FCP - Public Cloud Security 7.4 Administrator Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 250 questions. Use the simulator for timed and flashcard mode.

Try Simulator

FCP-PCS-7.4 Sample Questions

  1. Question 1

    Q1

    A cloud architect is designing a centralized security architecture in AWS using a Transit Gateway (TGW). The requirement is to inspect all East-West traffic between Spoke VPCs and all North-South traffic to the internet. The design includes a dedicated Security VPC with an Auto Scaling Group of FortiGate-VMs behind a Geneve-compliant Gateway Load Balancer (GWLB).

    Which routing configuration ensures the return traffic from the FortiGate fleet is correctly sent back to the original Spoke VPC destination?

    Show answer & explanation

    Correct answer: B

    When using a Transit Gateway with a centralized inspection VPC (Security VPC), asymmetric routing often occurs because the TGW might send return traffic to a different availability zone than the source. Enabling 'Appliance Mode' on the TGW attachment for the Security VPC ensures that return traffic is routed to the same availability zone where the inspection took place, maintaining flow symmetry required for stateful firewalls like FortiGate.

  2. Question 2

    Q2

    An administrator is deploying a FortiGate-VM active-passive High Availability (HA) cluster in Microsoft Azure. To ensure proper failover, the administrator decides to use the Azure SDN Connector with Managed Identity.

    Which specific Azure permission role must be assigned to the FortiGate-VM's Managed Identity to allow it to update the User Defined Routes (UDR) during a failover event?

    Show answer & explanation

    Correct answer: B

    The Network Contributor role provides the necessary permissions to manage network resources, including the ability to update route tables (UDRs) and IP configurations on network interfaces. This is required for the FortiGate SDN connector to rewrite route next-hops to the active unit during an HA failover.

  3. Question 3

    Q3

    A company is using FortiGate CNF (Cloud Native Firewall) in AWS to protect multiple VPCs. The architecture uses a Gateway Load Balancer (GWLB) Endpoint in each application VPC to redirect traffic to the FortiGate CNF service.

    What is the primary benefit of using FortiGate CNF over a traditional self-managed FortiGate-VM Auto Scaling group in this scenario?

    Show answer & explanation

    Correct answer: B

    FortiGate CNF is a fully managed SaaS offering. The primary benefit is that Fortinet manages the underlying infrastructure, including the provisioning, scaling, and patching of the firewall instances (CNF instances), allowing the customer to focus solely on security policy management via FortiManager or the CNF console.

  4. Question 4

    Q4Multiple answers

    You are troubleshooting a FortiGate-VM SDN Connector in AWS that is failing to resolve dynamic address objects based on EC2 tags. The connector status shows 'Down' in the FortiGate GUI.

    Which of the following troubleshooting steps should you prioritize? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    The SDN connector requires permissions to query the AWS API. Specifically, 'ec2:DescribeInstances', 'ec2:DescribeTags', and similar 'Describe' permissions are essential for the connector to fetch metadata about resources and populate dynamic address objects.

    The SDN connector runs on the management plane of the FortiGate. It must be able to reach the public AWS API endpoints (e.g., ec2.us-east-1.amazonaws.com). If the management interface is in a private subnet without a NAT Gateway or VPC Endpoint, the connection will fail.

  5. Question 5

    Q5

    True or False: In a FortiGate Active-Active HA configuration within Azure using an external Azure Load Balancer (ALB), the ALB uses the same public IP address to balance traffic to both FortiGate nodes, but Source NAT (SNAT) on the FortiGate is required to ensure symmetric return traffic.

    Show answer & explanation

    Correct answer: A

    This is True. In Azure Active-Active HA with an external Load Balancer, the ALB distributes inbound traffic to both nodes. However, when the FortiGate forwards traffic to backend servers, the return traffic from the server must go back to the same FortiGate node that processed the initial packet. Applying Source NAT (SNAT) on the FortiGate ensures the server replies to the FortiGate's interface IP rather than the original client IP, guaranteeing the return path matches the forward path.

  6. Question 6

    Q6

    A FortiGate administrator is configuring the config system sdn-connector settings for an Azure environment. The goal is to allow the FortiGate to automatically populate an address group with the IP addresses of all Virtual Machines tagged with 'Environment=Production'.

