View all questions & answers for the NSE 5 - FortiWeb 8.0 Administrator Exam Materials exam
NSE 5 - FortiWeb 8.0 Administrator Exam Materials-Question 43 Discussion
Comments
Selected Answers: No answers selected
The item "HTTP header request" is an incorrect distractor because it refers to a generic network function rather than a security mechanism.
Here is why Cross-Origin Resource Sharing (CORS) protection fits Stage 1, while "HTTP header request" does not:
Why CORS protection belongs in Stage 1: CORS is a proactive security policy. By explicitly declaring which external origins are authorized to interact with your application's resources, you establish a boundary that prevents unauthorized cross-origin requests from occurring in the first place.
Why "HTTP header request" is incorrect: An HTTP header request is simply standard web communication (the way browsers request data from a server). It is not a security defense or a configuration control that prevents attacks.
You are configuring the FortiWeb client-side protection feature to defend against browser-based attacks. Based on the layered defense strategy, drag and drop each control to the corresponding stage of defense. Select the step in the left column, hold and drag it to a blank position in the column on the right. Place the three correct steps in order, placing the first step in the position which is labeled as step 1. Once you place a step, you can move it again if you want to change your answer before moving to the next question. You need to drop three steps in the work area. Select and drag the screen divider to change the viewable area of the source and work areas. (Invalid number of answers)
Brave-Dump Clients Votes