Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Fortinet FCP_WCS_AD-7.4 - FCP - AWS Cloud Security 7.4 Administrator Exam

Page: 1 / 1
Total 35 questions

Refer to the exhibit.

Which two statements are correct about traffic flow in FortiWeb Cloud? (Choose two.)

A.

The DNS name for the application servers must point to FortiWeb Cloud.

B.

FortiWeb Cloud filters the incoming traffic from users, blocking the OWASP Top 10 attacks, zero-day threats, and other application layer attacks.

C.

FortiWeb Cloud can protect the application servers only if they are all located in the same virtual public cloud (VPC).

D.

Step 2 requires an AWS S3 bucket to be created.

Your company deployed a FortiSandbox for AWS.

Which statement is correct about FortiSandbox for AWS?

A.

FortiSandbox for AWS comes as a hybrid solution. The FortiSandbox manager is installed on-premises and analyzes the results of the sandboxing process received from AWS EC2 instances.

B.

The FortiSandbox manager is installed on the AWS platform and analyzes the results of the sandboxing process received from on-premises Windows instances.

C.

FortiSandbox for AWS does not need more resources because it performs only management and analysis tasks.

D.

FortiSandbox deploys new EC2 instances with the custom Windows and Linux VMs, then it sends malware, runs it, and captures the results for analysis.

Refer to the exhibit.

You deployed an active-passive FortiGate HA cluster using a CloudFormation template on an existing VPC. Now you want to test active-passive FortiGate HA failover by running a debug so you can see the API calls to change the Elastic and secondary IP addresses.

Which statement is correct about the output of the debug?

A.

The routing table for Fgt2 updated successfully, and port2 will provide internet access to Fgt2.

B.

The Elastic IP is associated with port1 of Fgt2.

C.

IP address 10.0.0.13 is now associated with eni-0b61d8afc0aefb8a2.

D.

The Elastic IP is associated with port2 of Fgt2, and the secondary IP address for port1 and port2 was updated successfully.

A customer has implemented GWLB between the partner and application VPCs. FortiGate appliances are deployed in the partner VPC with multiple AZs to inspect traffic transparently.

Which two things will happen to application traffic based on the GWLB deployment? (Choose two.)

A.

Inbound and outbound traffic will go to multiple devices, which will perform load balancing.

B.

Inbound and outbound traffic will go to the same device, which will perform stateful processing.

C.

The content of the original traffic exchanged between the GWLB and FortiGate will be preserved.

D.

The original trafficexchangedbetween the GWLB and FortiGate will be hashed for data integrity.

An organization has created a VPC with two subnets and deployed a FortiGate-VM (VM04/c4.xlarge) in AWS.

The EC2 instance is initially configured with two Elastic Network Interfaces (ENIs). The primary ENI is configured on the public subnet, and the secondary ENI is configured on the private subnet. To provide internet access for the FortiGate-VM, they now want to associate an EIP to its primary ENI, but the assignment is failing.

Which action would allow the EIP assignment to be successful?

A.

Create and associate a public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI.

B.

Shut down the FortiGate VM, if it is running, assign the EIP to the primary ENI, and then power it on.

C.

Create and attach an internet gateway to the VPC, and then assign the EIP to the primary ENI of the FortiGate VM.

D.

Create and attach a public routing table to the public subnet, associate the public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI.

A cloud administrator is tasked with protecting web applications hosted in AWS cloud.

Which three Fortinet cloud offerings can the administrator choose from to accomplish the task? (Choose three.)

A.

AWS WAF

B.

FortiEDR

C.

FortiGate Cloud-Native Firewall (CNF)

D.

Fortinet Managed Rules for AWS WAF

E.

FortiWeb Cloud

A customer has deployed FortiGate Cloud-Native Firewall (CNF).

Which two statements are correct about policy sets? (Choose two.)

A.

There is an implicit deny rule at the bottom of the policy set.

B.

The policy set must be manually synchronized to the CNF instance each time it is modified.

C.

A new policy set is created with each deployed CNF instance.

D.

Multiple policy sets can be applied to a single CNF instance.

Refer to the exhibit.

Which statement is correct about the VPC peering connections shown in the exhibit?

A.

To route packets directly from VPC B to VPC C through VPC A, you must add a route for network 192.168.0.0/16 in the VPC A routing table.

B.

You cannot route packets directly from VPC B to VPC C through VPC A.

C.

You can associate VPC ID pcx-23232323 with VPC B to form a VPC peering connection between VPC B and VPC C.

D.

You cannot create a separate VPC peering connection between VPC B and VPC C to route packets directly.

What is a drawback of deploying a FortiWeb VM inside a virtual public cloud (VPC) compared to FortiWeb Cloud?

A.

It is unable to support web applications from OWASP Top 10 threats.

B.

It does not support zero-day protection.

C.

It is slower than FortiWeb Cloud to apply advanced WAF protection.

D.

Only applications going through the VPC are protected.

Refer to the exhibit.

Which two statements are true about inbound traffic based on the IGW ingress route table and GWLB deployment shown in the exhibit? (Choose two.)

A.

GWLB forwards traffic to FortiGate without encapsulation in its dedicated subnet.

B.

Inbound traffic is directed to the GWLB through a GWLB endpoint.

C.

Inbound traffic is directed to the application subnet through a GWLB endpoint.

D.

GWLB encapsulates traffic with the GENEVE protocol and sends it to FortiGate.