FCP-ZCS-AD-7-4 Sample Questions & Answers
Standing up single FortiGate and FortiWeb instances in Azure gets the heaviest weighting, next to basic cloud and Azure concepts, Azure's networking and security building blocks, HA with load balancing and route-server concepts, and site-to-site VPN options.
Launch the full FCP-ZCS-AD-7-4 simulator →Free FCP-ZCS-AD-7-4 Sample Questions with Answers
Real questions from the Fortinet Certified Professional - Azure Cloud Security 7.4 Administrator practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1IntermediateSelect 2
Fortinet Product Deployment · Deploy a single FortiGate instance
A cloud engineer is deploying a single FortiGate-VM from the Azure Marketplace using the standard ARM template for a standalone firewall. The engineer needs to ensure traffic can be routed through the FortiGate for inspection. After the deployment is complete, which two actions are essential to enable the FortiGate VM to forward traffic between its network interfaces? (Select TWO).
Show answer & explanation
Correct answers: A, C
By default, Azure VMs are not allowed to forward IP packets that are not destined for them. To function as a router or firewall, the FortiGate VM requires IP forwarding to be explicitly enabled on its Azure NICs. This is an Azure-level setting. Secondly, even if Azure allows the forwarding, the FortiGate itself, being a firewall, will block traffic by default. A firewall policy must be created on the FortiGate to explicitly allow traffic to pass from one interface to another. NSGs control traffic to/from the NICs, but don't control the forwarding capability within the VM itself.
- Question 2Beginner
Fortinet Product Deployment · Fortinet solutions in Azure
True or False: When deploying a FortiGate-VM in Azure using a Pay-As-You-Go (PAYG) license from the Marketplace, a separate license file from Fortinet must be manually uploaded to the VM after deployment.
Show answer & explanation
Correct answer: B
This statement is false. The Pay-As-You-Go (PAYG) licensing model integrates the FortiGate software license cost directly into the Azure bill. The VM comes pre-licensed, and no manual license upload is required. This model is designed for flexibility and on-demand usage. The Bring-Your-Own-License (BYOL) model is the one that requires purchasing a license from Fortinet separately and uploading the license file to the VM.
- Question 3Intermediate
High Availability (HA) · Explain Azure route server use cases
A large enterprise has a complex hybrid network with multiple on-premises sites connected to Azure via ExpressRoute and S2S VPNs. They use a pair of FortiGate NVAs in Azure for traffic inspection and want to simplify their routing configuration. They need to dynamically exchange BGP routes between their on-premises gateways and the FortiGate NVAs without creating complex User Defined Routes. Which Azure service should be deployed to enable dynamic route exchange between the on-premises gateways and the FortiGate NVAs via BGP?
Show answer & explanation
Correct answer: C
Azure Route Server is specifically designed for this purpose. It acts as a BGP route reflector, allowing BGP-enabled devices (like on-premises gateways and FortiGate NVAs) to peer with it and exchange routing information dynamically. This simplifies the management of routing in the virtual network, as it injects the learned routes into the VNet's routing table, eliminating the need for extensive manual UDR management. Virtual WAN is a broader hub-and-spoke connectivity solution. Load Balancer distributes traffic, it doesn't participate in BGP route exchange. Traffic Manager is a DNS-based load balancer.
- Question 4Beginner
VPN Solutions in Azure · Explain Site-to-Site connection options in Azure
When configuring a Site-to-Site VPN in Azure, you need to create a resource that represents the on-premises VPN device (like a FortiGate) and defines its public IP address and the on-premises network address spaces. This Azure resource is called a ______.
Show answer & explanation
Correct answer: C
The Local Network Gateway is the Azure resource object that represents the on-premises side of the VPN connection. It holds the configuration details of the remote (on-premises) network, including the public IP address of the VPN device and the address prefixes of the on-premises network that Azure needs to route to. The Virtual Network Gateway represents the Azure side of the connection. The Connection is the resource that links the Virtual Network Gateway and the Local Network Gateway together.
- Question 5Advanced
Fortinet Product Deployment · Troubleshoot FortiGate Azure SDN integration
An administrator configured an Azure SDN connector on a FortiGate using a Managed Identity. They created a dynamic address object to match VMs with the tag
App:Database. However, the address object on the FortiGate remains empty, even though several VMs with that exact tag exist in the VNet. The FortiGate's system logs show no errors related to the SDN connector. What is the most likely reason the dynamic address object is not being populated?Show answer & explanation
Correct answer: A
For the SDN connector to function, the identity it uses (whether a Managed Identity or Service Principal) must have sufficient permissions to read resource information from the Azure API. The
Readerrole is the minimum required permission. If the Managed Identity does not have this role assigned at a scope that includes the VMs (such as the VNet, Resource Group, or Subscription), the FortiGate will be unable to query the Azure API for VMs and their tags, resulting in an empty dynamic address object. Tags in Azure are generally case-insensitive, but the most fundamental issue is permissions. The object should populate regardless of traffic. A reboot is not typically required. - Question 6Intermediate
High Availability (HA) · Configure HA using FortiGate in Azure
A consultant is designing a resilient architecture for a critical application in Azure using a FortiGate Active-Passive cluster. To achieve high availability across physical locations within an Azure region, they need to ensure the two FortiGate VMs are not on the same physical hardware rack. Which Azure feature should be used to deploy the two FortiGate VMs to protect against a localized hardware failure within a datacenter?
