Skip to content

FCP-PCS-7.4 FCP - Public Cloud Security 7.4 Administrator Practice Questions

Prepare for FCP-PCS-7.4 with more than an answer.

250 questions in the full set20 sample questionsUpdated Jan 31, 2026
Exam fee
$200 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 10
  1. Core exam: FCP_WCS_AD-7.4 — Public Cloud Fundamentals20%
  2. Core exam: FCP_WCS_AD-7.4 — AWS Components25%
  3. Core exam: FCP_WCS_AD-7.4 — Fortinet Product Deployment25%
  4. Core exam: FCP_WCS_AD-7.4 — High Availability20%
  5. Core exam: FCP_WCS_AD-7.4 — Load Balancers and FortiCNF10%
  6. Core exam: FCP_ZCS_AD-7.4 — Azure Public Cloud Concepts20%
  7. Core exam: FCP_ZCS_AD-7.4 — Azure Components25%
  8. Core exam: FCP_ZCS_AD-7.4 — Fortinet Product Deployment25%
  9. Core exam: FCP_ZCS_AD-7.4 — High Availability20%
  10. Core exam: FCP_ZCS_AD-7.4 — VPN Solutions10%
  1. 1

    A multinational corporation uses Azure Virtual WAN to connect 50 branch offices. They require a centralized security inspection point in the Virtual WAN Hub.

    Which Fortinet solution allows you to deploy a FortiGate directly inside the Azure Virtual WAN Hub to inspect all transit traffic?

    Show answer details

    Correct answer: A

    Azure Virtual WAN supports deploying select partner Network Virtual Appliances (NVAs) directly into the Virtual Hub. Fortinet is a supported partner, allowing you to deploy a FortiGate NVA inside the hub to provide NGFW capabilities for traffic flowing through the WAN.

  2. 2

    You are designing an AWS architecture where a FortiGate-VM fleet needs to inspect traffic destined for the internet from private instances. To ensure high availability and load distribution, you use a Gateway Load Balancer (GWLB).

    Which type of AWS route table entry is required in the application subnets to redirect internet-bound traffic to the FortiGate fleet?

    Show answer details

    Correct answer: C

    To force traffic through the GWLB architecture, the application subnet's route table must point the default route (0.0.0.0/0) to the Gateway Load Balancer Endpoint (GWLBE) located in the same availability zone. The GWLBE encapsulates the traffic and sends it to the GWLB, which distributes it to the FortiGates.

  3. 3

    What is the primary function of the 'Fabric Connector' when integrating FortiGate with AWS or Azure?

    Show answer details

    Correct answer: D

    The Fabric Connector (often referred to as SDN Connector in this context) connects to the cloud provider's API to fetch metadata such as VM tags, IDs, and states. This allows administrators to create dynamic address objects that automatically update when cloud resources change, ensuring policies remain current without manual intervention.

  4. 4

    A FortiGate-VM in AWS is configured with two ENIs. Port1 is in a public subnet and Port2 is in a private subnet. The FortiGate is acting as a NAT gateway for instances in the private subnet.

    Which command is necessary in the FortiGate configuration to ensuring traffic from the private instances is successfully masqueraded before leaving Port1?

    Show answer details

    Correct answer: C

    To function as a NAT gateway, the FortiGate must have a firewall policy allowing traffic from the internal interface (Port2) to the external interface (Port1) with 'set nat enable'. This performs Source NAT, replacing the private IP of the backend instance with the FortiGate's public-facing interface IP.

  5. 5

    Which specific AWS limitation often drives the decision to use the 'Transit Gateway Connect' attachment type with FortiGate?

    Show answer details

    Correct answer: B

    Standard IPsec VPN attachments to Transit Gateway are limited to 1.25 Gbps per tunnel. TGW Connect allows you to run GRE tunnels over the native VPC attachment (which has much higher bandwidth, up to 50 Gbps or more), enabling higher throughput for dynamic routing (BGP) integration compared to standard IPsec.

  6. 6

    A cloud architect is designing a centralized security architecture in AWS using a Transit Gateway (TGW). The requirement is to inspect all East-West traffic between Spoke VPCs and all North-South traffic to the internet. The design includes a dedicated Security VPC with an Auto Scaling Group of FortiGate-VMs behind a Geneve-compliant Gateway Load Balancer (GWLB).

    Which routing configuration ensures the return traffic from the FortiGate fleet is correctly sent back to the original Spoke VPC destination?

    Show answer details

    Correct answer: D

    When using a Transit Gateway with a centralized inspection VPC (Security VPC), asymmetric routing often occurs because the TGW might send return traffic to a different availability zone than the source. Enabling 'Appliance Mode' on the TGW attachment for the Security VPC ensures that return traffic is routed to the same availability zone where the inspection took place, maintaining flow symmetry required for stateful firewalls like FortiGate.

  7. 7

    An administrator is deploying a FortiGate-VM active-passive High Availability (HA) cluster in Microsoft Azure. To ensure proper failover, the administrator decides to use the Azure SDN Connector with Managed Identity.

    Which specific Azure permission role must be assigned to the FortiGate-VM's Managed Identity to allow it to update the User Defined Routes (UDR) during a failover event?

    Show answer details

    Correct answer: A

    The Network Contributor role provides the necessary permissions to manage network resources, including the ability to update route tables (UDRs) and IP configurations on network interfaces. This is required for the FortiGate SDN connector to rewrite route next-hops to the active unit during an HA failover.

  8. 8

    A company is using FortiGate CNF (Cloud Native Firewall) in AWS to protect multiple VPCs. The architecture uses a Gateway Load Balancer (GWLB) Endpoint in each application VPC to redirect traffic to the FortiGate CNF service.

    What is the primary benefit of using FortiGate CNF over a traditional self-managed FortiGate-VM Auto Scaling group in this scenario?

    Show answer details

    Correct answer: D

    FortiGate CNF is a fully managed SaaS offering. The primary benefit is that Fortinet manages the underlying infrastructure, including the provisioning, scaling, and patching of the firewall instances (CNF instances), allowing the customer to focus solely on security policy management via FortiManager or the CNF console.

  9. 9

    You are troubleshooting a FortiGate-VM SDN Connector in AWS that is failing to resolve dynamic address objects based on EC2 tags. The connector status shows 'Down' in the FortiGate GUI.

    Which of the following troubleshooting steps should you prioritize? (Select TWO)

    Show answer details

    Correct answer: C, D

    The SDN connector runs on the management plane of the FortiGate. It must be able to reach the public AWS API endpoints (e.g., ec2.us-east-1.amazonaws.com). If the management interface is in a private subnet without a NAT Gateway or VPC Endpoint, the connection will fail.

    The SDN connector requires permissions to query the AWS API. Specifically, 'ec2:DescribeInstances', 'ec2:DescribeTags', and similar 'Describe' permissions are essential for the connector to fetch metadata about resources and populate dynamic address objects.

  10. 10

    True or False: In a FortiGate Active-Active HA configuration within Azure using an external Azure Load Balancer (ALB), the ALB uses the same public IP address to balance traffic to both FortiGate nodes, but Source NAT (SNAT) on the FortiGate is required to ensure symmetric return traffic.

    Show answer details

    Correct answer: A

    This is True. In Azure Active-Active HA with an external Load Balancer, the ALB distributes inbound traffic to both nodes. However, when the FortiGate forwards traffic to backend servers, the return traffic from the server must go back to the same FortiGate node that processed the initial packet. Applying Source NAT (SNAT) on the FortiGate ensures the server replies to the FortiGate's interface IP rather than the original client IP, guaranteeing the return path matches the forward path.

Create an account to continue.