NSE 8 – Network Security Expert (812) — Question 81
A customer is planning on moving their secondary data center to a cloud-based IaaS. They want to place all the Oracle-based systems on Oracle Cloud, while the other systems will be on Microsoft Azure with ExpressRoute service to their main data center.
They have about 200 branches with two internet services as their only WAN connections. As a security consultant you are asked to design an architecture using Fortinet products with security, redundancy, and performance as a priority.
Which two design options are true based on these requirements? (Choose two.)
Answer options
- A. Systems running on Azure will need to go through the main data center to access the services on Oracle Cloud.
- B. Use FortiGate VM for IPSEC over ExpressRoute, as traffic is not encrypted by Azure.
- C. Branch FortiGate devices must be configured as VPN clients for the branches’ internal network to be able to access Oracle services without using public IPs.
- D. Two ExpressRoute services to the main data center are required to implement SD-WAN between a FortiGate VM in Azure and a FortiGate device at the data center edge.
Correct answer: B, C
Explanation
Option B is correct because IPSEC is necessary for encrypting traffic over ExpressRoute, which does not provide encryption by default. Option C is also correct as configuring branch FortiGate devices as VPN clients allows secure access to Oracle services without exposing public IPs. Options A and D are incorrect because they either introduce unnecessary complexity or do not align with the requirement for direct access to Oracle services.