لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
An organization has the requirement to connect a data VPC to the on-premises infrastructure of a branch office in a hybrid cloud environment. The connectivity needs the higher bandwidth but the organization does not want to use multiple connections between sites. Which AWS solution meets the requirement?
A. Transit VPC with IPSec
B. Internet Gateway
C. Transit Gateway multicast
D. Transit Gateway Connect
عرض الإجابة
اجابة صحيحة: D
السؤال #2
An organization has the requirement to connect a data VPC to the on - premises infrastructure of a branch office in a hybrid cloud environment. The connectivity needs the higher bandwidth but the organization does not want to use multiple connections between sites. Which AWS solution meets the requirement?
A. Transit VPC with IPSec
B. Internet Gateway
C. Transit Gateway multicast
D. Transit Gateway Connect
عرض الإجابة
اجابة صحيحة: D
السؤال #3
An organization has the requirement to connect a data VPC to the on-premises infrastructure of a branch office in a hybrid cloud environment. The connectivity needs the higher bandwidth but the organization does not want to use multiple connections between sites. Which AWS solution meets the requirement?
A. Transit VPC with IPSec
B. Internet Gateway
C. Transit Gateway multicast
D. Transit Gateway Connect
عرض الإجابة
اجابة صحيحة: D
السؤال #4
What is a drawback of deploying a FortiWeb VM inside a virtual public cloud (VPC) compared to FortiWeb Cloud?
A. It is unable to support web applications from OWASP Top 10 threats
B. It does not support zero-day protection
C. It is slower than FortiWeb Cloud to apply advanced WAF protection
D. Only applications going through the VPC are protected
عرض الإجابة
اجابة صحيحة: D
السؤال #5
An organization has the requirement to connect a data VPC to the on-premises infrastructure of a branch office in a hybrid cloud environment. The connectivity needs the higher bandwidth but the organization does not want to use multiple connections between sites.Which AWS solution meets the requirement?
A. Transit VPC with IPSec
B. Internet Gateway
C. Transit Gateway multicast
D. Transit Gateway Connect
عرض الإجابة
اجابة صحيحة: D
السؤال #6
Which three statements correctly describe FortiGate Cloud-Native Firewall (CNF)? (Choose three.)
A. It provides carrier-grade protection
B. It scales seamlessly
C. It uses AWS Elastic Load Balancing (ELB)
D. It is considered to be a Firewall-as-a-Service (FWaaS)
E. It can be managed by FortiManager and AWS firewall manager
عرض الإجابة
اجابة صحيحة: ABD
السؤال #7
An administrator has been asked to deploy an active-passive (A-P) FortiGate cluster in the AWS cloud across two availability zones. In addition to enhanced redundancy, which other major difference is there compared to deploying A-P high availability in the same availability zone?
A. The FortiGate devices act as a single, logical instance
B. Secondary IP address configuration is used
C. The number of subnets required is less
D. IP addressing and subnetting are not shared
عرض الإجابة
اجابة صحيحة: D
السؤال #8
Your organization is deciding between deploying an active-active (A-A) or active-passive (A-P) FortiGate high availability (HA) cluster in AWS cloud. Which two statements are true about A-A clusters compared to A-P clusters? (Choose two.)
A. For A-A clusters, FortiGate must perform SNAT inbound to ensure symmetric traffic flow
B. A-A clusters rely on API calls for failovers
C. A-A clusters always require a load balancer
D. A-A clusters can use a software-defined network (SDN) to perform a failover
عرض الإجابة
اجابة صحيحة: AC
السؤال #9
Refer to the exhibit. Traffic is initiated from the EC2 instance and is destined for the internet. Which traffic flow is correct?
A. EC2 instance > NAT GW > IGW > internet
B. There is no route to the internet in the Private Route Table
C. EC2 instance > GWLBe > NAT GW > IGW > internet
D. EC2 instance > GWLBe > internet
عرض الإجابة
اجابة صحيحة: C
السؤال #10
Traffic is initiated from the EC2 instance and is destined for the internet.Which traffic flow is correct?
A. EC2 instance > NAT GW > IGW > internet
B. There is no route to the internet in the Private Route Table
C. EC2 instance > GWLBe > NAT GW > IGW > internet
D. EC2 instance > GWLBe > internet
عرض الإجابة
اجابة صحيحة: C
السؤال #11
A customer has implemented GWLB between the partner and application VPCs. FortiGate appliances are deployed in the partner VPC with multiple AZs to inspect traffic transparently. Which two things will happen to application traffic based on the GWLB deployment? (Choose two.)
A. Inbound and outbound traffic will go to multiple devices, which will perform load balancing
B. Inbound and outbound traffic will go to the same device, which will perform stateful processing
C. The content of the original traffic exchanged between the GWLB and FortiGate will be preserved
D. The original traffic exchanged between the GWLB and FortiGate will be hashed for data integrity
عرض الإجابة
اجابة صحيحة: BC
السؤال #12
AWS native network services offer vast functionality and inter-connectivity between the cloud and on-premises networks. Which three additional functions can FortiGate for AWS offer to complement the native services offered by AWS? (Choose three.)
