FCSS_CDS_AR-7.6 Exam Questions
74 real FCSS_CDS_AR-7.6 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1FortiGate-VM Architectures in AWS
As part of your organization's monitoring plan, you have been tasked with obtaining and analyzing detailed information about the traffic sourced at one of your FortiGate EC2 instan...
VPC flow logsEC2 traffic monitoringAWS loggingnetwork visibility - Question #2FortiGate-VM Architectures in AWS
Refer to the exhibit. You are managing an active-passive FortiGate HA cluster in AWS that was deployed using CloudFormation. You have created a change set to examine the effects of...
CloudFormation change setsHA clusterPhysicalResourceIdstack updates - Question #3FortiGate-VM Architectures in Azure
Refer to the exhibit. What is the purpose of this section of an Azure Bicep file?
Azure BicepFortiOS version constraintsdeployment templatesallowed values - Question #4FortiGate-VM Architectures in AWS
In an SD-WAN TGW Connect topology, which three initial steps are mandatory when routing traffic from a spoke VPC to a security VPC through a Transit Gateway? (Choose three.)
Transit GatewaySD-WAN TGW Connectspoke VPC routingsecurity VPC - Question #5Multi-Cloud Security Orchestration
Refer to the exhibit. What would be the impact of confirming to delete all the resources in Terraform?
Terraform state fileterraform destroyinfrastructure as coderesource management - Question #6FortiGate-VM Architectures in AWS
An administrator is configuring a software-defined network (SDN) connector in FortiWeb to dynamically obtain information about existing objects in an Amazon Elastic Kubernetes Serv...
SDN connectorEKS integrationIAM policyFortiWeb - Question #7FortiGate-VM Architectures in AWS
Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?
Transit GatewayTGW route tablesVPC routingAWS networking - Question #8FortiGate-VM Architectures in Azure
Refer to the exhibit. You deployed an HA active-active load balance sandwich with two FortiGate VMs in Microsoft Azure. After the deployment, you prefer to use FGSP to synchronize...
FGSPHA active-activeAzure load balancer sandwichsession synchronization - Question #9FortiGate-VM Architectures in AWS
Refer to the exhibit. You attempted to access the Linux1 EC2 instance directly from the internet using its public IP address in AWS. However, your connection is not successful. Giv...
Internet Gatewayspoke VPCtransit gateway topologyconnectivity troubleshooting - Question #10Advanced Cloud Security Features
An administrator is trying to implement FortiCNP with Microsoft Azure Security integration. However, FortiCNP is not able to extract any cloud integration data from Azure; therefor...
FortiCNPAzure integrationIAM rolescloud security monitoring - Question #11Advanced Cloud Security Features
Refer to the exhibit. In which type of FortiCNP insights can an administrator examine the findings triggered by this policy?
FortiCNP insightsthreat detectionpolicy findingscloud monitoring - Question #12FortiGate-VM Architectures in Azure
Your monitoring team reports performance issues with a web application hosted in Azure. You suspect that the bottleneck might be due to unexpected inbound traffic spikes. Which met...
NSG flow logsAzure Monitortraffic analysisperformance troubleshooting - Question #13FortiGate-VM Architectures in AWS
The cloud administration team is reviewing an AWS deployment that was done using CloudFormation. The deployment includes six FortiGate instances that required custom configuration...
CloudFormation stack updateinstance replacementchange setFortiGate HA - Question #14FortiGate-VM Architectures in AWS
Refer to the exhibit. An experienced AWS administrator is creating a new Virtual Private Cloud (VPC) flow log with the settings shown in the exhibit. What is the purpose of this co...
VPC flow logslog retentionCloudWatchlogging configuration - Question #15Public Cloud Security Concepts
You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications re...
WAFOWASP Top 10FortiWebweb application protection - Question #16FortiGate-VM Architectures in Azure
An Azure administration team is looking for a FortiGate high availability (HA) solution that is able to: - Filter east-west traffic - Filter north-south traffic - Scale up - Scale...
Azure HA active-activeload balancerseast-west trafficscaling - Question #17Troubleshooting and Optimization
The DevOps team is troubleshooting a FortiGate software-defined network(SDN) connector that is failing to integrate with a Kubernetes cluster. While using several debug commands, t...
