exam questions

Exam FCP_WCS_AD-7.4 All Questions

View all questions & answers for the FCP_WCS_AD-7.4 exam

Exam FCP_WCS_AD-7.4 topic 1 question 24 discussion

Actual exam question from Fortinet's FCP_WCS_AD-7.4
Question #: 24
Topic #: 1
[All FCP_WCS_AD-7.4 Questions]

A customer has deployed FortiGate Cloud-Native Firewall (CNF).
Which two statements are correct about policy sets? (Choose two.)

  • A. There is an implicit deny rule at the bottom of the policy set.
  • B. The policy set must be manually synchronized to the CNF instance each time it is modified.
  • C. A new policy set is created with each deployed CNF instance.
  • D. Multiple policy sets can be applied to a single CNF instance.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
havokdu
2 weeks ago
Selected Answer: BC
From Fortigate CNF Administration guide 24.1.b B When a policy set is changed locally in the FortiGate CNF console, CNF instances are not automatically synchonized with the updated policy set. C FortiGate CNF comes with a preconfigured allow_all policy set that cannot be edited or deleted.The allow_all policy set should only be used during the initial testing stage to help test routing. It should not be used for production since it does not provide any security protection.
upvoted 1 times
...
myrmidon3
2 months, 2 weeks ago
Selected Answer: AC
The correct statements regarding FortiGate Cloud-Native Firewall (CNF) policy sets are: There is an implicit deny rule at the bottom of the policy set: This is common in many firewall policies, where an implicit deny rule ensures that any traffic not explicitly allowed by a preceding rule is denied. A new policy set is created with each deployed CNF instance: This is a standard practice for managing security and applying policies to individual firewall instances for better control and management.
upvoted 2 times
...
ipv84
4 months, 2 weeks ago
Selected Answer: AD
For me the correct answers are: A and D.
upvoted 1 times
ipv84
4 months, 1 week ago
Sorry, A nd C are correct.
upvoted 2 times
...
...
Spawni81
4 months, 2 weeks ago
B, C are correct. I found nothing in the Study Guide, but you can use the CNF Admin Guide. A - i find no implicit deny, but this: "Configuring policy sets -> The default allow_all policy set is pre-configured and automatically added to new instances." B: When a policy set is changed locally in the FortiGate CNF console, CNF instances are not automatically synchonized with the updated policy set. C/D: Only one policy set can be applied to an instance at a time.
upvoted 1 times
myrmidon3
2 months, 2 weeks ago
The reference for the implicit deny rule and policy sets for FortiGate CNF can be found in the document sections related to FortiGate CNF policy management. Specifically, these topics are discussed around **pages 156-160**, where the deployment of policies, instances, and rules are covered.
upvoted 1 times
...
...
the_giant
5 months ago
Selected Answer: AC
A, C are correct Implicit Deny Rule: Similar to traditional firewall rule sets, FortiGate Cloud-Native Firewall (CNF) includes an implicit deny rule at the bottom of each policy set. This means any traffic that does not match an existing rule in the policy set is automatically denied (Option A). Policy Set Creation: When a new CNF instance is deployed, a new policy set is created specifically for that instance. This ensures that each CNF instance can have a tailored set of security policies based on the specific needs of the deployment (Option C). Other Options Analysis: Option B is incorrect because policy sets do not require manual synchronization; they are applied automatically once configured. Option D is incorrect as a single CNF instance operates with a single policy set at a time.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago