Skip to content

FCP-FWB-AD-7-4 FCP - FortiWeb 7.4 Administrator Practice Questions

Prepare for FCP-FWB-AD-7-4 with more than an answer.

207 questions in the full set20 sample questionsUpdated Jan 25, 2026

Unlock the full exam and previous versions

  • v1Version 1 207 questions Current
  • NSE6_FWB-6.4Legacy Fortinet NSE 6 - FortiWeb 6.4 98 questions Locked
Exam fee
$200 USD
Level
Professional
Domains covered on the exam 4
  1. Deployment and Configuration25%
  2. Encryption, Authentication, and Compliance25%
  3. Web Application Security30%
  4. Machine Learning (ML)20%
  1. 1

    An organization hosts multiple distinct websites (e.g., www.site-a.com, www.site-b.com, www.site-c.com) on a single back-end server, all sharing the same IP address and port (443). The administrator needs to apply different security policies and use a unique SSL certificate for each site. Which FortiWeb feature is essential for this configuration?

    Show answer details

    Correct answer: B

    Server Name Indication (SNI) is a TLS extension that allows a client to indicate which hostname it is attempting to connect to at the start of the handshake process. This allows a server (or a proxy like FortiWeb) to present multiple certificates on the same IP address and port number. By configuring SNI on FortiWeb, the administrator can map each unique SSL certificate to its corresponding hostname, enabling tailored security policies for each site.

  2. 2

    True or False: The FortiWeb Machine Learning engine requires a minimum of one week of traffic sampling before a reliable anomaly detection model can be generated and put into blocking mode.

    Show answer details

    Correct answer: A

    This statement is true. Fortinet officially recommends a minimum data sampling period of seven days to build an accurate and reliable machine learning model. This duration allows the engine to observe a full weekly traffic cycle, including variations between weekdays and weekends, which is crucial for establishing a comprehensive baseline of normal behavior and minimizing false positives.

  3. 3

    A FortiWeb administrator is troubleshooting a web application where users are being unexpectedly logged out. The investigation reveals that the session cookies issued by the application are being blocked by the FortiWeb. The cookies are not encrypted, but they are essential for application functionality. What is the most likely cause of this issue?

    Show answer details

    Correct answer: B

    FortiWeb's 'Cookie Security' feature can be configured to encrypt all cookies passed between the client and the server. If this feature is enabled, but the back-end application is not designed to handle encrypted session cookies, it will be unable to read them, leading to session termination. The solution is to add the specific session cookie name to the exception list within the Cookie Security policy, allowing it to pass through unmodified while other cookies remain encrypted.

  4. 4

    When selecting a deployment mode for FortiWeb, a network architect has two primary requirements: the original client source IP address must be preserved and visible to the backend servers, and the FortiWeb must be able to block malicious traffic inline. Which deployment mode satisfies both requirements?

    Show answer details

    Correct answer: C

    True Transparent Proxy mode is designed for this exact scenario. It places the FortiWeb inline, allowing it to inspect and block traffic. Because it operates as a transparent Layer 2 bridge, it does not modify the IP headers, thus preserving the original client source IP address when the traffic reaches the backend servers. Reverse Proxy mode hides the source IP (requiring X-Forwarded-For), and Offline Protection cannot block traffic.

  5. 5

    A new administrator is trying to understand the traffic flow for an application protected by a FortiWeb in Reverse Proxy mode. They want to visualize the communication path from the client to the FortiWeb and then from the FortiWeb to the backend server. Which diagram best represents this flow?

    sequenceDiagram participant Client participant FortiWeb participant WebServer as Web Server Client->>FortiWeb: HTTPS Request (Connection 1) FortiWeb-->>Client: Acknowledges Request Note over FortiWeb: Decrypts, Inspects Traffic FortiWeb->>WebServer: HTTP Request (Connection 2) WebServer-->>FortiWeb: HTTP Response Note over FortiWeb: Inspects, Encrypts Traffic FortiWeb-->>Client: HTTPS Response

    Show answer details

    Correct answer: B

    The diagram correctly illustrates the behavior of a reverse proxy. The client establishes a connection (Connection 1) only with the FortiWeb. The FortiWeb then terminates this connection and, acting as a client itself, establishes a completely separate connection (Connection 2) to the backend web server. This full proxy architecture allows FortiWeb to decrypt, inspect, and modify the traffic before forwarding it.

