Fortinet FCP_WCS_AD-7.4 Practice Test - Questions Answers, Page 4
List of questions
Related questions
AWS native network services offer vast functionality and inter-connectivity between the cloud and on-premises networks.
Which three additional functions can FortiGate for AWS offer to complement the native services offered by AWS? (Choose three.)
A.
Higher VPN throughput
B.
Web filtering
C.
OSPF over IPSec
D.
Advanced dynamic routing
E.
Secure SD-WAN with application visibility
Your organization is deciding between deploying an active-active (A-A) or active-passive (A-P) FortiGate high availability (HA) cluster in AWS cloud.
Which two statements are true about A-A clusters compared to A-P clusters? (Choose two.)
A.
For A-A clusters, FortiGate must perform SNAT inbound to ensure symmetric traffic flow.
B.
A-A clusters rely on API calls for sfailovers.
C.
A-A clusters always require a load balancer.
D.
A-A clusters can use a software-defined network (SDN) to perform a failover.
Refer to the exhibit.
Which statement is correct about the VPC peering connections shown in the exhibit?
A.
To route packets directly from VPC B to VPC C through VPC A, you must add a route for network 192.168.0.0/16 in the VPC A routing table.
B.
You cannot route packets directly from VPC B to VPC C through VPC A.
C.
You can associate VPC ID pcx-23232323 with VPC B to form a VPC peering connection between VPC B and VPC C.
D.
You cannot create a separate VPC peering connection between VPC B and VPC C to route packets directly.
Refer to the exhibit.
What two conclusions can you draw from the FortiGate debug output? (Choose two.)
A.
The dynamic address object is automatically updated if the IP changes.
B.
The address object AWS Windows Server Lab can be manually changed on FortiGate.
C.
The SDN connector is correctly configured and authorized.
D.
The AWS user account used for software-defined network (SDN) integration must have full administrative rights.
Question