
FortinetNSE 5 - FortiWeb Administrator
Domain 4Objective 2
Implement Web Vulnerability Scans NSE5-FORTIWEB-ADMINISTRATOR Practice Questions (Page 3)
Part of the Compliance and Troubleshooting domain, which makes up ~20% of our current practice bank. Fortinet does not publish an official question count, but from its 65-minute exam (~25–45 total, ~5–9 in this domain), expect 3–5 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
2concepts
Questions 11–15
- 11
An e-commerce company needs to run a vulnerability scan on its payment processing page. The page is protected by a Web Application Firewall (WAF) that blocks malicious requests. The scan must be able to identify vulnerabilities without being blocked by the WAF. What should the administrator configure in FortiWeb?
Select an answer first - 12
A company runs a vulnerability scan on its web application every night. The scan takes about 45 minutes to complete. The administrator notices that the scan sometimes overlaps with the application's backup window, which causes performance issues. What should the administrator do to resolve this?
Select an answer first - 13
A company has a web application that is subject to PCI DSS compliance. The compliance team requires that a vulnerability scan be run quarterly, and the results must be reviewed and remediated. The last scan found several 'High' severity vulnerabilities, but the development team has not fixed them yet. The next quarterly scan is due in two weeks. What should the administrator do?
Select an answer first - 14
A vulnerability scan report shows a 'Low' severity finding for 'Clickjacking' on a web page. The page does not contain any sensitive functionality. The administrator needs to decide whether to remediate the finding. What should the administrator consider?
Select an answer first - 15
After running a vulnerability scan on a web application, the FortiWeb report shows a 'High' severity SQL injection finding on the login page and a 'Medium' severity cross-site scripting (XSS) finding on the search results page. The development team has limited resources and can only fix one issue this sprint. Based on the scan report, which remediation should the administrator prioritize?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Fortinet. “NSE5-FORTIWEB-ADMINISTRATOR” is a trademark of its owner, used for identification only.