Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

An administrator must deploy a web application firewall (WAF) solution to protect the web applications of their organization.

Why would the administrator choose FortiWeb Cloud over AWS WAF with Fortinet managed rules?

A.

WAF signatures must be manually updated by FortiGuard.

B.

The solution must meet PCI 6.6 compliance.

C.

SSL inspection is a requirement.

D.

Traffic must be inspected for malware.

Refer to the exhibit.

An administrator configured a FortiGate device to connect to the AWS API to retrieve resource values from the AWS console to create dynamic objects for the FortiGate policies. The administrator is unable to retrieve AWS dynamic objects on FortiGate.

Which two reasons can explain why? (Choose two.)

A.

The AWS API call is not supported on XML version 1.0.

B.

AWS was not able to validate credentials provided by the AWS Lab SDN connector because of a clock skew between FortiGate and AWS.

C.

The AWS Lab SDN connector is configured with an invalid AWS access or secret key.

D.

The AWS Lab SDN connector failed to connect on port 401.

E.

The AWS Lab SDN did not find any instances in the configured VPC.

Your customers have been reporting slow response times when accessing your web application.

What are two possible ways to increase response times from web servers protected by FortiWeb Cloud? (Choose two.)

Your customers have been reporting slow response times when accessing your web application.

What are two possible ways to increase response times from web servers protected by FortiWeb Cloud? (Choose two.)

A.

Deploy FortiWeb Cloud in the same region where your web application is being hosted.

B.

Enable a content delivery network

C.

Modify DNS entries to directly point to your web server.

D.

Disable WAF functionality.

What is a drawback of deploying a FortiWeb VM inside a virtual public cloud (VPC) compared to FortiWeb Cloud?

A.

It is unable to support web applications from OWASP Top 10 threats.

B.

It does not support zero-day protection.

C.

It is slower than FortiWeb Cloud to apply advanced WAF protection.

D.

Only applications going through the VPC are protected.

Refer to the exhibit.

A customer is using the AWS Elastic Load Balancer (ELB).

Which two statements are correct about the ELB configuration? (Choose two.)

A.

The load balancer is configured to load balance traffic among multiple availability zones.

B.

The Amazon Resource Name is used to access the load balancer node and targets.

C.

You can use the DNS name to reach the targets behind the ELB.

D.

The load balancer is configured for the internal traffic of the virtual public cloud (VPC).

You need to deploy a new Windows server in AWS to offload web traffic from an existing web server in a different availability zone.

According to the AWS shared responsibility model, what three actions must you take to secure the new EC2 instance? (Choose three.)

A.

Update software on the instance.

B.

Change the existing elastic load balancer (ELB) to a gateway load balancer

C.

Configure security groups.

D.

Manage the operating system on the instance.

E.

Move all web servers into the same availability zone.

A customer is attempting to deploy an active-passive high availability (HA) cluster using the software-defined network (SDN) connector in the AWS cloud.

What is an important consideration to ensure a successful formation of HA, failover, and traffic flow?

A.

Both cluster members must be in the same availability zone.

B.

VDOM exceptions must be configured.

C.

Unicast FortiGate Clustering Protocol (FGCP) must be used.

D.

Both cluster members must show as healthy in the elastic load balancer (ELB) configuration.

Your organization is deciding between deploying FortiWeb VM or Fortinet Managed Rules for AWS WAF.

What are two benefits of choosing FortiWeb VM? (Choose two.)

A.

Only pay for what is used.

B.

Up-to-date WAF signatures powered by FortiGuard.

C.

Zero-day protection.

D.

Advanced WAF functionality.

Refer to the exhibit.

What two conclusions can you draw from the FortiGate debug output? (Choose two.)

A.

The dynamic address object is automatically updated if the IP changes.

B.

The address object AWS Windows Server Lab can be manually changed on FortiGate.

C.

The SDN connector is correctly configured and authorized.

D.

The AWS user account used for software-defined network (SDN) integration must have full administrative rights.

Refer to the exhibit.

Which two statements are correct about traffic flow in FortiWeb Cloud? (Choose two.)

A.

The DNS name for the application servers must point to FortiWeb Cloud.

B.

FortiWeb Cloud filters the incoming traffic from users, blocking the OWASP Top 10 attacks, zero-day threats, and other application layer attacks.

C.

FortiWeb Cloud can protect the application servers only if they are all located in the same virtual public cloud (VPC).

D.

Step 2 requires an AWS S3 bucket to be created.