WAF01-05 Web Application Firewall -
Foundation
A newly created service has the following protection policy associated to it: - ANS-New services
do now not have any security regulations with the aid of default.
Passive
Custom
*Default*
Active
A security coverage may be assigned to only one service. Additional security rules should be
created if more services are delivered into the system. - ANS-False
Access logs are disabled by means of default and must be enabled on the Service
Configuration web page. - ANS-false
Antivirus signatures are updated even though the Energize Updates license has expired. -
ANS-fake
Bot mitigation policies can be used... - ANS-...To enforce limits within the TCP window length.
*...To permit credential stuffing safety.*
*...To restrict the amount of general requests to a selected a part of a web software.*
...To enforce limits in HTTP headers.
By the use of the WAF Access Control feature, Audit logs may be used to track the hobby of
customers logged into the web utility. - ANS-FALSE
Changing the device time area calls for a gadget reboot only if services are configured. -
ANS-fake
Client Fingerprints are enabled by default... - ANS-.. But may be disabled on the server.
*... However can be disabled at the provider.*
... And can not be disabled.
... But can be disabled at the libraries.
Clustering is initiated the usage of which interface? - ANS-br0
*WAN*
LAN
MANAGEMENT
, Data saved with the aid of the caching capability is saved in the... - ANS-...Internal MySQL
database.
...Difficult disks.
*...RAM.*
...SSDs and then moved to the difficult disks after the max age is expired.
Dual authentication is best to be had... - ANS-With the neighborhood authentication carrier.
*If LDAP is used as primary authentication provider.*
If KERBEROS is used as number one authentication provider.
If LDAP and KERBEROS are used as number one authentication services.
Extended Match policies can best be used in Bot mitigation policies. - ANS-False
If you want to fit a particular referer or parameter in an HTTP request, you want to use... -
ANS-...A URL Match rule.
...A Host Match rule.
*...An Extended Match rule.*
Since the Referer is contained in the IP packet header, the WAF can't retrieve this kind of data.
If you want to create signed certificates with Let's Encrypt... - ANS-.. The domain of the service
need to be on hand at port 443.
*... The provider ought to be in energetic mode.*
*... The domain of the provider have to be handy at port 80.*
... The service need to be in passive mode.
If you need to defend your logins in opposition to credential stuffing, you require an ABP license.
- ANS-True
In the 'Negative Security' model... - ANS-...The WAF configuration is best modified at some
stage in the initial setup.
...The entirety is blocked unless explicitly allowed.
*...Handiest specific styles are blocked. Everything else is permitted.*
...A very strict dating is hooked up between a web software and the WAF configuration.
In the 'Positive Security' version... - ANS-...Best unique patterns are blocked. Everything else is
allowed.
...Modifications to the net utility no longer pondered in the WAF configuration would possibly
result in false positives.
...The whole lot is blocked unless explicitly allowed. (1)
...The WAF configuration is simplest changed at some stage in the initial setup. (1)
(F)
In the Bridge-Path deployment... - ANS-...The LAN interface must face the Internet.
Foundation
A newly created service has the following protection policy associated to it: - ANS-New services
do now not have any security regulations with the aid of default.
Passive
Custom
*Default*
Active
A security coverage may be assigned to only one service. Additional security rules should be
created if more services are delivered into the system. - ANS-False
Access logs are disabled by means of default and must be enabled on the Service
Configuration web page. - ANS-false
Antivirus signatures are updated even though the Energize Updates license has expired. -
ANS-fake
Bot mitigation policies can be used... - ANS-...To enforce limits within the TCP window length.
*...To permit credential stuffing safety.*
*...To restrict the amount of general requests to a selected a part of a web software.*
...To enforce limits in HTTP headers.
By the use of the WAF Access Control feature, Audit logs may be used to track the hobby of
customers logged into the web utility. - ANS-FALSE
Changing the device time area calls for a gadget reboot only if services are configured. -
ANS-fake
Client Fingerprints are enabled by default... - ANS-.. But may be disabled on the server.
*... However can be disabled at the provider.*
... And can not be disabled.
... But can be disabled at the libraries.
Clustering is initiated the usage of which interface? - ANS-br0
*WAN*
LAN
MANAGEMENT
, Data saved with the aid of the caching capability is saved in the... - ANS-...Internal MySQL
database.
...Difficult disks.
*...RAM.*
...SSDs and then moved to the difficult disks after the max age is expired.
Dual authentication is best to be had... - ANS-With the neighborhood authentication carrier.
*If LDAP is used as primary authentication provider.*
If KERBEROS is used as number one authentication provider.
If LDAP and KERBEROS are used as number one authentication services.
Extended Match policies can best be used in Bot mitigation policies. - ANS-False
If you want to fit a particular referer or parameter in an HTTP request, you want to use... -
ANS-...A URL Match rule.
...A Host Match rule.
*...An Extended Match rule.*
Since the Referer is contained in the IP packet header, the WAF can't retrieve this kind of data.
If you want to create signed certificates with Let's Encrypt... - ANS-.. The domain of the service
need to be on hand at port 443.
*... The provider ought to be in energetic mode.*
*... The domain of the provider have to be handy at port 80.*
... The service need to be in passive mode.
If you need to defend your logins in opposition to credential stuffing, you require an ABP license.
- ANS-True
In the 'Negative Security' model... - ANS-...The WAF configuration is best modified at some
stage in the initial setup.
...The entirety is blocked unless explicitly allowed.
*...Handiest specific styles are blocked. Everything else is permitted.*
...A very strict dating is hooked up between a web software and the WAF configuration.
In the 'Positive Security' version... - ANS-...Best unique patterns are blocked. Everything else is
allowed.
...Modifications to the net utility no longer pondered in the WAF configuration would possibly
result in false positives.
...The whole lot is blocked unless explicitly allowed. (1)
...The WAF configuration is simplest changed at some stage in the initial setup. (1)
(F)
In the Bridge-Path deployment... - ANS-...The LAN interface must face the Internet.