A client is trying to start a session from a page that should normally be accessible only after they have logged in. When a start page rule detects the invalid session access, what can FortiWeb do? (Choose three.)
An attacker attempts to send an SQL injection attack containing the known attack string 'root'; -- through an API call. Which FortiWeb inspection feature will be able to detect this attack the quickest?