FCP-PCS-7.4 Sample Questions & Answers
Expect a mix of AWS and Azure networking and security components, deploying FortiGate and FortiWeb in both clouds, high availability with CloudFormation automation and Azure Route Server, load balancers and FortiCNF, and site-to-site VPN connectivity.
Launch the full FCP-PCS-7.4 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Fortinet Product Deployment · FortiGate Azure SDN Integration
A FortiGate administrator is configuring the
config system sdn-connectorsettings for an Azure environment. The goal is to allow the FortiGate to automatically populate an address group with the IP addresses of all Virtual Machines tagged with 'Environment=Production'.Which type of SDN connector configuration is most appropriate for this task?
Show answer & explanation
Correct answer: B
The standard 'Azure' type SDN connector (configured with a Service Principal or Managed Identity) allows the FortiGate to query the Azure API for resource tags and properties. This enables the creation of dynamic address objects that filter based on tags like 'Environment=Production' and automatically update as VMs are added or removed.
- Question 2Advanced
AWS Components · AWS Networking Components
In an AWS deployment, you are using a FortiGate-VM to inspect traffic between two VPCs connected via a Transit Gateway (TGW). The TGW has a single route table associated with all attachments. You observe that traffic between the VPCs is flowing directly and not passing through the FortiGate security VPC.
What architectural change is required to force traffic through the FortiGate?
Show answer & explanation
Correct answer: D
To inspect East-West traffic via a TGW, you must segment the routing domains. A common pattern is to have a 'Spoke Route Table' where the default route (0.0.0.0/0) or specific inter-VPC CIDRs point to the Security VPC attachment. The Security VPC attachment is associated with a separate 'Security Route Table' that propagates routes from the spokes, allowing the FortiGate to send traffic back to the correct destination.
- Question 3Beginner
Fortinet Product Deployment · FortiWeb Deployment
When deploying FortiWeb in a public cloud environment to protect a web application, which deployment mode allows FortiWeb to inspect traffic without requiring changes to the network architecture or IP addressing of the application servers, often referred to as 'Transparent Inspection'?
Show answer & explanation
Correct answer: B
In True Transparent Proxy mode, FortiWeb is deployed inline (layer 2 bridge) and inspects traffic without modifying the source or destination IP addresses. This makes the WAF invisible to the client and server. Note: In many public cloud environments (Layer 3 only), True Transparent is difficult to implement without specific overlay networking; however, conceptually, this is the mode for 'transparent inspection'. In Cloud native contexts, Reverse Proxy is more common, but the question asks for the mode definition.
- Question 4Intermediate
High Availability · FortiGate HA in Azure
An organization requires a highly available FortiGate solution in Azure. The design uses an Active-Passive configuration. During a failover test, the secondary unit becomes active but traffic is dropped because the User Defined Routes (UDRs) in the Azure subnets still point to the IP address of the failed primary unit.
Which component is responsible for detecting the failure and updating the Azure UDRs to point to the new active unit's IP?
Show answer & explanation
Correct answer: C
In an API-based HA architecture (often used when Load Balancers are not preferred for internal routing), the FortiGate SDN Connector on the unit becoming 'Primary' triggers an API call to Azure Resource Manager to update the Next Hop IP in the UDRs to its own interface IP.
- Question 5Advanced
AWS Components · Traffic Flow in AWS
Case Study:
Scenario
GlobalBank uses AWS for its core banking application. The architecture consists of a Hub VPC and three Spoke VPCs (App, DB, Partner). They use a FortiGate Active-Passive HA pair in the Hub VPC.Issue
The network team reports that traffic from the App VPC to the DB VPC is working fine and being inspected. However, traffic from the Partner VPC (10.2.0.0/16) to the App VPC (10.1.0.0/16) is failing intermittently.Configuration
- TGW is used for all inter-VPC communication.
- TGW Route Table has routes to 0.0.0.0/0 via the Hub VPC attachment.
