Easter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Question and Answers

Fortinet NSE 7 Public Cloud Security 7.2 (FCSS)

Last Update May 14, 2024
Total Questions : 59

We are offering FREE NSE7_PBC-7.2 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE7_PBC-7.2 free exam questions and then go for complete pool of Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) test questions that will help you more.

NSE7_PBC-7.2 pdf

NSE7_PBC-7.2 PDF

$35  $99.99
NSE7_PBC-7.2 Engine

NSE7_PBC-7.2 Testing Engine

$42  $119.99
NSE7_PBC-7.2 PDF + Engine

NSE7_PBC-7.2 PDF + Testing Engine

$56  $159.99
Questions 1

You have created a TGW route table to route traffic from your spoke VPC to the security VPC where two FortiGate devices are inspecting traffic. Your spoke VPC CIDR block is already propagated to the Transit Gateway (TGW) route table.

Which type of attachment should you use to advertise routes through BGP from the spoke VPC to the security VPC?

Options:

A.  

Connect attachment

B.  

VPC attachment

C.  

Route attachment

D.  

GRE attachment

Discussion 0
Questions 2

Refer to the exhibit.

You are configuring a second route table on a Transit Gateway to accommodate east-west traffic inspection between two VPCs_ However, you are getting an error during the transit gateway route table association With the Connect attachment.

Which action Should you take to fulfill your requirement?

Options:

A.  

Add both Associations and Propagations in the second TGW route table.

B.  

Delete the both Connect and Transport attachments from the first TGW route table

C.  

Add a static route in the Routes section

D.  

In the second route table: create a propagation with the Connect attachment.

Discussion 0
Questions 3

Refer to the exhibit

You deployed an HA active-passive FortiGate VM in Microsoft Azure.

Which two statements regarding this particular deployment are true? (Choose two.)

Options:

A.  

During the failover, the passive FortiGate issues API calls to Azure

B.  

Use the vdom-excepticn command to synchronize the configuration.

C.  

There is no SLA for API calls from Microsoft Azure.

D.  

By default, the configuration does not synchromze between the primary and secondary devices.

Discussion 0
Questions 4

Refer to Exhibit:

You are troubleshooting a Microsoft Azure SDN connector issue on your FortiGate VM in Azure

Which three settings should you check while troubleshooting this problem? (Choose three.)

Options:

A.  

Use the show vdom command to see hidden VDOMs.

B.  

use the diag sys va command.

C.  

Ensure FortiGate port4 can resolve DNS.

D.  

Ensure FortiGate portl has internet access

E.  

Ensure IP address 169.254.169_254 is not blocked

Discussion 0
Questions 5

A customer would like to use FortiGate fabric integration With FortiCNP

When configuring a FortiGate VM to add to FortiCNP, which three mandatory configuration steps must you follow on FortiGate? (Choose three.)

Options:

A.  

Enable send logs-

B.  

Create and IPS sensor and a firewall policy

C.  

Create an IPsec tunnel.

D.  

Create an SSL]SSH inspection profile.

E.  

Enable two-factor authentication.

Discussion 0
Questions 6

Refer to the exhibit

The exhibit shows a customer deployment of two Linux instances and their main routing table in Amazon Web Services (AWS). The customer also created a Transit Gateway (TGW) and two attachments

Which two steps are required to route traffic from Linux instances to the TGWQ (Choose two.)

Options:

A.  

In the TGW route table, add route propagation to 192.168.0 0/16

B.  

In the main subnet routing table in VPC A and B, add a new route with destination 0_0.0.0/0, next hop Internet gateway(IGW).

C.  

In the TGW route table, associate two attachments.

D.  

In the main subnet routing table in VPC A and B, add a new route with destination 0_0.0.0/0, next hop TGW.

Discussion 0
Questions 7

Refer to Exhibit:

After the initial Terraform configuration in Microsoft Azure, the terraform plan command is run Which two statements about running the plan command are true? (Choose two.)

Options:

A.  

The terraform plan command will deploy the rest of the resources except the service principle details.

B.  

You cannot run the terraform apply command before the terraform plan command.

C.  

You must run the terraform init command once, before the terraform plan command

D.  

The terraform plan command makes terraform do a dry run.

Discussion 0
Questions 8

Refer to the exhibit

A customer has deployed an environment in Amazon Web Services (AWS) and is now trying to send outbound traffic from the Linux1 and Linux2 instances to the internet through the security VPC (virtual private cloud). The FortiGate policies are configured to allow all outbound

traffic; however, the traffic is not reaching the FortiGate internal interface. Assume there are no issues with the Transit Gateway (TGW) configuration

Which two settings must the customer add to correct the issue? (Choose two.)

Options:

A.  

Both landing subnets in the spoke VPCs must have a 0.0.0.0/0 traffic route to the Internet Gateway (IOW).

B.  

Both landing subnets in the spoke VPCs must have a 0.0 00/0 traffic route to the TGW

C.  

Both landing subnets in the security VPC must have a 0.0.0.0/0 traffic route to the FortiGate port2.

D.  

The four landing subnets in all the VPCs must have a 0.0 0 0/0 traffic route to the TGW

Discussion 0
Questions 9

Refer to the exhibit

An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform However, during the configuration, the Azure client secret is no longer visible in the Azure portal.

How would the administrator obtain the Azure

client secret to configure on Terratorm?

Options:

A.  

The administrator must create a new Azure account

B.  

Log in to the Azure CLI with power user to obtain the client secret

C.  

The administrator can create a new client secret

D.  

The administrator must obtain the client secret through Azure Cloud Shell.

Discussion 0
Questions 10

When adding the Amazon Web Services (AWS) account to the FortiCNP, which three mandatory configuration steps must you follow? (Choose three.)

Options:

A.  

Add AWS accounts through FortiCNP.

B.  

Enable cloud protection through AWS Guard Duty and AWS Inspector

C.  

Accept FortiCNP to create CloudTrail for the account

D.  

Enable cross-reg Ion aggregation

E.  

Launch the CloudFormation template.

Discussion 0
Questions 11

Refer to the exhibit

The exhibit shows the results of a FortiCNP registry scan

Which two statements are correct? (Choose two )

Options:

A.  

When adding a repository, you can leave the Tag section blank to scan all images-

B.  

The registry scan is part of the FortiCNP cloud protection.

C.  

The registry scan is part of the FortiCNP container protection.

D.  

When adding a repository, you can add a minimum number of images to be imported through the CAP section.

Discussion 0