Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Question and Answers

Fortinet NSE 7 Public Cloud Security 7.2 (FCSS)

Last Update Oct 4, 2025
Total Questions : 59

We are offering FREE NSE7_PBC-7.2 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE7_PBC-7.2 free exam questions and then go for complete pool of Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) test questions that will help you more.

NSE7_PBC-7.2 pdf

NSE7_PBC-7.2 PDF

$36.75  $104.99
NSE7_PBC-7.2 Engine

NSE7_PBC-7.2 Testing Engine

$43.75  $124.99
NSE7_PBC-7.2 PDF + Engine

NSE7_PBC-7.2 PDF + Testing Engine

$57.75  $164.99
Questions 1

Refer to the exhibit.

An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer However, the connection is not successful and at the same time FortiGate is not receiving any HTTPS or SSH traffic to its external interface

What should the administrator check for possible issue?

Options:

A.  

Run a debug flow to check any network ACLs

B.  

Check the FortiGate firewall policies

C.  

Check the FortiGate instance ID

D.  

Check the inbound network security group rules

Discussion 0
Questions 2

Refer to the exhibit.

What would be the impact of confirming to delete all the resources in Terraform?

Options:

A.  

It destroys all the resources in the . tfvars file

B.  

It destroys all the resources tied to the AWS Identity and Access Management (1AM) user.

C.  

It destroys all the resources in the resource group

D.  

It destroys all the resources in the state file.

Discussion 0
Questions 3

You are using Red Hat Ansible to change the FortiGate VM configuration.

What is the minimum number of files you must create and which file must you use to configure the target FortiGate IP address?

Options:

A.  

Create two files and use the .yami file.

B.  

Create two files and use the hosts file

C.  

Create one file and use the variable file

D.  

Create three files and use the .yaml file.

Discussion 0
Questions 4

You are adding more spoke VPCs to an existing hub and spoke topology Your goal is to finish this task in the minimum amount of time without making errors.

Which Amazon AWS services must you subscribe to accomplish your goal?

Options:

A.  

GuardDuty, CloudWatch

B.  

WAF, DynamoDB

C.  

Inspector, S3

D.  

CloudWatch, S3

Discussion 0
Questions 5

You are automating configuration changes on one of the FortiGate VMS using Linux Red Hat Ansible.

How does Linux Red Hat Ansible connect to FortiGate to make the configuration change?

Options:

A.  

It uses a FortiGate internal or external IP address with TCP port 21

B.  

It uses SSH as a connection method to FortiOS.

C.  

It uses an API.

D.  

It uses YAML

Discussion 0
Questions 6

Refer to Exhibit:

You are troubleshooting a Microsoft Azure SDN connector issue on your FortiGate VM in Azure

Which three settings should you check while troubleshooting this problem? (Choose three.)

Options:

A.  

Use the show vdom command to see hidden VDOMs.

B.  

use the diag sys va command.

C.  

Ensure FortiGate port4 can resolve DNS.

D.  

Ensure FortiGate portl has internet access

E.  

Ensure IP address 169.254.169_254 is not blocked

Discussion 0
Questions 7

Refer to the exhibit

In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet However, your HTTPS connection to the FortiGate VM in the Customer VPC is not successful.

Also, you must ensure that the Customer VPC FortiGate VM sends all the outbound Internet traffic through the Security VPC How do you correct this Issue with minimal configuration changes?

(Choose three.)

Options:

A.  

Add a route With your local internet public IP address as the destination and target transit gateway

B.  

Add route destination 0 0.0 0/0 to target the transit gateway

C.  

Add a route With your local internet public IP address as the destination and target internet gateway

D.  

Deploy an internet gateway, associate an EIP in the private subnet, edit route tables, and add a new route destination 0.0.0.0/0 to the target internet gateway

E.  

Deploy an internet gateway, associate an EIP in the public subnet, and attach the internet gateway to the Customer VPC,

Discussion 0
Questions 8

How does the immutable infrastructure strategy work in automation?

