FCP-FWB-AD-7-4 Sample Questions

FCP-FWB-AD-7-4 Sample Questions & Answers

Web application security, from threat mitigation to DoS, defacement, and client-side protection, carries the most weight, alongside machine-learning bot and API defenses, SSL certificate handling with PCI DSS compliance, and deployment modes with high availability.

Launch the full FCP-FWB-AD-7-4 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Encryption, Authentication, and Compliance · PCI DSS Compliance

    A security administrator needs to ensure that all administrative changes made to a FortiWeb appliance are logged and that the integrity of these logs is maintained to meet PCI DSS Requirement 10. Which FortiWeb configuration provides the strongest assurance of log integrity?

    Show answer & explanation

    Correct answer: C

    PCI DSS requires logs to be stored securely and their integrity to be protected. Forwarding logs to a remote, centralized logging server like FortiAnalyzer prevents an attacker from altering logs on the local FortiWeb device. Enabling log file hashing (or digital signing) on the FortiAnalyzer provides a cryptographic mechanism to verify that the logs have not been tampered with, directly addressing the log integrity requirement.

  2. Question 2Intermediate

    Deployment and Configuration · Server Pools and Policies

    During the setup of a new web server policy on a FortiWeb appliance in Reverse Proxy mode, the administrator notices that the source IP addresses in the web server logs are all from the FortiWeb's own interface. This is causing issues for the analytics team. How can the administrator ensure the original client IP address is passed to the back-end web servers?

    Show answer & explanation

    Correct answer: B

    In Reverse Proxy mode, FortiWeb terminates the client connection and initiates a new one to the back-end server, which causes the source IP to be that of the FortiWeb. The standard method to preserve the original client IP is to enable the 'Add X-Forwarded-For Header' (or similar headers like X-Real-IP). This inserts an HTTP header containing the original client's IP address into the request sent to the back-end server. The web server must then be configured to log this header value.

  3. Question 3Advanced

    Web Application Security · API Protection

    A new administrator is protecting a GraphQL API endpoint with FortiWeb 7.4.1. They are concerned about denial-of-service attacks that exploit deeply nested or complex queries. Which specific FortiWeb feature should be configured to mitigate this threat?

    Show answer & explanation

    Correct answer: C

    FortiWeb 7.4.1 introduced specific protections for GraphQL, including query complexity analysis. This feature allows administrators to set limits on factors like query depth and the number of aliases. By enforcing these limits, FortiWeb can block overly complex queries designed to overwhelm the server, effectively mitigating this type of denial-of-service attack vector unique to GraphQL.

  4. Question 4Intermediate

    Encryption, Authentication, and Compliance · SSL/TLS and Certificate Management

    A hospital needs to protect its patient portal, which is hosted behind a FortiWeb appliance. To comply with data privacy regulations, all traffic between the client and the FortiWeb, as well as between the FortiWeb and the back-end web servers, must be encrypted. The FortiWeb must also inspect the traffic for attacks. Which SSL/TLS configuration fulfills these requirements?

    Show answer & explanation

    Correct answer: C

    This scenario requires end-to-end encryption with inspection in the middle. This is achieved through SSL Offloading where FortiWeb terminates the client's SSL connection, inspects the decrypted traffic, and then re-encrypts it before sending it to the back-end server. Setting the 'SSL/TLS mode' to 'HTTPS' in the server pool configuration ensures that the connection from FortiWeb to the back-end servers is also encrypted.

  5. Question 5Beginner

    Deployment and Configuration · High Availability

    An administrator is configuring a FortiWeb High Availability (HA) cluster in Active-Passive mode. What is the primary function of the HA heartbeat interface?

    Show answer & explanation

    Correct answer: C

    The HA heartbeat interface is a dedicated link used by the cluster members to send keep-alive packets to each other. Its primary purpose is to monitor the status and health of the other device in the cluster. If the active unit stops receiving heartbeat packets from the passive unit (or vice-versa), it assumes the peer is down and triggers a failover process to maintain service availability.

