Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

You are troubleshooting network connectivity issues between two VMs deployed in AWS.

One VM is a FortiGate located on subnet "LAN" that is part of the VPC "Encryption". The other VM is a Windows server located on the subnet "servers" which is also in the "Encryption" VPC. You are unable to ping the Windows server from FortiGate.

What are two reasons for this? (Choose two.)

A.

The firewall in the Windows VM is blocking the traffic.

B.

The default AWS Network Access Control List (NACL) does not allow this traffic.

C.

By default, AWS does not allow ICMP traffic between subnets.

D.

Add an inbound allow ICMP rule in the security group attached to the windows server.

An administrator wants to deploy a solution to automatically create firewall rules on FortiGate to accelerate time-to-protection for threats.

Which AWS service can be integrated with FortiGate to accomplish this?

A.

AWS Firewall Manager

B.

AWS network access control list

C.

SDN Connector for AWS

D.

AWS GuardDuty

Refer to the exhibit.

You deployed an active-passive FortiGate HA cluster using a CloudFormation template on an existing VPC. Now you want to test active-passive FortiGate HA failover by running a debug so you can see the API calls to change the Elastic and secondary IP addresses.

Which statement is correct about the output of the debug?

A.

The routing table for Fgt2 updated successfully, and port2 will provide internet access to Fgt2.

B.

The Elastic IP is associated with port1 of Fgt2.

C.

IP address 10.0.0.13 is now associated with eni-0b61d8afc0aefb8a2.

D.

The Elastic IP is associated with port2 of Fgt2, and the secondary IP address for port1 and port2 was updated successfully.

Your organization is deciding between deploying FortiWeb VM or Fortinet Managed Rules for AWS WAF.

What are two benefits of choosing FortiWeb VM? (Choose two.)

A.

Only pay for what is used.

B.

Up-to-date WAF signatures powered by FortiGuard.

C.

Zero-day protection.

D.

Advanced WAF functionality.

Refer to the exhibit.

What two conclusions can you draw from the FortiGate debug output? (Choose two.)

A.

The dynamic address object is automatically updated if the IP changes.

B.

The address object AWS Windows Server Lab can be manually changed on FortiGate.

C.

The SDN connector is correctly configured and authorized.

D.

The AWS user account used for software-defined network (SDN) integration must have full administrative rights.

What is a drawback of deploying a FortiWeb VM inside a virtual public cloud (VPC) compared to FortiWeb Cloud?

A.

It is unable to support web applications from OWASP Top 10 threats.

B.

It does not support zero-day protection.

C.

It is slower than FortiWeb Cloud to apply advanced WAF protection.

D.

Only applications going through the VPC are protected.

Which two statements about the FortiCloud portal are true? (Choose two.)

A.

You can gain remote access to your FortiGate VM directly from the portal.

B.

To assign permissions in the identity and access management (JAM) portal, you must write a JSON script.

C.

You can access the FortiFlex portal only after you purchase a FortiFlex license and register it on FortiCare.

D.

You can access only cloud services that you have subscribed to on AWS marketplace.

Refer to the exhibit.

Traffic is initiated from the EC2 instance and is destined for the internet.

Which traffic flow is correct?

A.

EC2 instance > NAT GW > IGW > internet

B.

There is no route to the internet in the Private Route Table. The traffic does not reach the internet.

C.

EC2 instance > GWLBe > NAT GW > IGW > internet

D.

EC2 instance > GWLBe > internet

You want to deploy the Fortinet HA CloudFormation template to stage and bootstrap the FortiGate configuration in the same region in which you created your VPC, which is Ohio US-East-2.

Based on this information, which statement is correct?

A.

You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration. The S3 bucket can be hosted in any region.

B.

The Fortinet HA cloud formation template automatically creates an S3 bucket.

C.

You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration. The S3 bucket needs to be hosted in the Ohio US-East-2 region.

D.

You create a DynamoDB to stage and bootstrap FortiGate with an FGCP unicast configuration. It needs to be hosted in the Ohio US-East-2 region.

Refer to the exhibit.

What occurs during a failover for an active-passive (A-P) cluster that is deployed in two different availability zones? (Choose two.)

A.

The cluster elastic IP address (EIP) is moved from Port1 of FGT-1 to Port1 of FGT-2.

B.

The secondary IP address of Port2 of FGT-1 is moved to Port2 of FGT-2.

C.

The default static route in the Private-AZ1 subnet route table is modified to forward all traffic to Port2 of FGT2.

D.

An additional route is added to the route table of the HA Sync AZ2 subnet to forward all traffic to the Internet GW.