Free FCP-FWB-AD-7-4 sample questions
Real questions from the FCP - FortiWeb 7.4 Administrator practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 10 of 20 free sample questions.
A retail company has a public-facing web application with a separate single-page application (SPA) front end hosted on `https://shop.example.com` and a back-end API on `https://api.example.com`. The front end needs to make `POST` requests with a custom `X-Auth-Token` header to the API. Which two FortiWeb configurations are required to enable this functionality securely while preventing Cross-Origin Resource Sharing (CORS) attacks? (Select TWO)
A DevOps team is deploying a new microservices-based application protected by FortiWeb. The API endpoints and parameters are constantly changing as part of their CI/CD pipeline. The security team does not have a static OpenAPI schema but needs to protect the APIs from malicious payloads and structural attacks. Which FortiWeb feature is specifically designed to address this challenge?
True or False: When FortiWeb is deployed in True Transparent Proxy mode, it can perform Layer 7 content rewriting, such as modifying HTTP headers.
An e-commerce platform is experiencing a sophisticated bot attack that mimics human behavior, making it difficult for signature-based and threshold-based detection methods to identify. The attacks are causing inventory exhaustion and application slowdowns. Which FortiWeb feature is most effective at mitigating this type of attack?
A security administrator needs to ensure that all administrative changes made to a FortiWeb appliance are logged and that the integrity of these logs is maintained to meet PCI DSS Requirement 10. Which FortiWeb configuration provides the strongest assurance of log integrity?
During the setup of a new web server policy on a FortiWeb appliance in Reverse Proxy mode, the administrator notices that the source IP addresses in the web server logs are all from the FortiWeb's own interface. This is causing issues for the analytics team. How can the administrator ensure the original client IP address is passed to the back-end web servers?
A new administrator is protecting a GraphQL API endpoint with FortiWeb 7.4.1. They are concerned about denial-of-service attacks that exploit deeply nested or complex queries. Which specific FortiWeb feature should be configured to mitigate this threat?
A hospital needs to protect its patient portal, which is hosted behind a FortiWeb appliance. To comply with data privacy regulations, all traffic between the client and the FortiWeb, as well as between the FortiWeb and the back-end web servers, must be encrypted. The FortiWeb must also inspect the traffic for attacks. Which SSL/TLS configuration fulfills these requirements?
An administrator is configuring a FortiWeb High Availability (HA) cluster in Active-Passive mode. What is the primary function of the HA heartbeat interface?
10 more free samples are waiting
Create a free account to unlock the whole FCP-FWB-AD-7-4 sample bank, or get full access to all 207 practice questions in the simulator.