DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Fortinet NSE5_FWB_AD-8.0 Practice Questions & Answers 2026 Part1 | Fortinet NSE 5 - FortiWeb Administrator

Are you preparing for the Fortinet NSE 5 - FortiWeb 8.0 Administrator certification exam? SPOTO offers the Fortinet NSE 5 - FortiWeb 8.0 Administrator Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
You are setting up a FortiWeb policy to protect a customer login portal. Users connect to https://login.training.lab, and you want FortiWeb to forward those requests to a load-balanced pool of back-end servers.Which three components must you configure to complete the server policy?
A. Real server, IPsec tunnel, and static route
B. Web application firewall (WAF) profile, DoS policy, and server name indication (SNI)-based certificate
C. Virtual server, server pool, and port settings (service)
D. DNS resolver, URL rewrite rule, and HTTP health check
View answer
Correct Answer: C
Question #2
Which high availability mode is commonly used to integrate with a traffic distributer like FortiADC?
A. Cold standby
B. Load sharing
C. Active-Active
D. Active-Passive
View answer
Correct Answer: C
Question #3
An attacker attempts to send an SQL injection attack containing the known attack string 'root'; -- through an API call.Which FortiWeb inspection feature will be able to detect this attack the quickest?
A. API gateway rule
B. Known signatures
C. Machine learning (ML)-based API protection--anomaly detection
D. ML-based API protection--threat detection
View answer
Correct Answer: B
Question #4
What other consideration must you take into account when configuring Defacement protection?
A. onfigure the FortiGate to perform Anti-Defacement as well
B. lso incorporate a FortiADC into your network
C. one
D. se FortiWeb to block SQL Injections and keep regular backups of the Database
View answer
Correct Answer: D
Question #5
Refer to the exhibit.You are a FortiWeb administrator. FortiWeb is deployed between a FortiGate and two back-end web servers, as shown in the diagram. No server policies are currently configured on FortiWeb.While testing, you notice that a student system in the 100.64.0.0/24 network is still able to access the back-end servers in 10.1.1.0/24, even though FortiWeb is not logging or inspecting the traffic.Which action should you take to ensure FortiWeb blocks or inspects all traffic before it reaches the back-end servers?
A. Configure FortiWeb in transparent mode to force traffic inspection
B. Enable network address translation (NAT) mode on FortiWeb to hide the backend server IP addresses
C. Add static routes on FortiGate to route traffic back through the FortiWeb internal interface
D. Disable ip-forward to prevent traffic from passing through FortiWeb without a matching server policy
View answer
Correct Answer: D
Question #6
Refer to the exhibit.A FortiWeb administrator notices an alert triggered under the Threshold Based Detection category, with the message: Threshold Based Content Scraping Detection (Bot Detection) violation.Based on the log details, what is the most likely cause of this alert?
A. An automated script or bot systematically accessing multiple pages to extract web content
B. A layer 4 SYN flood attack overwhelming the web server
C. A client sending malformed HTTP requests due to browser incompatibility
D. A vulnerability scanner triggering rate limits by simulating browser behavior
View answer
Correct Answer: A
Question #7
Which of the following FortiWeb features is part of the mitigation tools against OWASP A4 threats?
A. ensitive info masking
B. rute Force blocking
C. oison Cookie detection
D. ession Management
View answer
Correct Answer: D
Question #8
Refer to the exhibit.What can you conclude from this support vector machine (SVM) plot of a potential bot connection?
A. The connection is normal and within the expected averages
B. The connection uses too much bandwidth
C. The connection uses an excessive amount of TCP connections, but is harmless
D. The connection is possibly a bot
View answer
Correct Answer: D
Question #9
A user from group B sends 150 requests in one minute to this endpoint:Group B users are allowed access to only /api/v1/reports and are limited to 50 requests per minute.What should the FortiWeb administrator configure to stop this abuse?
A. Move the user to group A to increase their limit
B. Apply group-based rate limiting to restrict group B users to 50 requests per minute
C. Nothing
D. Change the host to block access to /api/v1/data
View answer
Correct Answer: B
Question #10
Your e-commerce platform is experiencing frequent SQL injection attempts. You need FortiWeb to actively inspect, enforce, and block attacks inline before traffic reaches the web servers.The deployment must support the full FortiWeb security feature set without operational limitations, including protocol validation, attack detection, and policy enforcement.Which FortiWeb operation mode should you configure to proactively intercept and block threats such as SQL injection attempts?
A. Reverse proxy
B. Web Cache Communication Protocol (WCCP) integration mode
C. Transparent bridge mode
D. Offline protection
View answer
Correct Answer: A
Question #11
Refer to the exhibit.A FortiWeb administrator tests a new form input value after training the machine learning (ML) anomaly detection system.The hidden Markov model (HMM) flags the input as abnormal, while the support vector machine (SVM) model classifies it as normal. FortiWeb allows the request.What does this result indicate about the FortiWeb ML anomaly detection behavior?