A. Higher VPN throughput
B. Web filtering
C. OSPF over IPSec
D. Advanced dynamic routing
E. Secure SD-WAN with application visibility
عرض الإجابة
اجابة صحيحة: BCE
السؤال #13
Refer to the exhibit. Traffic is initiated from the EC2 instance and is destined for the internet. Which traffic flow is correct?
A. EC2 instance > NAT GW > IGW > internet
B. There is no route to the internet in the Private Route Table
C. EC2 instance > GWLBe > NAT GW > IGW > internet
D. EC2 instance > GWLBe > internet
عرض الإجابة
اجابة صحيحة: C
السؤال #14
You want to deploy the Fortinet HA CloudFormation template to stage and bootstrap the FortiGate configuration in the same region in which you created your VPC, which is Ohio US-East-2. Based on this information, which statement is correct?
A. You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration
B. The Fortinet HA cloud formation template automatically creates an S3 bucket
C. You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration
D. You create a DynamoDB to stage and bootstrap FortiGate with an FGCP unicast configuration
عرض الإجابة
اجابة صحيحة: C
السؤال #15
A global organization with cloud networks deployed in several AWS regions wants to set up next-generation firewall (NGFW) protection using FortiGate Cloud-Native Firewall (CNF). What are two deployment considerations for the organization? (Choose two.)
A. They must choose AWS Firewall Manager to provision a CNF instance
B. A CNF instance is required for each AWS region that must be protected
C. More than one AWS account can be associated with a CNF instance
D. Only one CNF instance is required to protect all AWS regions
عرض الإجابة
اجابة صحيحة: BC
السؤال #16
An organization has created a VPC with two subnets and deployed a FortiGate-VM (VM04/c4.xlarge) in AWS. The EC2 instance is initially configured with two Elastic Network Interfaces (ENIs). The primary ENI is configured on the public subnet, and the secondary ENI is configured on the private subnet. To provide internet access for the FortiGate-VM, they now want to associate an EIP to its primary ENI, but the assignment is failing. Which action would allow the EIP assignment to be successful?
A. Create and associate a public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI
B. Shut down the FortiGate VM, if it is running, assign the EIP to the primary ENI, and then power it on
C. Create and attach an internet gateway to the VPC, and then assign the EIP to the primary ENI of the FortiGate VM
D. Create and attach a public routing table to the public subnet, associate the public subnet with the primary ENI of the FortiGate VM, and then assign the EIP to the primary ENI
عرض الإجابة
اجابة صحيحة: C
السؤال #17
Which two statements about the FortiCloud portal are true? (Choose two.)
A. You can gain remote access to your FortiGate VM directly from the portal
B. To assign permissions in the identity and access management (IAM) portal, you must write a JSON script
C. You can access the FortiFlex portal only after you purchase a FortiFlex license and register it on FortiCare
D. You can access only cloud services that you have subscribed to on AWS marketplace
عرض الإجابة
اجابة صحيحة: AC
السؤال #18
An administrator has been asked to deploy an active-passive (A-P) FortiGate cluster in the AWS cloud across two availability zones.In addition to enhanced redundancy, which other major difference is there compared to deploying A-P high availability in the same availability zone?
A. The FortiGate devices act as a single, logical instance
B. Secondary IP address configuration is used
C. The number of subnets required is less
D. IP addressing and subnetting are not shared
عرض الإجابة
اجابة صحيحة: D
السؤال #19
An organization deployed the application servers in the AWS VPC that connects to the corporate data center using Transit Gateway Connect. Demand for the applications has grown and the connection requires more bandwidth.What is required to achieve higher bandwidth?
A. Use routable public IP addresses instead of private IP addresses for connectivity
B. You cannot increase bandwidth the connection has a fixed limit
C. No configuration change is required because GRE tunnels are scaled to provide higher bandwidth
D. You add a Transit VPC between the organization's VPCs
عرض الإجابة
اجابة صحيحة: C
السؤال #20
An organization deployed the application servers in the AWS VPC that connects to the corporate data center using Transit Gateway Connect. Demand for the applications has grown and the connection requires more bandwidth.What is required to achieve higher bandwidth?
A. Use routable public IP addresses instead of private IP addresses for connectivity
B. You cannot increase bandwidth the connection has a fixed limit
C. No configuration change is required because GRE tunnels are scaled to provide higher bandwidth
D. You add a Transit VPC between the organization's VPCs
عرض الإجابة
اجابة صحيحة: C
السؤال #21
A customer has implemented GWLB between the partner and application VPCs. FortiGate appliances are deployed in the partner VPC with multiple AZs to inspect traffic transparently. Which two things will happen to application traffic based on the GWLB deployment? (Choose two.)
