Which of the following is a common threat mitigation technique to protect against SQL injection attacks?
A. Cross-site scripting (XSS) prevention
B. Data encryption at rest
C. Input validation and sanitization
D. Server load balancing
正解:C
質問 2:
What is the primary goal of bot detection and mitigation in web application security?
A. Accelerating web application performance
B. Identifying and blocking malicious bots
C. Ensuring user privacy
D. Enhancing user authentication
正解:B
質問 3:
What is a common technique to mitigate Cross-Site Scripting (XSS) attacks in web applications?
A. Captcha verification for login forms
B. SSL/TLS encryption
C. Input validation and escaping
D. Encryption of user passwords
正解:C
質問 4:
How does your FortiWeb configuration differ if the FortiWeb is upstream of the SNAT device instead of downstream of the SNAT device?
A. No special configuration required
B. You must enable the "Use" X-Forwarded-For: option.
C. FortiWeb must be set for Transparent Mode
D. You must enable "Add" X-Forwarded-For: instead of the "Use" X-Forwarded-For: option.
正解:D
質問 5:
What capability can FortiWeb add to your Web App that your Web App may or may not already have?
A. SSL Inspection
B. High Availability
C. Automatic backup and recovery
D. HTTP/HTML Form Authentication
正解:D
質問 6:
When configuring machine learning for web application security, what is the primary role of machine learning algorithms?
A. Filtering unwanted spam emails
B. Identifying patterns and anomalies in web traffic
C. Encrypting sensitive data during transmission
D. Authenticating user credentials
正解:B
質問 7:
Refer to the exhibits.


What will happen when a client attempts a mousedown cross-site scripting (XSS) attack against the site http://my.blog.org/userl1/blog.php and FortiWeb is enforcing the highlighted signature?
A. The connection will be allowed.
B. The connection will be blocked as an XSS attack.
C. The connection will be stripped of the mousedown JavaScript code.
D. FortiWeb will report the new mousedown attack to FortiGuard.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
Which FortiWeb configuration element is used to define rules for allowing or blocking specific types of traffic?
A. High Availability (HA)
B. Protected hostname
C. Security profile
D. Firewall policy
正解:D
質問 9:
Refer to the exhibit.

Based on the configuration, what would happen if this FortiWeb were to lose power? (Choose two.)
A. Traffic that passes between port5 and port6 will be inspected.
B. All traffic will be interrupted.
C. Traffic will be interrupted between port3 and port4.
D. Traffic will pass between port5 and port6 uninspected.
正解:C,D
Jinbo -
持ち歩きは面倒というのであれば、全ページが電子化されているので、PDFファイルでダウンロードすることもできるところが大好きです。解釈でわかりやく内容を明示。つまづきやすいポイントをフォローしてくれてる。Pass4Testさんの押さえるべきポイントを確実に覚えればなかなかFCP_FWB_AD-7.4試験でいい点は取れると思う。