Fortinet Certified Professional - AWS Cloud Security 7.4 Administrator Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 206 questions. Use the simulator for timed and flashcard mode.

Try Simulator

FCP-WCS-AD-7-4 Sample Questions

  1. Question 1

    Q1

    A security architect is designing a multi-account AWS environment using FortiGate CNF for centralized egress filtering. The design includes a central networking account with a transit gateway and multiple spoke VPCs in different member accounts. To inspect traffic from the spoke VPCs, the architect has created a GWLB endpoint in each spoke. What is the final critical step required in the spoke VPC route tables to direct egress traffic through the FortiGate CNF for inspection?

    Show answer & explanation

    Correct answer: B

    To enforce inspection, all egress traffic (0.0.0.0/0) from the spoke VPC subnets must be routed to the Gateway Load Balancer Endpoint (GWLBe). The GWLBe then forwards the traffic to the FortiGate CNF instance via the GWLB in the central security VPC for inspection before it proceeds to the internet.

  2. Question 2

    Q2

    An engineer deployed a FortiGate Active-Passive HA cluster in AWS using the official CloudFormation template. During a failover test, the secondary unit fails to promote to primary, and session state is lost. The IAM role has permissions for EC2 route table updates and EIP association, and the S3 bucket is in the correct region. What is the most likely cause of the FGCP unicast session synchronization failure?

    Show answer & explanation

    Correct answer: C

    FGCP unicast session synchronization and heartbeat communication in FortiOS occur over TCP port 703. If the Security Group governing the HA synchronization interface does not explicitly allow this traffic between the primary and secondary FortiGate instances, the cluster cannot synchronize sessions or properly detect failures, leading to failover failure.

  3. Question 3

    Q3

    A startup is deploying its first web application on AWS and requires basic web application firewall (WAF) protection against common exploits like SQL injection and cross-site scripting (XSS). The company has a limited budget and no dedicated security staff to manage a full WAF appliance. Which Fortinet solution is the most cost-effective and simplest to deploy for this requirement?

    Show answer & explanation

    Correct answer: D

    Using the native AWS WAF service and subscribing to the 'Fortinet Managed Rules for AWS WAF' is the simplest and most cost-effective solution. It provides expert-curated protection without the overhead of deploying, managing, and scaling a separate virtual appliance. This is ideal for organizations without dedicated security staff.

  4. Question 4

    Q4Multiple answers

    A DevSecOps team wants to automate security responses for newly discovered vulnerabilities on their EC2 instances. They are using AWS Inspector to scan instances and have configured a FortiGate with an SDN connector. Which two actions can be automated using the AWS SDN connector when AWS Inspector reports a high-severity vulnerability on an EC2 instance? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    The SDN connector can use metadata from AWS services like Inspector to dynamically update address objects on the FortiGate, effectively quarantining a vulnerable instance.

    By placing the vulnerable instance into a dynamic address group, a firewall policy can be pre-configured to apply a more restrictive security profile (like a specific IPS profile) to any traffic from members of that group.

  5. Question 5

    Q5

    When configuring a FortiGate Active-Passive cluster in AWS using FGCP, the heartbeat communication must be established. Because AWS environments do not support Layer 2 mechanisms like broadcast or multicast, the FGCP configuration must be set to ________.

    Show answer & explanation

    Correct answer: B

    Public cloud platforms like AWS do not support the Layer 2 broadcast or multicast traffic that default FGCP (FortiGate Clustering Protocol) relies on. Therefore, the cluster must be configured in unicast mode, where heartbeat packets are sent directly to the specific IP address of the peer member.

  6. Question 6

    Q6

    An e-commerce company is using FortiWeb Cloud to protect its primary application, which is hosted behind an AWS Application Load Balancer (ALB). To route traffic through FortiWeb Cloud for inspection, what critical DNS change must be made for their public domain www.ecom-store.com?

