Question 1 of 30
A multinational corporation is migrating its hybrid cloud infrastructure to a more robust public cloud environment, leveraging AWS. They have deployed FortiGate NGFW virtual appliances within a dedicated security Virtual Private Cloud (VPC) to act as a central inspection point for all inter-VPC communication and internet-bound traffic originating from various application VPCs. The organization\'s security policy mandates that all outbound internet traffic from the development and staging environments must be inspected by the FortiGate for compliance and threat prevention. Given this architecture, what is the most critical cloud-native routing configuration required within the development and staging VPCs to ensure this traffic is directed to the FortiGate for inspection?
Modify the Route Tables in the development and staging VPCs to include a default route (destination `0.0.0.0/0`) that targets the FortiGate's Elastic Network Interface (ENI) as the next hop.
Implement AWS Network Access Control Lists (NACLs) on the subnets hosting the FortiGate to permit all inbound traffic from the development and staging VPC CIDRs.
Configure VPC Flow Logs in the development and staging VPCs to capture and analyze traffic patterns, forwarding logs to a SIEM for correlation with FortiGate events.
Establish AWS Transit Gateway route propagation rules to direct all traffic destined for the internet through the security VPC where the FortiGate resides.

Preparing for NSE7_PBC7.2 Fortinet NSE 7 Public Cloud Security 7.2? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free