ExamDumpster

Free FCP-PCS-7.4 sample questions

Real questions from the FCP - Public Cloud Security 7.4 Administrator practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A cloud architect is designing a centralized security architecture in AWS using a Transit Gateway (TGW). The requirement is to inspect all East-West traffic between Spoke VPCs and all North-South traffic to the internet. The design includes a dedicated Security VPC with an Auto Scaling Group of FortiGate-VMs behind a Geneve-compliant Gateway Load Balancer (GWLB). Which routing configuration ensures the return traffic from the FortiGate fleet is correctly sent back to the original Spoke VPC destination?

Question 2Choose one

An administrator is deploying a FortiGate-VM active-passive High Availability (HA) cluster in Microsoft Azure. To ensure proper failover, the administrator decides to use the Azure SDN Connector with Managed Identity. Which specific Azure permission role must be assigned to the FortiGate-VM's Managed Identity to allow it to update the User Defined Routes (UDR) during a failover event?

Question 3Choose one

A company is using FortiGate CNF (Cloud Native Firewall) in AWS to protect multiple VPCs. The architecture uses a Gateway Load Balancer (GWLB) Endpoint in each application VPC to redirect traffic to the FortiGate CNF service. What is the primary benefit of using FortiGate CNF over a traditional self-managed FortiGate-VM Auto Scaling group in this scenario?

Question 4Choose 2

You are troubleshooting a FortiGate-VM SDN Connector in AWS that is failing to resolve dynamic address objects based on EC2 tags. The connector status shows 'Down' in the FortiGate GUI. Which of the following troubleshooting steps should you prioritize? (Select TWO)

Question 5Choose one

True or False: In a FortiGate Active-Active HA configuration within Azure using an external Azure Load Balancer (ALB), the ALB uses the same public IP address to balance traffic to both FortiGate nodes, but Source NAT (SNAT) on the FortiGate is required to ensure symmetric return traffic.

Question 6Choose one

A FortiGate administrator is configuring the `config system sdn-connector` settings for an Azure environment. The goal is to allow the FortiGate to automatically populate an address group with the IP addresses of all Virtual Machines tagged with 'Environment=Production'. Which type of SDN connector configuration is most appropriate for this task?

Question 7Choose one

In an AWS deployment, you are using a FortiGate-VM to inspect traffic between two VPCs connected via a Transit Gateway (TGW). The TGW has a single route table associated with all attachments. You observe that traffic between the VPCs is flowing directly and not passing through the FortiGate security VPC. What architectural change is required to force traffic through the FortiGate?

Question 8Choose one

When deploying FortiWeb in a public cloud environment to protect a web application, which deployment mode allows FortiWeb to inspect traffic without requiring changes to the network architecture or IP addressing of the application servers, often referred to as 'Transparent Inspection'?

Question 9Choose one

An organization requires a highly available FortiGate solution in Azure. The design uses an Active-Passive configuration. During a failover test, the secondary unit becomes active but traffic is dropped because the User Defined Routes (UDRs) in the Azure subnets still point to the IP address of the failed primary unit. Which component is responsible for detecting the failure and updating the Azure UDRs to point to the new active unit's IP?

Question 10Choose one

Case Study: **Scenario** GlobalBank uses AWS for its core banking application. The architecture consists of a Hub VPC and three Spoke VPCs (App, DB, Partner). They use a FortiGate Active-Passive HA pair in the Hub VPC. **Issue** The network team reports that traffic from the App VPC to the DB VPC is working fine and being inspected. However, traffic from the Partner VPC (10.2.0.0/16) to the App VPC (10.1.0.0/16) is failing intermittently. **Configuration** - TGW is used for all inter-VPC communication. - TGW Route Table has routes to 0.0.0.0/0 via the Hub VPC attachment. - Hub VPC has FortiGates in different AZs (AZ1 and AZ2). - Partner VPC attachment is associated with the TGW Route Table. - TGW 'Appliance Mode' is disabled on the Hub VPC attachment. Which action will permanently resolve the intermittent connectivity issue while maintaining traffic inspection?

10 more free samples are waiting

Create a free account to unlock the whole FCP-PCS-7.4 sample bank, or get full access to all 250 practice questions in the simulator.

Create account