NSE7_PBC-7.2 Exam Questions
89 real NSE7_PBC-7.2 exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #51FortiGate-VM in Public Cloud
You are automating configuration changes on one of the FortiGate VMS using Linux Red Hat Ansible. How does Linux Red Hat Ansible connect to FortiGate to make the configuration chan...
AnsibleFortiGate REST APIconfiguration automationFortiOS integration - Question #52FortiGate-VM in Public Cloud
Refer to the exhibit. An administrator deployed an HA active-active load balance sandwich in Microsoft Azure. The setup requires configuration synchronization between devices. What...
HA active-activeload balance sandwichAzureconfiguration synchronization - Question #53FortiGate-VM in Public Cloud
Refer to the exhibit. An administrator deployed a FortiGate-VM in a high availability (HA) (active/passive) architecture in Amazon Web Services (AWS) using Terraform for testing pu...
Terraformterraform destroyresource cleanupAWS Marketplace - Question #54FortiGate-VM in Public Cloud
You are tasked with deploying a FortiGate HA solution in Amazon Web Services (AWS) using Terraform. What are two steps you must take to complete this deployment? (Choose two.)
TerraformAWS IAMFortiGate HA deploymentCloudShell - Question #55FortiGate-VM in Public Cloud
Refer to the exhibit. Consider the active-active load balance sandwich scenario in Microsoft Azure. What are two important facts in the active-active load balance sandwich scenario...
HA active-activeload balance sandwichNAT policysession synchronization - Question #56FortiGate-VM in Public Cloud
Refer to the exhibit. An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform. However, during the configuration, the Azure client secret is no longe...
Azure client secretTerraform authenticationservice principalAzure credentials - Question #57FortiGate-VM in Public Cloud
What are two main features in Amazon Web Services (AWS) network access control lists (ACLs)? (Choose two.)
Network ACLstateless filteringdefault ACL rulesAWS security - Question #58FortiGate-VM in Public Cloud
Refer to the exhibit. In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet. However, your HTTPS connection to t...
AWS VPC routingtransit gatewaysecurity VPCinternet gateway - Question #59Cloud Security Concepts
You must allow an SSH traffic rule in an Amazon Web Services (AWS) network access list (NACL) to allow SSH traffic to travel to a subnet for temporary testing purposes. When you re...
AWS NACLrule orderingSSH trafficnetwork access control - Question #60FortiGate-VM in Public Cloud
Refer to Exhibit. The exhibit shows the Connect Peers settings on Amazon Web Services (AWS) transit gateway attachments with two FortiGate VMS in a security VPC. Which two statemen...
transit gateway connectGRE peersBGP inside CIDRFortiGate interface - Question #61FortiGate-VM in Public Cloud
Refer to the exhibit. You are configuring a second route table on a Transit Gateway to accommodate east-west traffic inspection between two VPCs. However, you are getting an error...
transit gateway route tableeast-west inspectionConnect attachmentTGW propagation - Question #62FortiGate-VM in Public Cloud
Refer to Exhibit. You are troubleshooting a Microsoft Azure SDN connector issue on your FortiGate VM in Azure. Which three settings should you check while troubleshooting this prob...
Azure SDN connectorDNS resolutionmetadata IP 169.254.169.254troubleshooting - Question #63FortiGate-VM in Public Cloud
Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary d...
Azure HA failoverfloating IPservice principalcontributor role - Question #64FortiGate-VM in Public Cloud
You are troubleshooting an Azure SDN connectivity issue with your FortiGate VM. Which two queries does that SDN connector use to interact with the Azure management API? (Choose two...
Azure SDN connectormanagement APItoken authenticationpublic IP management - Question #65FortiCWP
When adding the Amazon Web Services (AWS) account to the FortiCNP, which three mandatory configuration steps must you follow? (Choose three.)
FortiCNP onboardingAWS account setupCloudFormation templateCloudTrail - Question #66FortiCWP
Refer to the exhibit. The exhibit shows the results of a FortiCNP registry scan. Which two statements are correct? (Choose two )
FortiCNP registry scancontainer protectionimage scanningrepository tags - Question #67FortiCWP
A customer would like to use FortiGate fabric integration With FortiCNP. When configuring a FortiGate VM to add to FortiCNP, which three mandatory configuration steps must you foll...
FortiCNP FortiGate integrationIPS sensorlog forwardingSSL inspection profile - Question #68Cloud Security Concepts
How does an administrator secure container environments from newly emerged security threats?
container securityDocker signaturesapplication controlthreat prevention - Question #69FortiGate-VM in Public Cloud
What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD- WAN?
