Skip to content

FCP-WCS-AD-7-4 FCP - AWS Cloud Security 7.4 Administrator Practice Questions

Prepare for FCP-WCS-AD-7-4 with more than an answer.

206 questions in the full set20 sample questionsUpdated Dec 7, 2025
Exam fee
$200 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 5
  1. Public Cloud Fundamentals20%
  2. AWS Components25%
  3. Fortinet Product Deployment30%
  4. High Availability15%
  5. Autoscaling, Load Balancers & Advanced Features10%
  1. 1

    When integrating a fleet of FortiGate VMs with an AWS Gateway Load Balancer (GWLB) for transparent traffic inspection, what protocol is used for the health checks between the GWLB and the FortiGate target group instances by default?

    Show answer details

    Correct answer: D

    AWS Gateway Load Balancer uses the GENEVE (Generic Network Virtualization Encapsulation) protocol on port 6081 to encapsulate traffic sent to security appliances. The health checks for the target group also operate over this protocol. Therefore, the Security Group for the FortiGate instances must allow traffic on UDP port 6081 from the GWLB for both traffic inspection and health checks to function.

  2. 2

    For a FortiGate HA cluster in AWS to successfully use an S3 bucket for bootstrapping and configuration synchronization, the IAM role attached to the FortiGate instances needs specific permissions. Which of the following represents the minimum required S3 permissions for the IAM role to ensure proper HA operation?

    Show answer details

    Correct answer: A

    The FortiGate instances need s3:GetObject to download configuration files, s3:PutObject to upload status and heartbeat information, and s3:ListBucket to discover objects within the designated bucket path. These three permissions are the minimum required for the S3-based HA mechanism to function correctly.

  3. 3

    A mobile banking application relies heavily on REST APIs hosted on AWS. The development team is concerned about API-specific threats, such as broken object level authorization and mass assignment, which are part of the OWASP API Security Top 10. Which FortiWeb feature is specifically designed to protect against these types of API threats?

    Show answer details

    Correct answer: C

    FortiWeb can import an OpenAPI (formerly Swagger) schema file that defines the API's structure, endpoints, parameters, and expected data formats. It then validates all incoming API requests against this schema. This provides strong positive security, effectively preventing threats like mass assignment or parameter tampering by rejecting any request that does not conform to the defined API specification.

  4. 4

    A manufacturing company, IndustrioCorp, operates a hybrid cloud environment. Their primary manufacturing control systems are located in an on-premises data center, while their data analytics applications are hosted in multiple VPCs in AWS. They are using an AWS Direct Connect for connectivity, but the current 1 Gbps connection is becoming a bottleneck and needs to be increased to at least 5 Gbps.

    The security policy mandates that all traffic between on-premises and AWS must be encrypted and inspected by a FortiGate appliance. The on-premises edge device is a high-performance FortiGate. The solution must provide native AWS integration, high bandwidth, and support for dynamic routing protocols like BGP.

    Which solution best meets IndustrioCorp's bandwidth, security, and routing requirements?

    Show answer details

    Correct answer: C

    AWS Transit Gateway Connect is specifically designed for this use case. It allows SD-WAN appliances (like FortiGate) to establish GRE tunnels over Direct Connect or VPN, providing higher bandwidth than standard VPN connections (up to 5 Gbps per Connect attachment). It natively supports BGP for dynamic routing and integrates seamlessly with Transit Gateway, meeting all of the company's requirements for bandwidth, dynamic routing, and native integration.

  5. 5

    True or False: According to the AWS Shared Responsibility Model, when a customer deploys a FortiGate VM on an EC2 instance, the customer is responsible for patching the FortiOS firmware, while AWS is responsible for patching the underlying host operating system and hypervisor.

    Show answer details

    Correct answer: A

    This statement is true. In the IaaS model, AWS is responsible for the security 'of' the cloud (physical infrastructure, hardware, hypervisor). The customer is responsible for security 'in' the cloud, which includes the guest operating system (if applicable), all application software (including the FortiOS firmware on the VM), and firewall configuration.

  6. 6

    A security architect is designing a multi-account AWS environment using FortiGate CNF for centralized egress filtering. The design includes a central networking account with a transit gateway and multiple spoke VPCs in different member accounts. To inspect traffic from the spoke VPCs, the architect has created a GWLB endpoint in each spoke. What is the final critical step required in the spoke VPC route tables to direct egress traffic through the FortiGate CNF for inspection?

    Show answer details

    Correct answer: B

    To enforce inspection, all egress traffic (0.0.0.0/0) from the spoke VPC subnets must be routed to the Gateway Load Balancer Endpoint (GWLBe). The GWLBe then forwards the traffic to the FortiGate CNF instance via the GWLB in the central security VPC for inspection before it proceeds to the internet.

  7. 7

    An engineer deployed a FortiGate Active-Passive HA cluster in AWS using the official CloudFormation template. During a failover test, the secondary unit fails to promote to primary, and session state is lost. The IAM role has permissions for EC2 route table updates and EIP association, and the S3 bucket is in the correct region. What is the most likely cause of the FGCP unicast session synchronization failure?

    Show answer details

    Correct answer: C

    FGCP unicast session synchronization and heartbeat communication in FortiOS occur over TCP port 703. If the Security Group governing the HA synchronization interface does not explicitly allow this traffic between the primary and secondary FortiGate instances, the cluster cannot synchronize sessions or properly detect failures, leading to failover failure.

  8. 8

    A startup is deploying its first web application on AWS and requires basic web application firewall (WAF) protection against common exploits like SQL injection and cross-site scripting (XSS). The company has a limited budget and no dedicated security staff to manage a full WAF appliance. Which Fortinet solution is the most cost-effective and simplest to deploy for this requirement?

    Show answer details

    Correct answer: D

    Using the native AWS WAF service and subscribing to the 'Fortinet Managed Rules for AWS WAF' is the simplest and most cost-effective solution. It provides expert-curated protection without the overhead of deploying, managing, and scaling a separate virtual appliance. This is ideal for organizations without dedicated security staff.

  9. 9

    A DevSecOps team wants to automate security responses for newly discovered vulnerabilities on their EC2 instances. They are using AWS Inspector to scan instances and have configured a FortiGate with an SDN connector. Which two actions can be automated using the AWS SDN connector when AWS Inspector reports a high-severity vulnerability on an EC2 instance? (Select TWO)

    Show answer details

    Correct answer: B, D

    The SDN connector can use metadata from AWS services like Inspector to dynamically update address objects on the FortiGate, effectively quarantining a vulnerable instance.

    By placing the vulnerable instance into a dynamic address group, a firewall policy can be pre-configured to apply a more restrictive security profile (like a specific IPS profile) to any traffic from members of that group.

  10. 10

    When configuring a FortiGate Active-Passive cluster in AWS using FGCP, the heartbeat communication must be established. Because AWS environments do not support Layer 2 mechanisms like broadcast or multicast, the FGCP configuration must be set to ________.

    Show answer details

    Correct answer: B

    Public cloud platforms like AWS do not support the Layer 2 broadcast or multicast traffic that default FGCP (FortiGate Clustering Protocol) relies on. Therefore, the cluster must be configured in unicast mode, where heartbeat packets are sent directly to the specific IP address of the peer member.

Create an account to continue.