New Year Special Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > Fortinet Certification > NSE6_WCS-7.0

NSE6_WCS-7.0 Fortinet NSE 6 - Cloud Security 7.0 for AWS Question and Answers

Question # 4

Your customers have been reporting slow response times when accessing your web application.

What are two possible ways to increase response times from web servers protected by FortiWeb Cloud? (Choose two.)

Your customers have been reporting slow response times when accessing your web application.

What are two possible ways to increase response times from web servers protected by FortiWeb Cloud? (Choose two.)

A.

Deploy FortiWeb Cloud in the same region where your web application is being hosted.

B.

Enable a content delivery network

C.

Modify DNS entries to directly point to your web server.

D.

Disable WAF functionality.

Full Access
Question # 5

AWS native network services offer vast functionality and inter-connectivity between the cloud and on-premises networks.

Which three additional functions can FortiGate for AWS offer to complement the native services offered by AWS? (Choose three.)

A.

Higher VPN throughput

B.

Web filtering

C.

OSPF over IPSec

D.

Advanced dynamic routing

E.

Secure SD-WAN with application visibility

Full Access
Question # 6

You want to deploy the Fortinet HA CloudFormation template to stage and bootstrap the FortiGate configuration in the same region in which you created your VPC, which is Ohio US-East-2.

Based on this information, which statement is correct?

A.

You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration. The S3 bucket can be hosted in any region.

B.

The Fortinet HA cloud formation template automatically creates an S3 bucket.

C.

You create an S3 bucket to stage and bootstrap FortiGate with an FGCP unicast configuration. The S3 bucket needs to be hosted in the Ohio US-East-2 region.

D.

You create a DynamoDB to stage and bootstrap FortiGate with an FGCP unicast configuration. It needs to be hosted in the Ohio US-East-2 region.

Full Access
Question # 7

Your organization is deciding between deploying an active-active (A-A) or active-passive (A-P) FortiGate high availability (HA) cluster in AWS cloud.

Which two statements are true about A-A clusters compared to A-P clusters? (Choose two.)

A.

For A-A clusters, FortiGate must perform SNAT inbound to ensure symmetric traffic flow.

B.

A-A clusters rely on API calls for sfailovers.

C.

A-A clusters always require a load balancer.

D.

A-A clusters can use a software-defined network (SDN) to perform a failover.

Full Access
Question # 8

Refer to the exhibit.

Which two statements are true about inbound traffic based on the IGW ingress route table and GWLB deployment shown in the exhibit? (Choose two.)

A.

GWLB forwards traffic to FortiGate without encapsulation in its dedicated subnet.

B.

Inbound traffic is directed to the GWLB through a GWLB endpoint.

C.

Inbound traffic is directed to the application subnet through a GWLB endpoint.

D.

GWLB encapsulates traffic with the GENEVE protocol and sends it to FortiGate.

Full Access
Question # 9

A customer is attempting to deploy an active-passive high availability (HA) cluster using the software-defined network (SDN) connector in the AWS cloud.

What is an important consideration to ensure a successful formation of HA, failover, and traffic flow?

A.

Both cluster members must be in the same availability zone.

B.

VDOM exceptions must be configured.

C.

Unicast FortiGate Clustering Protocol (FGCP) must be used.

D.

Both cluster members must show as healthy in the elastic load balancer (ELB) configuration.

Full Access
Question # 10

Refer to the exhibit.

A customer is using the AWS Elastic Load Balancer (ELB).

Which two statements are correct about the ELB configuration? (Choose two.)

A.

The load balancer is configured to load balance traffic among multiple availability zones.

B.

The Amazon Resource Name is used to access the load balancer node and targets.

C.

You can use the DNS name to reach the targets behind the ELB.

D.

The load balancer is configured for the internal traffic of the virtual public cloud (VPC).

Full Access