  6. Question 6Advanced

    Web Application Security · Threat Detection and Mitigation

    Case Study: Global Travel Corp

    Global Travel Corp (GTC) is a large travel booking company that relies on a complex web application for its core business. The application is protected by a pair of FortiWeb-VMs in an Active-Passive HA cluster deployed in AWS. The FortiWebs are configured in Reverse Proxy mode to perform SSL offloading and load balancing for a fleet of backend web servers.

    Recently, GTC's security team has been alerted to a new zero-day vulnerability in the web application's framework. The development team cannot patch the vulnerability for at least 48 hours. The security team needs to implement a virtual patch immediately to block any attempts to exploit this vulnerability. The exploit involves a specific, complex string pattern in the URL query string, such as ?user_pref=payload(exploit_code).

    The security team's primary goal is to block this specific exploit pattern with zero false positives, without disrupting legitimate traffic. They also need to be alerted immediately if an exploit attempt is detected. Which is the most precise and effective method to achieve this on FortiWeb?

    Show answer & explanation

    Correct answer: B

    This is the best approach for virtual patching a specific zero-day vulnerability. Creating a custom signature with a precise regular expression allows the security team to target the exact exploit pattern. This minimizes the risk of false positives that could be caused by enabling broad signature categories. Setting the action to 'Alert & Deny' meets both requirements: it blocks the attack and immediately notifies the security team. This is a targeted, surgical approach ideal for zero-day mitigation.

  7. Question 7BeginnerSelect 2

    Deployment and Configuration · Server Pools and Policies

    Which two of the following are valid server load balancing algorithms available in a FortiWeb server pool? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    The 'Least Connections' algorithm directs new connections to the server with the fewest active connections, which is useful for balancing load on servers with varying capacity.

    'Weighted Round Robin' is a common algorithm that distributes connections sequentially among servers but allows an administrator to assign a weight to each server, sending more traffic to servers with higher capacity.

  8. Question 8Intermediate

    Encryption, Authentication, and Compliance · Authentication and Access Control

    An administrator is configuring FortiWeb to authenticate administrative users against a Microsoft Active Directory server using LDAP. After entering the server details and credentials, the 'Test Connection' fails. The FortiWeb has network connectivity to the LDAP server. Which configuration parameter is a common cause for this issue?

    Show answer & explanation

    Correct answer: B

    A common point of failure in LDAP configuration is an incorrect 'Common Name Identifier' (e.g., 'sAMAccountName' for Active Directory) or an incorrect 'Distinguished Name' (DN) for the base search location or the bind user. These values must exactly match the directory schema and structure. Even a small typo in the OU or DC components will cause the connection or user lookup to fail.

  9. Question 9Intermediate

    Machine Learning (ML) · ML-Based Bot Detection

    A website is frequently targeted by web scraping bots that are harvesting pricing information. The administrator wants to prevent this without impacting legitimate users or search engine crawlers like Googlebot. Which FortiWeb configuration is the most appropriate first step?

    Show answer & explanation

    Correct answer: B

    The 'Known Bots' feature uses a signature database to identify well-known bots, including legitimate search engines and malicious scrapers. By enabling this feature, an administrator can easily classify incoming bot traffic. Setting the action for the 'Search Engine' category to 'Allow' ensures that crawlers like Googlebot are not blocked, while other categories like 'Web Scraper' can be set to 'Block' or 'Monitor'. This is a precise way to differentiate between good and bad bots.

  10. Question 10Beginner

    Web Application Security · DoS and Defacement Protection

    What is the primary purpose of the 'defacement protection' feature in FortiWeb?

    Show answer & explanation

    Correct answer: B

    Defacement protection is designed to maintain the content integrity of a website. It works by creating a baseline (a 'golden image') of the website's files and appearance. FortiWeb then periodically checks the live site against this baseline. If an unauthorized change is detected (a defacement), it can alert administrators and automatically restore the original content from its backup, ensuring the website's intended appearance is maintained.

Ready for the real thing?

The full FCP-FWB-AD-7-4 simulator has every exam-style question, timed mode, and instant scoring.