- Hub VPC has FortiGates in different AZs (AZ1 and AZ2).
- Partner VPC attachment is associated with the TGW Route Table.
- TGW 'Appliance Mode' is disabled on the Hub VPC attachment.
Which action will permanently resolve the intermittent connectivity issue while maintaining traffic inspection?
Show answer & explanation
Correct answer: D
The issue is likely asymmetric routing caused by the Transit Gateway crossing Availability Zones. When traffic leaves the Hub VPC (after inspection), TGW might send it to an AZ in the destination VPC different from the source. However, the return traffic might enter the TGW in a different AZ and be routed to the passive FortiGate or the wrong interface in the Hub VPC if Appliance Mode is not on. Enabling Appliance Mode forces the TGW to use the same AZ attachment for the return traffic flow, ensuring it hits the active FortiGate processing the session.
- Question 6Intermediate
High Availability · Automation with CloudFormation
When implementing FortiGate Autoscale in AWS using the official CloudFormation templates, which AWS service is primarily used to store the state and configuration synchronization data between the FortiGate instances?
Show answer & explanation
Correct answer: C
Fortinet's standard AWS Autoscale solution uses a DynamoDB table to maintain the state of the cluster, track the primary instance, and synchronize configuration details and heartbeat information between the FortiGate instances and the Lambda functions managing the cluster.
- Question 7Intermediate
VPN Solutions · FortiGate and Azure VPN Gateway Integration
You are configuring a site-to-site IPsec VPN between an on-premises FortiGate and a FortiGate-VM in Azure. You want to use BGP to exchange routes dynamically.
Which configuration parameter must match on both the Azure Route Table (if using Route Server) or the Azure VPN Gateway and the FortiGate to ensuring BGP peering is established?
Show answer & explanation
Correct answer: A
For BGP peering to work, you must configure the correct Autonomous System (AS) number. Azure VPN Gateways typically use a default ASN (e.g., 65515), and the on-premise/FortiGate device must peer with this ASN. If the ASNs are mismatched or not configured as expected peers, the BGP session will not establish.
- Question 8Beginner
Public Cloud Fundamentals · AWS Public Cloud Concepts
A customer wants to deploy a FortiGate-VM in AWS with two network interfaces: port1 for public-facing traffic and port2 for internal private traffic.
What AWS networking feature must be disabled on the port2 network interface to allow the FortiGate to route traffic for other instances (i.e., act as a NAT/Router)?
Show answer & explanation
Correct answer: B
By default, AWS performs source/destination checks on EC2 instances, meaning the instance must be the source or destination of any traffic it sends or receives. For a NAT instance or Firewall (FortiGate) to route traffic through it (where the source/destination IPs are not its own), this check must be disabled on the interface.
- Question 9Intermediate
High Availability · HA Deployment in AWS
Which of the following statements correctly describes the 'Unicast' HA heartbeat mechanism for FortiGate-VM in public cloud environments (AWS/Azure)?
Show answer & explanation
Correct answer: A
Public cloud networks (AWS VPC, Azure VNet) do not support Layer 2 multicast or broadcast. Therefore, FortiGate HA must use Unicast heartbeats. These packets are typically encapsulated (often UDP port 703) to travel between the cluster members over the Layer 3 cloud network.
- Question 10Beginner
Fortinet Product Deployment · FortiGate Configuration
You are deploying a FortiGate-VM in Azure using a 'Bootstrap' configuration method. You want the FortiGate to apply a specific configuration file immediately upon first boot.
Where should you place the configuration text during the VM creation process in the Azure Portal?
Show answer & explanation
Correct answer: C
In Azure, the 'Custom Data' field (found in the Advanced tab during VM creation) is used to pass configuration data to the VM. For FortiGate, you can paste CLI commands or a full config file here, and the device will execute them during the initial boot process (bootstrapping).
Ready for the real thing?
The full FCP-PCS-7.4 simulator has every exam-style question, timed mode, and instant scoring.