SD-WAN TGW ConnectGRE tunnel attachmenttransit gatewaybandwidth - Question #70FortiCASB and FortiNAC for Public Cloud
An administrator is looking for a solution that can provide insight into users and data stored in major SaaS applications in the multicloud environment Which product should the adm...
FortiCASBSaaS securitymulticloud visibilityCASB - Question #71FortiGate-VM in Public Cloud
What kind of underlying mechanism does Transit Gateway Connect use to send traffic from the virtual private cloud (VPC) to the transit gateway?
transit gateway connecttransport attachmentGRE encapsulationVPC routing - Question #72FortiGate-VM in Public Cloud
Which two statements are true about Transit Gateway Connect peers in anlPv4 BGP configuration'? (Choose two.)
BGP peeringinside CIDR /29link-local rangetransit gateway connect peers - Question #73FortiGate-VM in Public Cloud
In an SD-WAN TGW Connect topology, which three initial steps are mandatory when routing traffic from a spoke VPC to a security VPC through a Transit Gateway? (Choose three.)
SD-WAN TGW topologyspoke VPC routingsecurity VPC route tables0.0.0.0/0 routing - Question #74FortiGate-VM in Public Cloud
Which two Amazon Web Services (AWS) features do you use for the transit virtual private cloud (VPC) automation process to add new spoke N/PCs? (Choose two )
transit VPC automationCloudWatchtransit gatewayspoke VPC addition - Question #75FortiGate-VM in Public Cloud
You are adding a new spoke to the existing transit VPC environment using the AWS Cloud Formation template. Which two components must you use for this deployment? (Choose two.)
CloudFormation deploymenttransit VPCBGP ASNspoke tag value - Question #76Cloud Security Concepts
Which statement about immutable infrastructure in automation is true?
immutable infrastructureinfrastructure as codeserver deploymentautomation - Question #77Cloud Security Concepts
How does Terraform keep track of provisioned resources?
Terraformstate fileinfrastructure as coderesource tracking - Question #78FortiGate-VM in Public Cloud
Refer to the exhibit. The exhibit shows an active-passive high availability FortiGate pair with external and internal Azure load balancers. There is no SDN connector used in this s...
Azure load balancerHA active-passiveprobe IPstatic routes - Question #79FortiGate-VM in Public Cloud
Your goal is to deploy resources in multiple places and regions in the public cloud using Terraform. What is the most efficient way to deploy resources without changing much of the...
Terraformtfvarsmulti-region deploymentinfrastructure as code - Question #80FortiGate-VM in Public Cloud
You are using Red Hat Ansible to change the FortiGate VM configuration. What is the minimum number of files you must create and which file must you use to configure the target Fort...
Ansiblehosts fileplaybookFortiGate automation - Question #81FortiGate-VM in Public Cloud
Refer to the exhibit. You deployed an HA active-active load balance sandwich with two FortiGate VMs in Microsoft Azure. After the deployment, you prefer to use FGSP to synchronize...
FGSPAzure load balanceractive-active HApeerip - Question #82FortiGate-VM in Public Cloud
Refer to the exhibit. What value or values must the administrator use in the SSH Key section to deploy a FortiGate VM using Terraform in Amazon Web Services (AWS)?
TerraformAWS key pairFortiGate deploymentSSH key - Question #83FortiGate-VM in Public Cloud
Refer to the exhibit. What would be the impact of confirming to delete all the resources in Terraform?
Terraformstate fileterraform destroyresource management - Question #84FortiGate-VM in Public Cloud
Refer to the exhibit. An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer. Ho...
AWS security groupsFortiGate VMconnectivity troubleshootingnetwork ACL - Question #85FortiGate-VM in Public Cloud
Refer to the exhibit. You have deployed a Linux EC2 instance in Amazon Web Services (AWS) with the settings shown on the exhibit What next step must the administrator take to acces...
AWS EC2Elastic IPpublic internet accessinstance configuration - Question #86FortiGate-VM in Public Cloud
Refer to the exhibit. What could be the reason that the administrator cannot access the EC2 instance?
AWS EC2SSH keypem file pathaccess troubleshooting - Question #87FortiGate-VM in Public Cloud
An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure However, the SDN connector is failing on the connection What mus...
Azure managed identitySDN connectorFortiGate configurationRBAC - Question #88FortiGate-VM in Public Cloud
You are configuring the failover settings on a FortiGate active-passive SDN connector solution in Microsoft Azure. Which two mandatory settings are required after the initial deplo...
Azure SDN connectoractive-passive HAfailover settingssubscription ID - Question #89FortiCWP
An administrator would like to keep track of sensitive data files located in the Amazon Web Services (AWS) S3 bucket and protect it from malware. Which Fortinet product or feature...
FortiCNPDLP policiesAWS S3data protection