Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Fortinet FCP_ZCS_AD-7.4 - FCP - Azure Cloud Security 7.4 Administrator

Page: 1 / 1
Total 35 questions

What are two characteristics of Azure standard public IP addresses? (Choose two.)

A.

They support the use of availability zones

B.

They can be dynamic or static

C.

They can be used with load balancers of any SKU

D.

They require the configuration of NSGs for inbound traffic

Refer to the exhibits.

A high availability (HA) active-active FortiGate with Elastic Load Balancing (ELB) and Internal Load Balancing (ILB) was deployed with a default setup to filter traffic to a Linux server running Apache server.

Ports 80 and 22 are open on the Linux server, and on FortiGate a VIP and firewall policy are configured to allow traffic through ports 80 and 22. Traffic on port 80 is successful, but traffic on port 22 is not detected by FortiGate.

What configuration changes could you perform to allow SSH traffic?

A.

Configure a customized port under the Frontend IP configuration

B.

Add a new Azure load balancing rule

C.

Include the Linux server in the back-end pool options

D.

Add a new Inbound NAT rule

After integrating a FortiGate VM with Azure Route Server, you detect that routes are not propagating successfully.

What initial step could you perform to diagnose the root cause?

A.

Examine the Azure Microsoft Entra ID permissions associated with the FortiGate VM to ensure that correct authentication is being used for BGP peering

B.

Monitor the network latency between the FortiGate VM and Azure Route Server to identify potential communication delays affecting route propagation

C.

Verify that the FortiGate VM is running the latest firmware version

D.

Verify the BGP peering status on both the FortiGate VM and Azure Route Server

What is a requirement when you deploy a FortiGate active-active cluster in Azure?

A.

You must assign the public IP address to an Azure load balancer.

B.

You must use unicast FGCP to synchronize the configurations.

C.

You must configure both load balancers to allow administrative access.

D.

You must configure all FortiGate VMs with three or more interfaces.

Refer to the exhibits.

Two new dynamic firewall addresses have been configured on the FortiGate VM using the external connector to Integrate within the same Azure environment.

The debug output shows that one IP address can be resolved successfully, but the second is empty.

Which steps could you perform to correct the misconfiguration? (Choose all that apply.)

A.

Verify the filter used for the dynamic firewall address

B.

Verify the tags on the target VM

C.

Check for a mistyped Microsof Entra ID subscription

D.

Verify the NSG for the target VM

E.

Verify the Microsoft Entra ID role assignment access rights

Your organization is in the process of optimizing its Azure network architecture and wants to dynamically manage and exchange routing information between its virtual networks and on-premises networks.

Which Azure service would help to provide a centralized point for efficient route management and dynamic routing?

A.

Azure Virtual WAN

B.

Azure VPN Gateway

C.

Azure ExpressRoute

D.

Azure Route Server

Refer to the exhibits.

You are configuring an SDN connector for Azure on a FortiGate device You completed all the required steps on the Azure side. While configuring the FortiGate side, you notice that you did not save the client secret used in the Azure App Registration.

What is the quickest way to obtain the value of the client secret?

A.

Create a new resource group

B.

Create a new client secret

C.

Create a new app registration

D.

Create a new external connector for Azure

Which additional features does Azure Firewall Premium offer compared to Azure Firewall Standard?

A.

Content filtering and threat intelligence integration

B.

Antivirus detection and AI prevention capabilities

C.

Advanced DDoS protection and VPN diagnostics

D.

Enhanced URL filtering and web categories

You want to take advantage of Azure availability zones for your cloud-based Fortinet deployment.

Which two benefits do Azure availability zones provide? (Choose two.)

A.

Enhanced protection for application and data in a single Azure region

B.

Improve database performance and reliability

C.

Protect applications and data through high availability with fault isolation and redundancy

D.

Protect applications and data across multiple Azure regions

Refer to the exhibit.

A high availability, active-active FortiGate with Elastic Load Balancing (ELB) and Internal Load Balancing (ILB) was deployed in your Azure environment.

Which tools can you use to configure synchronization? (Choose two.)

A.

FortiGate Clustering Protocol (FGCP)

B.

Autoscale

C.

Heartbeat interfaces

D.

Software-defined network (SDN) Fabric Connector

E.

FortiManager