CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 11: NSE5_FWB_AD-8.0: Fortinet NSE 5 - FortiWeb 8.0 Administrator

You have configured parameter validation, file security, and machine learning (ML) anomaly detection for a web form, but some server-side request forgery tests are still succeeding. You need to advise the team on what to prioritize next to improve SSRF protection without compromising other parts of the application. Wh…

Nội dung câu hỏi

You have configured parameter validation, file security, and machine learning (ML) anomaly detection for a web form, but some server-side request forgery tests are still succeeding. You need to advise the team on what to prioritize next to improve SSRF protection without compromising other parts of the application. Which recommendation would best strengthen FortiWeb's ability to block remaining SSRF attempts?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Disable ML anomaly detection and rely solely on parameter inspection.
  2. B. Apply HTTPS inspection at the transport layer, which FortiWeb does not use to block SSRF.
  3. C. Offload all server-side request forgery (SSRF) protection to FortiGate and remove FortiWeb from the API flow.
  4. D. Review and refine input validation logic, as SSRF may be exploiting backend behavior or bypassing weak filters. — đáp án hiện tại

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề