Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet FCP_ZCS_AD-7.4 FCP - Azure Cloud Security 7.4 Administrator Exam Practice Test

Demo: 10 questions
Total 35 questions

FCP - Azure Cloud Security 7.4 Administrator Questions and Answers

Question 1

When you deploy a single FortiGate VM using the available template from the Azure Marketplace, several other resources are also created.

Which two resources, among others, are created during the process? (Choose two.)

Options:

A.

Two virtual NICs

B.

One NSG for each interface

C.

One VM Scale set

D.

One new route table

Question 2

A Linux server was deployed in a protected subnet with a dynamic IP address. A FortiGate VM in the internal subnet provides traffic filtering to it. and you must implement a firewall policy using the IP address of the Linux server.

Which feature could help integrate FortiGate using Linux server tags?

Options:

A.

Targets Management

B.

Microsoft Entra ID

C.

Software-defined network (SDN) connector

D.

Service Fabric Cluster

Question 3

Refer to the exhibit.

A high availability, active-active FortiGate with Elastic Load Balancing (ELB) and Internal Load Balancing (ILB) was deployed in your Azure environment.

Which tools can you use to configure synchronization? (Choose two.)

Options:

A.

FortiGate Clustering Protocol (FGCP)

B.

Autoscale

C.

Heartbeat interfaces

D.

Software-defined network (SDN) Fabric Connector

E.

FortiManager

Question 4

You want to take advantage of Azure availability zones for your cloud-based Fortinet deployment.

Which two benefits do Azure availability zones provide? (Choose two.)

Options:

A.

Enhanced protection for application and data in a single Azure region

B.

Improve database performance and reliability

C.

Protect applications and data through high availability with fault isolation and redundancy

D.

Protect applications and data across multiple Azure regions

Question 5

You deployed a FortiGate active-active with ELB/ILB solution using the template from Azure Marketplace.

What is the purpose of the inbound NAT rules configured in the external load balancer in this deployment?

Options:

A.

To load balance the incoming traffic between both FortiGate VMs

B.

To filter inbound traffic before it reaches the FortiGate instances

C.

To forward the health probes to both FortiGate VMs

D.

To allow administrative access to the FortiGate VMs

Question 6

Refer to the exhibit.

An Azure Route Server and an active-passive FortiGate with Elastic Load Balancing (ELB) and Internal Load Balancing (ILB) have been deployed successfully and they are sharing and populating BGP routes in the Protected VNet.

A Linux server has been deployed in a new VNet spoke. It is expected that Azure Route Server

should inject the FortiGate BGP routes into the Linux server but that failed.

How can you diagnose the problem?

Options:

A.

Monitor effective routes on the Azure network interface (NIC) of the Linux server

B.

Review FortiGate BGP neighbors

C.

Verify the BGP setup on Azure Route Server

D.

Linux server doesn't support BGP negotiation with Azure Route Server

Question 7

Refer to the exhibits.

A high availability (HA) active-active FortiGate with Elastic Load Balancing (ELB) and Internal Load Balancing (ILB) was deployed with a default setup to filter traffic to a Linux server running Apache server.

Ports 80 and 22 are open on the Linux server, and on FortiGate a VIP and firewall policy are configured to allow traffic through ports 80 and 22. Traffic on port 80 is successful, but traffic on port 22 is not detected by FortiGate.

What configuration changes could you perform to allow SSH traffic?

Options:

A.

Configure a customized port under the Frontend IP configuration

B.

Add a new Azure load balancing rule

C.

Include the Linux server in the back-end pool options

D.

Add a new Inbound NAT rule

Question 8

Refer to the exhibit.

The exhibit shows some of the properties of a virtual NIC that is used by a FortiGate VM deployed in Azure.

The virtual NIC shown is connected to a subnet (10.0.1.0/26) with several VMs that will be accessing the internet through the FortiGate VM.

Which statement is true for this scenario?

Options:

A.

The NIC in the exhibit needs to be assigned a public IP address.

B.

The VMs in the 10.0.1.0/26 subnet can access the internet through FortiGate.

C.

You must change the default gateway on the VMs in the Internal Subnet for this to work.

D.

The parameters of the virtual NIC are not configured correctly.

Question 9

Why would you use a user-defined route in Azure?

Options:

A.

To manage user authentication and access control

B.

To have the traffic from the other VMs inspected by FortiGate

C.

To allow inbound management access to FortiGate VMs

D.

To allow communication between FortiGate VMs on two subnets in the same VNET

Question 10

How are the configurations synchronized between two FortiGate VMs in an active-passive HA with SDN connector failover deployed from the Azure marketplace?

Options:

A.

Using unicast FGCP

B.

Using system autoscaling during a failover

C.

An Azure function distributes the configuration files

D.

By configuring FGSP on the primary

Demo: 10 questions
Total 35 questions