NSE7_PBC-7.2 Exam Questions
89 real NSE7_PBC-7.2 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
An Amazon Web Services (AWS) auto-scale FortiGate cluster has just experienced a scale-down event, terminating a FortiGate in availability zone C. This has now black-holed the priv...
- Question #2
Refer to the exhibit. Consider an active-passive HA deployment in Microsoft Azure. The exhibit shows an excerpt from the passive FortiGate-VM node. If the active FortiGate-VM fails...
- Question #3FortiGate-VM in Public Cloud
Which two Amazon Web Services (AWS) topologies support east-west traffic inspection within the AWS cloud by the FortiGate VM? (Choose two.)
east-west traffictransit VPCtransit gatewayAWS topology - Question #4FortiGate-VM in Public Cloud
You have previously deployed an Amazon Web Services (AWS) transit virtual private cloud (VPC) with a pair of FortiGate firewalls (VM04 / c4.xlarge) as your security perimeter. You...
auto-scalingtransit VPChigh CPUEC2 instance sizing - Question #5
Which two statements about Amazon Web Services (AWS) networking are correct? (Choose two.)
- Question #6
An organization deploys a FortiGate-VM (VM04 / c4.xlarge) in Amazon Web Services (AWS) and configures two elastic network interfaces (ENIs). Now, the same organization wants to add...
- Question #7
Refer to the exhibit. You are configuring an active-passive FortiGate clustering protocol (FGCP) HA configuration in a single availability zone in Amazon Web Services (AWS), using...
- Question #8
Customer XYZ has an ExpressRoute connection from Microsoft Azure to a data center. They want to secure communication over ExpressRoute, and to install an in-line FortiGate to perfo...
- Question #9FortiGate-VM in Public Cloud
You need to deploy FortiGate VM devices in a highly available topology in the Microsoft Azure cloud. The following are the requirements of your deployment: - Two FortiGate devices...
active-active HAAzure load balanceravailability zonesauto-scale config - Question #10FortiCWP
When configuring the FortiCASB policy, which three configuration options are available? (Choose three.)
FortiCASB policythreat protectionDLPcompliance policies - Question #11
You have been tasked with deploying FortiGate VMs in a highly available topology on the Amazon Web Services (AWS) cloud. The requirements for your deployment are as follows: - You...
- Question #12FortiGate-VM in Public Cloud
You are deploying Amazon Web Services (AWS) GuardDuty to monitor malicious or unauthorized behaviors related to AWS resources. You will also use the Fortinet aws-lambda-guardduty s...
AWS GuardDutyexternal threat feedLambda integrationDynamoDB - Question #13
Refer to the exhibit. A customer has deployed an environment in Amazon Web Services (AWS) and is now trying to send outbound traffic from the Web servers to the Internet. The Forti...
- Question #14
Refer to the exhibit. Your senior administrator successfully configured a FortiGate fabric connector with the Azure resource manager, and created a dynamic address object on the Fo...
- Question #15
Refer to the exhibit. You are deploying a FortiGate-VM in Microsoft Azure using the PAYG/On- demand licensing model. After you configure the FortiGate-VM, the validation process fa...
- Question #16Cloud Security Concepts
Which two statements about Microsoft Azure network security groups are true? (Choose two.)
Azure NSGstateful filteringsubnet associationNIC association - Question #17FortiGate-VM in Public Cloud
Refer to the exhibit. In your Amazon Web Services (AWS) virtual private cloud (VPC), you must allow outbound access to the internet and upgrade software on an EC2 instance, without...
AWS NAT gatewayprivate subnetEIPVPC routing - Question #18
What is the bandwidth limitation of an Amazon Web Services (AWS) transit gateway VPC attachment?
- Question #19
A company deployed a FortiGate-VM with an on-demand license using Amazon Web Services (AWS) Market Place Cloud Formation template. After deployment, the administrator cannot rememb...
- Question #20
You have been asked to secure your organization's salesforce application that is running on Microsoft Azure, and find an effective method for inspecting shadow IT activities in the...
- Question #21FortiGate-VM in Public Cloud
Your company deploys FortiGate VM devices in high availability (HA) (active-active) mode with Microsoft Azure load balancers using the Microsoft Azure ARM template. Your senior adm...
Azure HAload balancer NAT rulespublic IPmanagement access - Question #22
Refer to the exhibit. The exhibit shows a topology where multiple connections from clients to the same FortiGate-VM instance, regardless of the protocol being used, are required. W...
- Question #23
Refer to the exhibit. Which two conditions will enable you to segregate and secure the traffic between the hub and the spokes in Microsoft Azure? (Choose two.)
- Question #24FortiGate-VM in Public Cloud
An organization deployed a FortiGate-VM in the Google Cloud Platform and initially configured it with two vNICs. Now, the same organization wants to add additional vNICs to this ex...
GCP vNICFortiGate-VM limitationsvirtual NICsGoogle Cloud - Question #25
You have been asked to develop an Azure Resource Manager infrastructure as a code template for the FortiGate-VM, that can be reused for multiple deployments. The deployment fails,...
- Question #26FortiGate-VM in Public Cloud
Which statement about FortiSandbox in Amazon Web Services (AWS) is true?
FortiSandbox AWSWindows VMsfile inspectionsandbox deployment - Question #27
Which two statements about the Amazon Cloud Services (AWS) network access control lists (ACLs) are true? (Choose two.)
- Question #28FortiGate-VM in Public Cloud
When an organization deploys a FortiGate-VM in a high availability (HA) (active/active) architecture in Microsoft Azure, they need to determine the default timeout values of the lo...
Azure load balancer probesHA failoverhealth probe timeoutactive-active - Question #29Cloud Security Concepts
Which three properties are configurable Microsoft Azure network security group rule settings? (Choose three.)
Azure NSG rulesactionport rangesNSG properties - Question #30
Refer to the exhibit. You attempted to deploy the FortiGate-VM in Microsoft Azure with the JSON template, and it failed to boot up. The exhibit shows an excerpt from the JSON templ...
- Question #31FortiGate-VM in Public Cloud
A Network security administrator is searching for a solution to secure traffic going in and out of the container infrastructure. In which two ways can Fortinet container security h...
container securitynorth-south trafficlabel-aware policiesFortiSandbox - Question #32FortiWeb in Public Cloud
You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications re...
OWASP Top 10FortiWebCloudweb application firewallpublic cloud WAF - Question #33FortiGate-VM in Public Cloud
Refer to the exhibit. You attempted to access the Linux1 EC2 instance directly from the internet using its public IP address in AWS. However, your connection is not successful. Giv...
internet gatewayspoke VPCAWS routingtransit gateway topology - Question #34FortiGate-VM in Public Cloud
Refer to the exhibit. The exhibit shows a customer deployment of two Linux instances and their main routing table in Amazon Web Services (AWS). The customer also created a Transit...
transit gatewayTGW route tableVPC attachmentsrouting configuration - Question #35FortiGate-VM in Public Cloud
Which two attachments are necessary to connect a transit gateway to an existing VPC with BGP? (Choose two )
transit gateway BGPconnect attachmenttransport attachmentTGW connectivity - Question #36FortiGate-VM in Public Cloud
You have created a TGW route table to route traffic from your spoke VPC to the security VPC where two FortiGate devices are inspecting traffic. Your spoke VPC CIDR block is already...
TGW route tableVPC attachmentBGP route advertisementsecurity VPC - Question #37FortiGate-VM in Public Cloud
Refer to the exhibit. A customer has deployed an environment in Amazon Web Services (AWS) and is now trying to send outbound traffic from the Linux1 and Linux2 instances to the int...
spoke VPC routingTGW routingsecurity VPCoutbound traffic inspection - Question #38FortiGate-VM in Public Cloud
Which two Amazon Web Services (AWS) features support east-west traffic inspection within the AWS cloud by the FortiGate VM? (Choose two.)
east-west traffic inspectionTransit GatewayTransit VPCAWS networking - Question #39FortiGate-VM in Public Cloud
Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?
Transit GatewayTGW route tablesroute propagationAWS networking - Question #40FortiGate-VM in Public Cloud
You are asked to find a solution to replace the existing VPC peering topology to have a higher bandwidth connection from Amazon Web Services (AWS) to the on-premises data center. W...
VPC peeringECMP VPNTransit VPChigh bandwidth connectivity - Question #41FortiGate-VM in Public Cloud
You are adding more spoke VPCs to an existing hub and spoke topology. Your goal is to finish this task in the minimum amount of time without making errors. Which Amazon AWS service...
hub and spoke topologyCloudWatchS3spoke VPC scaling - Question #42FortiGate-VM in Public Cloud
Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs. What are the tw...
Azure vWANExpressRouteVPN Gatewaybranch connectivity - Question #43FortiGate-VM in Public Cloud
Refer to the exhibit. You are tasked with deploying FortiGate using Terraform. When you run the terraform version command during the Terraform installation, you get an error messag...
Terraform installationbinary PATHcommand not foundAWS deployment - Question #44FortiGate-VM in Public Cloud
How does the immutable infrastructure strategy work in automation?
immutable infrastructureautomation strategyblue-green deploymentlive environments - Question #45FortiGate-VM in Public Cloud
Refer to the exhibit. You deployed an HA active-passive FortiGate VM in Microsoft Azure. Which two statements regarding this particular deployment are true? (Choose two.)
HA active-passiveAzure failoverAPI callsconfiguration sync - Question #46FortiGate-VM in Public Cloud
Refer to the exhibit. You are deploying two FortiGate VMS in HA active-passive mode with load balancers in Microsoft Azure. Which two statements are true in this load balancing sce...
Azure load balancerHA active-passiveinternal load balancermanagement interface - Question #47FortiGate-VM in Public Cloud
Refer to Exhibit. After the initial Terraform configuration in Microsoft Azure, the terraform plan command is run. Which two statements about running the plan command are true? (Ch...
Terraformterraform planterraform initdry run - Question #48FortiGate-VM in Public Cloud
What are three important steps required to get Terraform ready using Microsoft Azure Cloud Shell? (Choose three.)
TerraformAzure Cloud Shellstorage accountbinary installation - Question #49FortiGate-VM in Public Cloud
Refer to the exhibit. You are tasked with deploying a webserver and FortiGate VMS in AWS. You are using Terraform to automate the process. Which two important details should you kn...
Terraformoutput valuesvariables.tfAWS deployment - Question #50FortiGate-VM in Public Cloud
Refer to the exhibit. You are tasked to deploy a FortiGate VM with private and public subnets in Amazon Web Services (AWS). You examined the variables.tf file. What will be the fin...
Terraformvariables.tfFortiGate VM deploymentAWS region configuration