    Show answer & explanation

    Correct answer: C

    FortiWeb Cloud operates as a reverse proxy. To direct traffic to it, the application's public DNS record (e.g., www.ecom-store.com) must be changed from an A record pointing to the ALB to a CNAME record pointing to the specific hostname provided by the FortiWeb Cloud service. FortiWeb Cloud then forwards legitimate traffic to the original server (the ALB).

  7. Question 7

    Q7

    A financial services company, FinSecure, is migrating its applications to a multi-VPC architecture in AWS. They have strict compliance requirements to inspect all east-west traffic between their 'Staging' and 'Production' VPCs, and all egress traffic to the internet from both VPCs. The security team must maintain stateful sessions and have centralized logging for audits. They want to avoid complex routing changes within the application VPCs.

    The current setup involves a Transit Gateway connecting the VPCs. The security team has experience with FortiGate appliances and wants to leverage them in the cloud. Performance is critical, and the solution must scale horizontally without manual intervention. Centralized policy management is a key requirement from their existing FortiManager.

    Which architecture best meets FinSecure's requirements for transparent, scalable, and stateful inspection?

    graph TD subgraph Central_Security_VPC TGW_Attachment --- GWLB[Gateway Load Balancer] GWLB --- FG_ASG[FortiGate Auto Scaling Group] end subgraph Spoke_VPC_Staging App_Staging[Staging App] --> TGW_Attachment_Staging end subgraph Spoke_VPC_Production App_Prod[Production App] --> TGW_Attachment_Prod end TGW[Transit Gateway] -- routes to --> TGW_Attachment TGW_Attachment_Staging --> TGW TGW_Attachment_Prod --> TGW Internet((Internet)) -- egress --> TGW

    Show answer & explanation

    Correct answer: C

    This architecture, often called the 'centralized inspection VPC' model, meets all requirements. The Transit Gateway centralizes routing. The GWLB provides transparent, stateful inspection, ensuring traffic symmetry. The FortiGate Auto Scaling group provides horizontal scalability. This design minimizes routing changes in spoke VPCs and allows for centralized management via FortiManager and logging via FortiAnalyzer.

  8. Question 8

    Q8

    True or False: In a FortiGate Active-Passive HA cluster deployed across two different AWS Availability Zones, both the primary and secondary FortiGate instances require a public IP address to be active simultaneously for failover to function correctly.

    Show answer & explanation

    Correct answer: B

    This statement is false. In an AWS A-P HA setup, a single Elastic IP (EIP) is used. During a failover event, API calls are made to AWS to disassociate the EIP from the failed primary instance and re-associate it with the newly promoted secondary instance. Only one instance holds the EIP at any given time.

  9. Question 9

    Q9

    A large enterprise with hundreds of FortiGate VMs deployed across multiple AWS regions wants to enforce a consistent security policy baseline. They need to ensure that specific compliance rules, such as blocking outbound traffic to known malicious IPs, are applied to all FortiGates, while still allowing regional teams to add their own specific policies. How can this be achieved most efficiently using FortiManager?

    Show answer & explanation

    Correct answer: C

    FortiManager's Global ADOM is designed for this purpose. Policies created in a global policy package can be inherited by subordinate ADOMs (e.g., regional ADOMs). This enforces a consistent baseline across the organization, while administrators of the subordinate ADOMs can still add their own local policies.

  10. Question 10

    Q10

    A network administrator is setting up a new VPC in AWS for a three-tier application. They need to ensure that the database servers in the private subnet can download security patches from the internet without being directly accessible from the internet. Which AWS component is required in the public subnet to facilitate this one-way internet access?

    Show answer & explanation

    Correct answer: B

    A NAT (Network Address Translation) Gateway is placed in a public subnet and allows instances in a private subnet to initiate outbound traffic to the internet while preventing unsolicited inbound traffic from being initiated from the internet. The private subnet's route table would have a default route pointing to the NAT Gateway.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the FCP-WCS-AD-7-4 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 206 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon