Labour Day Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Fortinet NSE7_PBC-7.2 Dumps

Fortinet NSE 7 - Public Cloud Security 7.2 Questions and Answers

Question 1

You are configuring the failover settings on a FortiGate active-passive SDN connector solution in Microsoft Azure. Which two mandatory settings are required after the initial deployment? (Choose two)

Options:

A.

Subscription-id

B.

FortiGate license file

C.

Active FortiGate serial number

D.

Resource group name

Question 2

Refer to Exhibit:

You are troubleshooting a Microsoft Azure SDN connector issue on your FortiGate VM in Azure

Which three settings should you check while troubleshooting this problem? (Choose three.)

Options:

A.

Use the show vdom command to see hidden VDOMs.

B.

use the diag sys va command.

C.

Ensure FortiGate port4 can resolve DNS.

D.

Ensure FortiGate portl has internet access

E.

Ensure IP address 169.254.169_254 is not blocked

Question 3

You are adding a new spoke to the existing transit VPC environment using the AWS Cloud Formation template. Which two components must you use for this deployment? (Choose two.)

Options:

A.

The OSPF AS value used for the hub.

B.

The Amazon CloudWatch tag value.

C.

The BGPASN value used for the transit VPC.

D.

The tag value of the spoke

Question 4

Refer to the exhibit

In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet However, your HTTPS connection to the FortiGate VM in the Customer VPC is not successful.

Also, you must ensure that the Customer VPC FortiGate VM sends all the outbound Internet traffic through the Security VPC How do you correct this Issue with minimal configuration changes?

(Choose three.)

Options:

A.

Add a route With your local internet public IP address as thedestination and target transit gateway

B.

Add route destination 0 0.0 0/0 to target the transit gateway

C.

Add a route With your local internet public IP address as the destination and target internet gateway

D.

Deploy an internet gateway, associate an EIP in the private subnet, edit route tables, and add a new route destination0.0.0.0/0 to the target internet gateway

E.

Deploy an internet gateway, associate an EIP in the public subnet, and attach the internet gateway to the Customer VPC,

Question 5

Refer to the exhibit

The exhibit shows a customer deployment of two Linux instances and their main routing table in Amazon Web Services (AWS). The customer also created a Transit Gateway (TGW) and two attachments

Which two steps are required to route traffic from Linux instances to the TGWQ (Choose two.)

Options:

A.

In the TGW route table, add route propagation to 192.168.0 0/16

B.

In the main subnet routing table in VPC A and B, add a new route with destination 0_0.0.0/0, next hop Internet gateway(IGW).

C.

In the TGW route table, associate two attachments.

D.

In the main subnet routing table in VPC A and B, add a new route with destination 0_0.0.0/0, next hop TGW.

Question 6

Refer to the exhibit.

What could be the reason that the administrator cannot access the EC2 instance?

Options:

A.

You must elevate the permissions to access the EC2 instance

B.

You must run the chmod 400 Staging-key.peracommand before accessing the instance.

C.

There is no . pem key created on in Amazon Web Services (AWS)

D.

The directory location of the . pem file is incorrect.

Question 7

Refer to the exhibit

You are deploying two FortiGate VMS in HA active-passive mode with load balancers in Microsoft Azure

Which two statements are true in this load balancing scenario? (Choose two.)

Options:

A.

The FortiGate public IP is the next-hop for all the traffic.

B.

An internal load balancer listener is the next-hop for outgoing traffic.

C.

You must add a route to the Microsoft VIP used for the health check.

D.

A dedicated management interface can be used for load balancing.

Question 8

Refer to the exhibit.

An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer However, the connection is not successful and at the same time FortiGate is not receiving any HTTPS or SSH traffic to its external interface

What should the administrator check for possible issue?

Options:

A.

Run a debug flow to check any network ACLs

B.

Check the FortiGate firewall policies

C.

Check the FortiGate instance ID

D.

Check the inbound network security group rules

Question 9

Refer to the exhibit.

You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary

device does not have the previous primary device floating IP

address.

What could be the possible issue With this scenario?

Options:

A.

FortiGate port4 does not have internet access.

B.

A wrong client secret credential is used

C.

The error is caused by credential time expiration.

D.

The Azure service principle account must have a contributor role.

Question 10

Refer to the exhibit.

What value or values must the administrator use in the SSH Key section to deploy a FortiGate VM using Terraform in Amazon Web Services (AWS)?

Options:

A.

Use the Name and ID values of the key pair

B.

Use the Name of the key pair

C.

Use the ID value of the key pair.

D.

Use the Fingerprint value of the key pair

Question 11

An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure However, the SDN connector is failing on the connection What must the administrator do to correct this issue?

Options:

A.

Make sure to add the Tenant ID on FortiGate side of the configuration

B.

Make sure to set the type to system managed identity on FortiGate SDN connectorsettings

C.

Make sure to enable the system assigned managed identity on Azure

D.

Make sure to add the Client secret on FortiGate side of the configuration

Question 12

An administrator would like to keep track of sensitive data files located in the Amazon Web Services (AWS) S3 bucket and protect it from malware. Which Fortinet product or feature should the administrator use?

Options:

A.

FortiCNP application control policies

B.

FortiCNP web sensitive polices

C.

FortiCNP DLP policies

D.

FortiCNP compliance scanning policies

Question 13

You must allow an SSH traffic rule in an Amazon Web Services (AWS) network access list (NACL) to allow SSH traffic to travel to a subnet for temporary testing purposes. When you review the current inbound network ACL rules, you notice that rule number 5 demes SSH and telnet traffic to the subnet

What can you do to allow SSH traffic?

Options:

A.

You must create a new allow SSH rule below rule number 5

B.

You must create a new allow SSH rule above rule number 5-

C.

You must create a new allow SSH rule anywhere in the network ACL rule base to allow SSH traffic.

D.

You do not have to create any NACL rules because the default security group rule automatically allows SSH traffic to the subnet.

Question 14

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.

What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)

Options:

A.

ExpressRoute

B.

GRE tunnels

C.

SSL VPN connections

D.

An L2TP connection

E.

VPN Gateway

Question 15

Refer to the exhibit.

The exhibit shows an active-passive high availability FortiGate pair with external and internal Azure load balancers. There is no SDN connector used in this solution

Which configuration should the administrator implement?

Options:

A.

Lambda IP address with one static route.

B.

Probe IP address with two static routes

C.

Probe IP address with one BGP route

D.

Public load balancer IP address with two BGP routes.

Question 16

Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?

Options:

A.

TGW can have multiple TGW route tables.

B.

Both the TGW attachment and propagation must be in the same TGW route table

C.

A TGW attachment can be associated with multiple TGW route tables.

D.

The TGW default route table cannot be disabled.

Question 17

Refer to the exhibit

You attempted to access the Linux1 EC2 instance directly from the internet using its public IP address in AWS.

However, your connection is not successful.

Given the network topology, what can be the issue?

Options:

A.

There is no connection between VPC A and VPC B.

B.

There is no elastic IP address attached to FortiGate in the Security VPC.

C.

The Transit Gateway BGP IP address is incorrect.

D.

There is no internet gateway attached to the Spoke VPC A.