Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Refer to the exhibits.


A new domain, https://finance.fortinet.demo, was added but not explicitly mapped. Users report the site loads correctly, but you're unsure which back-end server is being used.
Why is this request succeeding despite no explicit routing rule for finance.fortinet.demo?
The exhibit shows FortiWeb using HTTP content routing, with multiple routing policies and one policy marked as the default. The domain finance.fortinet.demo does not match the explicit routing rules shown, so FortiWeb falls back to the default HTTP content routing entry. In the policy table, app_server_1 is marked as the default route, meaning unmatched requests are sent to that server pool. The certificate does not determine back-end routing; it only supports TLS identity. FortiWeb does not automatically create routing policies for new domains, and the request is not passed to FortiGate for secondary content routing. Because no explicit hostname match exists, the default content routing policy handles the request.
A FortiWeb administrator needs to allow a known web indexer to scan the website for search engine visibility.
What is the easiest way to allow this on FortiWeb?
FortiWeb bot mitigation separates malicious bots from useful bots such as legitimate search engine crawlers. The FortiGuard Known Search Engines category is designed for this exact use case: allowing recognized search engines to crawl and index protected websites without being treated as hostile automation. Adding a source IP to a general trusted IP list may allow the crawler, but it is broader than necessary because it can bypass more protections than intended. An inline profile exception is more manual and less clean. User-agent exceptions are weak because user-agent strings are easy to spoof. The best FortiWeb-native approach is to use the known search engine handling within bot mitigation so legitimate indexing remains available while malicious bots remain controlled.
Refer to the exhibit.


A FortiWeb administrator is trying to enable policy-based traffic logging on FortiWeb but doesn't see the traffic log option available in the server policy settings.
What is the most likely reason this option is not visible?
Traffic logging is more storage-intensive than normal event or attack logging, so FortiWeb does not always expose policy traffic-log selection by default. The Study Guide states that traffic logs must be enabled from the CLI before they can be selected in a server policy. This matches the exhibit: the administrator is in the server policy wizard but cannot see the traffic log option. FortiAnalyzer or FortiSIEM can receive logs, but they do not make the policy option appear. Deployment mode is also not the determining factor here. FortiAppSec Cloud licensing is unrelated. The correct cause is that global traffic logging must first be enabled manually through the CLI, after which policy-based traffic logging can be selected.
Refer to the exhibit.

You are configuring SSL offloading on FortiWeb to protect a public-facing application. Clients connect using HTTPS, while FortiWeb forwards requests to the back-end server using HTTP.
You are reviewing certificate deployment and need to decide where to install the private key for the certificate used in client connections.
In this SSL offloading setup, which device is responsible for using the private key associated with the web server certificate?
In SSL offloading, FortiWeb is the TLS endpoint for client connections. The client negotiates HTTPS with FortiWeb, not directly with the back-end web server. Therefore, FortiWeb must have the website certificate and associated private key so it can complete the TLS handshake, decrypt inbound HTTPS traffic, inspect the HTTP content, and then forward the request to the server using HTTP or a separate back-end connection. Option B is wrong because TLS termination requires the private key. Option C describes SSL inspection or direct server termination, not offloading. Option D is wrong because clients verify the certificate but do not possess or use the server's private key. FortiWeb owns the private-key function in this design.
Refer to the exhibit.

There is only one administrator account configured on FortiWeb and IPv6 is not configured on any interface.
Which action should an administrator take to restrict any brute force attacks that attempt to gain access to the FortiWeb management GUI?
The exhibit shows the administrator account using IPv4 trusted hosts with a broad entry that effectively allows management access attempts from any IPv4 source. To reduce brute force exposure against the FortiWeb GUI, the administrator should restrict the trusted host entry to a specific trusted management IP address or subnet. FortiWeb administrator accounts can be limited by trusted host settings, so only defined source addresses can even attempt to authenticate. Changing the upstream device may help, but FortiWeb should still enforce its own management access restriction. Deleting the built-in administrator account does not solve the source-access problem. Changing the access profile to read-only only limits privileges after login; it does not prevent brute force attempts against the GUI.
You are reviewing SSL-related issues on FortiWeb. An administrator reports that they receive a certificate warning when they access the FortiWeb GUI over HTTPS. Separately, your FortiWeb device also makes outbound HTTPS requests to a back-end API server.
In which two situations would FortiWeb use its own certificates to establish or secure the connection? (Choose two.)
The correct answers are C and D. FortiWeb uses its own built-in/self-signed or configured server certificate when an administrator connects to the FortiWeb GUI over HTTPS. FortiWeb can also authenticate as a client when it connects to protected back-end servers over HTTPS, and it may present its own certificate for client PKI authentication. Option A is wrong because transparent inspection mode does not make FortiWeb the SSL endpoint in the same way; it inspects traffic without acting as the primary TLS termination point. Option B is also wrong because simply routing HTTPS without decryption does not require FortiWeb to present its own certificate. FortiWeb certificates matter when FortiWeb is an HTTPS endpoint or an authenticated HTTPS client.
Exam domains verified against: Official Fortinet NSE5_FWB_AD-8.0 exam guide, last checked October 2026.
Understand FortiWeb deployment methods, operation modes, and basic administration. Configure server objects, policies, and implement SSL inspection, offloading, and high availability clustering to ensure secure and efficient web application protection in your network.
Apply security best practices to protect web applications and APIs from OWASP Top 10 threats. Configure API discovery and protection, implement bot mitigation strategies, and tune security profiles to defend against sophisticated automated attacks and zero-day exploits.
Optimize application delivery for performance and reliability while maintaining security. Implement denial of service protections, configure logging and monitoring, and leverage FortiAI machine learning features to improve protection and operational visibility.
Troubleshoot deployment and system-related issues to resolve configuration problems and performance bottlenecks. Implement web vulnerability scans, analyze security events, and validate compliance with security policies and regulatory requirements in your FortiWeb environment.
Sample question from this domain above: Q3
Common questions about the exam itself