Winter Special Flat 65% Limited Time Discount offer - Ends in 0d 00h 00m 00s - Coupon code: suredis

Fortinet NSE7_PBC-7.2 Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Exam Practice Test

Demo: 17 questions
Total 59 questions

Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Questions and Answers

Question 1

An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure However, the SDN connector is failing on the connection What must the administrator do to correct this issue?

Options:

A.

Make sure to add the Tenant ID on FortiGate side of the configuration

B.

Make sure to set the type to system managed identity on FortiGate SDN connector settings

C.

Make sure to enable the system assigned managed identity on Azure

D.

Make sure to add the Client secret on FortiGate side of the configuration

Question 2

How does an administrator secure container environments from newly emerged security threats?

Options:

A.

Use distributed network-related application control signatures.

B.

Use Amazon AWS-related application control signatures

C.

Use Amazon AWS_S3-related application control signatures

D.

Use Docker-related application control signatures

Question 3

Refer to the exhibit.

What value or values must the administrator use in the SSH Key section to deploy a FortiGate VM using Terraform in Amazon Web Services (AWS)?

Options:

A.

Use the Name and ID values of the key pair

B.

Use the Name of the key pair

C.

Use the ID value of the key pair.

D.

Use the Fingerprint value of the key pair

Question 4

How does the immutable infrastructure strategy work in automation?

Options:

A.

It runs a single live environment for configuration changes.

B.

It runs one idle and a single live environment for configuration changes.

C.

It runs two live environments for configuration changes.

D.

It runs one idle and two live environments for configuration changes.

Question 5

Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?

Options:

A.

TGW can have multiple TGW route tables.

B.

Both the TGW attachment and propagation must be in the same TGW route table

C.

A TGW attachment can be associated with multiple TGW route tables.

D.

The TGW default route table cannot be disabled.

Question 6

Refer to the exhibit

You are deploying two FortiGate VMS in HA active-passive mode with load balancers in Microsoft Azure

Which two statements are true in this load balancing scenario? (Choose two.)

Options:

A.

The FortiGate public IP is the next-hop for all the traffic.

B.

An internal load balancer listener is the next-hop for outgoing traffic.

C.

You must add a route to the Microsoft VIP used for the health check.

D.

A dedicated management interface can be used for load balancing.

Question 7

Your goal is to deploy resources in multiple places and regions in the public cloud using Terraform.

What is the most efficient way to deploy resources without changing much of the Terraform code?

Options:

A.

Use multiple terraform.tfvars files With a variables.tf file.

B.

Use the provider. tf file to add all the new values

C.

Install and configure two Terraform staging servers to deploy resources.

D.

Use the variable, tf file and edit its values to match multiple resources

Question 8

An administrator is looking for a solution that can provide insight into users and data stored in major SaaS applications in the multicloud environment Which product should the administrator deploy to have secure access to SaaS applications?

Options:

A.

FortiProxy

B.

FortiSandbox

C.

ForliCASB

D.

FortiWeb

Question 9

Refer to the exhibit

You are tasked with deploying FortiGate using Terraform. When you run the terraform version command during the Terraform installation, you get an error message.

What could be the reason that you are getting the command not found error?

Options:

A.

You must move the binary file to the bin directory.

B.

You must change the directory location to the root directory

C.

You must assign correct permissions to the ec2-user.

D.

You must reinstall Terraform

Question 10

Which two attachments are necessary to connect a transit gateway to an existing VPC with BGP? (Choose two )

Options:

A.

A transport attachment

B.

A BGP attachment

C.

A connect attachment

D.

A GRE attachment

Question 11

You are tasked with deploying a FortiGate HA solution in Amazon Web Services (AWS) using Terraform What are two steps you must take to complete this deployment? (Choose two.)

Options:

A.

Enable automation on the AWS portal.

B.

Create an AWS Identity and Access Management (IAM) user With permissions.

C.

Use CloudSheIl to install Terraform.

D.

Create an AWS Active Directory user with permissions.

Question 12

You are asked to find a solution to replace the existing VPC peering topology to have a higher bandwidth connection from Amazon Web Services (AWS) to the on-premises data center Which two solutions will satisfy the requirement? (Choose two.)

Options:

A.

Use ECMP and VPN to achieve higher bandwidth.

B.

Use transit VPC to build multiple VPC connections to the on-premises data center

C.

Use a transit VPC with hub and spoke topology to create multiple VPN connections to the on-premises data center.

D.

Use the transit gateway attachment With VPN option to create multiple VPN connections to the on-premises data center

Question 13

Which two Amazon Web Services (AWS) features do you use for the transit virtual private cloud (VPC) automation process to add new spoke N/PCs? (Choose two )

Options:

A.

Amazon S3 bucket

B.

AWS Security Hub

C.

AWS Transit Gateway

D.

Amazon CloudWatch

Question 14

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.

What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)

Options:

A.

ExpressRoute

B.

GRE tunnels

C.

SSL VPN connections

D.

An L2TP connection

E.

VPN Gateway

Question 15

Refer to the exhibit

A customer has deployed an environment in Amazon Web Services (AWS) and is now trying to send outbound traffic from the Linux1 and Linux2 instances to the internet through the security VPC (virtual private cloud). The FortiGate policies are configured to allow all outbound

traffic; however, the traffic is not reaching the FortiGate internal interface. Assume there are no issues with the Transit Gateway (TGW) configuration

Which two settings must the customer add to correct the issue? (Choose two.)

Options:

A.

Both landing subnets in the spoke VPCs must have a 0.0.0.0/0 traffic route to the Internet Gateway (IOW).

B.

Both landing subnets in the spoke VPCs must have a 0.0 00/0 traffic route to the TGW

C.

Both landing subnets in the security VPC must have a 0.0.0.0/0 traffic route to the FortiGate port2.

D.

The four landing subnets in all the VPCs must have a 0.0 0 0/0 traffic route to the TGW

Question 16

You are adding a new spoke to the existing transit VPC environment using the AWS Cloud Formation template. Which two components must you use for this deployment? (Choose two.)

Options:

A.

The OSPF AS value used for the hub.

B.

The Amazon CloudWatch tag value.

C.

The BGPASN value used for the transit VPC.

D.

The tag value of the spoke

Question 17

Which two statements are true about Transit Gateway Connect peers in anlPv4 BGP configuration'? (Choose two.)

Options:

A.

The inside CIDR blocks are used for BGP peering

B.

You cannot use IPv6 addresses

C.

You must specify a /29CIDR block from the 169.254.0.0/16 range

D.

You must configure the second address from the IPv4 range on the device as the BGP IP address

Demo: 17 questions
Total 59 questions