Fortinet NSE5_FWB_AD-8.0 Practice Exam Questions & Answers

6 Free Questions · Last reviewed: October 6, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

Fortinet NSE5_FWB_AD-8.0 Exam Details

Key details for this exam, checked against the published exam outline

36 Practice Questions (Our Bank)
75 minutes Exam Duration
USD 200 Official Exam Fee
Exam Code
NSE5_FWB_AD-8.0
Full Name
Fortinet NSE 5 - FortiWeb 8.0 Administrator
Issuing Body
Fortinet
Question Format (Our Bank)
Multiple Choice, Drag & Drop
Delivery
Pearson VUE test centre or online proctored (OnVUE)
Eligibility
3 years networking experience, 1 year network security experience, 6 months hands-on FortiWeb experience recommended
Validity
2 years from exam completion date
Practice Questions

Free NSE5_FWB_AD-8.0 Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our NSE5_FWB_AD-8.0 exam preparation team, who also write the explanation shown with each one. How we research and review these pages

Refer to the exhibits.

A new domain, https://finance.fortinet.demo, was added but not explicitly mapped. Users report the site loads correctly, but you're unsure which back-end server is being used.

Why is this request succeeding despite no explicit routing rule for finance.fortinet.demo?

Correct Answer: D
Explanation

The exhibit shows FortiWeb using HTTP content routing, with multiple routing policies and one policy marked as the default. The domain finance.fortinet.demo does not match the explicit routing rules shown, so FortiWeb falls back to the default HTTP content routing entry. In the policy table, app_server_1 is marked as the default route, meaning unmatched requests are sent to that server pool. The certificate does not determine back-end routing; it only supports TLS identity. FortiWeb does not automatically create routing policies for new domains, and the request is not passed to FortiGate for secondary content routing. Because no explicit hostname match exists, the default content routing policy handles the request.

A FortiWeb administrator needs to allow a known web indexer to scan the website for search engine visibility.

What is the easiest way to allow this on FortiWeb?

Correct Answer: C
Explanation

FortiWeb bot mitigation separates malicious bots from useful bots such as legitimate search engine crawlers. The FortiGuard Known Search Engines category is designed for this exact use case: allowing recognized search engines to crawl and index protected websites without being treated as hostile automation. Adding a source IP to a general trusted IP list may allow the crawler, but it is broader than necessary because it can bypass more protections than intended. An inline profile exception is more manual and less clean. User-agent exceptions are weak because user-agent strings are easy to spoof. The best FortiWeb-native approach is to use the known search engine handling within bot mitigation so legitimate indexing remains available while malicious bots remain controlled.

Refer to the exhibit.

A FortiWeb administrator is trying to enable policy-based traffic logging on FortiWeb but doesn't see the traffic log option available in the server policy settings.

What is the most likely reason this option is not visible?

Correct Answer: C
Explanation

Traffic logging is more storage-intensive than normal event or attack logging, so FortiWeb does not always expose policy traffic-log selection by default. The Study Guide states that traffic logs must be enabled from the CLI before they can be selected in a server policy. This matches the exhibit: the administrator is in the server policy wizard but cannot see the traffic log option. FortiAnalyzer or FortiSIEM can receive logs, but they do not make the policy option appear. Deployment mode is also not the determining factor here. FortiAppSec Cloud licensing is unrelated. The correct cause is that global traffic logging must first be enabled manually through the CLI, after which policy-based traffic logging can be selected.

Refer to the exhibit.

You are configuring SSL offloading on FortiWeb to protect a public-facing application. Clients connect using HTTPS, while FortiWeb forwards requests to the back-end server using HTTP.

You are reviewing certificate deployment and need to decide where to install the private key for the certificate used in client connections.

In this SSL offloading setup, which device is responsible for using the private key associated with the web server certificate?

Correct Answer: A
Explanation

In SSL offloading, FortiWeb is the TLS endpoint for client connections. The client negotiates HTTPS with FortiWeb, not directly with the back-end web server. Therefore, FortiWeb must have the website certificate and associated private key so it can complete the TLS handshake, decrypt inbound HTTPS traffic, inspect the HTTP content, and then forward the request to the server using HTTP or a separate back-end connection. Option B is wrong because TLS termination requires the private key. Option C describes SSL inspection or direct server termination, not offloading. Option D is wrong because clients verify the certificate but do not possess or use the server's private key. FortiWeb owns the private-key function in this design.

Refer to the exhibit.

There is only one administrator account configured on FortiWeb and IPv6 is not configured on any interface.

Which action should an administrator take to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?

Correct Answer: B
Explanation

The exhibit shows the administrator account using IPv4 trusted hosts with a broad entry that effectively allows management access attempts from any IPv4 source. To reduce brute force exposure against the FortiWeb GUI, the administrator should restrict the trusted host entry to a specific trusted management IP address or subnet. FortiWeb administrator accounts can be limited by trusted host settings, so only defined source addresses can even attempt to authenticate. Changing the upstream device may help, but FortiWeb should still enforce its own management access restriction. Deleting the built-in administrator account does not solve the source-access problem. Changing the access profile to read-only only limits privileges after login; it does not prevent brute force attempts against the GUI.

You are reviewing SSL-related issues on FortiWeb. An administrator reports that they receive a certificate warning when they access the FortiWeb GUI over HTTPS. Separately, your FortiWeb device also makes outbound HTTPS requests to a back-end API server.

In which two situations would FortiWeb use its own certificates to establish or secure the connection? (Choose two.)

