nerdexam
Fortinet

FCSS_CDS_AR-7.6 · Question #49

Your organization has several FortiGate VMs deployed in Azure. You need to implement a solution with Azure native tools that allows you to determine whether packets are being permitted or blocked by…

The correct answer is C. Use IP flow verify for each of the VMs. Azure IP flow verify is part of Network Watcher and lets you check if traffic is allowed or denied for a specific VM by analyzing its effective security rules and routing. This provides visibility into whether packets are being permitted or blocked for the FortiGate VMs.

Troubleshooting and Optimization

Question

Your organization has several FortiGate VMs deployed in Azure. You need to implement a solution with Azure native tools that allows you to determine whether packets are being permitted or blocked by the FortiGate VMs. Which solution can you use to meet these requirements?

Options

  • AInsert the VM traffic logs in Azure Sentinel.
  • BInstall the Azure Monitor agent in all VMs.
  • CUse IP flow verify for each of the VMs.
  • DConfigure Azure Advisor to analyze the network traffic.

How the community answered

(66 responses)
  • A
    5% (3)
  • B
    3% (2)
  • C
    91% (60)
  • D
    2% (1)

Explanation

Azure IP flow verify is part of Network Watcher and lets you check if traffic is allowed or denied for a specific VM by analyzing its effective security rules and routing. This provides visibility into whether packets are being permitted or blocked for the FortiGate VMs.

Topics

#Azure Network Watcher#IP flow verify#packet filtering#FortiGate troubleshooting

Community Discussion

No community discussion yet for this question.

Full FCSS_CDS_AR-7.6 Practice