SDN connectorKubernetesHTTP 401authentication error - Question #18Public Cloud Security Concepts
Which two statements about the Amazon Web Services (AWS) security groups are true? (Choose two.)
security groupsstateful firewallENIinstance-level security - Question #19Advanced Cloud Security Features
An administrator would like to use FortiCNP to keep track of sensitive data files located in the Amazon Web Services (AWS) S3 bucket and protect it from malware. Which FortiCNP fea...
FortiCNPdata scanningS3 bucketmalware protection - Question #20Multi-Cloud Security Orchestration
You are using Ansible to modify the configuration of several FortiGate VMs. What is the minimum number of files you need to create, and in which file should you configure the targe...
Ansibleinventory fileplaybookFortiGate automation - Question #21FortiGate-VM Architectures in Azure
Refer to the exhibit. The exhibit shows an active-passive high availability FortiGate pair with external and internal Azure load balancers. There is no SDN connector used in this s...
active-passive HAAzure load balancerstatic routesprobe IP - Question #22FortiGate-VM Architectures in Azure
Your DevOps team is evaluating different Infrastructure as Code (IaC) solutions for deploying complex Azure environments. What is an advantage of choosing Azure Bicep over other Ia...
Azure BicepIaCARM templatespreview services - Question #23Public Cloud Security Concepts
You must add an Amazon Web Services (AWS) network access list (NACL) rule to allow SSH traffic to a subnet for temporary testing purposes. When you review the current inbound and o...
AWS NACLrule numberingSSH trafficsubnet security - Question #24FortiGate-VM Architectures in Azure
Refer to the exhibit. After the initial Terraform configuration in Microsoft Azure, the terraform plan command is run. Which two statements about running the terraform plan command...
Terraformterraform plandry runterraform init - Question #25Advanced Cloud Security Features
A network security administrator is searching for a solution to secure traffic going in and out of the container infrastructure. In which two ways can Fortinet container security h...
container securityFortiGate NGFWnorth-south trafficFortiWeb - Question #26Advanced Cloud Security Features
An organization is deploying FortiDevSec to enhance security for containerized applications, and they need to ensure containers are monitored for suspicious behavior at runtime. Wh...
FortiDevSeccontainer scannerruntime threatscontainer security - Question #27Troubleshooting and Optimization
Refer to the exhibit. You are troubleshooting a Microsoft Azure SDN connector issue on your FortiGate VM in Azure. Which command can you use to examine details about API calls sent...
SDN connectordebug commandsAzure API callscloud-connector - Question #28Advanced Cloud Security Features
You are tasked with adding public cloud accounts to FortiCNP cloud protection. After adding an Azure account, you notice the status shows as Partially running. What can you conclud...
FortiCNPcloud account statusAzure integrationcloud monitoring - Question #29FortiGate-VM Architectures in AWS
A DevOps team is configuring Terraform to deploy Amazon Web Services (AWS) resources. They want to use environment variables to authenticate Terraform with AWS, while ensuring that...
Terraform authenticationAWS credentialsenvironment variablesaccess keys - Question #30Advanced Cloud Security Features
An administrator is planning to use FortiDevSec to detect vulnerabilities in container images and is researching any platform limitations that they must take into account when usin...
FortiDevSeccontainer scanningprivate imagestool limitations - Question #31Public Cloud Security Concepts
Refer to the exhibit. An experienced AWS administrator is creating a new virtual public cloud (VPC) flow log with the settings shown in the exhibit. What is the purpose of this con...
VPC flow logsAWS loggingtraffic analysisCloudWatch - Question #32FortiGate-VM Architectures in AWS
An AWS administrator must ensure that each member of the cloud deployment team has the correct permissions to deploy and manage resources using CloudFormation. The administrator is...
CloudFormationEKSHelm chartIAM permissions - Question #33Troubleshooting and Optimization
An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure. However, the SDN connector is failing on the connection. What m...
SDN connectormanaged identityAzure authenticationFortiGate configuration - Question #34Troubleshooting and Optimization
Refer to the exhibit. A Managed Security Service Provider (MSSP) administration team is trying to deploy a new HA cluster in Azure to filter traffic to and from a client that is al...
