| Exam Code/Number: | NSE5_FWB_AD-8.0Join the discussion |
| Exam Name: | Fortinet NSE 5 - FortiWeb 8.0 Administrator |
| Certification: | Fortinet |
| Question Number: | 63 |
| Publish Date: | Aug 29, 2026 |
|
Rating
100%
|
|
An administrator is troubleshooting why FortiWeb is not decrypting HTTPS traffic for inspection in reverse proxy mode. What is the most likely missing configuration?
You are setting up a FortiWeb policy to protect a customer login portal. Users connect to
https://login.training.lab, and you want FortiWeb to forward those requests to a load-balanced pool of back-end servers. Which three components must you configure to complete the server policy?
Refer to the exhibit.
You are a FortiWeb administrator. FortiWeb is deployed between a FortiGate and two back-end web servers, as shown in the diagram. No server policies are currently configured on FortiWeb.
While testing, you notice that a student system in the 100.64.0.0/24 network is still able to access the back-end servers in 10.1.1.0/24, even though FortiWeb is not logging or inspecting the traffic.
Which action should you take to ensure FortiWeb blocks or inspects all traffic before it reaches the back-end servers?
Refer to the exhibit.
What is does the exhibit show?
You have configured parameter validation, file security, and machine learning (ML) anomaly detection for a web form, but some server-side request forgery tests are still succeeding. You need to advise the team on what to prioritize next to improve SSRF protection without compromising other parts of the application. Which recommendation would best strengthen FortiWeb's ability to block remaining SSRF attempts?