FCSS_CDS_AR-7.6 Online Practice Questions

Home / Fortinet / FCSS_CDS_AR-7.6

Latest FCSS_CDS_AR-7.6 Exam Practice Questions

The practice questions for FCSS_CDS_AR-7.6 exam was last updated on 2025-09-15 .

Viewing page 1 out of 2 pages.

Viewing questions 1 out of 14 questions.

Question#1

Refer to the exhibit.



You have deployed a Linux EC2 instance in Amazon Web Services (AWS) with the settings shown in the exhibit.
What next step must the administrator take to access this instance from the internet?

A. Allocate an Elastic IP address and assign it to the instance.
B. Create a VIP on FortiGate to allow access.
C. Enable SSH and allocate it to the device.
D. Configure the user name and password.

Question#2

Refer to the exhibit.



The exhibit shows an active-passive high availability FortiGate pair with external and internal Azure load balancers.
There is no SDN connector used in this solution.
Which configuration must the administrator implement on each FortiGate?

A. Single BGP route to Azure probe IP address.
B. One static route to Azure Lambda IP address.
C. Two static routes to Azure probe IP address.
D. Two BGP routes to Azure probe IP address.

Question#3

As part of your organization’s monitoring plan, you have been tasked with obtaining and analyzing detailed information about the traffic sourced at one of your FortiGate EC2 instances.
What can you do to achieve this goal?

A. Use AWS CloudTrail to capture and then examine traffic from the EC2 instance.
B. Create a virtual public cloud (VPC) flow log at the network interface level for the EC2 instance.
C. Add the EC2 instance as a target in CloudWatch to collect its traffic logs.
D. Configure a network access analyzer scope with the EC2 instance as a match finding.

Question#4

You have deployed a FortiGate HA cluster in Azure using a Gateway Load Balancer for traffic inspection. However, traffic is not being routed correctly through the firewalls.
What can be the cause of the issue?

A. The Fortinet VMs have IP forwarding disabled, which is required for traffic inspection.
B. The health probes for the Gateway Load Balancer are failing, which causes traffic to bypass the HA cluster.
C. The Gateway Load Balancer is not associated with the correct network security group (NSG) rules, which allow traffic to pass through.
D. The protected VMs are in a different Azure subscription, which prevents the Gateway Load Balancer from forwarding traffic.

Question#5

A network security administrator is searching for a solution to secure traffic going in and out of the container infrastructure.
In which two ways can Fortinet container security help secure container infrastructures? (Choose two.)

A. FortiGate NGFW can inspect north-south container traffic with label-aware policies.
B. FortiGate NGFW and FortiWeb can be used to secure container traffic.
C. FortiGate NGFW can connect to the worker nodes and protect the containers.
D. FortiGate NGFW can be placed between each application container for north-south traffic inspection.

Exam Code: FCSS_CDS_AR-7.6Q & A: 38 Q&AsUpdated:  2025-09-15

 Get All FCSS_CDS_AR-7.6 Q&As