Exit demo FCP_WCS_AD-7.4 FCP - AWS Cloud Security 7.4 Administrator PDF format · free preview

Fortinet FCP_WCS_AD-7.4 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/fcp-wcs-ad-74.html

Question 1
Multiple choice

A customer has implemented GWLB between the partner and application VPCs. FortiGate appliances are deployed in the partner VPC with multiple AZs to inspect traffic transparently.

Which two things will happen to application traffic based on the GWLB deployment? (Choose two.)

A.

Inbound and outbound traffic will go to multiple devices, which will perform load balancing.

B.

Inbound and outbound traffic will go to the same device, which will perform stateful processing.

C.

The content of the original traffic exchanged between the GWLB and FortiGate will be preserved.

D.

The original trafficexchangedbetween the GWLB and FortiGate will be hashed for data integrity.

Question 2
Single choice

An administrator needs to attach an Elastic Network Interface (ENI) to an application instance in a VPC with multiple availability zones. An instance runs in availability zone 1.

Which ENI property must the administrator consider when implementing this requirement?

A.

An ENI cannot attach to an instance in availability zone 2.

B.

After the ENI detaches from one instance, it can reattach only to the same instance.

C.

You can detach the primary ENI from an AWS instance.

D.

When you move an ENI, network traffic remains directed to the old instance until you terminate that instance.

Question 3
Multiple choice

Refer to the exhibit.

An administrator configured a FortiGate device to connect to the AWS API to retrieve resource values from the AWS console to create dynamic objects for the FortiGate policies. The administrator is unable to retrieve AWS dynamic objects on FortiGate.

Which two reasons can explain why? (Choose two.)

A.

The AWS API call is not supported on XML version 1.0.

B.

AWS was not able to validate credentials provided by the AWS Lab SDN connector because of a clock

skew between FortiGate and AWS.

C.

The AWS Lab SDN connector is configured with an invalid AWS access or secret key.

D.

The AWS Lab SDN connector failed to connect on port 401.

E.

The AWS Lab SDN did not find any instances in the configured VPC.

Question 4
Single choice

An administrator must deploy a web application firewall (WAF) solution to protect the web applications of their organization.

Why would the administrator choose FortiWeb Cloud over AWS WAF with Fortinet managed rules?

A.

WAF signatures must be manually updated by FortiGuard.

B.

The solution must meet PCI 6.6 compliance.

C.

SSL inspection is a requirement.

D.

Traffic must be inspected for malware.

Question 5
Multiple choice

Refer to the exhibit.

A customer is using the AWS Elastic Load Balancer (ELB).

Which two statements are correct about the ELB configuration? (Choose two.)

A.

The load balancer is configured to load balance traffic among multiple availability zones.

B.

The Amazon Resource Name is used to access the load balancer node and targets.

C.

You can use the DNS name to reach the targets behind the ELB.

D.

The load balancer is configured for the internal traffic of the virtual public cloud (VPC).

Question 6
Multiple choice

You are troubleshooting network connectivity issues between two VMs deployed in AWS.

One VM is a FortiGate located on subnet "LAN" that is part of the VPC "Encryption". The other VM is a Windows server located on the subnet "servers" which is also in the "Encryption" VPC. You are unable to

ping the Windows server from FortiGate.

What are two reasons for this? (Choose two.)

A.

The firewall in the Windows VM is blocking the traffic.

B.

The default AWS Network Access Control List (NACL) does not allow this traffic.

C.

By default, AWS does not allow ICMP traffic between subnets.

D.

Add an inbound allow ICMP rule in the security group attached to the windows server.

Question 7
Single choice

A customer is attempting to deploy an active-passive high availability (HA) cluster using the software-defined network (SDN) connector in the AWS cloud.

What is an important consideration to ensure a successful formation of HA, failover, and traffic flow?

A.

Both cluster members must be in the same availability zone.

B.

VDOM exceptions must be configured.

C.

Unicast FortiGate Clustering Protocol (FGCP) must be used.

D.

Both cluster members must show as healthy in the elastic load balancer (ELB) configuration.

Question 8
Multiple choice

Your organization is deciding between deploying an active-active (A-A) or active-passive (A-P) FortiGate high availability (HA) cluster in AWS cloud.

Which two statements are true about A-A clusters compared to A-P clusters? (Choose two.)

A.

For A-A clusters, FortiGate must perform SNAT inbound to ensure symmetric traffic flow.

B.

A-A clusters rely on API calls forsfailovers.

C.

A-A clusters always require a load balancer.

D.

A-A clusters can use a software-defined network (SDN) to perform a failover.

Question 9
Single choice

You want to deploy the Fortinet HA CloudFormation template to stage and bootstrap the FortiGate configuration in the same region in which you created your VPC, which is Ohio US-East-2.

Based on this information, which statement is correct?

A.

You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration. The S3 bucket can be hosted in any region.

B.

The Fortinet HA cloud formation template automatically creates an S3 bucket.

C.

You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration. The S3 bucket needs to be hosted in the Ohio US-East-2 region.

D.

You create a DynamoDB to stage and bootstrap FortiGate with an FGCP unicast configuration. It needs to be hosted in the Ohio US-East-2 region.

Question 10
Multiple choice

An AWS administrator is designing internet connectivity for an organization's virtual public cloud (VPC).
The organization has web servers with private addresses that must be reachable from the internet. The web servers must be highly available.

Which two configurations can you use to ensure the web servers are highly available and reachable from the internet? (Choose two.)

A.

Deploy a network load balancer.

B.

Configure a network address translation (NAT) Gateway in your VPC. Place web servers behind the
NAT Gateway.

C.

Add a route to the default virtual public cloud (VPC) route table forwarding all traffic to the internet gateway.

D.

Deploy web servers in multiple availability zones.

Showing 10 of 35 questions · Unlock the full set