Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Fortinet NSE 5 - FortiWeb 8.0 Administrator Question and Answers

Fortinet NSE 5 - FortiWeb 8.0 Administrator

Last Update Aug 29, 2026
Total Questions : 36

We are offering FREE NSE5_FWB_AD-8.0 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE5_FWB_AD-8.0 free exam questions and then go for complete pool of Fortinet NSE 5 - FortiWeb 8.0 Administrator test questions that will help you more.

NSE5_FWB_AD-8.0 pdf

NSE5_FWB_AD-8.0 PDF

$36.75  $104.99
NSE5_FWB_AD-8.0 Engine

NSE5_FWB_AD-8.0 Testing Engine

$43.75  $124.99
NSE5_FWB_AD-8.0 PDF + Engine

NSE5_FWB_AD-8.0 PDF + Testing Engine

$57.75  $164.99
Questions 1

A FortiWeb administrator wants to stop coordinated scraping traffic coming from several IP addresses, each making only a few requests so thresholds never trigger.

Which tactic should the administrator deploy to identify botnets using shared behavioral signals instead of volume?

Options:

A.  

A DoS protection profile with extremely low request limits for the entire site.

B.  

A static blocklist for all IP addresses seen in logs, even if most appear only once.

C.  

Bot mitigation with device fingerprinting to correlate clients by behavior, headers, and JavaScript challenges instead of IP address volume.

D.  

A web application firewall (WAF) rule that blocks every user agent that is not on a manually created allowlist.

Discussion 0
Questions 2

You are reviewing the FortiWeb integration with the Advanced Bot Protection (ABP) service.

Match each step in the ABP flow with its description.

Options:

Discussion 0
Questions 3

You need to monitor and respond to repeated suspicious activity from individual users who are accessing your web application.

Your goal is to evaluate each action the user takes and apply a response when their behavior becomes risky.

What can you configure on FortiWeb to track user behavior and respond automatically when risky activity continues?

Options:

A.  

Configure rate limiting on the IP reputation blocklist.

B.  

Add a custom signature to block suspicious URLs immediately.

C.  

Enable automatic cookie security under the server policy.

D.  

Set up scoring in the protection profile to track request behavior over time.

Discussion 0
Questions 4

You are reviewing SSL-related issues on FortiWeb. An administrator reports that they receive a certificate warning when they access the FortiWeb GUI over HTTPS. Separately, your FortiWeb device also makes outbound HTTPS requests to a back-end API server.

In which two situations would FortiWeb use its own certificates to establish or secure the connection? (Choose two.)

Options:

A.  

When a client browser initiates an SSL session and FortiWeb is in transparent inspection mode.

B.  

When FortiWeb is routing an HTTPS connection to a FortiGate without decrypting it.

C.  

When an administrator connects to the FortiWeb GUI using HTTPS in a browser.

D.  

When FortiWeb connects to a back-end server over HTTPS as a client.

Discussion 0
Questions 5

Refer to the exhibit.

You have deployed FortiWeb behind a FortiGate that is configured as a reverse proxy and inserts the X-Forwarded-For HTTP header when forwarding HTTP and HTTPS traffic.

FortiWeb is using a custom inline protection profile, and logging is enabled, as shown in the exhibit.

You notice that FortiWeb is blocking legitimate users, and all requests in the attack logs appear to come from the FortiGate IP address, not the original client IP address.

Which action should you take to fix this issue?

Options:

A.  

Replace the current deployment mode with a one-arm proxy to expose source IP addresses.

B.  

Disable IP-based detection features on FortiWeb to avoid IP-related blocking.

C.  

Recreate the server policy using the predefined profile instead of a custom one.

D.  

Modify the protection profile to use the X-Forwarded-For header for client IP address detection.

Discussion 0
Questions 6

Refer to the exhibits.

You are configuring a FortiWeb device in reverse proxy mode, placed downstream from a FortiGate. The server pool includes two back-end web servers: 10.1.1.21 and 10.1.1.22, and you’ve defined a health check policy.

After completing the server policy configuration and applying it to a virtual server, you notice that FortiWeb is not forwarding traffic to the back-end servers. No errors or health check failures appear in the logs.

Based on the configuration shown in the exhibit, which change should you make to restore back-end traffic flow?

Options:

A.  

Select the correct server pool in the FortiWeb server policy.

B.  

Enable Client Real IP to ensure traffic goes to the back-end servers.

C.  

Change the virtual server IP address to match one of the back-end servers.

D.  

Configure FortiGate to forward traffic to the back-end IP addresses directly.

Discussion 0
Questions 7

Refer to the exhibit.

A FortiWeb administrator is trying to enable policy-based traffic logging on FortiWeb but doesn’t see the traffic log option available in the server policy settings.

What is the most likely reason this option is not visible?

Options:

A.  

The FortiWeb administrator must first connect to FortiSIEM or FortiAnalyzer, and then enable policy logs from those devices.

B.  

Server policy logging only becomes available when FortiWeb is deployed in reverse-proxy mode and transparent mode.

C.  

The global traffic log setting must be enabled manually in the CLI for the option to appear.

D.  

The FortiWeb administrator must get a license to use this feature with FortiAppSec Cloud.

Discussion 0
Questions 8

Which URL should you rewrite to reduce security risk?

Options:

A.  

https://www.example.com/about/team

B.  

https://www.example.com/wordpress/?feed=rss2

C.  

https://www.example.com/products/today

D.  

https://www.example.com/25.3.6/Browse/MediaData

Discussion 0
Questions 9

You are hosting multiple secure web applications behind a single public IP address on FortiWeb.

When a client connects to a service, FortiWeb needs to:

    Identify the correct SSL certificate.

    Decrypt the request.

    Route the request to the correct back-end server.

Match each FortiWeb function to the request handling step that performs the function.

Options:

Discussion 0
Questions 10

You are setting up a FortiWeb policy to protect a customer login portal. Users connect to https://login.training.lab, and you want FortiWeb to forward those requests to a load-balanced pool of back-end servers.

Which three components must you configure to complete the server policy?

Options:

A.  

Virtual server, server pool, and port settings (service).

B.  

Web application firewall (WAF) profile, DoS policy, and server name indication (SNI)-based certificate.

C.  

DNS resolver, URL rewrite rule, and HTTP health check.

D.  

Real server, IPsec tunnel, and static route.

Discussion 0