ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 1 - FCP_WCS_AD-7.4 discussion

Report
Export

A customer has deployed FortiGate Cloud-Native Firewall (CNF).

Which two statements are correct about policy sets? (Choose two.)

A.
There is an implicit deny rule at the bottom of the policy set.
Answers
A.
There is an implicit deny rule at the bottom of the policy set.
B.
The policy set must be manually synchronized to the CNF instance each time it is modified.
Answers
B.
The policy set must be manually synchronized to the CNF instance each time it is modified.
C.
A new policy set is created with each deployed CNF instance.
Answers
C.
A new policy set is created with each deployed CNF instance.
D.
Multiple policy sets can be applied to a single CNF instance.
Answers
D.
Multiple policy sets can be applied to a single CNF instance.
Suggested answer: A, C

Explanation:

Implicit Deny Rule:

Similar to traditional firewall rule sets, FortiGate Cloud-Native Firewall (CNF) includes an implicit deny rule at the bottom of each policy set. This means any traffic that does not match an existing rule in the policy set is automatically denied (Option A).

Policy Set Creation:

When a new CNF instance is deployed, a new policy set is created specifically for that instance. This ensures that each CNF instance can have a tailored set of security policies based on the specific needs of the deployment (Option C).

Other Options Analysis:

Option B is incorrect because policy sets do not require manual synchronization; they are applied automatically once configured.

Option D is incorrect as a single CNF instance operates with a single policy set at a time.

FortiGate CNF Documentation: FortiGate CNF

Firewall Policy Best Practices: Fortinet Policies

asked 18/09/2024
Alejandro Meza
33 questions
NextNext
User
Your answer:
0 comments
Sorted by

Leave a comment first