A. FortiWeb is correctly allowing an unusual but non-malicious input based on combined HMM and SVM evaluation
B. The anomaly detection thresholds are too low and must be increased
C. FortiWeb failed to detect an attack and should have blocked the request
D. One of the ML models should be disabled to avoid inconsistent results
View answer
Correct Answer: A
Question #12
A third-party penetration test reveals that users can bypass login controls through a mobile API. Your current FortiWeb configuration includes zero trust network access (ZTNA) profiles and cookie security, but API protection and client management are not enabled. The security team asks you to recommend the most effective way to close this gap.Which FortiWeb adjustment would best prevent future unauthorized API access?
A. Switch to a reverse-proxy mode to bypass cookie-based controls
B. Enable API protection and client management to enforce identity checks on mobile API traffic
C. Log only API traffic and rely on FortiAnalyzer for future alerts
D. Replace ZTNA with bot protection to reduce false positives
View answer
Correct Answer: B
Question #13
Which operation mode requires additional configuration in order to allow FTP traffic into your web server?
A. everse proxy
B. rue transparent proxy
C. ffline protection
D. ransparent inspection
View answer
Correct Answer: A
Question #14
Refer to the exhibits.You are configuring a FortiWeb device in reverse proxy mode, placed downstream from a FortiGate. The server pool includes two back-end web servers: 10.1.1.21 and 10.1.1.22, and you've defined a health check policy.After completing the server policy configuration and applying it to a virtual server, you notice that FortiWeb is not forwarding traffic to the back-end servers. No errors or health check failures appear in the logs.Based on the configuration shown in the exhibit, which change should you make to restore back-end traffic flow?
A. hange the virtual server IP address to match one of the back-end servers
B. nable Client Real IP to ensure traffic goes to the back-end servers
C. onfigure FortiGate to forward traffic to the back-end IP addresses directly
D. elect the correct server pool in the FortiWeb server policy
View answer
Correct Answer: D
Question #15
What is the difference between an API gateway protection schema and a machine learning (ML) API protection schema?
A. An API gateway protection schema does not allow authentication
B. An API gateway protection schema handles response bodies
C. An API gateway protection schema supports data types other than string
D. An API gateway protection schema cannot change without administrator intervention
View answer
Correct Answer: D
Question #16
How are bot machine learning (ML) models different from API or anomaly detection models?
A. Bot ML models analyze multiple connections overtime instead analyzing each connection as a single unit
B. Bot ML models detect only anomalies and not actual threats
C. Bot ML models inspect more types of connection properties
D. Bot ML models do not update models periodically from new data
View answer
Correct Answer: A
Question #17
Refer to the exhibit.Attack ID 20000010 is brute force logins.Which statement is accurate about the potential attack?
A. The attacker has successfully retrieved the credentials to www
B. www
C. The attack has happened 10 times
D. 192
View answer
Correct Answer: D
Question #18
A customer wants to be able to index your websites for search and advertisement purposes.What is the easiest way to allow this on a FortiWeb?
A. Add the indexer IP address to the trusted IP list on the FortiWeb
B. Add the indexer IP address to the FortiGuard "Known Search Engines" category
C. Create a firewall rule to bypass the FortiWeb entirely for the indexer IP address
D. Do not allow any external sites to index your websites
View answer
Correct Answer: A
Question #19
Refer to the exhibit.What are two additional configuration elements that you must be configure for this API gateway? (Choose two.)
A. You must define rate limits
B. You must define URL prefixes
C. You must select a setting in the Allow User Group field
D. You must enable and configure Host Status
View answer
Correct Answer: AB
Question #20
How are bot machine learning (ML) models different from API or anomaly detection models?
A. ot ML models inspect more types of connection properties
B. ot ML models detect only anomalies and not actual threats
C. ot ML models analyze multiple connections overtime instead analyzing each connection as a single unit
D. ot ML models do not update models periodically from new data
View answer
Correct Answer: C
Question #21
Which would be a reason to implement HTTP rewriting?
A. To redirect HTTP to HTTPS
B. To implement load balancing
C. To replace a vulnerable element in a requested URL
D. The original page has moved to a new URL
View answer
Correct Answer: C
Question #22
What capability can FortiWeb add to your Web App that your Web App may or may not already have?
A. TTP/HTML Form Authentication
B. utomatic backup and recovery
C. igh Availability
D. SL Inspection
View answer
Correct Answer: A
Question #23
Refer to the exhibit.What are two additional configuration elements that you must be configure for this API gateway? (Choose two.)
A. You must define rate limits
B. You must define URL prefixes
C. You must select a setting in the Allow User Group field
D. You must enable and configure Host Status
View answer
Correct Answer: AB
Question #24
Which high availability mode is commonly used to integrate with a traffic distributer like FortiADC?
A. Cold standby
B. Load sharing
C. Active-Active
D. Active-Passive
View answer
Correct Answer: C
Question #25
Which implementation is most suited for a deployment that must meet PCI DSS compliance criteria?
A. SL offloading with FortiWeb in reverse proxy mode
B. SL offloading with FortiWeb in full transparent proxy mode
C. SL offloading with FortiWeb in transparency mode
D. SL offloading with FortiWeb in PCI DSS mode
View answer
Correct Answer: D

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us