Show answer & explanation
Correct answer: C
An Azure Availability Set is the feature designed to provide resiliency against hardware failures within a datacenter. It distributes VMs across different fault domains (racks with independent power and network) and update domains (groups of VMs that can be rebooted at the same time). Placing the two HA FortiGate VMs in the same Availability Set ensures they will be on different fault domains, protecting the cluster from a single rack failure. A VM Scale Set is for scaling, not just HA for a pair. Resource Groups are for logical organization. A Proximity Placement Group does the opposite; it co-locates VMs for low latency.
- Question 7Intermediate
Azure Components · Explain Azure components and networking elements
An architect has designed a hub-spoke network in Azure. The hub VNet contains a FortiGate firewall. The spoke VNets are peered with the hub VNet. The architect needs to ensure that all traffic from the spoke VNets destined for the internet is routed through the FortiGate in the hub for inspection. What must be configured in the spoke VNets to force internet-bound traffic to the FortiGate in the hub VNet?
Show answer & explanation
Correct answer: C
The standard mechanism in Azure for overriding the default system routing is to use User Defined Routes (UDRs). By creating a route table with a route for 0.0.0.0/0 (representing all internet traffic) and setting the next-hop type to 'VirtualAppliance' with the private IP of the hub FortiGate, all outbound traffic from the associated spoke subnets will be forced through the firewall for inspection. While enabling gateway transit is necessary for some peering scenarios, it doesn't by itself force traffic to a firewall NVA. NSG rules and Azure policies can block traffic but do not redirect it.
- Question 8Intermediate
Fortinet Product Deployment · Deploy a single FortiWeb instance
A company has deployed a web application on an Azure VM. They want to protect this application from common web vulnerabilities like SQL injection and cross-site scripting (XSS). They have deployed a FortiWeb VM in the same VNet. What is the primary function of the FortiWeb VM in this scenario?
Show answer & explanation
Correct answer: B
FortiWeb's core function is to be a Web Application Firewall (WAF). It is deployed as a reverse proxy that sits in front of web applications, inspecting incoming HTTP/HTTPS traffic for threats like those mentioned in the OWASP Top 10 (SQLi, XSS, etc.). While it has Layer 4 capabilities, its primary value is at Layer 7. It can perform SSL offloading, but its purpose is not encrypting backend traffic. It is not a DNS load balancer.
- Question 9AdvancedSelect 2
VPN Solutions in Azure · Deploy Azure virtual WAN
A multinational corporation with offices across North America, Europe, and Asia is migrating to Azure. They require a scalable, managed solution to connect all their branch offices to each other and to Azure resources deployed in multiple regions. They want to simplify network management and optimize performance for a hub-and-spoke topology. Which two benefits does Azure Virtual WAN provide for this corporation's requirements? (Select TWO).
Show answer & explanation
Correct answers: A, D
Azure Virtual WAN is a managed networking service that provides a global transit backbone for large-scale site-to-site, point-to-site, and ExpressRoute connectivity. Its key benefits include providing a unified hub for any-to-any connectivity (transitive routing between all connected sites) and centralizing management, which simplifies the overall network topology. It does not automatically configure on-premises devices, nor does it have built-in WAF capabilities.
- Question 10Intermediate
High Availability (HA) · Troubleshoot HA using FortiGate in Azure
An Azure administrator is monitoring a FortiGate Active-Passive cluster. They notice that a failover event occurred, but they want to understand why. The HA is configured for session pickup, and the monitor interfaces are correctly tracking upstream and downstream connectivity. Which FortiGate CLI command would be most useful for viewing the HA event log to diagnose the cause of the failover?
Show answer & explanation
Correct answer: C
The
diagnose sys ha history readcommand displays the HA event history log. This log contains detailed information about HA state changes, failover triggers, synchronization status, and other events related to the HA cluster's operation. It is the primary tool for post-mortem analysis of a failover event.get system ha statusshows the current real-time status but not the historical events.diagnose sys topshows real-time process utilization, andget router info routing-tabledisplays the routing table; neither is for diagnosing HA event history.
Ready for the real thing?
The full FCP-ZCS-AD-7-4 simulator has every exam-style question, timed mode, and instant scoring.