
FortinetNSE 5 - FortiWeb Administrator
Domain 2Objective 1
Apply Web Application Security NSE5-FORTIWEB-ADMINISTRATOR Practice Questions (Page 3)
Part of the Web Application and API Security with Botnet Mitigation domain, which makes up ~34% of our current practice bank. Fortinet does not publish an official question count, but from its 65-minute exam (~25–45 total, ~9–15 in this domain), expect 3–5 from this objective — we provide 16 practice questions to prepare you well beyond it. (estimate)
16questions here
4free pages
3concepts
Questions 11–15
- 11
A company's web application is protected by FortiWeb. The machine-learning anomaly detection engine has been running for a month and has established a baseline. The security team wants to ensure that the engine is still accurately reflecting the application's normal traffic after a major feature update that changed user behavior. What should the administrator do?
Select an answer first - 12
A company hosts two web applications on the same FortiWeb appliance. The first application is a public marketing site that requires only basic protection. The second is a customer portal that handles sensitive data and requires strict signature-based protection and machine-learning anomaly detection. The administrator wants to enforce different security policies for each application. What should the administrator do?
Select an answer first - 13
A financial services company uses FortiWeb to protect its customer portal. The portal experiences normal traffic patterns during business hours and low traffic at night. The security team wants to detect and block unusual traffic that deviates from the established baseline, such as a sudden spike in login attempts from a single IP. Which FortiWeb feature should be enabled in the protection profile?
Select an answer first - 14
How does FortiWeb's machine-learning engine identify potential threats?
Select an answer first - 15
A company is deploying FortiWeb to protect a new API that will be accessed by both internal employees and external partners. The security team wants to enforce signature-based protection for known attacks and machine-learning anomaly detection for unknown threats. The team also wants to ensure that the API's protection profile is easy to manage and can be reused if the API is moved to a different virtual server. What should the administrator do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE5-FORTIWEB-ADMINISTRATOR” is a trademark of its owner, used for identification only.