Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dcdisc65

Page: 1 / 1
Total 10 questions
Exam Code: FCP_WCS_AD-7.4                Update: Oct 15, 2025
Exam Name: FCP - AWS Cloud Security 7.4 Administrator Exam

Fortinet FCP - AWS Cloud Security 7.4 Administrator Exam FCP_WCS_AD-7.4 Exam Dumps: Updated Questions & Answers (October 2025)

Question # 1

An organization has created a VPC with two subnets and deployed a FortiGate-VM (VM04/c4.xlarge) in AWS.

The EC2 instance is initially configured with two Elastic Network Interfaces (ENIs). The primary ENI is configured on the public subnet, and the secondary ENI is configured on the private subnet. To provide internet access for the FortiGate-VM, they now want to associate an EIP to its primary ENI, but the assignment is failing.

Which action would allow the EIP assignment to be successful?

A.

Create and associate a public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI.

B.

Shut down the FortiGate VM, if it is running, assign the EIP to the primary ENI, and then power it on.

C.

Create and attach an internet gateway to the VPC, and then assign the EIP to the primary ENI of the FortiGate VM.

D.

Create and attach a public routing table to the public subnet, associate the public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI.

Question # 2

Refer to the exhibit.

You deployed an active-passive FortiGate HA cluster using a CloudFormation template on an existing VPC. Now you want to test active-passive FortiGate HA failover by running a debug so you can see the API calls to change the Elastic and secondary IP addresses.

Which statement is correct about the output of the debug?

A.

The routing table for Fgt2 updated successfully, and port2 will provide internet access to Fgt2.

B.

The Elastic IP is associated with port1 of Fgt2.

C.

IP address 10.0.0.13 is now associated with eni-0b61d8afc0aefb8a2.

D.

The Elastic IP is associated with port2 of Fgt2, and the secondary IP address for port1 and port2 was updated successfully.

Question # 3

Refer to the exhibit.

Traffic is initiated from the EC2 instance and is destined for the internet.

Which traffic flow is correct?

A.

EC2 instance > NAT GW > IGW > internet

B.

There is no route to the internet in the Private Route Table. The traffic does not reach the internet.

C.

EC2 instance > GWLBe > NAT GW > IGW > internet

D.

EC2 instance > GWLBe > internet

Question # 4

Refer to the exhibit.

A customer is using the AWS Elastic Load Balancer (ELB).

Which two statements are correct about the ELB configuration? (Choose two.)

A.

The load balancer is configured to load balance traffic among multiple availability zones.

B.

The Amazon Resource Name is used to access the load balancer node and targets.

C.

You can use the DNS name to reach the targets behind the ELB.

D.

The load balancer is configured for the internal traffic of the virtual public cloud (VPC).

Question # 5

An AWS administrator is designing internet connectivity for an organization's virtual public cloud (VPC). The organization has web servers with private addresses that must be reachable from the internet. The web servers must be highly available.

Which two configurations can you use to ensure the web servers are highly available and reachable from the internet? (Choose two.)

A.

Deploy a network load balancer.

B.

Configure a network address translation (NAT) Gateway in your VPC. Place web servers behind the NAT Gateway.

C.

Add a route to the default virtual public cloud (VPC) route table forwarding all traffic to the internet gateway.

D.

Deploy web servers in multiple availability zones.

Question # 6

Refer to the exhibit.

Which two statements are correct about traffic flow in FortiWeb Cloud? (Choose two.)

A.

The DNS name for the application servers must point to FortiWeb Cloud.

B.

FortiWeb Cloud filters the incoming traffic from users, blocking the OWASP Top 10 attacks, zero-day threats, and other application layer attacks.

C.

FortiWeb Cloud can protect the application servers only if they are all located in the same virtual public cloud (VPC).

D.

Step 2 requires an AWS S3 bucket to be created.

Question # 7

Refer to the exhibit.

An organization deployed the application servers in the AWS VPC that connects to the corporate data center using Transit Gateway Connect. Demand for the applications has grown and the connection requires more bandwidth.

What is required to achieve higher bandwidth?

A.

Use routable public IP addresses instead of private IP addresses for connectivity.

B.

You cannot increase bandwidth the connection has a fixed limit.

C.

No configuration change is required because GRE tunnels are scaled to provide higher bandwidth.

D.

You add a Transit VPC between the organization's VPCs.

Question # 8

Which three statements correctly describe FortiGate Cloud-Native Firewall (CNF)? (Choose three.)

A.

It provides carrier-grade protection.

B.

It scales seamlessly.

C.

It uses AWS Elastic Load Balancing (ELB).

D.

It is considered to be a Firewall-as-a-Service (FWaaS).

E.

It can be managed by FortiManager and AWS firewall manager.

Question # 9

An administrator is adding a web application to be protected by FortiWeb Cloud.

Which two steps are necessary to successfully onboard the application? (Choose two.)

An administrator is adding a web application to be protected by FortiWeb Cloud.

Which two steps are necessary to successfully onboard the application? (Choose two.)

A.

Wait for the EC2 instance to be created.

B.

Provide a web application name.

C.

Create DNS records in the domain server that hosts the application.

D.

Enable a content delivery network (CDN) in the same region where your application is located.

Question # 10

You are troubleshooting network connectivity issues between two VMs deployed in AWS.

One VM is a FortiGate located on subnet "LAN" that is part of the VPC "Encryption". The other VM is a Windows server located on the subnet "servers" which is also in the "Encryption" VPC. You are unable to ping the Windows server from FortiGate.

What are two reasons for this? (Choose two.)

A.

The firewall in the Windows VM is blocking the traffic.

B.

The default AWS Network Access Control List (NACL) does not allow this traffic.

C.

By default, AWS does not allow ICMP traffic between subnets.

D.

Add an inbound allow ICMP rule in the security group attached to the windows server.

Page: 1 / 1
Total 10 questions

Most Popular Certification Exams

Payment

       

Contact us

dumpscollection live chat

Site Secure

mcafee secure

TESTED 16 Oct 2025