Question 1
Q1A financial services company, FinSecure Capital, has deployed a FortiGate VM in Azure. They are using Azure tags to categorize VMs based on their environment (e.g., env:prod, env:dev). The security team wants to create a firewall policy that automatically applies to all production VMs, even as new ones are provisioned. What is the most efficient method on the FortiGate to create a firewall policy destination that dynamically includes all Azure VMs tagged with env:prod?
Show answer & explanation
Correct answer: B
The Azure SDN connector is designed for this exact purpose. It integrates with Azure APIs to discover resources and their metadata, like tags. By creating a dynamic address object filtered by the env:prod tag, the FortiGate will automatically update the object's members as VMs are added or removed, ensuring the firewall policy remains accurate without manual intervention. Manual updates are inefficient and error-prone. FQDN objects might not be feasible and are less dynamic. Scripting is a possible but more complex solution that reinvents the functionality already provided by the SDN connector.