Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Fortinet Public Cloud Security FCP_WCS_AD-7.4 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam FCP_WCS_AD-7.4 Premium Access

View all detail and faqs for the FCP_WCS_AD-7.4 exam


451 Students Passed

92% Average Score

96% Same Questions
Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
Questions # 1:

You are troubleshooting network connectivity issues between two VMs deployed in AWS.

One VM is a FortiGate located on subnet "LAN" that is part of the VPC "Encryption". The other VM is a Windows server located on the subnet "servers" which is also in the "Encryption" VPC. You are unable to ping the Windows server from FortiGate.

What are two reasons for this? (Choose two.)

Options:

A.

The firewall in the Windows VM is blocking the traffic.

B.

The default AWS Network Access Control List (NACL) does not allow this traffic.

C.

By default, AWS does not allow ICMP traffic between subnets.

D.

Add an inbound allow ICMP rule in the security group attached to the windows server.

Questions # 2:

A global organization with cloud networks deployed in several AWS regions wants to set up next-generation firewall (NGFW) protection using FortiGate Cloud-Native Firewall (CNF).

What are two deployment considerations for the organization? (Choose two.)

Options:

A.

They must choose AWS Firewall Manager to provision a CNF instance.

B.

A CNF instance is required for each AWS region that must be protected.

C.

More than one AWS account can be associated with a CNF instance.

D.

Only one CNF instance is required to protect all AWS regions.

Questions # 3:

An administrator has been asked to deploy an active-passive (A-P) FortiGate cluster in the AWS cloud across two availability zones.

In addition to enhanced redundancy, which other major difference is there compared to deploying A-P high availability in the same availability zone?

Options:

A.

The FortiGate devices act as a single, logical instance.

B.

Secondary IP address configuration is used.

C.

The number of subnets required is less.

D.

IP addressing and subnetting are not shared.

Questions # 4:

Refer to the exhibit.

Question # 4

An administrator configured a FortiGate device to connect to the AWS API to retrieve resource values from the AWS console to create dynamic objects for the FortiGate policies. The administrator is unable to retrieve AWS dynamic objects on FortiGate.

Which two reasons can explain why? (Choose two.)

Options:

A.

The AWS API call is not supported on XML version 1.0.

B.

AWS was not able to validate credentials provided by the AWS Lab SDN connector because of a clock skew between FortiGate and AWS.

C.

The AWS Lab SDN connector is configured with an invalid AWS access or secret key.

D.

The AWS Lab SDN connector failed to connect on port 401.

E.

The AWS Lab SDN did not find any instances in the configured VPC.

Questions # 5:

You want to deploy the Fortinet HA CloudFormation template to stage and bootstrap the FortiGate configuration in the same region in which you created your VPC, which is Ohio US-East-2.

Based on this information, which statement is correct?

Options:

A.

You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration. The S3 bucket can be hosted in any region.

B.

The Fortinet HA cloud formation template automatically creates an S3 bucket.

C.

You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration. The S3 bucket needs to be hosted in the Ohio US-East-2 region.

D.

You create a DynamoDB to stage and bootstrap FortiGate with an FGCP unicast configuration. It needs to be hosted in the Ohio US-East-2 region.

Questions # 6:

An administrator needs to attach an Elastic Network Interface (ENI) to an application instance in a VPC with multiple availability zones. An instance runs in availability zone 1.

Which ENI property must the administrator consider when implementing this requirement?

Options:

A.

An ENI cannot attach to an instance in availability zone 2.

B.

After the ENI detaches from one instance, it can reattach only to the same instance.

C.

You can detach the primary ENI from an AWS instance.

D.

When you move an ENI, network traffic remains directed to the old instance until you terminate that instance.

Questions # 7:

Which three statements are correct about VPC flow logs? (Choose three.)

Options:

A.

Flow logs do not capture traffic to and from 169.254.169.254 for instance metadata.

B.

Flow logs do not capture DHCP traffic.

C.

Flow logs can capture traffic to the reserved IP address for the default VPC router.

D.

Flow logs can be used as a security tool to monitor the traffic that is reaching the instance.

E.

Flow logs can capture real-time log streams for the network interfaces.

Questions # 8:

An administrator must deploy a web application firewall (WAF) solution to protect the web applications of their organization.

Why would the administrator choose FortiWeb Cloud over AWS WAF with Fortinet managed rules?

Options:

A.

WAF signatures must be manually updated by FortiGuard.

B.

The solution must meet PCI 6.6 compliance.

C.

SSL inspection is a requirement.

D.

Traffic must be inspected for malware.

Questions # 9:

What is a drawback of deploying a FortiWeb VM inside a virtual public cloud (VPC) compared to FortiWeb Cloud?

Options:

A.

It is unable to support web applications from OWASP Top 10 threats.

B.

It does not support zero-day protection.

C.

It is slower than FortiWeb Cloud to apply advanced WAF protection.

D.

Only applications going through the VPC are protected.

Questions # 10:

A customer has deployed FortiGate Cloud-Native Firewall (CNF).

Which two statements are correct about policy sets? (Choose two.)

Options:

A.

There is an implicit deny rule at the bottom of the policy set.

B.

The policy set must be manually synchronized to the CNF instance each time it is modified.

C.

A new policy set is created with each deployed CNF instance.

D.

Multiple policy sets can be applied to a single CNF instance.

Viewing page 1 out of 1 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.