. Once you match a FortiWeb feature to the OWASP issue, you can move it again if you want to change your answer by clicking on the FortiWeb feature. You need to match five FortiWeb features to the OWASP issue in the work area.

Correct Answer:

Explanation:
A01: Broken Access Control → Site publish
A03: Injection → Parameter validation
A04: Insecure Design → Web vulnerability scan
A05: Security Misconfiguration → HSTS header
Site publish helps enforce controlled access to protected applications. Parameter validation restricts unsafe or unexpected input that could be used in injection attacks. Web vulnerability scanning helps identify application weaknesses and design-related exposure before attackers exploit them. HSTS reduces security misconfiguration risk by forcing browsers to use HTTPS for the protected site.
QUESTION NO: 6
Which statement best describes the difference between SAML authentication and HTML authentication in FortiWeb site publishing?
Which statement best describes the difference between SAML authentication and HTML authentication in FortiWeb site publishing?
Correct Answer: C
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).
QUESTION NO: 7
Your company hosts two different web applications: a shopping site and a blog. You want FortiWeb to apply different protection profiles and forwarding rules to each application. How should you configure FortiWeb to support this?
Your company hosts two different web applications: a shopping site and a blog. You want FortiWeb to apply different protection profiles and forwarding rules to each application. How should you configure FortiWeb to support this?
Correct Answer: C
Explanation: Only visible for Pass4Test members. You can sign-up / login (it's free).




