Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE5_FWB_AD-8.0 Exam - Topic 3 Question 2 Discussion

A third-party penetration test reveals that users can bypass login controls through a mobile API. Your current FortiWeb configuration includes zero trust network access (ZTNA) profiles and cookie security, but API protection and client management are not enabled. The security team asks you to recommend the most effective way to close this gap.Which FortiWeb adjustment would best prevent future unauthorized API access?
B) Enable API protection and client management to enforce identity checks on mobile API traffic.
A) Switch to a reverse-proxy mode to bypass cookie-based controls.
C) Replace ZTNA with bot protection to reduce false positives.
D) Log only API traffic and rely on FortiAnalyzer for future alerts.

Fortinet NSE5_FWB_AD-8.0 Exam - Topic 3 Question 2 Discussion

Actual exam question for Fortinet's NSE5_FWB_AD-8.0 exam
Question #: 2
Topic #: 3
[All NSE5_FWB_AD-8.0 Questions]

A third-party penetration test reveals that users can bypass login controls through a mobile API. Your current FortiWeb configuration includes zero trust network access (ZTNA) profiles and cookie security, but API protection and client management are not enabled. The security team asks you to recommend the most effective way to close this gap.

Which FortiWeb adjustment would best prevent future unauthorized API access?

Show Suggested Answer Hide Answer
Suggested Answer: B

The issue is unauthorized access through a mobile API, so the control must enforce API-specific identity and access rules. FortiWeb API protection can validate API structure, methods, paths, and authorization requirements, while client management can help associate requests with legitimate clients or authenticated users. ZTNA profiles and cookie security can help with access and session protection, but they do not replace API-specific authorization controls. Switching reverse-proxy mode to bypass cookie controls makes no sense and could weaken protection. Replacing ZTNA with bot protection addresses a different problem: automation, not API authorization. Logging only records activity after the fact and does not prevent bypass. The correct action is to enable API protection and client management for mobile API traffic.

================


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel