Weekend Sale Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Fortinet NSE7_PBC-7.2 Fortinet NSE 7 - Public Cloud Security 7.2 Exam Practice Test

Page: 1 / 6
Total 59 questions

Fortinet NSE 7 - Public Cloud Security 7.2 Questions and Answers

Question 1

An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure However, the SDN connector is failing on the connection What must the administrator do to correct this issue?

Options:

A.

Make sure to add the Tenant ID on FortiGate side of the configuration

B.

Make sure to set the type to system managed identity on FortiGate SDN connectorsettings

C.

Make sure to enable the system assigned managed identity on Azure

D.

Make sure to add the Client secret on FortiGate side of the configuration

Question 2

How does the immutable infrastructure strategy work in automation?

Options:

A.

It runs a single live environment for configuration changes.

B.

It runs one idle and a single live environment for configuration changes.

C.

It runs two live environments for configuration changes.

D.

It runs one idle and two live environments for configuration changes.

Question 3

You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications reside, with minimum traffic cost

Which solution meets the requirements?

Options:

A.

Use FortiADC

B.

Use FortiCNP

C.

Use FortiWebCloud

D.

Use FortiGate

Question 4

Refer to the exhibit

Question # 4

An administrator deployed a FortiGate-VM in a high availability (HA)

(active/passive) architecture in Amazon Web Services (AWS) using Terraform

for testing purposes. At the same time, the administrator deployed a single

Linux server using AWS Marketplace

Which two options are available for the administrator to delete all the resources

created in this test? (Choose two.)

Options:

A.

Use the terraform destroy command

B.

Use the terraform validate command.

C.

Use the terraform destroy all command.

D.

The administrator must manually delete the Linux server.

Question 5

Refer to the exhibit.

Question # 5

You have deployed a Linux EC2 instance in Amazon Web Services (AWS) with the settings shown on the exhibit

What next step must the administrator take to access this instance from the internet?

Options:

A.

Configure the user name and password.

B.

Enable source and destination checks on the instance

C.

Enable SSH and allocate it to the device

D.

Allocate an Elastic IP address and assign it to the instance

Question 6

Refer to the exhibit.

Question # 6

Question # 6

What could be the reason that the administrator cannot access the EC2 instance?

Options:

A.

You must elevate the permissions to access the EC2 instance

B.

You must run the chmod 400 Staging-key.peracommand before accessing the instance.

C.

There is no . pem key created on in Amazon Web Services (AWS)

D.

The directory location of the . pem file is incorrect.

Question 7

Refer to the exhibit

Question # 7

An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform However, during the configuration, the Azure client secret is no longer visible in the Azure portal.

How would the administrator obtain the Azure

client secret to configure on Terratorm?

Options:

A.

The administrator must create a new Azure account

B.

Log in to the Azure CLI with power user to obtain the client secret

C.

The administrator can create a new client secret

D.

The administrator must obtain the client secret through Azure Cloud Shell.

Question 8

What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

Options:

A.

It eliminates the use of ECMP

B.

You can use GRE-based tunnel attachments

C.

You can combine it with IPsec to achieve higher bandwidth

D.

You can use BGP over IPsec for maximum throughput

Question 9

Refer to Exhibit:

Question # 9

The exhibit shows the Connect Peers settings on Amazon Web Services (AWS) transit gateway attachments With two FortiGate VMS in a security VPC.

Which two statements are correct? (Choose two.)

Options:

A.

The peer GRE address is the FortiGate external interface IP address.

B.

The Transit Gateway GRE address is auto-generated

C.

The BGP inside CIDR blocks can be any CIDR block with /29

D.

The Peer GRE address is the FortiGate internal interface IP address

Question 10

Refer to the exhibit.

Question # 10

What would be the impact of confirming to delete all the resources in Terraform?

Options:

A.

It destroys all the resources in the . tfvars file

B.

It destroys all the resources tied to the AWS Identity and Access Management (1AM) user.

C.

It destroys all the resources in the resource group

D.

It destroys all the resources in the state file.

Question 11

Refer to the exhibit

Question # 11

You are deploying two FortiGate VMS in HA active-passive mode with load balancers in Microsoft Azure

Which two statements are true in this load balancing scenario? (Choose two.)

Options:

A.

The FortiGate public IP is the next-hop for all the traffic.

B.

An internal load balancer listener is the next-hop for outgoing traffic.

C.

You must add a route to the Microsoft VIP used for the health check.

D.

A dedicated management interface can be used for load balancing.

Question 12

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.

What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)

Options:

A.

ExpressRoute

B.

GRE tunnels

C.

SSL VPN connections

D.

An L2TP connection

E.

VPN Gateway

Question 13

Refer to the exhibit

Question # 13

You are tasked with deploying a webserver and FortiGate VMS in AWS_ You are using Terraform to automate the process

Which two important details should you know about the Terraform files? (Choose two.)

Options:

A.

All the output values are available after a successful terraform apply command

B.

The subnet_private 1 value is defined in the variables . tf file

C.

After the deployment, Terraform output values are visible only through AWS CloudShell.

D.

You must specify all the AWS credentials in the output. of file.

Question 14

You are configuring the failover settings on a FortiGate active-passive SDN connector solution in Microsoft Azure. Which two mandatory settings are required after the initial deployment? (Choose two)

Options:

A.

Subscription-id

B.

FortiGate license file

C.

Active FortiGate serial number

D.

Resource group name

Question 15

You are tasked with deploying a FortiGate HA solution in Amazon Web Services (AWS) using Terraform What are two steps you must take to complete this deployment? (Choose two.)

Options:

A.

Enable automation on the AWS portal.

B.

Create an AWS Identity and Access Management (IAM) user With permissions.

C.

Use CloudSheIl to install Terraform.

D.

Create an AWS Active Directory user with permissions.

Question 16

Which two Amazon Web Services (AWS) features support east-west traffic inspection within the AWS cloud by the FortiGate VM? (Choose two.)

Options:

A.

A NAT gateway with an EIP

B.

A transit gateway with an attachment

C.

An Internet gateway with an EIP

D.

A transit VPC

Question 17

What are two main features in Amazon Web Services (AWS) network access control lists (ACLs)? (Choose two.)

Options:

A.

You cannot use Network ACL and Security Group at the same time.

B.

The default network ACL is configured to allow all traffic

C.

NetworkACLs are stateless, and inbound and outbound rules are used for traffic filtering

D.

Network ACLs are tied to an instance

Page: 1 / 6
Total 59 questions