Azure HA clusterdeployment failureactive-active HAAzure load balancer - Question #35FortiGate-VM Architectures in Azure
Refer to the exhibit. You deployed a FortiGate HA active-passive cluster in Microsoft Azure. Which two statements regarding this particular deployment are true? (Choose two.)
Azure HAactive-passiveconfig synchronizationAPI SLA - Question #36Troubleshooting and Optimization
Refer to the exhibit. You are tasked with deploying FortiGate using Terraform. When you run the terraform version command during the Terraform installation, you get an error messag...
Terraform installationbinary PATHcommand not foundLinux environment - Question #37FortiGate-VM Architectures in Azure
Refer to the exhibit. An administrator used the what-if tool to preview changes to an Azure Bicep file. What will happen if the administrator decides to apply these changes in Azur...
Azure Bicepwhat-if previewsubnet deploymentIaC changes - Question #38Troubleshooting and Optimization
Refer to the exhibit. After analyzing the native monitoring tools available in Azure, an administrator decides to use the tool displayed in the exhibit. Why would an administrator...
Azure monitoringnetwork latencyconnection monitoron-premises comparison - Question #39FortiGate-VM Architectures in AWS
Refer to the exhibit. An administrator implements FortiWeb ingress controller to protect containerized web applications in an AWS Elastic Kubernetes Service (EKS) cluster. What can...
FortiWebEKS ingress controllerSDN connectorFortiView topology - Question #40FortiGate-VM Architectures in AWS
Which statement about Amazon Web Services (AWS) Transit Gateway is true for SD-WAN transit gateway (TGW) Connect with FortiGate?
Transit GatewaySD-WANBGP routingVPC route tables - Question #41Multi-Cloud Security Orchestration
While working with Terraform files, an administrator notices that some of the variables do not have their type explicitly declared. What type of variable is vpccidr in the exhibit?
Terraformvariable typesinfrastructure as codeHCL - Question #42FortiGate-VM Architectures in Azure
An administrator is relying on an Azure Bicep linter to find possible issues in Bicep files. Which problem can the administrator expect to find?
Azure BiceplinterIaC validationdependsOn - Question #43FortiGate-VM Architectures in Azure
You have deployed a FortiGate HA cluster in Azure using a Gateway Load Balancer for traffic inspection. However, traffic is not being routed correctly through the firewalls. What c...
Azure Gateway Load BalancerFortiGate HAIP forwardingtraffic inspection - Question #44FortiGate-VM Architectures in AWS
Refer to the exhibit. You have deployed a Linux EC2 instance in Amazon Web Services (AWS) with the settings shown in the exhibit. What next step must the administrator take to acce...
AWS EC2Elastic IPpublic accessinstance networking - Question #45FortiGate-VM Architectures in AWS
Refer to the exhibit. In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet. However, your HTTPS connection to t...
AWS VPCtransit gatewayinternet gatewayEIP routing - Question #46FortiGate-VM Architectures in AWS
Refer to the exhibit. A senior administrator in a multinational organization needs to include a comment in the template shown in the exhibit to ensure that administrators from othe...
CloudFormationYAML commentstemplate syntaxAMI ID - Question #47FortiGate-VM Architectures in AWS
What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD- WAN?
SD-WANTransit Gateway ConnectGRE tunnelsAWS networking - Question #48Multi-Cloud Security Orchestration
A DevOps team is using Terraform to manage their infrastructure across multiple environments. Currently, the Terraform state file is stored locally on a developer's machine. The te...
Terraformremote statecollaborationIaC best practices - Question #49Troubleshooting and Optimization
Your organization has several FortiGate VMs deployed in Azure. You need to implement a solution with Azure native tools that allows you to determine whether packets are being permi...
Azure Network WatcherIP flow verifypacket filteringFortiGate troubleshooting - Question #50FortiGate-VM Architectures in Azure
Refer to the exhibit. An administrator deployed an HA active-active load balance sandwich in Microsoft Azure. The setup requires configuration synchronization between devices. What...
FortiGate HAAzure active-activeFGCPconfig synchronization