Question 26
While reviewing FortiWeb logs, you notice a suspicious login request that failed authentication.
You suspect it may be part of an injection attack targeting the login form. Which input pattern is an example of a typical SQL injection attempt that could bypass authentication checks?
Question 27
Refer to the exhibit.
You are a FortiWeb administrator reviewing the biometrics-based detection rule shown in the exhibit.
Your goal is to configure a rule that detects bots that avoid typical human interactions like using a mouse or clicking. You also want to log the detection event and apply a high-severity alert.
Based on the current configuration, which settings should you change to meet this goal?
Question 28
Which two statements are true regarding FortiWeb operating in Offline Protection mode? (Choose two.)
Question 29
Drag and Drop Question
Refer to the exhibit.
You are a FortiWeb administrator reviewing how FortiAI protects sensitive data when interacting with a large language model (LLM).
Drag each label to the corresponding step in the FortiAI data privacy workflow.
Select the step in the left column, hold and drag it to a blank position in the column on the right.
Place the six correct steps in order, placing the first step in the position which is labeled as step 1.
Once you place a step, you can move it again if you want to change your answer before moving to the next question. You need to drop six steps in the work area.
Select and drag the screen divider to change the viewable area of the source and work areas.
Question 30
A web application requires that FortiWeb detect and block credential stuffing attempts where a botnet cycles through many username/password combinations. Which FortiWeb feature is best suited for this?

