Refer to the exhibit.

Which two statements are true about inbound traffic based on the IGW ingress route table and GWLB deployment shown in the exhibit? (Choose two.)
A. Inbound traffic is directed to the GWLB through a GWLB endpoint.
B. Inbound traffic is directed to the application subnet through a GWLB endpoint.
C. GWLB encapsulates traffic with the GENEVE protocol and sends it to FortiGate.
D. GWLB forwards traffic to FortiGate without encapsulation in its dedicated subnet.
正解:A,C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
A customer has deployed FortiGate Cloud-Native Firewall (CNF).
Which two statements are correct about policy sets? (Choose two.)
A. There is an implicit deny rule at the bottom of the policy set.
B. The policy set must be manually synchronized to the CNF instance each time it is modified.
C. Multiple policy sets can be applied to a single CNF instance.
D. A new policy set is created with each deployed CNF instance.
正解:A,D
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Refer to the exhibit.

An administrator configured a FortiGate device to connect to the AWS API to retrieve resource values from the AWS console to create dynamic objects for the FortiGate policies. The administrator is unable to retrieve AWS dynamic objects on FortiGate.
Which two reasons can explain why? (Choose two.)
A. The AWS Lab SDN connector is configured with an invalid AWS access or secret key.
B. AWS was not able to validate credentials provided by the AWS Lab SDN connector because of a clock skew between FortiGate and AWS.
C. The AWS Lab SDN connector failed to connect on port 401.
D. The AWS Lab SDN did not find any instances in the configured VPC.
E. The AWS API call is not supported on XML version 1.0.
正解:A,B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
A customer is attempting to deploy an active-passive high availability (HA) cluster using the software-defined network (SDN) connector in the AWS cloud.
What is an important consideration to ensure a successful formation of HA, failover, and traffic flow?
A. Unicast FortiGate Clustering Protocol (FGCP) must be used.
B. Both cluster members must show as healthy in the elastic load balancer (ELB) configuration.
C. VDOM exceptions must be configured.
D. Both cluster members must be in the same availability zone.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
Mizushima -
ソフトとアプリがもらえて、内容も濃く、問題や擬似問題集と回答などもあり