Question 11
You are reviewing a report from your FortiWeb logs and notice a JavaScript payload like
<script>document.cookie</script> submitted through a product review form. The page doesn't filter the script, and users who view the review have their session cookies exposed. Which type of attack does this scenario represent?
Question 12
You are a FortiWeb administrator investigating an SQL injection attack on your company's customer portal.
The network firewall and intrusion prevention system (IPS) did not stop the attack.
You decide to deploy a web application firewall (WAF) to help prevent this type of attack.
Which two actions can you take to block application-layer threats? (Choose two.)
Question 13
A FortiWeb administrator needs to allow a known web indexer to scan the website for search engine visibility.
What is the easiest way to allow this on FortiWeb?
Question 14
You are hosting multiple secure web applications behind a single public IP address on FortiWeb.
When a client connects to a service, FortiWeb needs to:
* Identify the correct SSL certificate.
* Decrypt the request.
* Route the request to the correct back-end server.
Match each FortiWeb function to the request handling step that performs the function.
Question 15
A FortiWeb administrator needs to distribute traffic geographically across data centers in different regions for disaster recovery and performance. Which feature accomplishes this?