    Which type of SDN connector configuration is most appropriate for this task?

    Show answer & explanation

    Correct answer: B

    The standard 'Azure' type SDN connector (configured with a Service Principal or Managed Identity) allows the FortiGate to query the Azure API for resource tags and properties. This enables the creation of dynamic address objects that filter based on tags like 'Environment=Production' and automatically update as VMs are added or removed.

  7. Question 7

    Q7

    In an AWS deployment, you are using a FortiGate-VM to inspect traffic between two VPCs connected via a Transit Gateway (TGW). The TGW has a single route table associated with all attachments. You observe that traffic between the VPCs is flowing directly and not passing through the FortiGate security VPC.

    What architectural change is required to force traffic through the FortiGate?

    Show answer & explanation

    Correct answer: B

    To inspect East-West traffic via a TGW, you must segment the routing domains. A common pattern is to have a 'Spoke Route Table' where the default route (0.0.0.0/0) or specific inter-VPC CIDRs point to the Security VPC attachment. The Security VPC attachment is associated with a separate 'Security Route Table' that propagates routes from the spokes, allowing the FortiGate to send traffic back to the correct destination.

  8. Question 8

    Q8

    When deploying FortiWeb in a public cloud environment to protect a web application, which deployment mode allows FortiWeb to inspect traffic without requiring changes to the network architecture or IP addressing of the application servers, often referred to as 'Transparent Inspection'?

    Show answer & explanation

    Correct answer: B

    In True Transparent Proxy mode, FortiWeb is deployed inline (layer 2 bridge) and inspects traffic without modifying the source or destination IP addresses. This makes the WAF invisible to the client and server. Note: In many public cloud environments (Layer 3 only), True Transparent is difficult to implement without specific overlay networking; however, conceptually, this is the mode for 'transparent inspection'. In Cloud native contexts, Reverse Proxy is more common, but the question asks for the mode definition.

  9. Question 9

    Q9

    An organization requires a highly available FortiGate solution in Azure. The design uses an Active-Passive configuration. During a failover test, the secondary unit becomes active but traffic is dropped because the User Defined Routes (UDRs) in the Azure subnets still point to the IP address of the failed primary unit.

    Which component is responsible for detecting the failure and updating the Azure UDRs to point to the new active unit's IP?

    Show answer & explanation

    Correct answer: B

    In an API-based HA architecture (often used when Load Balancers are not preferred for internal routing), the FortiGate SDN Connector on the unit becoming 'Primary' triggers an API call to Azure Resource Manager to update the Next Hop IP in the UDRs to its own interface IP.

  10. Question 10

    Q10

    Case Study:

    Scenario
    GlobalBank uses AWS for its core banking application. The architecture consists of a Hub VPC and three Spoke VPCs (App, DB, Partner). They use a FortiGate Active-Passive HA pair in the Hub VPC.

    Issue
    The network team reports that traffic from the App VPC to the DB VPC is working fine and being inspected. However, traffic from the Partner VPC (10.2.0.0/16) to the App VPC (10.1.0.0/16) is failing intermittently.

    Configuration

    • TGW is used for all inter-VPC communication.
    • TGW Route Table has routes to 0.0.0.0/0 via the Hub VPC attachment.
    • Hub VPC has FortiGates in different AZs (AZ1 and AZ2).
    • Partner VPC attachment is associated with the TGW Route Table.
    • TGW 'Appliance Mode' is disabled on the Hub VPC attachment.

    Which action will permanently resolve the intermittent connectivity issue while maintaining traffic inspection?

    Show answer & explanation

    Correct answer: A

    The issue is likely asymmetric routing caused by the Transit Gateway crossing Availability Zones. When traffic leaves the Hub VPC (after inspection), TGW might send it to an AZ in the destination VPC different from the source. However, the return traffic might enter the TGW in a different AZ and be routed to the passive FortiGate or the wrong interface in the Hub VPC if Appliance Mode is not on. Enabling Appliance Mode forces the TGW to use the same AZ attachment for the return traffic flow, ensuring it hits the active FortiGate processing the session.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the FCP-PCS-7.4 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 250 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon