Fortinet Certified Professional - Azure Cloud Security 7.4 Administrator Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 217 questions. Use the simulator for timed and flashcard mode.

Try Simulator

FCP-ZCS-AD-7-4 Sample Questions

  1. Question 1

    Q1

    A financial services company, FinSecure Capital, has deployed a FortiGate VM in Azure. They are using Azure tags to categorize VMs based on their environment (e.g., env:prod, env:dev). The security team wants to create a firewall policy that automatically applies to all production VMs, even as new ones are provisioned. What is the most efficient method on the FortiGate to create a firewall policy destination that dynamically includes all Azure VMs tagged with env:prod?

    Show answer & explanation

    Correct answer: B

    The Azure SDN connector is designed for this exact purpose. It integrates with Azure APIs to discover resources and their metadata, like tags. By creating a dynamic address object filtered by the env:prod tag, the FortiGate will automatically update the object's members as VMs are added or removed, ensuring the firewall policy remains accurate without manual intervention. Manual updates are inefficient and error-prone. FQDN objects might not be feasible and are less dynamic. Scripting is a possible but more complex solution that reinvents the functionality already provided by the SDN connector.

  2. Question 2

    Q2

    An administrator has configured a FortiGate Active-Passive HA cluster in Azure behind an external Azure Load Balancer. During a failover test, the passive unit becomes active, but external traffic is not reaching the newly active FortiGate. Internal traffic and HA synchronization are working correctly. The Azure Load Balancer health probe is configured to check an HTTPS service on port 443 on the FortiGates. Which configuration error is the most likely cause for the failure of external traffic to reach the new active unit?

    Show answer & explanation

    Correct answer: D

    In an Azure FortiGate HA setup, the Azure Load Balancer directs traffic to the active unit. During a failover, the newly active unit must take over the IP configurations from the failed unit. However, the Azure fabric itself is unaware of this internal FGCP failover. The failover mechanism relies on an API call to Azure to re-associate the secondary IP configurations (including the one in the LB's backend pool) from the old primary's NIC to the new primary's NIC. If this API call fails or is not configured, the LB will continue sending traffic to the NIC of the now-passive (failed) unit. Internal UDRs affect outbound and east-west traffic, not inbound external traffic through the LB. A split-brain would cause more severe issues. A failing health probe would stop traffic to both units, not just the newly active one.

  3. Question 3

    Q3

    An organization is deploying a multi-tiered application in Azure and needs to enforce network traffic filtering rules at the subnet level. They want to control both inbound and outbound traffic for their Virtual Machines. Which Azure component is used to filter network traffic to and from Azure resources in an Azure Virtual Network?

    Show answer & explanation

    Correct answer: C

    Network Security Groups (NSGs) are the fundamental tool in Azure for filtering network traffic. They contain a list of security rules that allow or deny traffic based on source/destination IP address, port, and protocol. NSGs can be associated with network interfaces or subnets to enforce traffic policies. Azure Firewall is a more advanced, stateful firewall-as-a-service. UDRs are used for routing, not filtering. Azure Application Gateway is a Layer 7 load balancer with WAF capabilities, operating at a higher level than basic network filtering.

  4. Question 4

    Q4

    A network engineer is configuring a site-to-site IPsec VPN tunnel between an on-premises FortiGate and an Azure VPN Gateway. The tunnel fails to establish. The engineer has verified that the pre-shared key and IP addresses are correct. The FortiGate is configured to use IKEv2 with AES-256 for encryption and SHA256 for integrity in Phase 1. Which of the following is a common reason for the VPN tunnel failure in this scenario?

    Show answer & explanation

    Correct answer: B

    Mismatched IPsec/IKE parameters are a primary cause of VPN tunnel failures. Azure VPN Gateways have default policies that specify cryptographic algorithms, including a specific Diffie-Hellman group for the key exchange. If the FortiGate is configured with a different DH group (e.g., Group 14) and the Azure side expects another (e.g., Group 2), the Phase 1 negotiation will fail. An incorrect IP range in the local network gateway would affect routing after the tunnel is up, not the establishment itself. A missing static route is also a post-establishment routing issue. Mismatched DPD might cause stability issues but usually doesn't prevent the initial connection.

  5. Question 5

    Q5

    Global E-Commerce Inc. runs a large retail platform on Azure, protected by a cluster of FortiGate firewalls. During peak shopping seasons, they experience massive traffic surges that can overwhelm the fixed number of firewalls, leading to performance degradation and dropped connections. Their current setup is an Active-Passive HA pair, which provides redundancy but not scalability. The primary business requirement is to maintain high performance and availability during unpredictable traffic spikes, while minimizing costs during off-peak hours. The solution must automatically scale the number of firewalls based on CPU utilization. All firewalls in the pool must have an identical security policy, which is managed centrally.

    The architecture team is proposing a new solution. The proposed architecture involves placing the FortiGate instances into an Azure VM Scale Set (VMSS). An external Azure Load Balancer will distribute incoming internet traffic to the FortiGates, and an internal Load Balancer will handle traffic from the application subnets. A User Defined Route (UDR) on the application subnets will direct all outbound traffic to the internal load balancer. The team needs to ensure that newly provisioned FortiGates automatically receive the correct configuration and licenses.

    Which combination of Fortinet and Azure services is required to build this scalable and automated firewall solution?

    Show answer & explanation

    Correct answer: A

    This scenario perfectly describes the use case for a FortiGate autoscaling deployment. The core components are: Azure VM Scale Set (VMSS) to manage the pool of FortiGates and handle scaling events; Azure Load Balancers to distribute traffic; a bootstrap configuration (often using a customdata file stored in Azure Storage) to provide initial settings to new instances; and FortiManager to act as the central configuration and licensing server. FortiManager ensures that as new FortiGates are spun up by the VMSS, they automatically register, receive the correct license, and pull the latest unified policy. The other options are incorrect for various reasons related to scalability and automated configuration management.

  6. Question 6

    Q6Multiple answers

    A cloud engineer is deploying a single FortiGate-VM from the Azure Marketplace using the standard ARM template for a standalone firewall. The engineer needs to ensure traffic can be routed through the FortiGate for inspection. After the deployment is complete, which two actions are essential to enable the FortiGate VM to forward traffic between its network interfaces? (Select TWO).

    Show answer & explanation

    Correct answers: A, C

    By default, Azure VMs are not allowed to forward IP packets that are not destined for them. To function as a router or firewall, the FortiGate VM requires IP forwarding to be explicitly enabled on its Azure NICs. This is an Azure-level setting. Secondly, even if Azure allows the forwarding, the FortiGate itself, being a firewall, will block traffic by default. A firewall policy must be created on the FortiGate to explicitly allow traffic to pass from one interface to another. NSGs control traffic to/from the NICs, but don't control the forwarding capability within the VM itself.

  7. Question 7

    Q7

    True or False: When deploying a FortiGate-VM in Azure using a Pay-As-You-Go (PAYG) license from the Marketplace, a separate license file from Fortinet must be manually uploaded to the VM after deployment.

    Show answer & explanation

    Correct answer: B

    This statement is false. The Pay-As-You-Go (PAYG) licensing model integrates the FortiGate software license cost directly into the Azure bill. The VM comes pre-licensed, and no manual license upload is required. This model is designed for flexibility and on-demand usage. The Bring-Your-Own-License (BYOL) model is the one that requires purchasing a license from Fortinet separately and uploading the license file to the VM.

  8. Question 8

    Q8

    A large enterprise has a complex hybrid network with multiple on-premises sites connected to Azure via ExpressRoute and S2S VPNs. They use a pair of FortiGate NVAs in Azure for traffic inspection and want to simplify their routing configuration. They need to dynamically exchange BGP routes between their on-premises gateways and the FortiGate NVAs without creating complex User Defined Routes. Which Azure service should be deployed to enable dynamic route exchange between the on-premises gateways and the FortiGate NVAs via BGP?

    Show answer & explanation

    Correct answer: C

    Azure Route Server is specifically designed for this purpose. It acts as a BGP route reflector, allowing BGP-enabled devices (like on-premises gateways and FortiGate NVAs) to peer with it and exchange routing information dynamically. This simplifies the management of routing in the virtual network, as it injects the learned routes into the VNet's routing table, eliminating the need for extensive manual UDR management. Virtual WAN is a broader hub-and-spoke connectivity solution. Load Balancer distributes traffic, it doesn't participate in BGP route exchange. Traffic Manager is a DNS-based load balancer.

  9. Question 9

    Q9

    When configuring a Site-to-Site VPN in Azure, you need to create a resource that represents the on-premises VPN device (like a FortiGate) and defines its public IP address and the on-premises network address spaces. This Azure resource is called a ______.

    Show answer & explanation

    Correct answer: C

    The Local Network Gateway is the Azure resource object that represents the on-premises side of the VPN connection. It holds the configuration details of the remote (on-premises) network, including the public IP address of the VPN device and the address prefixes of the on-premises network that Azure needs to route to. The Virtual Network Gateway represents the Azure side of the connection. The Connection is the resource that links the Virtual Network Gateway and the Local Network Gateway together.

  10. Question 10

    Q10

    An administrator configured an Azure SDN connector on a FortiGate using a Managed Identity. They created a dynamic address object to match VMs with the tag App:Database. However, the address object on the FortiGate remains empty, even though several VMs with that exact tag exist in the VNet. The FortiGate's system logs show no errors related to the SDN connector. What is the most likely reason the dynamic address object is not being populated?

    Show answer & explanation

    Correct answer: A

    For the SDN connector to function, the identity it uses (whether a Managed Identity or Service Principal) must have sufficient permissions to read resource information from the Azure API. The Reader role is the minimum required permission. If the Managed Identity does not have this role assigned at a scope that includes the VMs (such as the VNet, Resource Group, or Subscription), the FortiGate will be unable to query the Azure API for VMs and their tags, resulting in an empty dynamic address object. Tags in Azure are generally case-insensitive, but the most fundamental issue is permissions. The object should populate regardless of traffic. A reboot is not typically required.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the FCP-ZCS-AD-7-4 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 217 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon