An administrator must deploy a web application firewall (WAF) solution to protect the web applications of their organization. Why would the administrator choose FortiWeb Cloud over AWS WAF with Fortinet managed rules?
A.
WAF signatures must be manually updated by FortiGuard.
Study guide page 111
Both Fortiweb cloud and AWS WAF with Fortinet managed rules supports "Meet PCI 6.6 compliance" and "SSL inspection".
There is no malware protection in AWS WAF partner rules because there is no engine to protect malware. FortiWeb Cloud, on the other hand, extends beyond signature-based web protection and can inspect the traffic for malware.
C. SSL inspection is a requirement.
FortiWeb Cloud offers SSL inspection capabilities, allowing it to inspect encrypted traffic (HTTPS) and provide deeper protection for web applications. If SSL inspection is a key requirement, FortiWeb Cloud would be preferred over AWS WAF with Fortinet managed rules, as AWS WAF does not natively support SSL decryption and inspection without additional configuration.
Here’s why the other options are less relevant:
A: WAF signatures are automatically updated by FortiGuard, so manual updates are not required for either solution.
B: Both FortiWeb Cloud and AWS WAF with Fortinet managed rules can help meet PCI 6.6 compliance.
D: Traffic inspection for malware is typically handled by a security solution beyond just WAF functionality. FortiWeb Cloud provides more advanced protection, but malware inspection is not the primary factor in this comparison.
D should be correct. WAF & Forti can do Web Attack Signatures, PCI 6.6 Comp. and SSL Inspection. Study Guide 7.4 Page 11 -> WAF cannot do Antivirus/Antimalware, while FortiWeb can.
Explanation:
SSL inspection is a requirement:
Correct: FortiWeb Cloud provides advanced SSL inspection capabilities, which allow it to decrypt and inspect SSL/TLS traffic to detect threats hidden in encrypted traffic. AWS WAF, on the other hand, typically requires additional configuration or integration with other services to handle SSL inspection effectively.
this answer is SSL inspection, as both options offer PCI 6.6. Compliance.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
havokdu
4 weeks agomyrmidon3
2 months, 3 weeks agoe5c20bb
4 months, 3 weeks agoSpawni81
4 months, 4 weeks agoyakisiklisubay
4 months, 4 weeks agothe_giant
5 months, 1 week agosclu650
7 months agosclu650
7 months ago