Skip to content

FCP-ZCS-AD-7-4 FCP - Azure Cloud Security 7.4 Administrator Practice Questions

Prepare for FCP-ZCS-AD-7-4 with more than an answer.

217 questions in the full set20 sample questionsUpdated Dec 7, 2025
Exam fee
$200 USD
Level
Professional
Valid for
2 years
Domains covered on the exam 5
  1. Azure Public Cloud Concepts15%
  2. Azure Components20%
  3. Fortinet Product Deployment30%
  4. High Availability (HA)25%
  5. VPN Solutions in Azure10%
  1. 1

    A startup is moving its entire infrastructure to the cloud. They want the cloud provider to manage the underlying hardware, operating systems, and middleware, allowing their developers to focus solely on deploying and managing their application code. Which cloud service model best fits the startup's requirements?

    Show answer details

    Correct answer: B

    Platform as a Service (PaaS) provides a platform where the cloud provider manages the runtime, middleware, operating system, servers, storage, and networking. The customer is only responsible for their applications and data. This aligns perfectly with the startup's goal of abstracting away the underlying infrastructure management. IaaS would require them to manage the OS and middleware. SaaS would involve using a ready-made application, not deploying their own code.

  2. 2

    AeroSpace Dynamics, a defense contractor, uses a highly segmented network in Azure to enforce strict data separation between projects. Each project's VMs are tagged with a unique ProjectID, for example, ProjectID:Apollo or ProjectID:Orion. The security policy mandates that VMs from different projects cannot communicate with each other unless explicitly allowed. The network team has deployed a central FortiGate firewall to inspect all inter-project (east-west) traffic. The number of projects and VMs changes frequently, making manual IP-based policies unmanageable.

    To automate this, they configured an Azure SDN connector on the FortiGate. They created dynamic address objects for each project, such as azure-apollo-vms filtered on ProjectID:Apollo and azure-orion-vms filtered on ProjectID:Orion. They then created a firewall policy to allow traffic from azure-apollo-vms to a specific server in the Orion project. However, they are now being asked to create a 'deny-all' rule for inter-project traffic as a baseline.

    What is the most effective way to create a firewall policy on the FortiGate that denies all traffic between different projects, while still allowing the specific Apollo-to-Orion rule to function?

    Show answer details

    Correct answer: C

    FortiGate policies are processed in a top-down order. The correct approach is to first create the specific 'allow' policies (like the Apollo-to-Orion rule). Below these, a single, broader 'deny' policy can be created to act as a catch-all. By creating a group containing all the project-specific dynamic address objects (e.g., All-Project-VMs) and setting this group as both the source and destination in a deny policy, any traffic between projects that did not match a preceding allow rule will be blocked. This is scalable and efficient. The other options are either not scalable or would incorrectly block intra-project traffic.

  3. 3

    A FortiGate VMSS (Virtual Machine Scale Set) is deployed behind an Azure external Load Balancer to handle inbound web traffic. The administrator needs to ensure the Load Balancer only sends traffic to healthy FortiGate instances. What component must be configured on the Azure Load Balancer to determine the health status of the FortiGate instances in the backend pool?

    Show answer details

    Correct answer: C

    A health probe is a feature of Azure Load Balancer used to check the health of instances in the backend pool. The probe periodically connects to the instances on a specified port and protocol (e.g., TCP, HTTP). If an instance fails to respond correctly to the probe, the Load Balancer stops sending new traffic to it until it becomes healthy again. This is the essential mechanism for ensuring traffic is only sent to operational FortiGate VMs in the scale set.

  4. 4

    True or False: Azure ExpressRoute provides an encrypted connection over the public internet between an on-premises network and Microsoft Azure.

    Show answer details

    Correct answer: B

    This statement is false. Azure ExpressRoute provides a private, dedicated connection to Microsoft Azure through a connectivity provider. It does not go over the public internet. While the connection is private, traffic on an ExpressRoute circuit is not encrypted by default. Customers who require encryption over ExpressRoute must implement it themselves, for example, by running an IPsec VPN tunnel over the private peering.

  5. 5

    An architect has designed an Active-Passive FortiGate HA cluster in Azure. The design uses an external and an internal Azure Standard Load Balancer. A UDR on the internal workload subnets points to the private IP of the internal load balancer's frontend. The goal is to ensure seamless failover for both inbound and outbound traffic. During a failover from FGTA (Active) to FGTB (Passive), what is the critical mechanism that redirects outbound traffic from the internal workloads to the newly active FGTB?

    graph TD subgraph "VNet" subgraph "External Subnet" ELB[External LB] --> FGTA(FGTA - Active) ELB --> FGTB(FGTB - Passive) end subgraph "Internal Subnet" ILB[Internal LB] --> FGTA ILB --> FGTB end subgraph "Workload Subnet" VM[Workload VM] --> RT{Route Table} RT -- 0.0.0.0/0 --> ILB end end Internet --> ELB

    Show answer details

    Correct answer: A

    In this specific design where UDRs point to an internal load balancer, the redirection of outbound traffic relies on the LB's health probe. The health probe will detect that the previously active unit (FGTA) is no longer responding. The LB will mark it as unhealthy and stop sending traffic to it. Since FGTB is now active and responding to health probes, the LB will direct all new flows from the workloads (forwarded by the UDR) to FGTB. The Azure API call to move IPs is used in designs without an internal load balancer where the UDR points directly to the active FortiGate's IP. GARP is not effective in a cloud environment like Azure. BGP is not part of this standard HA design.

