New Year Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

FCP_WCS_AD-7.4 FCP - AWS Cloud Security 7.4 Administrator Exam Questions and Answers

Questions 4

You are troubleshooting network connectivity issues between two VMs deployed in AWS.

One VM is a FortiGate located on subnet "LAN" that is part of the VPC "Encryption". The other VM is a Windows server located on the subnet "servers" which is also in the "Encryption" VPC. You are unable to ping the Windows server from FortiGate.

What are two reasons for this? (Choose two.)

Options:

A.

The firewall in the Windows VM is blocking the traffic.

B.

The default AWS Network Access Control List (NACL) does not allow this traffic.

C.

By default, AWS does not allow ICMP traffic between subnets.

D.

Add an inbound allow ICMP rule in the security group attached to the windows server.

Buy Now
Questions 5

Refer to the exhibit.

FCP_WCS_AD-7.4 Question 5

Which two statements are correct about traffic flow in FortiWeb Cloud? (Choose two.)

Options:

A.

The DNS name for the application servers must point to FortiWeb Cloud.

B.

FortiWeb Cloud filters the incoming traffic from users, blocking the OWASP Top 10 attacks, zero-day threats, and other application layer attacks.

C.

FortiWeb Cloud can protect the application servers only if they are all located in the same virtual public cloud (VPC).

D.

Step 2 requires an AWS S3 bucket to be created.

Buy Now
Questions 6

Refer to the exhibit.

FCP_WCS_AD-7.4 Question 6

You deployed an active-passive FortiGate HA cluster using a CloudFormation template on an existing VPC. Now you want to test active-passive FortiGate HA failover by running a debug so you can see the API calls to change the Elastic and secondary IP addresses.

Which statement is correct about the output of the debug?

Options:

A.

The routing table for Fgt2 updated successfully, and port2 will provide internet access to Fgt2.

B.

The Elastic IP is associated with port1 of Fgt2.

C.

IP address 10.0.0.13 is now associated with eni-0b61d8afc0aefb8a2.

D.

The Elastic IP is associated with port2 of Fgt2, and the secondary IP address for port1 and port2 was updated successfully.

Buy Now
Questions 7

An organization has created a VPC with two subnets and deployed a FortiGate-VM (VM04/c4.xlarge) in AWS.

The EC2 instance is initially configured with two Elastic Network Interfaces (ENIs). The primary ENI is configured on the public subnet, and the secondary ENI is configured on the private subnet. To provide internet access for the FortiGate-VM, they now want to associate an EIP to its primary ENI, but the assignment is failing.

Which action would allow the EIP assignment to be successful?

Options:

A.

Create and associate a public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI.

B.

Shut down the FortiGate VM, if it is running, assign the EIP to the primary ENI, and then power it on.

C.

Create and attach an internet gateway to the VPC, and then assign the EIP to the primary ENI of the FortiGate VM.

D.

Create and attach a public routing table to the public subnet, associate the public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI.

Buy Now
Questions 8

An organization has the requirement to connect a data VPC to the on-premises infrastructure of a branch office in a hybrid cloud environment. The connectivity needs the higher bandwidth but the organization does not want to use multiple connections between sites.

Which AWS solution meets the requirement?

Options:

A.

Transit VPC with IPSec

B.

Internet Gateway

C.

Transit Gateway multicast

D.

Transit Gateway Connect

Buy Now
Questions 9

A customer has deployed FortiGate Cloud-Native Firewall (CNF).

Which two statements are correct about policy sets? (Choose two.)

Options:

A.

There is an implicit deny rule at the bottom of the policy set.

B.

The policy set must be manually synchronized to the CNF instance each time it is modified.

C.

A new policy set is created with each deployed CNF instance.

D.

Multiple policy sets can be applied to a single CNF instance.

Buy Now
Questions 10

An administrator wants to deploy a solution to automatically create firewall rules on FortiGate to accelerate time-to-protection for threats.

Which AWS service can be integrated with FortiGate to accomplish this?

Options:

A.

AWS Firewall Manager

B.

AWS network access control list

C.

SDN Connector for AWS

D.

AWS GuardDuty

Buy Now
Exam Code: FCP_WCS_AD-7.4
Exam Name: FCP - AWS Cloud Security 7.4 Administrator Exam
Last Update: Dec 22, 2024
Questions: 35

PDF + Testing Engine

$57.75  $164.99

Testing Engine

$43.75  $124.99
buy now FCP_WCS_AD-7.4 testing engine

PDF (Q&A)

$36.75  $104.99
buy now FCP_WCS_AD-7.4 pdf