Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCP_FWB_AD-7.4 Exam - Topic 2 Question 23 Discussion

An attacker attempts to send an SQL injection attack containing the known attack string 'root'; -- through an API call.Which FortiWeb inspection feature will be able to detect this attack the quickest?
B) Known signatures
A) API gateway rule
C) Machine learning (ML)-based API protection---anomaly detection
D) ML-based API protection---threat detection

Fortinet FCP_FWB_AD-7.4 Exam - Topic 2 Question 23 Discussion

Actual exam question for Fortinet's FCP_FWB_AD-7.4 exam
Question #: 23
Topic #: 2
[All FCP_FWB_AD-7.4 Questions]

An attacker attempts to send an SQL injection attack containing the known attack string 'root'; -- through an API call.

Which FortiWeb inspection feature will be able to detect this attack the quickest?

Show Suggested Answer Hide Answer
Suggested Answer: B

The quickest detection for an SQL injection attack like the one described ('root'; --) would be through known signatures. FortiWeb utilizes signature-based detection to match incoming traffic against predefined attack patterns. Since SQL injection attacks are commonly known and have specific patterns (such as 'root'; --), known signatures would immediately recognize and flag this type of attack.


Contribute your Thoughts:

0/2000 characters
Lashawna
9 hours ago
I’m leaning towards the known signatures option too, but I wonder if the API gateway rule could also catch it quickly. It’s a tough choice!
upvoted 0 times
...
Valentine
6 days ago
I practiced a similar question, and I feel like machine learning-based detection could take longer to identify a known attack compared to signatures.
upvoted 0 times
...
Lindsey
11 days ago
I'm not entirely sure, but I remember something about API gateway rules being effective for specific patterns. Could that be the answer?
upvoted 0 times
...
Remona
16 days ago
I think the known signatures feature might be the quickest for detecting that specific SQL injection string since it's a well-known attack.
upvoted 0 times
...

Save Cancel