Pass the Fortinet Public Cloud Security FCP_WCS_AD-7.4 Questions and answers with CertsForce

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

Traffic is initiated from the EC2 instance and is destined for the internet.

Which traffic flow is correct?

Options:

A.

EC2 instance > NAT GW > IGW > internet


B.

There is no route to the internet in the Private Route Table. The traffic does not reach the internet.


C.

EC2 instance > GWLBe > NAT GW > IGW > internet


D.

EC2 instance > GWLBe > internet


Expert Solution
Questions # 2:

Which three statements correctly describe FortiGate Cloud-Native Firewall (CNF)? (Choose three.)

Options:

A.

It provides carrier-grade protection.


B.

It scales seamlessly.


C.

It uses AWS Elastic Load Balancing (ELB).


D.

It is considered to be a Firewall-as-a-Service (FWaaS).


E.

It can be managed by FortiManager and AWS firewall manager.


Expert Solution
Questions # 3:

Your organization is deciding between deploying FortiWeb VM or Fortinet Managed Rules for AWS WAF.

What are two benefits of choosing FortiWeb VM? (Choose two.)

Options:

A.

Only pay for what is used.


B.

Up-to-date WAF signatures powered by FortiGuard.


C.

Zero-day protection.


D.

Advanced WAF functionality.


Expert Solution
Questions # 4:

Refer to the exhibit.

Question # 4

Which statement is correct about the VPC peering connections shown in the exhibit?

Options:

A.

To route packets directly from VPC B to VPC C through VPC A, you must add a route for network 192.168.0.0/16 in the VPC A routing table.


B.

You cannot route packets directly from VPC B to VPC C through VPC A.


C.

You can associate VPC ID pcx-23232323 with VPC B to form a VPC peering connection between VPC B and VPC C.


D.

You cannot create a separate VPC peering connection between VPC B and VPC C to route packets directly.


Expert Solution
Questions # 5:

A customer is attempting to deploy an active-passive high availability (HA) cluster using the software-defined network (SDN) connector in the AWS cloud.

What is an important consideration to ensure a successful formation of HA, failover, and traffic flow?

Options:

A.

Both cluster members must be in the same availability zone.


B.

VDOM exceptions must be configured.


C.

Unicast FortiGate Clustering Protocol (FGCP) must be used.


D.

Both cluster members must show as healthy in the elastic load balancer (ELB) configuration.


Expert Solution
Questions # 6:

An organization has the requirement to connect a data VPC to the on-premises infrastructure of a branch office in a hybrid cloud environment. The connectivity needs the higher bandwidth but the organization does not want to use multiple connections between sites.

Which AWS solution meets the requirement?

Options:

A.

Transit VPC with IPSec


B.

Internet Gateway


C.

Transit Gateway multicast


D.

Transit Gateway Connect


Expert Solution
Questions # 7:

A customer has deployed FortiGate Cloud-Native Firewall (CNF).

Which two statements are correct about policy sets? (Choose two.)

Options:

A.

There is an implicit deny rule at the bottom of the policy set.


B.

The policy set must be manually synchronized to the CNF instance each time it is modified.


C.

A new policy set is created with each deployed CNF instance.


D.

Multiple policy sets can be applied to a single CNF instance.


Expert Solution
Questions # 8:

You are troubleshooting network connectivity issues between two VMs deployed in AWS.

One VM is a FortiGate located on subnet "LAN" that is part of the VPC "Encryption". The other VM is a Windows server located on the subnet "servers" which is also in the "Encryption" VPC. You are unable to ping the Windows server from FortiGate.

What are two reasons for this? (Choose two.)

Options:

A.

The firewall in the Windows VM is blocking the traffic.


B.

The default AWS Network Access Control List (NACL) does not allow this traffic.


C.

By default, AWS does not allow ICMP traffic between subnets.


D.

Add an inbound allow ICMP rule in the security group attached to the windows server.


Expert Solution
Questions # 9:

An organization has created a VPC with two subnets and deployed a FortiGate-VM (VM04/c4.xlarge) in AWS.

The EC2 instance is initially configured with two Elastic Network Interfaces (ENIs). The primary ENI is configured on the public subnet, and the secondary ENI is configured on the private subnet. To provide internet access for the FortiGate-VM, they now want to associate an EIP to its primary ENI, but the assignment is failing.

Which action would allow the EIP assignment to be successful?

Options:

A.

Create and associate a public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI.


B.

Shut down the FortiGate VM, if it is running, assign the EIP to the primary ENI, and then power it on.


C.

Create and attach an internet gateway to the VPC, and then assign the EIP to the primary ENI of the FortiGate VM.


D.

Create and attach a public routing table to the public subnet, associate the public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI.


Expert Solution
Questions # 10:

Refer to the exhibit.

Question # 10

What occurs during a failover for an active-passive (A-P) cluster that is deployed in two different availability zones? (Choose two.)

Options:

A.

The cluster elastic IP address (EIP) is moved from Port1 of FGT-1 to Port1 of FGT-2.


B.

The secondary IP address of Port2 of FGT-1 is moved to Port2 of FGT-2.


C.

The default static route in the Private-AZ1 subnet route table is modified to forward all traffic to Port2 of FGT2.


D.

An additional route is added to the route table of the HA Sync AZ2 subnet to forward all traffic to the Internet GW.


Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions