Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Fortinet logo

FortinetNSE 5 - FortiWeb Administrator

Domain 2Objective 2

Configure API Discovery and Protection NSE5-FORTIWEB-ADMINISTRATOR Practice Questions (Page 3)

Part of the Web Application and API Security with Botnet Mitigation domain, which makes up ~34% of our current practice bank. Fortinet does not publish an official question count, but from its 65-minute exam (~25–45 total, ~9–15 in this domain), expect 3–5 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
8concepts

Questions 11–15

  1. 11application · medium

    After running API discovery, a FortiWeb administrator reviews the learned schema and notices that a /users/{id} endpoint is recorded with a parameter named 'id' but no data type is shown. The API documentation states that 'id' must be an integer. What should the administrator do to ensure FortiWeb can validate requests against this requirement?

    Select an answer first
  2. 12application · medium

    A development team is rolling out a new API in phases. The first phase includes only the /v1/users and /v1/products endpoints. The security team wants FortiWeb to discover only these endpoints and not any other paths that might be accessed on the same virtual server. What should the administrator configure?

    Select an answer first
  3. 13application · medium

    A healthcare organization uses FortiWeb to protect its patient-facing API. The security team notices that a /patients/{id} endpoint is returning full medical records when the requesting application only needs a summary. This is causing excessive data exposure. What should the administrator configure to mitigate this issue?

    Select an answer first
  4. 14expert · hard

    A financial API exposes a /transfer endpoint that accepts a 'amount' parameter. Attackers have been sending requests with negative amounts to exploit a business logic flaw. The API schema defines 'amount' as a positive number. The security team wants FortiWeb to block negative amounts while allowing all other valid requests. What should the administrator configure?

    Select an answer first
  5. 15expert · hard

    A company's API has a /v1/orders endpoint that is accessed by both a web application and a mobile app. The web application uses OAuth tokens, while the mobile app uses API keys. The security team wants FortiWeb to enforce different rate limits for each client type. What should the administrator configure?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE5-FORTIWEB-ADMINISTRATOR” is a trademark of its owner, used for identification only.