Correct Answer: C, D
Explanation

The correct answers are C and D. FortiWeb uses its own built-in/self-signed or configured server certificate when an administrator connects to the FortiWeb GUI over HTTPS. FortiWeb can also authenticate as a client when it connects to protected back-end servers over HTTPS, and it may present its own certificate for client PKI authentication. Option A is wrong because transparent inspection mode does not make FortiWeb the SSL endpoint in the same way; it inspects traffic without acting as the primary TLS termination point. Option B is also wrong because simply routing HTTPS without decryption does not require FortiWeb to present its own certificate. FortiWeb certificates matter when FortiWeb is an HTTPS endpoint or an authenticated HTTPS client.

Full Access

Get the complete NSE5_FWB_AD-8.0 question set

  • 36 questions covering all exam domains
  • Correct answers with explanations, like the free questions above
  • PDF and online practice test
  • 90 days of free updates
Starting from 50% OFF
$20 $40
Get Full Access

One-time payment · Instant download

Study Guide

What the Fortinet NSE5_FWB_AD-8.0 Exam Covers

Exam domains verified against: Official Fortinet NSE5_FWB_AD-8.0 exam guide, last checked October 2026.

Domain 1: Deployment and configuration

Understand FortiWeb deployment methods, operation modes, and basic administration. Configure server objects, policies, and implement SSL inspection, offloading, and high availability clustering to ensure secure and efficient web application protection in your network.

Sample questions from this domain above: Q1Q2Q6

Domain 2: Web application and API security with botnet mitigation

Apply security best practices to protect web applications and APIs from OWASP Top 10 threats. Configure API discovery and protection, implement bot mitigation strategies, and tune security profiles to defend against sophisticated automated attacks and zero-day exploits.

Sample questions from this domain above: Q4Q5

Domain 3: Application delivery and additional configuration

Optimize application delivery for performance and reliability while maintaining security. Implement denial of service protections, configure logging and monitoring, and leverage FortiAI machine learning features to improve protection and operational visibility.

Domain 4: Compliance and troubleshooting

Troubleshoot deployment and system-related issues to resolve configuration problems and performance bottlenecks. Implement web vulnerability scans, analyze security events, and validate compliance with security policies and regulatory requirements in your FortiWeb environment.

Sample question from this domain above: Q3

FAQ

NSE5_FWB_AD-8.0 Exam FAQ

Common questions about the exam itself

What does the NSE5_FWB_AD-8.0 exam test and who should take it?
This exam tests your ability to deploy, configure, administer, manage, and monitor FortiWeb devices to protect web applications and APIs from sophisticated attacks. It is intended for security professionals, WAF administrators, and network engineers responsible for FortiWeb administration in small to medium enterprise environments.
What background and experience do I need before attempting NSE5_FWB_AD-8.0?
Fortinet recommends at least 3 years of general networking experience, 1 year in network security roles, and 6 months of hands-on experience with FortiWeb devices. Passing NSE 4 FortiOS Administrator first helps you build foundational knowledge of Fortinet platforms and security concepts.
How much time should I spend preparing for this exam?
Preparation time varies based on your background, but most candidates need 4 to 8 weeks of regular study combined with hands-on lab practice. If you already hold NSE 4 certification and have FortiWeb experience, you may need less time. The Fortinet training course covers about 9 hours of structured content.
What is the exam format and how much time do I get?
The exam consists of 35 to 40 multiple choice and multiple select questions. You have 75 minutes to complete it, which averages about 2 minutes per question. Questions are scored pass or fail with no partial credit, and you receive your result immediately after finishing.
What is the exam fee and where do I take it?
The exam costs USD 200. You can take it at a Pearson VUE testing centre or online through OnVUE proctoring from home. You schedule directly through Pearson VUE and can reschedule or cancel up to 24 hours before your appointment.
What is the passing score and how is it calculated?
Fortinet does not publish the exact passing score or percentage. The exam uses a pass or fail scoring method with no scaled score. Based on candidate reports, you typically need approximately 70 percent of questions correct to pass, but this is not officially confirmed.
How long is my NSE5_FWB_AD-8.0 certification valid and what do I do when it expires?
Your certification is valid for 2 years from the date you pass the exam. To renew it, you must pass the current version of an NSE 5 FortiWeb exam or achieve a higher-level certification such as NSE 6 or NSE 8 before your certification expires.
How does NSE5_FWB_AD-8.0 relate to the FCP in Cloud Security certification?
Passing NSE5_FWB_AD-8.0 is one of two exams required for the FCP in Cloud Security credential. You must also pass the NSE 4 FortiOS Administrator exam within 2 years. Once you pass both exams, you earn the FCP in Cloud Security certification, which remains valid for 2 years.
What is the difference between NSE 5 FortiWeb and NSE 6 FortiWeb exams?
NSE 5 FortiWeb focuses on core administration, deployment, configuration, and day-to-day management of FortiWeb in typical enterprise environments. NSE 6 FortiWeb covers more advanced topics, complex troubleshooting, and specialized configurations. NSE 5 is sufficient for most security roles. NSE 6 is for senior engineers and FortiWeb specialists.
Can I retake NSE5_FWB_AD-8.0 if I fail, and are there any restrictions?
Yes, you can retake the exam. There is no official waiting period between attempts announced by Fortinet, but each new exam attempt requires a new USD 200 voucher. You schedule retakes through Pearson VUE just like your initial attempt.