New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE7_CDS_AR-7.6 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit.

Question # 11

In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet. However, your HTTPS connection to the FortiGate VM in the Customer VPC is not successful.

Also, you must ensure that the Customer VPC FortiGate VM sends all the outbound Internet traffic through the Security VPC.

How do you correct this issue with minimal configuration changes? (Choose three.)

Options:

A.

Add a route with your local internet public IP address as the destination and the internet gateway as the target.


B.

Add a route with your local internet public IP address as the destination and the transit gateway as the target.


C.

Add a route to the destination 0.0.0.0/0 with the transit gateway as the target.


D.

Deploy an internet gateway, associate an EIP with the Customer VPC private subnet, and then add a new route with destination 0.0.0.0/0 with the internet gateway as the target.


E.

Deploy an internet gateway, attach it to the Customer VPC, and then associate an EIP with the port1 of the FortiGate in the Customer VPC.


Expert Solution
Questions # 12:

An administrator implements FortiWeb ingress controller to protect containerized web applications in an AWS Elastic Kubernetes Service (EKS) cluster.

What can you conclude about the topology shown in FortiView?

Options:

A.

The FortiWeb VM gets the latest cluster information through an SDN connector.


B.

This topology has two services and two ingress controllers deployed.


C.

Both services will be load balanced among the two nodes and the four pods.


D.

Adding a new service will update the FortiWeb configuration automatically.


Expert Solution
Questions # 13:

An organization is deploying FortiDevSec to enhance security for containerized applications, and they need to ensure containers are monitored for suspicious behavior at runtime.

Which FortiDevSec feature is best for detecting runtime threats?

Options:

A.

FortiDevSec software composition analysis (SCA)


B.

FortiDevSec static application security testing (SAST)


C.

FortiDevSec dynamic application security testing (DAST)


D.

FortiDevSec container scanner


Expert Solution
Questions # 14:

Refer to the exhibit.

An experienced AWS administrator is creating a new virtual public cloud (VPC) flow log with the settings shown in the exhibit.

What is the purpose of this configuration?

Options:

A.

To maximize the number of logs saved


B.

To monitor logs in real time


C.

To retain logs for a long term


D.

To troubleshoot a log flow issue


Expert Solution
Questions # 15:

Refer to the exhibit.

You deployed an HA active-active load balance sandwich with two FortiGate VMs in Microsoft Azure.

After the deployment, you prefer to use FGSP to synchronize sessions, and allow asymmetric return traffic. In the environment, FortiGate port 1 and port 2 are facing external and internal load balancers respectively.

What IP address must you use in the peerip configuration?

Options:

A.

The opposite FortiGate port 2 IP address.


B.

The public load balancer port 2 IP address.


C.

The internal load balancer port 1 IP address.


D.

The opposite FortiGate port 1 IP address.


Expert Solution
Questions # 16:

Refer to the exhibit.

Question # 16

You are managing an active-passive FortiGate HA cluster in AWS that was deployed using CloudFormation. You have created a change set to examine the effects of some proposed changes to the current infrastructure. The exhibit shows some sections of the change set.

What will happen if you apply these changes?

Options:

A.

This deployment can be done without any traffic interruption.


B.

Both FortiGate VMs will get a new PhysicalResourceId.


C.

The updated FortiGate VMs will not have the latest configuration changes.


D.

CloudFormation checks if you will surpass your account quota.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions