FCP-WCS-AD-7-4 Sample Questions & Answers
Deploying FortiGate and FortiWeb in AWS with FortiManager and FortiAnalyzer integration carries the most weight, alongside public-cloud fundamentals, AWS networking, security, and traffic-flow components, HA design, and autoscaling with load balancers.
Launch the full FCP-WCS-AD-7-4 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Fortinet Product Deployment · FortiWeb Cloud Deployment
An e-commerce company is using FortiWeb Cloud to protect its primary application, which is hosted behind an AWS Application Load Balancer (ALB). To route traffic through FortiWeb Cloud for inspection, what critical DNS change must be made for their public domain
www.ecom-store.com?Show answer & explanation
Correct answer: C
FortiWeb Cloud operates as a reverse proxy. To direct traffic to it, the application's public DNS record (e.g.,
www.ecom-store.com) must be changed from an A record pointing to the ALB to a CNAME record pointing to the specific hostname provided by the FortiWeb Cloud service. FortiWeb Cloud then forwards legitimate traffic to the original server (the ALB). - Question 2Advanced
Fortinet Product Deployment · Centralized Security Architecture
A financial services company, FinSecure, is migrating its applications to a multi-VPC architecture in AWS. They have strict compliance requirements to inspect all east-west traffic between their 'Staging' and 'Production' VPCs, and all egress traffic to the internet from both VPCs. The security team must maintain stateful sessions and have centralized logging for audits. They want to avoid complex routing changes within the application VPCs.
The current setup involves a Transit Gateway connecting the VPCs. The security team has experience with FortiGate appliances and wants to leverage them in the cloud. Performance is critical, and the solution must scale horizontally without manual intervention. Centralized policy management is a key requirement from their existing FortiManager.
Which architecture best meets FinSecure's requirements for transparent, scalable, and stateful inspection?
graph TD subgraph Central_Security_VPC TGW_Attachment --- GWLB[Gateway Load Balancer] GWLB --- FG_ASG[FortiGate Auto Scaling Group] end subgraph Spoke_VPC_Staging App_Staging[Staging App] --> TGW_Attachment_Staging end subgraph Spoke_VPC_Production App_Prod[Production App] --> TGW_Attachment_Prod end TGW[Transit Gateway] -- routes to --> TGW_Attachment TGW_Attachment_Staging --> TGW TGW_Attachment_Prod --> TGW Internet((Internet)) -- egress --> TGWShow answer & explanation
Correct answer: C
This architecture, often called the 'centralized inspection VPC' model, meets all requirements. The Transit Gateway centralizes routing. The GWLB provides transparent, stateful inspection, ensuring traffic symmetry. The FortiGate Auto Scaling group provides horizontal scalability. This design minimizes routing changes in spoke VPCs and allows for centralized management via FortiManager and logging via FortiAnalyzer.
- Question 3Beginner
High Availability · HA Architecture
True or False: In a FortiGate Active-Passive HA cluster deployed across two different AWS Availability Zones, both the primary and secondary FortiGate instances require a public IP address to be active simultaneously for failover to function correctly.
Show answer & explanation
Correct answer: B
This statement is false. In an AWS A-P HA setup, a single Elastic IP (EIP) is used. During a failover event, API calls are made to AWS to disassociate the EIP from the failed primary instance and re-associate it with the newly promoted secondary instance. Only one instance holds the EIP at any given time.
- Question 4Intermediate
Fortinet Product Deployment · FortiManager Centralized Management
A large enterprise with hundreds of FortiGate VMs deployed across multiple AWS regions wants to enforce a consistent security policy baseline. They need to ensure that specific compliance rules, such as blocking outbound traffic to known malicious IPs, are applied to all FortiGates, while still allowing regional teams to add their own specific policies. How can this be achieved most efficiently using FortiManager?
Show answer & explanation
Correct answer: C
FortiManager's Global ADOM is designed for this purpose. Policies created in a global policy package can be inherited by subordinate ADOMs (e.g., regional ADOMs). This enforces a consistent baseline across the organization, while administrators of the subordinate ADOMs can still add their own local policies.
- Question 5Beginner
Public Cloud Fundamentals · AWS Infrastructure Components
A network administrator is setting up a new VPC in AWS for a three-tier application. They need to ensure that the database servers in the private subnet can download security patches from the internet without being directly accessible from the internet. Which AWS component is required in the public subnet to facilitate this one-way internet access?
Show answer & explanation
Correct answer: B
A NAT (Network Address Translation) Gateway is placed in a public subnet and allows instances in a private subnet to initiate outbound traffic to the internet while preventing unsolicited inbound traffic from being initiated from the internet. The private subnet's route table would have a default route pointing to the NAT Gateway.
- Question 6Advanced
Fortinet Product Deployment · FortiGate CNF Management
An organization has deployed FortiGate CNF. A central security team uses FortiManager for global policy management, and a separate cloud operations team prefers using native AWS tools. How can both teams manage the FortiGate CNF rule sets without creating conflicts?
Show answer & explanation
Correct answer: B
FortiGate CNF is designed to be managed by either FortiManager or AWS Firewall Manager. When integrated, they work together. Typically, FortiManager can be used for advanced threat protection and security fabric policies, while AWS Firewall Manager can be used for network-level rules and AWS-native integrations, providing a flexible, co-management model.
- Question 7Intermediate
High Availability · HA Failover Mechanism
In an AWS environment, what is the primary mechanism that a secondary FortiGate unit in an A-P cluster uses to redirect traffic to itself after detecting a failure of the primary unit?
Show answer & explanation
Correct answer: C
Since traditional Layer 2 failover mechanisms like gratuitous ARP are not supported in AWS, the FortiGate HA solution relies on AWS API calls. Upon failover, the newly promoted primary unit makes an API call to the AWS control plane to modify the VPC route tables, changing the next-hop for relevant routes from the old primary's ENI to its own ENI.
- Question 8IntermediateSelect 2
Fortinet Product Deployment · Licensing Models
A company is planning to deploy FortiGate VMs in AWS for a project with fluctuating traffic demands. They want a flexible licensing model that allows them to scale up and down without being locked into a fixed capacity. Which two Fortinet licensing models would be most suitable for this use case? (Select TWO)
Show answer & explanation
Correct answers: B, D
PAYG, available through the AWS Marketplace, is an on-demand model where you pay an hourly rate for the FortiGate software. It is ideal for scaling as you only pay for what you use.
FortiFlex is a consumption-based licensing program that allows organizations to use points to dynamically provision and de-provision licenses and services, offering maximum flexibility for environments with changing demands.
- Question 9Beginner
Fortinet Product Deployment · FortiAnalyzer Logging and Analytics
A healthcare provider is using FortiGate VMs in AWS to protect patient data. They need to generate monthly compliance reports for HIPAA. The logs from multiple FortiGates must be aggregated, archived for long-term storage, and analyzed for potential security incidents. Which Fortinet product is designed specifically for these functions?
Show answer & explanation
Correct answer: C
FortiAnalyzer is Fortinet's centralized logging, analytics, and reporting solution. It is designed to collect logs from multiple Fortinet devices, provide forensic analysis capabilities, and generate pre-built reports for various compliance standards, including HIPAA, PCI-DSS, and SOC 2.
- Question 10Intermediate
Public Cloud Fundamentals · AWS Security Components
A cloud engineer is troubleshooting a connectivity issue where an EC2 instance in a public subnet cannot receive traffic from the internet on port 443. The Security Group attached to the instance allows inbound traffic on port 443 from
0.0.0.0/0. However, traffic is still being blocked. Which other AWS security component operates at the subnet level and could be blocking the traffic?Show answer & explanation
Correct answer: C
Network ACLs (NACLs) are stateless firewalls that operate at the subnet level. Traffic must be allowed by both the NACL (at the subnet boundary) and the Security Group (at the instance level). If the Security Group is correctly configured, the next logical place to check is the NACL associated with the subnet, as it could have a rule explicitly denying the inbound traffic.
Ready for the real thing?
The full FCP-WCS-AD-7-4 simulator has every exam-style question, timed mode, and instant scoring.