DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Fortinet NSE5_FWB_AD-8.0 Practice Questions & Answers 2026 Part2 | Fortinet NSE 5 - FortiWeb Administrator

Are you preparing for the Fortinet NSE 5 - FortiWeb 8.0 Administrator certification exam? SPOTO offers the Fortinet NSE 5 - FortiWeb 8.0 Administrator Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Which implementation is most suited for a deployment that must meet PCI DSS compliance criteria?
A. SSL offloading with FortiWeb in reverse proxy mode
B. SSL offloading with FortiWeb in PCI DSS mode
C. SSL offloading with FortiWeb in transparency mode
D. SSL offloading with FortiWeb in full transparent proxy mode
View answer
Correct Answer: B
Question #2
Refer to the exhibit.A FortiWeb device is deployed upstream of a device performing source network address translation (SNAT) or load balancing.What configuration must you perform on FortiWeb to preserve the original IP address of the client?
A. Enable and configure the Preserve Client IP setting
B. Use a transparent operating mode on FortiWeb
C. Enable and configure the Add X-Forwarded-For setting
D. Turn off NAT on the FortiWeb
View answer
Correct Answer: A
Question #3
Which would be a reason to implement HTTP rewriting?
A. To redirect HTTP to HTTPS
B. To implement load balancing
C. To replace a vulnerable element in a requested URL
D. The original page has moved to a new URL
View answer
Correct Answer: A
Question #4
Review the following configuration:What are two routing behaviors that you can expect on FortiWeb after this configuration change? (Choose two.)
A. Non-HTTP traffic routed through the FortiWeb is allowed
B. IPv6 routing is enabled
C. Non-HTTP traffic destined to the FortiWeb virtual server IP address is dropped
D. Only ICMP traffic is allowed
View answer
Correct Answer: AC
Question #5
Refer to the exhibit.What are two additional configuration elements that you must be configure for this API gateway? (Choose two.)
A. You must define rate limits
B. You must define URL prefixes
C. You must select a setting in the Allow User Group field
D. You must enable and configure Host Status
View answer
Correct Answer: AB
Question #6
Which statement best describes the difference between SAML authentication and HTML authentication in FortiWeb site publishing?
A. SAML authentication delegates login to an external system, while HTML authenticates directly on FortiWeb
B. SAML authentication is used for internal apps while HTML authentication is used for cloud apps
C. SAML authentication encrypts passwords while HTML authentication sends passwords in cleartext format
D. SAML authentication uses a passwordless login, while HTML authentication uses tokens
View answer
Correct Answer: A
Question #7
Which of the following is true about Local User Accounts?
A. an be used for site publishing
B. ust be assigned regardless of any other authentication
C. est suited for large environments with many users
D. an be used for Single Sign On
View answer
Correct Answer: A
Question #8
You are reviewing a report from your FortiWeb logs and notice a JavaScript payload like < script > document.cookie < /script > is submitted through a product review form. The page doesn't filter the script, and when users view the review, their session cookies are exposed.Why is this attack dangerous?
A. t executes code in the victim's browser
B. t forces a victim to click malicious links
C. t bypasses login pages
D. t leaks back-end database information
View answer
Correct Answer: A
Question #9
Which implementation is most suited for a deployment that must meet PCI DSS compliance criteria?
A. SSL offloading with FortiWeb in reverse proxy mode
B. SSL offloading with FortiWeb in PCI DSS mode
C. SSL offloading with FortiWeb in transparency mode
D. SSL offloading with FortiWeb in full transparent proxy mode
View answer
Correct Answer: B
Question #10
Which would be a reason to implement HTTP rewriting?
A. To redirect HTTP to HTTPS
B. To implement load balancing
C. To replace a vulnerable element in a requested URL
D. The original page has moved to a new URL
View answer
Correct Answer: A
Question #11
Refer to the exhibit.You are deploying FortiWeb to handle HTTPS traffic from clients and forward cleartext traffic to a back-end server.You want FortiWeb to decrypt the HTTPS session, inspect the traffic, and then send the traffic to the server using HTTP.What can you configure on FortiWeb to make this behavior happen?
A. Enable reencryption on the back-end interface so the server receives HTTPS traffic
B. Configure passive SSL inspection so FortiWeb analyzes encrypted packets without terminating SSL
C. Configure FortiWeb to reuse the same certificate for inbound and outbound HTTPS traffic without decrypting traffic
D. Enable SSL offloading so FortiWeb terminates the client's HTTPS session and forwards decrypted HTTP traffic to the back-end server
View answer
Correct Answer: D
Question #12
When is it possible to use a self-signed certificate, rather than one purchased from a commercial certificate authority?
A. If you are an enterprise whose employees use only mobile devices
B. If you are a small business or home office
C. If you are an enterprise whose computers all trust the active directory or CA server that signed the certificate
D. If you are an enterprise whose resources do not need security or https connections
View answer
Correct Answer: C
Question #13
Refer to the exhibit.What are two additional configuration elements that you must be configure for this API gateway? (Choose two.)
A. You must define rate limits
B. You must define URL prefixes
C. You must select a setting in the Allow User Group field
D. You must enable and configure Host Status
View answer
Correct Answer: AB
Question #14
Review the following configuration:What are two routing behaviors that you can expect on FortiWeb after this configuration change? (Choose two.)
A. Non-HTTP traffic routed through the FortiWeb is allowed
B. IPv6 routing is enabled
C. Non-HTTP traffic destined to the FortiWeb virtual server IP address is dropped
D. Only ICMP traffic is allowed
View answer
Correct Answer: AC
Question #15
Refer to the exhibits.What will happen when a client attempts a mousedown cross-site scripting (XSS) attack against the site http://my.blog.org/userl1/blog.php and FortiWeb is enforcing the highlighted signature?
A. The connection will be stripped of the mousedown JavaScript code
B. The connection will be blocked as an XSS attack
C. FortiWeb will report the new mousedown attack to FortiGuard
D. The connection will be allowed
View answer
Correct Answer: D
Question #16
Which URL should you rewrite to reduce security risk?
A. https://www
B. https://www
C. https://www
D. https://www
View answer
Correct Answer: A
Question #17
An attacker attempts to send an SQL injection attack containing the known attack string 'root'; -- through an API call.Which FortiWeb inspection feature will be able to detect this attack the quickest?
A. API gateway rule
B. Known signatures
C. Machine learning (ML)-based API protection--anomaly detection
D. ML-based API protection--threat detection
View answer
Correct Answer: B
Question #18
Which implementation is most suited for a deployment that must meet PCI DSS compliance criteria?
A. SSL offloading with FortiWeb in reverse proxy mode
B. SSL offloading with FortiWeb in PCI DSS mode
C. SSL offloading with FortiWeb in transparency mode
D. SSL offloading with FortiWeb in full transparent proxy mode
View answer
Correct Answer: B
Question #19
Where in the controller interface can you find a wireless client's upstream and downstream link rates?
A. n the AP CLI, using the cw_diag ksta command
B. n the controller CLI, using the WiFi Client monitor
C. n the controller CLI, using the diag wireless-controller wlac -d sta command
D. n the AP CLI, using the cw_diag -d sta command
View answer
Correct Answer: A
Question #20
Refer to the exhibit.A FortiWeb device is deployed upstream of a device performing source network address translation (SNAT) or load balancing.What configuration must you perform on FortiWeb to preserve the original IP address of the client?
A. Enable and configure the Preserve Client IP setting
B. Use a transparent operating mode on FortiWeb
C. Enable and configure the Add X-Forwarded-For setting
D. Turn off NAT on the FortiWeb
View answer
Correct Answer: A
Question #21
You are using HTTP content routing on FortiWeb. Requests for web app A should be forwarded to a cluster of web servers which all host the same web app. Requests for web app B should be forwarded to a different, single web server.Which is true about the solution?
A. o achieve HTTP content routing, you must chain policies: the first policy accepts all traffic, and forwards requests for web app A to the virtual server for policy A
B. tatic or policy-based routes are not required
C. ou must put the single web server into a server pool in order to use it with HTTP content routing
D. he server policy applies the same protection profile to all its protected web apps
View answer
Correct Answer: A
Question #22
Review the following configuration:What are two routing behaviors that you can expect on FortiWeb after this configuration change? (Choose two.)
A. Non-HTTP traffic routed through the FortiWeb is allowed
B. IPv6 routing is enabled
C. Non-HTTP traffic destined to the FortiWeb virtual server IP address is dropped
D. Only ICMP traffic is allowed
View answer
Correct Answer: AC
Question #23
An attacker attempts to send an SQL injection attack containing the known attack string 'root'; -- through an API call.Which FortiWeb inspection feature will be able to detect this attack the quickest?
A. API gateway rule
B. Known signatures
C. Machine learning (ML)-based API protection—anomaly detection
D. ML-based API protection—threat detection
View answer
Correct Answer: B
Question #24
Which Layer 7 routing method does FortiWeb support?
A. GP
B. RL policy routing
C. SPF
D. TTP content routing
View answer
Correct Answer: D

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us