  6. 6

    A financial institution is using FortiWeb's Machine Learning (ML) feature to protect its online banking portal. During a routine review, an administrator observes that the ML model has incorrectly flagged several legitimate, complex user transactions as anomalies. The goal is to reduce these false positives without significantly weakening security. Which action should the administrator take?

    Show answer details

    Correct answer: B

    The most appropriate action is to create exceptions for the specific, legitimate traffic that is being misidentified. FortiWeb's ML allows administrators to review detected anomalies and mark them as false positives, effectively training the model to ignore similar legitimate patterns in the future. This refines the model's accuracy without disabling it or lowering its overall sensitivity, which would expose the application to other threats.

  7. 7

    A retail company has a public-facing web application with a separate single-page application (SPA) front end hosted on https://shop.example.com and a back-end API on https://api.example.com. The front end needs to make POST requests with a custom X-Auth-Token header to the API. Which two FortiWeb configurations are required to enable this functionality securely while preventing Cross-Origin Resource Sharing (CORS) attacks? (Select TWO)

    Show answer details

    Correct answer: A, C

    The primary step in configuring CORS is to explicitly whitelist the origin from which the cross-domain requests are allowed. In this case, the front-end application's domain must be added to the 'Allowed Origins' list.

    Because the request includes a custom header (X-Auth-Token), this header must be explicitly listed in the 'Allowed Headers' section of the CORS rule. Without this, the browser's preflight OPTIONS request will fail, blocking the actual POST request.

  8. 8

    A DevOps team is deploying a new microservices-based application protected by FortiWeb. The API endpoints and parameters are constantly changing as part of their CI/CD pipeline. The security team does not have a static OpenAPI schema but needs to protect the APIs from malicious payloads and structural attacks. Which FortiWeb feature is specifically designed to address this challenge?

    Show answer details

    Correct answer: C

    ML-based API Protection with continuous learning is the ideal solution for dynamic API environments. It analyzes live traffic to automatically discover and model the API structure, including endpoints and parameters. The continuous adjustment feature (new in 7.4) allows the model to adapt to frequent changes from a CI/CD pipeline without manual intervention, providing protection even without a static schema.

  9. 9

    True or False: When FortiWeb is deployed in True Transparent Proxy mode, it can perform Layer 7 content rewriting, such as modifying HTTP headers.

    Show answer details

    Correct answer: B

    This statement is false. Layer 7 content rewriting, such as modifying HTTP headers or rewriting content in the body, requires FortiWeb to act as a full proxy that terminates the connection. This functionality is available in Reverse Proxy mode, typically with SSL offloading, but not in True Transparent Proxy mode, which operates at a lower level to inspect traffic without terminating the session.

  10. 10

    An e-commerce platform is experiencing a sophisticated bot attack that mimics human behavior, making it difficult for signature-based and threshold-based detection methods to identify. The attacks are causing inventory exhaustion and application slowdowns. Which FortiWeb feature is most effective at mitigating this type of attack?

    Show answer details

    Correct answer: B

    ML-based Bot Detection using biometric modeling is specifically designed to counter sophisticated bots that mimic human behavior. It analyzes subtle patterns like mouse movements, typing speed, and mobile device orientation (part of the 13 behavioral dimensions) to create a model of genuine human interaction. This allows it to distinguish advanced bots from real users, which simpler methods like rate limiting or signature matching cannot do.

Create an account to continue.