  6. 6

    A financial services company, FinSecure Capital, has deployed a FortiGate VM in Azure. They are using Azure tags to categorize VMs based on their environment (e.g., env:prod, env:dev). The security team wants to create a firewall policy that automatically applies to all production VMs, even as new ones are provisioned. What is the most efficient method on the FortiGate to create a firewall policy destination that dynamically includes all Azure VMs tagged with env:prod?

    Show answer details

    Correct answer: B

    The Azure SDN connector is designed for this exact purpose. It integrates with Azure APIs to discover resources and their metadata, like tags. By creating a dynamic address object filtered by the env:prod tag, the FortiGate will automatically update the object's members as VMs are added or removed, ensuring the firewall policy remains accurate without manual intervention. Manual updates are inefficient and error-prone. FQDN objects might not be feasible and are less dynamic. Scripting is a possible but more complex solution that reinvents the functionality already provided by the SDN connector.

  7. 7

    An administrator has configured a FortiGate Active-Passive HA cluster in Azure behind an external Azure Load Balancer. During a failover test, the passive unit becomes active, but external traffic is not reaching the newly active FortiGate. Internal traffic and HA synchronization are working correctly. The Azure Load Balancer health probe is configured to check an HTTPS service on port 443 on the FortiGates. Which configuration error is the most likely cause for the failure of external traffic to reach the new active unit?

    Show answer details

    Correct answer: D

    In an Azure FortiGate HA setup, the Azure Load Balancer directs traffic to the active unit. During a failover, the newly active unit must take over the IP configurations from the failed unit. However, the Azure fabric itself is unaware of this internal FGCP failover. The failover mechanism relies on an API call to Azure to re-associate the secondary IP configurations (including the one in the LB's backend pool) from the old primary's NIC to the new primary's NIC. If this API call fails or is not configured, the LB will continue sending traffic to the NIC of the now-passive (failed) unit. Internal UDRs affect outbound and east-west traffic, not inbound external traffic through the LB. A split-brain would cause more severe issues. A failing health probe would stop traffic to both units, not just the newly active one.

  8. 8

    An organization is deploying a multi-tiered application in Azure and needs to enforce network traffic filtering rules at the subnet level. They want to control both inbound and outbound traffic for their Virtual Machines. Which Azure component is used to filter network traffic to and from Azure resources in an Azure Virtual Network?

    Show answer details

    Correct answer: C

    Network Security Groups (NSGs) are the fundamental tool in Azure for filtering network traffic. They contain a list of security rules that allow or deny traffic based on source/destination IP address, port, and protocol. NSGs can be associated with network interfaces or subnets to enforce traffic policies. Azure Firewall is a more advanced, stateful firewall-as-a-service. UDRs are used for routing, not filtering. Azure Application Gateway is a Layer 7 load balancer with WAF capabilities, operating at a higher level than basic network filtering.

  9. 9

    A network engineer is configuring a site-to-site IPsec VPN tunnel between an on-premises FortiGate and an Azure VPN Gateway. The tunnel fails to establish. The engineer has verified that the pre-shared key and IP addresses are correct. The FortiGate is configured to use IKEv2 with AES-256 for encryption and SHA256 for integrity in Phase 1. Which of the following is a common reason for the VPN tunnel failure in this scenario?

    Show answer details

    Correct answer: B

    Mismatched IPsec/IKE parameters are a primary cause of VPN tunnel failures. Azure VPN Gateways have default policies that specify cryptographic algorithms, including a specific Diffie-Hellman group for the key exchange. If the FortiGate is configured with a different DH group (e.g., Group 14) and the Azure side expects another (e.g., Group 2), the Phase 1 negotiation will fail. An incorrect IP range in the local network gateway would affect routing after the tunnel is up, not the establishment itself. A missing static route is also a post-establishment routing issue. Mismatched DPD might cause stability issues but usually doesn't prevent the initial connection.

  10. 10

    Global E-Commerce Inc. runs a large retail platform on Azure, protected by a cluster of FortiGate firewalls. During peak shopping seasons, they experience massive traffic surges that can overwhelm the fixed number of firewalls, leading to performance degradation and dropped connections. Their current setup is an Active-Passive HA pair, which provides redundancy but not scalability. The primary business requirement is to maintain high performance and availability during unpredictable traffic spikes, while minimizing costs during off-peak hours. The solution must automatically scale the number of firewalls based on CPU utilization. All firewalls in the pool must have an identical security policy, which is managed centrally.

    The architecture team is proposing a new solution. The proposed architecture involves placing the FortiGate instances into an Azure VM Scale Set (VMSS). An external Azure Load Balancer will distribute incoming internet traffic to the FortiGates, and an internal Load Balancer will handle traffic from the application subnets. A User Defined Route (UDR) on the application subnets will direct all outbound traffic to the internal load balancer. The team needs to ensure that newly provisioned FortiGates automatically receive the correct configuration and licenses.

    Which combination of Fortinet and Azure services is required to build this scalable and automated firewall solution?

    Show answer details

    Correct answer: A

    This scenario perfectly describes the use case for a FortiGate autoscaling deployment. The core components are: Azure VM Scale Set (VMSS) to manage the pool of FortiGates and handle scaling events; Azure Load Balancers to distribute traffic; a bootstrap configuration (often using a customdata file stored in Azure Storage) to provide initial settings to new instances; and FortiManager to act as the central configuration and licensing server. FortiManager ensures that as new FortiGates are spun up by the VMSS, they automatically register, receive the correct license, and pull the latest unified policy. The other options are incorrect for various reasons related to scalability and automated configuration management.

Create an account to continue.