B. You must use unicast FGCP to synchronize the configurations.
This is also a requirement for any FortiGate HA cluster in Azure (both active-active and
active-passive), not specifically just for active-active. Therefore, option A is more precise to the
active-active scenario.
C. You must configure both load balancers to allow administrative access.
This is incorrect. Exposing administrative interfaces through a public-facing load balancer is a
significant security vulnerability and is contrary to security best practices, not a requirement.
D. You must configure all FortiGate VMs with three or more interfaces.
While using a dedicated interface for HA synchronization (resulting in 3+ interfaces) is a
recommended best practice, it is not a strict technical requirement. The core function can be
configured with fewer interfaces.