Options:

A.  

It runs a single live environment for configuration changes.

B.  

It runs one idle and a single live environment for configuration changes.

C.  

It runs two live environments for configuration changes.

D.  

It runs one idle and two live environments for configuration changes.

Discussion 0
Questions 9

Which two statements are true about Transit Gateway Connect peers in anlPv4 BGP configuration'? (Choose two.)

Options:

A.  

The inside CIDR blocks are used for BGP peering

B.  

You cannot use IPv6 addresses

C.  

You must specify a /29CIDR block from the 169.254.0.0/16 range

D.  

You must configure the second address from the IPv4 range on the device as the BGP IP address

Discussion 0
Questions 10

Refer to the exhibit

An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform However, during the configuration, the Azure client secret is no longer visible in the Azure portal.

How would the administrator obtain the Azure

client secret to configure on Terratorm?

Options:

A.  

The administrator must create a new Azure account

B.  

Log in to the Azure CLI with power user to obtain the client secret

C.  

The administrator can create a new client secret

D.  

The administrator must obtain the client secret through Azure Cloud Shell.

Discussion 0
Questions 11

An administrator would like to keep track of sensitive data files located in the Amazon Web Services (AWS) S3 bucket and protect it from malware. Which Fortinet product or feature should the administrator use?

Options:

A.  

FortiCNP application control policies

B.  

FortiCNP web sensitive polices

C.  

FortiCNP DLP policies

D.  

FortiCNP compliance scanning policies

Discussion 0
Questions 12

A Network security administrator is searching for a solution to secure traffic going in and out of the container infrastructure.

In which two ways can Fortinet container security help secure container infrastructure? (Choose two.)

Options:

A.  

FortiGate NGFW can be placed between each application container for north-south traffic inspection

B.  

FortiGate NGFW can connect to the worker node and protects the container-

C.  

FortiGate NGFW can inspect north-south container traffic with label aware policies

D.  

FortiGate NGFW and FortiSandbox can be used to secure container traffic

Discussion 0
Questions 13

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.

What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)

Options:

A.  

ExpressRoute

B.  

GRE tunnels

C.  

SSL VPN connections

D.  

An L2TP connection

E.  

VPN Gateway

Discussion 0
Questions 14

Refer to the exhibit

An administrator deployed an HA active-active load balance sandwich in Microsoft Azure. The setup requires configuration synchronization between devices-

What are two outcomes from the configured settings? (Choose two.)

Options:

A.  

FortiGate-VM instances are scaled out automatically according to predefined workload levels.

B.  

FortiGate A and FortiGate B are two independent devices.

C.  

By default, FortiGate uses FGCP

D.  

It does not synchronize the FortiGate hostname

Discussion 0
Questions 15

Refer to the exhibit

You are tasked to deploy a FortiGate VM with private and public subnets in Amazon Web Services (AWS).

You examined the variables.tf file.

What will be the final result after running the terraform init and terraform apply commands?

Options:

A.  

Terraform will not deploy a FortiGate VM

B.  

Terraform will deploy a FortiGate VM in the eu-West-Ia region with private and public subnets.

C.  

Terraform will deploy a FortiGate VM in the eu-West-1a region with two subnets and byol license.

D.  

Terraform will deploy a FortiGate VM in the eu-West-Ia region without any subnets.

Discussion 0
Questions 16

What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

Options:

A.  

It eliminates the use of ECMP

B.  

You can use GRE-based tunnel attachments

C.  

You can combine it with IPsec to achieve higher bandwidth

D.  

You can use BGP over IPsec for maximum throughput

Discussion 0
Questions 17

What are three important steps required to get Terraform ready using Microsoft Azure Cloud Shell? (Choose three.)

Options:

A.  

Set up a storage account in Azure.

B.  

use the -O command to download Terraform.

C.  

Subscribe to Terraform in Azure.

D.  

Move the Terraform file to the bin directory.

E.  

Use the wget (te=aform vession) command to upload Terraform.

Discussion 0