A. Inbound and outbound traffic will go to multiple devices, which will perform load balancing
B. Inbound and outbound traffic will go to the same device, which will perform stateful processing
C. The content of the original traffic exchanged between the GWLB and FortiGate will be preserved
D. The original traffic exchanged between the GWLB and FortiGate will be hashed for data integrity
عرض الإجابة
اجابة صحيحة: AB
السؤال #22
A global organization with cloud networks deployed in several AWS regions wants to set up next-generation firewall (NGFW) protection using FortiGate Cloud-Native Firewall (CNF).What are two deployment considerations for the organization? (Choose two.)
A. They must choose AWS Firewall Manager to provision a CNF instance
B. A CNF instance is required for each AWS region that must be protected
C. More than one AWS account can be associated with a CNF instance
D. Only one CNF instance is required to protect all AWS regions
عرض الإجابة
اجابة صحيحة: BC
السؤال #23
Refer to the exhibit. Traffic is initiated from the EC2 instance and is destined for the internet. Which traffic flow is correct?
A. EC2 instance > NAT GW > IGW > internet
B. There is no route to the internet in the Private Route Table
C. EC2 instance > GWLBe > NAT GW > IGW > internet
D. EC2 instance > GWLBe > internet
عرض الإجابة
اجابة صحيحة: C
السؤال #24
Your organization is deciding between deploying an active-active (A-A) or active-passive (A-P) FortiGate high availability (HA) cluster in AWS cloud.Which two statements are true about A-A clusters compared to A-P clusters? (Choose two.)
A. For A-A clusters, FortiGate must perform SNAT inbound to ensure symmetric traffic flow
B. A-A clusters rely on API calls for sfailovers
C. A-A clusters always require a load balancer
D. A-A clusters can use a software-defined network (SDN) to perform a failover
عرض الإجابة
اجابة صحيحة: AC
السؤال #25
You want to deploy the Fortinet HA CloudFormation template to stage and bootstrap the FortiGate configuration in the same region in which you created your VPC, which is Ohio US-East-2. Based on this information, which statement is correct?
A. You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration
B. The Fortinet HA cloud formation template automatically creates an S3 bucket
C. You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration
D. You create a DynamoDB to stage and bootstrap FortiGate with an FGCP unicast configuration
عرض الإجابة
اجابة صحيحة: C
السؤال #26
Refer to the exhibit. A customer is using the AWS Elastic Load Balancer (ELB). Which two statements are correct about the ELB configuration? (Choose two.)
A. The load balancer is configured to load balance traffic among multiple availability zones
B. The Amazon Resource Name is used to access the load balancer node and targets
C. You can use the DNS name to reach the targets behind the ELB
D. The load balancer is configured for the internal traffic of the virtual public cloud (VPC)
عرض الإجابة
اجابة صحيحة: AC
السؤال #27
A global organization with cloud networks deployed in several AWS regions wants to set up next-generation firewall (NGFW) protection using FortiGate Cloud-Native Firewall (CNF). What are two deployment considerations for the organization? (Choose two.)
A. They must choose AWS Firewall Manager to provision a CNF instance
B. A CNF instance is required for each AWS region that must be protected
C. More than one AWS account can be associated with a CNF instance
D. Only one CNF instance is required to protect all AWS regions
عرض الإجابة
اجابة صحيحة: BC
السؤال #28
You want to deploy the Fortinet HA CloudFormation template to stage and bootstrap the FortiGate configuration in the same region in which you created your VPC, which is Ohio US-East-2. Based on this information, which statement is correct?
A. You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration
B. The Fortinet HA cloud formation template automatically creates an S3 bucket
C. You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration
D. You create a DynamoDB to stage and bootstrap FortiGate with an FGCP unicast configuration
عرض الإجابة
اجابة صحيحة: C
السؤال #29
What is a drawback of deploying a FortiWeb VM inside a virtual public cloud (VPC) compared to FortiWeb Cloud?
A. It is unable to support web applications from OWASP Top 10 threats
B. It does not support zero-day protection
C. It is slower than FortiWeb Cloud to apply advanced WAF protection
D. Only applications going through the VPC are protected
عرض الإجابة
اجابة صحيحة: D
السؤال #30
Refer to the exhibit. Which two statements are true about inbound traffic based on the IGW ingress route table and GWLB deployment shown in the exhibit? (Choose two.)
A. GWLB forwards traffic to FortiGate without encapsulation in its dedicated subnet
B. Inbound traffic is directed to the GWLB through a GWLB endpoint
C. Inbound traffic is directed to the application subnet through a GWLB endpoint
D. GWLB encapsulates traffic with the GENEVE protocol and sends it to FortiGate
عرض الإجابة
اجابة صحيحة: BD

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف: