ExamGecko
Home Home / Fortinet / NSE6_WCS-6.4

Fortinet NSE6_WCS-6.4 Practice Test - Questions Answers

Question list
Search
Search

List of questions

Search

Related questions











An administrator has deployed an environment in AWS and is now trying to send outbound traffic from the web servers to the internet through FortiGate. The FortiGate policies are configured to allow all outbound traffic. however.

the traffic is not reaching the FortiGate internal interface.

Which two statements Can be the reasons for this behavior? (Choose two )

A.
FortiGate is not configured as a default gateway tor web servers.
A.
FortiGate is not configured as a default gateway tor web servers.
Answers
B.
Internet Gateway (IGW) is not configured for VPC.
B.
Internet Gateway (IGW) is not configured for VPC.
Answers
C.
AWS security groups are blocking the traffic.
C.
AWS security groups are blocking the traffic.
Answers
D.
AWS source destination checks are enabled on the FortiGate internal interfaces.
D.
AWS source destination checks are enabled on the FortiGate internal interfaces.
Answers
Suggested answer: C, D

You are network connectivity issues between two VMS deployed in AWS. One VM is a FortiGate located on subnet •LAN- that is part Of the VPC "Encryption". The Other VM is a Windows server located on the subnet "servers" Which is also in the "Encryption" VPC. You are unable to ping the Windows server from FortiGate.

What is the reason for this?

A.
You have not created a VPN to allow traffic between those subnets.
A.
You have not created a VPN to allow traffic between those subnets.
Answers
B.
By default. AWS does not allow ICMP traffic between subnets.
B.
By default. AWS does not allow ICMP traffic between subnets.
Answers
C.
The default AWS Network Access Control List (NACL) does not allow this traffic.
C.
The default AWS Network Access Control List (NACL) does not allow this traffic.
Answers
D.
The firewall in the Windows VM is blocking the traffic.
D.
The firewall in the Windows VM is blocking the traffic.
Answers
Suggested answer: D

Your company deployed a FortiSandb0X for AWS.

Which statement is correct about FortiSandbox for AWS?

A.
FortiSandbox for AWS does not need more resources because it performs only management and analysis tasks.
A.
FortiSandbox for AWS does not need more resources because it performs only management and analysis tasks.
Answers
B.
The FortiSandbox manager is installed on AWS platform and analyzes the results of the sandboxing process received from on-premises Windows instances.
B.
The FortiSandbox manager is installed on AWS platform and analyzes the results of the sandboxing process received from on-premises Windows instances.
Answers
C.
FortiSandbox for AWS comes as hybrid solution. The FortiSandb0X manager is installed onpremises and analyzes the results Of the sandboxing process received from AWS EC2 instances
C.
FortiSandbox for AWS comes as hybrid solution. The FortiSandb0X manager is installed onpremises and analyzes the results Of the sandboxing process received from AWS EC2 instances
Answers
D.
FortiSandbox deploys new EC2 instances with the custom Windows and Linux VMS, then it sends malware, runs it, and captures the results for analysis.
D.
FortiSandbox deploys new EC2 instances with the custom Windows and Linux VMS, then it sends malware, runs it, and captures the results for analysis.
Answers
Suggested answer: A

An organization has created a VPC and deployed a FortiGate-VM (VM04 /c4.xlarge) in AWS, FortiGate-VM is initially configured With two Elastic Network Interfaces (ENIs). The primary ENI of FortiGate-VM is configured for a public subnet. and the second ENI is configured for a private subnet. In order to provide internet access. they now want to add an EIP to the primary ENI of FortiGate, but the

EIP assignment is failing.

Which action would allow the EIP assignment to be successful?

A.
Shut down the FortiGate VM. if it is running. assign the EIP to the primary ENI. and then power it on.
A.
Shut down the FortiGate VM. if it is running. assign the EIP to the primary ENI. and then power it on.
Answers
B.
Create and associate a public subnet With the primary ENI Of FortiGate, and then assign the EIP to the primary ENI.
B.
Create and associate a public subnet With the primary ENI Of FortiGate, and then assign the EIP to the primary ENI.
Answers
C.
Create and attach a public routing table to the public subnet, associate the public subnet With the primary ENI Of FortiGate. and then assign the EP to the primary ENI.
C.
Create and attach a public routing table to the public subnet, associate the public subnet With the primary ENI Of FortiGate. and then assign the EP to the primary ENI.
Answers
D.
Create and attach an Internet gateway to the VPC. and then assign the EIP to the primary ENI Of FortiGate.
D.
Create and attach an Internet gateway to the VPC. and then assign the EIP to the primary ENI Of FortiGate.
Answers
Suggested answer: D

HOW is traffic failover handled in a FortiGate active-active cluster deployed in AWS?

