Month End Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

NSE7_PBC-7.2 Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Free Practice Exam Questions (2025 Updated)

Prepare effectively for your Fortinet NSE7_PBC-7.2 Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2025, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 1 / 1
Total 59 questions

You are asked to find a solution to replace the existing VPC peering topology to have a higher bandwidth connection from Amazon Web Services (AWS) to the on-premises data center Which two solutions will satisfy the requirement? (Choose two.)

A.

Use ECMP and VPN to achieve higher bandwidth.

B.

Use transit VPC to build multiple VPC connections to the on-premises data center

C.

Use a transit VPC with hub and spoke topology to create multiple VPN connections to the on-premises data center.

D.

Use the transit gateway attachment With VPN option to create multiple VPN connections to the on-premises data center

You have created a TGW route table to route traffic from your spoke VPC to the security VPC where two FortiGate devices are inspecting traffic. Your spoke VPC CIDR block is already propagated to the Transit Gateway (TGW) route table.

Which type of attachment should you use to advertise routes through BGP from the spoke VPC to the security VPC?

A.

Connect attachment

B.

VPC attachment

C.

Route attachment

D.

GRE attachment

Refer to the exhibit.

An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer However, the connection is not successful and at the same time FortiGate is not receiving any HTTPS or SSH traffic to its external interface

What should the administrator check for possible issue?

A.

Run a debug flow to check any network ACLs

B.

Check the FortiGate firewall policies

C.

Check the FortiGate instance ID

D.

Check the inbound network security group rules

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.

What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)

A.

ExpressRoute

B.

GRE tunnels

C.

SSL VPN connections

D.

An L2TP connection

E.

VPN Gateway

Refer to the exhibit

An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform However, during the configuration, the Azure client secret is no longer visible in the Azure portal.

How would the administrator obtain the Azure

client secret to configure on Terratorm?

A.

The administrator must create a new Azure account

B.

Log in to the Azure CLI with power user to obtain the client secret

C.

The administrator can create a new client secret

D.

The administrator must obtain the client secret through Azure Cloud Shell.

How does the immutable infrastructure strategy work in automation?

A.

It runs a single live environment for configuration changes.

B.

It runs one idle and a single live environment for configuration changes.

C.

It runs two live environments for configuration changes.

D.

It runs one idle and two live environments for configuration changes.

What are two main features in Amazon Web Services (AWS) network access control lists (ACLs)? (Choose two.)

A.

You cannot use Network ACL and Security Group at the same time.

B.

The default network ACL is configured to allow all traffic

C.

NetworkACLs are stateless, and inbound and outbound rules are used for traffic filtering

D.

Network ACLs are tied to an instance

Which two Amazon Web Services (AWS) features support east-west traffic inspection within the AWS cloud by the FortiGate VM? (Choose two.)

A.

A NAT gateway with an EIP

B.

A transit gateway with an attachment

C.

An Internet gateway with an EIP

D.

A transit VPC

Refer to the exhibit

An administrator deployed a FortiGate-VM in a high availability (HA)

(active/passive) architecture in Amazon Web Services (AWS) using Terraform

for testing purposes. At the same time, the administrator deployed a single

Linux server using AWS Marketplace

Which two options are available for the administrator to delete all the resources

created in this test? (Choose two.)

A.

Use the terraform destroy command

B.

Use the terraform validate command.

C.

Use the terraform destroy all command.

D.

The administrator must manually delete the Linux server.

You are adding more spoke VPCs to an existing hub and spoke topology Your goal is to finish this task in the minimum amount of time without making errors.

Which Amazon AWS services must you subscribe to accomplish your goal?

A.

GuardDuty, CloudWatch

B.

WAF, DynamoDB

C.

Inspector, S3

D.

CloudWatch, S3

You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications reside, with minimum traffic cost

Which solution meets the requirements?

A.

Use FortiADC

B.

Use FortiCNP

C.

Use FortiWebCloud

D.

Use FortiGate

Refer to the exhibit.

What value or values must the administrator use in the SSH Key section to deploy a FortiGate VM using Terraform in Amazon Web Services (AWS)?

A.

Use the Name and ID values of the key pair

B.

Use the Name of the key pair

C.

Use the ID value of the key pair.

D.

Use the Fingerprint value of the key pair

Refer to the exhibit

An administrator deployed an HA active-active load balance sandwich in Microsoft Azure. The setup requires configuration synchronization between devices-

What are two outcomes from the configured settings? (Choose two.)

A.

FortiGate-VM instances are scaled out automatically according to predefined workload levels.

B.

FortiGate A and FortiGate B are two independent devices.

C.

By default, FortiGate uses FGCP

D.

It does not synchronize the FortiGate hostname

Refer to the exhibit

You deployed an HA active-passive FortiGate VM in Microsoft Azure.

Which two statements regarding this particular deployment are true? (Choose two.)

A.

During the failover, the passive FortiGate issues API calls to Azure

B.

Use the vdom-excepticn command to synchronize the configuration.

C.

There is no SLA for API calls from Microsoft Azure.

D.

By default, the configuration does not synchromze between the primary and secondary devices.

When adding the Amazon Web Services (AWS) account to the FortiCNP, which three mandatory configuration steps must you follow? (Choose three.)

A.

Add AWS accounts through FortiCNP.

B.

Enable cloud protection through AWS Guard Duty and AWS Inspector

C.

Accept FortiCNP to create CloudTrail for the account

D.

Enable cross-reg Ion aggregation

E.

Launch the CloudFormation template.

Refer to the exhibit

You are deploying two FortiGate VMS in HA active-passive mode with load balancers in Microsoft Azure

Which two statements are true in this load balancing scenario? (Choose two.)

A.

The FortiGate public IP is the next-hop for all the traffic.

B.

An internal load balancer listener is the next-hop for outgoing traffic.

C.

You must add a route to the Microsoft VIP used for the health check.

D.

A dedicated management interface can be used for load balancing.

An administrator would like to keep track of sensitive data files located in the Amazon Web Services (AWS) S3 bucket and protect it from malware. Which Fortinet product or feature should the administrator use?

A.

FortiCNP application control policies

B.

FortiCNP web sensitive polices

C.

FortiCNP DLP policies

D.

FortiCNP compliance scanning policies

Page: 1 / 1
Total 59 questions
Copyright © 2014-2025 Solution2Pass. All Rights Reserved