Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Fortinet Public Cloud Security FCP_WCS_AD-7.4 Questions and answers with ValidTests

Exam FCP_WCS_AD-7.4 All Questions
Exam FCP_WCS_AD-7.4 Premium Access

View all detail and faqs for the FCP_WCS_AD-7.4 exam

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

Traffic is initiated from the EC2 instance and is destined for the internet.

Which traffic flow is correct?

Options:

A.

EC2 instance > NAT GW > IGW > internet

B.

There is no route to the internet in the Private Route Table. The traffic does not reach the internet.

C.

EC2 instance > GWLBe > NAT GW > IGW > internet

D.

EC2 instance > GWLBe > internet

Expert Solution
Questions # 2:

Your organization is deciding between deploying an active-active (A-A) or active-passive (A-P) FortiGate high availability (HA) cluster in AWS cloud.

Which two statements are true about A-A clusters compared to A-P clusters? (Choose two.)

Options:

A.

For A-A clusters, FortiGate must perform SNAT inbound to ensure symmetric traffic flow.

B.

A-A clusters rely on API calls forsfailovers.

C.

A-A clusters always require a load balancer.

D.

A-A clusters can use a software-defined network (SDN) to perform a failover.

Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

What occurs during a failover for an active-passive (A-P) cluster that is deployed in two different availability zones? (Choose two.)

Options:

A.

The cluster elastic IP address (EIP) is moved from Port1 of FGT-1 to Port1 of FGT-2.

B.

The secondary IP address of Port2 of FGT-1 is moved to Port2 of FGT-2.

C.

The default static route in the Private-AZ1 subnet route table is modified to forward all traffic to Port2 of FGT2.

D.

An additional route is added to the route table of the HA Sync AZ2 subnet to forward all traffic to the Internet GW.

Expert Solution
Questions # 4:

You need to deploy a new Windows server in AWS to offload web traffic from an existing web server in a different availability zone.

According to the AWS shared responsibility model, what three actions must you take to secure the new EC2 instance? (Choose three.)

Options:

A.

Update software on the instance.

B.

Change the existing elastic load balancer (ELB) to a gateway load balancer

C.

Configure security groups.

D.

Manage the operating system on the instance.

E.

Move all web servers into the same availability zone.

Expert Solution
Questions # 5:

An administrator has been asked to deploy an active-passive (A-P) FortiGate cluster in the AWS cloud across two availability zones.

In addition to enhanced redundancy, which other major difference is there compared to deploying A-P high availability in the same availability zone?

Options:

A.

The FortiGate devices act as a single, logical instance.

B.

Secondary IP address configuration is used.

C.

The number of subnets required is less.

D.

IP addressing and subnetting are not shared.

Expert Solution
Questions # 6:

Your company deployed a FortiSandbox for AWS.

Which statement is correct about FortiSandbox for AWS?

Options:

A.

FortiSandbox for AWS comes as a hybrid solution. The FortiSandbox manager is installed on-premises and analyzes the results of the sandboxing process received from AWS EC2 instances.

B.

The FortiSandbox manager is installed on the AWS platform and analyzes the results of the sandboxing process received from on-premises Windows instances.

C.

FortiSandbox for AWS does not need more resources because it performs only management and analysis tasks.

D.

FortiSandbox deploys new EC2 instances with the custom Windows and Linux VMs, then it sends malware, runs it, and captures the results for analysis.

Expert Solution
Questions # 7:

A cloud administrator is tasked with protecting web applications hosted in AWS cloud.

Which three Fortinet cloud offerings can the administrator choose from to accomplish the task? (Choose three.)

Options:

A.

AWS WAF

B.

FortiEDR

C.

FortiGate Cloud-Native Firewall (CNF)

D.

Fortinet Managed Rules for AWS WAF

E.

FortiWeb Cloud

Expert Solution
Questions # 8:

Refer to the exhibit.

Question # 8

You deployed an active-passive FortiGate HA cluster using a CloudFormation template on an existing VPC. Now you want to test active-passive FortiGate HA failover by running a debug so you can see the API calls to change the Elastic and secondary IP addresses.

Which statement is correct about the output of the debug?

Options:

A.

The routing table for Fgt2 updated successfully, and port2 will provide internet access to Fgt2.

B.

The Elastic IP is associated with port1 of Fgt2.

C.

IP address 10.0.0.13 is now associated with eni-0b61d8afc0aefb8a2.

D.

The Elastic IP is associated with port2 of Fgt2, and the secondary IP address for port1 and port2 was updated successfully.

Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

Which statement is correct about the VPC peering connections shown in the exhibit?

Options:

A.

To route packets directly from VPC B to VPC C through VPC A, you must add a route for network 192.168.0.0/16 in the VPC A routing table.

B.

You cannot route packets directly from VPC B to VPC C through VPC A.

C.

You can associate VPC ID pcx-23232323 with VPC B to form a VPC peering connection between VPC B and VPC C.

D.

You cannot create a separate VPC peering connection between VPC B and VPC C to route packets directly.

Expert Solution
Questions # 10:

AWS native network services offer vast functionality and inter-connectivity between the cloud and on-premises networks.

Which three additional functions can FortiGate for AWS offer to complement the native services offered by AWS? (Choose three.)

Options:

A.

Higher VPN throughput

B.

Web filtering

C.

OSPF over IPSec

D.

Advanced dynamic routing

E.

Secure SD-WAN with application visibility

Expert Solution
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions