Fortinet FCP - Google Cloud Security 7.6 Administrator FCP_GCS_AD-7.6 Exam Questions

Page: 1 / 14
Total 35 questions
Question 1

For what three reasons must you deploy a set of Google Cloud passthrough network load balancers for an active-passive high-availability (HA) FortiGate cluster instead of a set of Google Cloud proxy network load balancers? (Choose three.)



Answer : B, D, E

Passthrough load balancers support health checks to monitor backend health for failover.

They can forward all protocols, not limited to HTTP/HTTPS like proxy load balancers.

Passthrough load balancers provide higher throughput because they don't terminate sessions.


Question 2

An organization has decided to deploy an active-active high-availability cluster in Google Cloud.

Which three load balancing features are critical to the successful deployment of the cluster? (Choose three.)



Answer : A, B, E

Health checks ensure load balancers route traffic only to healthy cluster members.

Forwarding rules act as next hops in routing, directing traffic appropriately within the HA cluster.

Symmetric hashing ensures consistent and balanced traffic distribution across cluster members, critical for active-active deployments.


Question 3

Refer to the exhibit.

Which two statements about FortiWeb instances deployed in Google Cloud are true?



Answer : A, B

FortiWeb's operation mode can be changed, such as between reverse proxy and transparent modes, to suit different deployment scenarios.

FortiWeb in Google Cloud supports flexible licensing models, including pay-as-you-go and bring-your-own-license (BYOL).


Question 4

Your organization has decided to deploy a high-availability (HA) cluster. One kye requirement of the deployment is to support configuration synchronization.

Which three deployment types should be considered? (Choose three.)



Answer : A, B, D

These three deployment types support configuration synchronization between HA cluster members, which is critical for maintaining consistent state and seamless failover.


Question 5

Your organization has deployed an active-active high-availability (HA) FortiGate cluster in Google Cloud. You have noticed a significant increase in asymmetrical traffic flow.

Which two actions can you take to mitigate the issue? (Choose two.)



Answer : A, B

Enabling source NAT ensures consistent source IPs, promoting symmetric traffic flow.

Symmetric hashing on the load balancer helps distribute traffic flows evenly and consistently across cluster members, reducing asymmetric routing.


Question 6

Refer to the exhibit.

An administrator is troubleshooting network connectivity issues between two VMs deployed in Google Cloud.

One VM is a FortiGate located in the subnet ''wan'' that is part of the VPC ''e-commerce''. The other VM is a Windows server located in subnet ''servers'', which is also in the ''e-commerce'' VPC.

What are two reasons you cannot pint the Windows server from FortiGate? (Choose two.)



Answer : A, B

Google Cloud firewall rules are stateful and, by default, do not allow ICMP traffic; you must explicitly allow ICMP inbound traffic to the Windows VM.

The Windows VM's own firewall might block ICMP traffic, preventing ping responses.


Question 7

An administrator is tasked to deploy two FortiGate devices in two different zoned to achieve geographical redundancy.

Which two architectural considerations must the administrator address? (Choose two.)



Answer : A, C

Deploying FortiGate devices in different regions ensures geographic redundancy.

The second IP address in a subnet is reserved for the default gateway in Google Cloud, so FortiGate devices cannot use that IP.


Page:    1 / 14   
Total 35 questions