ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 19 - FCP_WCS_AD-7.4 discussion

Report
Export

Refer to the exhibit.

An administrator configured a FortiGate device to connect to the AWS API to retrieve resource values from the AWS console to create dynamic objects for the FortiGate policies. The administrator is unable to retrieve AWS dynamic objects on FortiGate.

Which two reasons can explain why? (Choose two.)

A.
The AWS API call is not supported on XML version 1.0.
Answers
A.
The AWS API call is not supported on XML version 1.0.
B.
AWS was not able to validate credentials provided by the AWS Lab SDN connector because of a clock skew between FortiGate and AWS.
Answers
B.
AWS was not able to validate credentials provided by the AWS Lab SDN connector because of a clock skew between FortiGate and AWS.
C.
The AWS Lab SDN connector is configured with an invalid AWS access or secret key.
Answers
C.
The AWS Lab SDN connector is configured with an invalid AWS access or secret key.
D.
The AWS Lab SDN connector failed to connect on port 401.
Answers
D.
The AWS Lab SDN connector failed to connect on port 401.
E.
The AWS Lab SDN did not find any instances in the configured VPC.
Answers
E.
The AWS Lab SDN did not find any instances in the configured VPC.
Suggested answer: B, C

Explanation:

Invalid Credentials:

The debug output shows an 'AuthFailure' error, indicating that AWS was not able to validate the provided access credentials. This usually points to incorrect or invalid AWS access or secret keys configured in the AWS Lab SDN connector (Option C).

Clock Skew:

Another common reason for authentication failures in AWS API calls is a clock skew between the FortiGate device and AWS. AWS requires that the system time of the client making the API call is synchronized with its own time, within a small margin. If there is a significant time difference, AWS will reject the credentials (Option B).

Other Options Analysis:

Option A is incorrect because the AWS API supports XML version 1.0.

Option D is incorrect as the error message does not indicate an issue with connecting on port 401.

Option E is incorrect because the error is related to authentication, not the absence of instances.

AWS API Authentication: AWS API Security

FortiGate AWS Integration Guide: FortiGate AWS Integration

asked 18/09/2024
Rakesh Sharma
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first