Halloween Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Fortinet NSE7_PBC-7.2 Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Exam Practice Test

Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$36  $119.99

PDF Study Guide

  • Product Type: PDF Study Guide
$31.5  $104.99
Question 1

What are three important steps required to get Terraform ready using Microsoft Azure Cloud Shell? (Choose three.)

Options:

A.

Set up a storage account in Azure.

B.

use the -O command to download Terraform.

C.

Subscribe to Terraform in Azure.

D.

Move the Terraform file to the bin directory.

E.

Use the wget (te=aform vession) command to upload Terraform.

Question 2

Refer to the exhibit

You deployed an HA active-passive FortiGate VM in Microsoft Azure.

Which two statements regarding this particular deployment are true? (Choose two.)

Options:

A.

During the failover, the passive FortiGate issues API calls to Azure

B.

Use the vdom-excepticn command to synchronize the configuration.

C.

There is no SLA for API calls from Microsoft Azure.

D.

By default, the configuration does not synchromze between the primary and secondary devices.

Question 3

Refer to the exhibit

In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet However, your HTTPS connection to the FortiGate VM in the Customer VPC is not successful.

Also, you must ensure that the Customer VPC FortiGate VM sends all the outbound Internet traffic through the Security VPC How do you correct this Issue with minimal configuration changes?

(Choose three.)

Options:

A.

Add a route With your local internet public IP address as thedestination and target transit gateway

B.

Add route destination 0 0.0 0/0 to target the transit gateway

C.

Add a route With your local internet public IP address as the destination and target internet gateway

D.

Deploy an internet gateway, associate an EIP in the private subnet, edit route tables, and add a new route destination0.0.0.0/0 to the target internet gateway

E.

Deploy an internet gateway, associate an EIP in the public subnet, and attach the internet gateway to the Customer VPC,

Question 4

Refer to the exhibit

You are tasked with deploying a webserver and FortiGate VMS in AWS_ You are using Terraform to automate the process

Which two important details should you know about the Terraform files? (Choose two.)

Options:

A.

All the output values are available after a successful terraform apply command

B.

The subnet_private 1 value is defined in the variables . tf file

C.

After the deployment, Terraform output values are visible only through AWS CloudShell.

D.

You must specify all the AWS credentials in the output. of file.

Question 5

Refer to the exhibit

Consider the active-active load balance sandwich scenario in Microsoft Azure.

What are two important facts in the active-active load balance sandwich scenario? (Choose two )

Options:

A.

It uses the vdom-exception command to exclude the configuration from being synced

B.

It is recommended to enable NAT on FortiGate policies.

C.

It uses the FGCP protocol

D.

It supports session synchronization for handling asynchronous traffic.

Question 6

Refer to the exhibit.

You are configuring a second route table on a Transit Gateway to accommodate east-west traffic inspection between two VPCs_ However, you are getting an error during the transit gateway route table association With the Connect attachment.

Which action Should you take to fulfill your requirement?

Options:

A.

Add both Associations and Propagations in the second TGW route table.

B.

Delete the both Connect and Transport attachments from the first TGW route table

C.

Add a static route in the Routes section

D.

In the second route table: create a propagation with the Connect attachment.

Question 7

You are using Red Hat Ansible to change the FortiGate VM configuration.

What is the minimum number of files you must create and which file must you use to configure the target FortiGate IP address?

Options:

A.

Create two files and use the .yami file.

B.

Create two files and use the hosts file

C.

Create one file and use the variable file

D.

Create three files and use the .yarai file.

Question 8

Refer to Exhibit:

The exhibit shows the Connect Peers settings on Amazon Web Services (AWS) transit gateway attachments With two FortiGate VMS in a security VPC.

Which two statements are correct? (Choose two.)

Options:

A.

The peer GRE address is the FortiGate external interface IP address.

B.

The Transit Gateway GRE address is auto-generated

C.

The BGP inside CIDR blocks can be any CIDR block with /29

D.

The Peer GRE address is the FortiGate internal interface IP address

Question 9

Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?

Options:

A.

TGW can have multiple TGW route tables.

B.

Both the TGW attachment and propagation must be in the same TGW route table

C.

A TGW attachment can be associated with multiple TGW route tables.

D.

The TGW default route table cannot be disabled.

Question 10

How does the immutable infrastructure strategy work in automation?

Options:

A.

It runs a single live environment for configuration changes.

B.

It runs one idle and a single live environment for configuration changes.

C.

It runs two live environments for configuration changes.

D.

It runs one idle and two live environments for configuration changes.

Question 11

Refer to the exhibit

The exhibit shows the results of a FortiCNP registry scan

Which two statements are correct? (Choose two )

Options:

A.

When adding a repository, you can leave the Tag section blank to scan all images-

B.

The registry scan is part of the FortiCNP cloud protection.

C.

The registry scan is part of the FortiCNP container protection.

D.

When adding a repository, you can add a minimum number of images to be imported through the CAP section.

Question 12

Refer to Exhibit:

You are troubleshooting a Microsoft Azure SDN connector issue on your FortiGate VM in Azure

Which three settings should you check while troubleshooting this problem? (Choose three.)

Options:

A.

Use the show vdom command to see hidden VDOMs.

B.

use the diag sys va command.

C.

Ensure FortiGate port4 can resolve DNS.

D.

Ensure FortiGate portl has internet access

E.

Ensure IP address 169.254.169_254 is not blocked

Question 13

A customer would like to use FortiGate fabric integration With FortiCNP

When configuring a FortiGate VM to add to FortiCNP, which three mandatory configuration steps must you follow on FortiGate? (Choose three.)

Options:

A.

Enable send logs-

B.

Create and IPS sensor and a firewall policy

C.

Create an IPsec tunnel.

D.

Create an SSL]SSH inspection profile.

E.

Enable two-factor authentication.

Question 14

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.

What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)

Options:

A.

ExpressRoute

B.

GRE tunnels

C.

SSL VPN connections

D.

An L2TP connection

E.

VPN Gateway

Question 15

What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

Options:

A.

It eliminates the use of ECMP

B.

You can use GRE-based tunnel attachments

C.

You can combine it with IPsec to achieve higher bandwidth

D.

You can use BGP over IPsec for maximum throughput

Question 16

You are asked to find a solution to replace the existing VPC peering topology to have a higher bandwidth connection from Amazon Web Services (AWS) to the on-premises data center Which two solutions will satisfy the requirement? (Choose two.)

Options:

A.

Use ECMP and VPN to achieve higher bandwidth.

B.

Use transit VPC to build multiple VPC connections to the on-premises data center

C.

Use a transit VPC with hub and spoke topology to create multiple VPN connections to the on-premises data center.

D.

Use the transit gateway attachment With VPN option to create multiple VPN connections to the on-premises data center

Question 17

What are two main features in Amazon Web Services (AWS) network access control lists (ACLs)? (Choose two.)

Options:

A.

You cannot use Network ACL and Security Group at the same time.

B.

The default network ACL is configured to allow all traffic

C.

NetworkACLs are stateless, and inbound and outbound rules are used for traffic filtering

D.

Network ACLs are tied to an instance