Fortinet FCSS_CDS_AR-7.6 - FCSS - Public Cloud Security 7.6 Architect Exam
Page: 3 / 14
Total 66 questions
Question #11 (Topic: Exam A)
Refer to the exhibit.

You have deployed a Linux EC2 instance in Amazon Web Services (AWS) with the settings shown on the exhibit.
What next step must the administrator take to access this instance from the internet?

You have deployed a Linux EC2 instance in Amazon Web Services (AWS) with the settings shown on the exhibit.
What next step must the administrator take to access this instance from the internet?
A. Configure the user name and password.
B. Enable SSH and allocate it to the device.
C. Allocate an Elastic IP address and assign it to the instance.
D. Create a VIP on FortiGate to allow access.
Answer: C
Question #12 (Topic: Exam A)
What are two main features in Amazon Web Services (AWS) network access control lists (NACLs)? (Choose two.)
A. NACLs are tied to an instance.
B. The default NACL is configured to allow all traffic.
C. NACLs are stateless, and inbound and outbound rules are used for traffic filtering.
D. You cannot use NACLs and Security Groups at the same time.
Answer: BC
Question #13 (Topic: Exam A)
Refer to the exhibit.

An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer. However, the connection is not successful, and at the same time FortiGate is not receiving any HTTPS or SSH traffic to its external interface.
What should the administrator check for possible issue?

An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer. However, the connection is not successful, and at the same time FortiGate is not receiving any HTTPS or SSH traffic to its external interface.
What should the administrator check for possible issue?
A. Check the debug flow for any network ACLs.
B. Check the inbound rules of the security groups.
C. Check the FortiGate firewall policies.
D. Check the FortiGate instance ID.
Answer: B
Question #14 (Topic: Exam A)
Refer to the exhibit.

An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform. However, during the configuration, the Azure client secret is no longer visible in the Azure portal.
How would the administrator obtain the Azure client secret to configure on Terraform?

An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform. However, during the configuration, the Azure client secret is no longer visible in the Azure portal.
How would the administrator obtain the Azure client secret to configure on Terraform?
A. Log in to the Azure CLI as a power user to obtain the client secret.
B. Create a new Azure account and assign it the Administrator role.
C. Create a new client secret and take note of it.
D. Use the Terraform output file values to obtain the client secret.
Answer: C
Question #15 (Topic: Exam A)
Which statement about immutable infrastructure in automation is true?
A. It is the practice of deploying a new server for every configuration change.
B. It is the practice of deploying two parallel servers for high availability.
C. It is the practice of modifying the existing server configuration after it is deployed.
D. It is the practice of applying hotfixes and OS patches after deployment.
Answer: A