Black Friday Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet FCP_WCS_AD-7.4 FCP - AWS Cloud Security 7.4 Administrator Exam Exam Practice Test

FCP - AWS Cloud Security 7.4 Administrator Exam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

A customer has deployed FortiGate Cloud-Native Firewall (CNF).

Which two statements are correct about policy sets? (Choose two.)

Options:

A.

There is an implicit deny rule at the bottom of the policy set.

B.

The policy set must be manually synchronized to the CNF instance each time it is modified.

C.

A new policy set is created with each deployed CNF instance.

D.

Multiple policy sets can be applied to a single CNF instance.

Question 2

Refer to the exhibit.

A customer is using the AWS Elastic Load Balancer (ELB).

Which two statements are correct about the ELB configuration? (Choose two.)

Options:

A.

The load balancer is configured to load balance traffic among multiple availability zones.

B.

The Amazon Resource Name is used to access the load balancer node and targets.

C.

You can use the DNS name to reach the targets behind the ELB.

D.

The load balancer is configured for the internal traffic of the virtual public cloud (VPC).

Question 3

Refer to the exhibit.

What occurs during a failover for an active-passive (A-P) cluster that is deployed in two different availability zones? (Choose two.)

Options:

A.

The cluster elastic IP address (EIP) is moved from Port1 of FGT-1 to Port1 of FGT-2.

B.

The secondary IP address of Port2 of FGT-1 is moved to Port2 of FGT-2.

C.

The default static route in the Private-AZ1 subnet route table is modified to forward all traffic to Port2 of FGT2.

D.

An additional route is added to the route table of the HA Sync AZ2 subnet to forward all traffic to the Internet GW.

Question 4

Refer to the exhibit.

Which two statements are correct about traffic flow in FortiWeb Cloud? (Choose two.)

Options:

A.

The DNS name for the application servers must point to FortiWeb Cloud.

B.

FortiWeb Cloud filters the incoming traffic from users, blocking the OWASP Top 10 attacks, zero-day threats, and other application layer attacks.

C.

FortiWeb Cloud can protect the application servers only if they are all located in the same virtual public cloud (VPC).

D.

Step 2 requires an AWS S3 bucket to be created.

Question 5

A customer has implemented GWLB between the partner and application VPCs. FortiGate appliances are deployed in the partner VPC with multiple AZs to inspect traffic transparently.

Which two things will happen to application traffic based on the GWLB deployment? (Choose two.)

Options:

A.

Inbound and outbound traffic will go to multiple devices, which will perform load balancing.

B.

Inbound and outbound traffic will go to the same device, which will perform stateful processing.

C.

The content of the original traffic exchanged between the GWLB and FortiGate will be preserved.

D.

The original trafficexchangedbetween the GWLB and FortiGate will be hashed for data integrity.

Question 6

An organization has the requirement to connect a data VPC to the on-premises infrastructure of a branch office in a hybrid cloud environment. The connectivity needs the higher bandwidth but the organization does not want to use multiple connections between sites.

Which AWS solution meets the requirement?

Options:

A.

Transit VPC with IPSec

B.

Internet Gateway

C.

Transit Gateway multicast

D.

Transit Gateway Connect

Question 7

Your company deployed a FortiSandbox for AWS.

Which statement is correct about FortiSandbox for AWS?

Options:

A.

FortiSandbox for AWS comes as a hybrid solution. The FortiSandbox manager is installed on-premises and analyzes the results of the sandboxing process received from AWS EC2 instances.

B.

The FortiSandbox manager is installed on the AWS platform and analyzes the results of the sandboxing process received from on-premises Windows instances.

C.

FortiSandbox for AWS does not need more resources because it performs only management and analysis tasks.

D.

FortiSandbox deploys new EC2 instances with the custom Windows and Linux VMs, then it sends malware, runs it, and captures the results for analysis.

Question 8

Refer to the exhibit.

Which statement is correct about the VPC peering connections shown in the exhibit?

Options:

A.

To route packets directly from VPC B to VPC C through VPC A, you must add a route for network 192.168.0.0/16 in the VPC A routing table.

B.

You cannot route packets directly from VPC B to VPC C through VPC A.

C.

You can associate VPC ID pcx-23232323 with VPC B to form a VPC peering connection between VPC B and VPC C.

D.

You cannot create a separate VPC peering connection between VPC B and VPC C to route packets directly.

Question 9

An administrator wants to deploy a solution to automatically create firewall rules on FortiGate to accelerate time-to-protection for threats.

Which AWS service can be integrated with FortiGate to accomplish this?

Options:

A.

AWS Firewall Manager

B.

AWS network access control list

C.

SDN Connector for AWS

D.

AWS GuardDuty

Question 10

Refer to the exhibit.

What two conclusions can you draw from the FortiGate debug output? (Choose two.)

Options:

A.

The dynamic address object is automatically updated if the IP changes.

B.

The address object AWS Windows Server Lab can be manually changed on FortiGate.

C.

The SDN connector is correctly configured and authorized.

D.

The AWS user account used for software-defined network (SDN) integration must have full administrative rights.