A.
The elastic load balancer handles traffic failover using FGCP.
A.
The elastic load balancer handles traffic failover using FGCP.
Answers
B.
The elastic load balancer handles bi-directional traffic failover using a health probe.
B.
The elastic load balancer handles bi-directional traffic failover using a health probe.
Answers
C.
All FortiGate cluster members send health probes using a dedicated interface.
C.
All FortiGate cluster members send health probes using a dedicated interface.
Answers
D.
All FortiGate cluster members use unicast FGCP_
D.
All FortiGate cluster members use unicast FGCP_
Answers
Suggested answer: B

Which AWS product integrates With FortiGate to automate security remediation for workloads running on the AWS platform?

A.
AWS Protector
A.
AWS Protector
Answers
B.
AWS Inspector
B.
AWS Inspector
Answers
C.
AWS Shield
C.
AWS Shield
Answers
D.
AWS GuardDuty
D.
AWS GuardDuty
Answers
Suggested answer: D

A customer deployed an HA Cloud formation to Stage and bootstrap the FortiGate configuration.

Which AWS functions are used by FortiGate HA to call the HA failover?

A.
AWS Lambda functions
A.
AWS Lambda functions
Answers
B.
AWS Mapping functions
B.
AWS Mapping functions
Answers
C.
AWS S3 functions
C.
AWS S3 functions
Answers
D.
AWS DynamoDB functions
D.
AWS DynamoDB functions
Answers
Suggested answer: A

What is the purpose of the created as part Of a FortiGate autoscale deployment using Fortinet cloud formation template in AWS?

A.
To store information about varying states of auto scaling conditions.
A.
To store information about varying states of auto scaling conditions.
Answers
B.
To Store the information used for the scale set.
B.
To Store the information used for the scale set.
Answers
C.
To store the traffic logs Of all FortiGates.
C.
To store the traffic logs Of all FortiGates.
Answers
D.
To store the firewall policies used by all FortiGates_
D.
To store the firewall policies used by all FortiGates_
Answers
Suggested answer: A

Refer to the exhibit.

An administrator configured two auto-scaling polices that they now want to test, What Will be the impact on payg-auto-scaling-group for the FortiGate devices if the administrator executes a scale-in policy?

A.
The scale-in policy will decrease instances from two to one.
A.
The scale-in policy will decrease instances from two to one.
Answers
B.
The scale-in policy will decrease the desired capacity from two to one
B.
The scale-in policy will decrease the desired capacity from two to one
Answers
C.
The scale-in policy will decrease the number of maximum instances from four to three.
C.
The scale-in policy will decrease the number of maximum instances from four to three.
Answers
Suggested answer: C

Refer to the exhibit.

Which statement is correct about the VPC peering connections shown in the exhibit?

A.
You can associate VPC ID pcx-23232323 with VPC B to form a VPC peering connection between VPC B and VPC C.
A.
You can associate VPC ID pcx-23232323 with VPC B to form a VPC peering connection between VPC B and VPC C.
Answers
B.
You cannot route packets directly from VPC B to VPC C through VPC A.
B.
You cannot route packets directly from VPC B to VPC C through VPC A.
Answers
C.
TO route packets directly from VPC B to VPC C through VPC A, you must add a route for network 192.168.0.0/16 in the VPC A routing table.
C.
TO route packets directly from VPC B to VPC C through VPC A, you must add a route for network 192.168.0.0/16 in the VPC A routing table.
Answers
D.
You cannot create a VPC peering connection between VPC B and VPC C to route packets directly.
D.
You cannot create a VPC peering connection between VPC B and VPC C to route packets directly.
Answers
Suggested answer: B
Total 30 questions
Go to page: of 3