Weekend Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpm65

NSE7_PBC-7.2 Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Questions and Answers

Questions 4

You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications reside, with minimum traffic cost

Which solution meets the requirements?

Options:

A.

Use FortiADC

B.

Use FortiCNP

C.

Use FortiWebCloud

D.

Use FortiGate

Buy Now
Questions 5

Refer to the exhibit.

NSE7_PBC-7.2 Question 5

You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary

device does not have the previous primary device floating IP

address.

What could be the possible issue With this scenario?

Options:

A.

FortiGate port4 does not have internet access.

B.

A wrong client secret credential is used

C.

The error is caused by credential time expiration.

D.

The Azure service principle account must have a contributor role.

Buy Now
Questions 6

A Network security administrator is searching for a solution to secure traffic going in and out of the container infrastructure.

In which two ways can Fortinet container security help secure container infrastructure?(Choose two.)

Options:

A.

FortiGate NGFW can be placed between each application container for north-south traffic inspection

B.

FortiGate NGFW can connect to the worker node and protects the container-

C.

FortiGate NGFW can inspect north-south container traffic with label aware policies

D.

FortiGate NGFW and FortiSandbox can be used to secure container traffic

Buy Now
Questions 7

How does an administrator secure container environments from newly emerged security threats?

Options:

A.

Use distributed network-related application control signatures.

B.

Use Amazon AWS-related application control signatures

C.

Use Amazon AWS_S3-related application control signatures

D.

Use Docker-related application control signatures

Buy Now
Questions 8

Refer to the exhibit

NSE7_PBC-7.2 Question 8

You are tasked with deploying a webserver and FortiGate VMS in AWS_ You are using Terraform to automate the process

Which two important details should you know about the Terraform files? (Choose two.)

Options:

A.

All the output values are available after a successful terraform apply command

B.

The subnet_private 1 value is defined in the variables . tf file

C.

After the deployment, Terraform output values are visible only through AWS CloudShell.

D.

You must specify all the AWS credentials in the output. of file.

Buy Now
Questions 9

What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

Options:

A.

It eliminates the use of ECMP

B.

You can use GRE-based tunnel attachments

C.

You can combine it with IPsec to achieve higher bandwidth

D.

You can use BGP over IPsec for maximum throughput

Buy Now
Questions 10

Refer to the exhibit.

NSE7_PBC-7.2 Question 10

NSE7_PBC-7.2 Question 10

What value or values must the administrator use in the SSH Key section to deploy a FortiGate VM using Terraform in Amazon Web Services (AWS)?

Options:

A.

Use the Name and ID values of the key pair

B.

Use the Name of the key pair

C.

Use the ID value of the key pair.

D.

Use the Fingerprint value of the key pair

Buy Now
Questions 11

You have created a TGW route table to route traffic from your spoke VPC to the security VPC where two FortiGate devices are inspecting traffic. Your spoke VPC CIDR block is already propagated to the Transit Gateway (TGW) route table.

Which type of attachment should you use to advertise routes through BGP from the spoke VPC to the security VPC?

Options:

A.

Connect attachment

B.

VPC attachment

C.

Route attachment

D.

GRE attachment

Buy Now
Questions 12

What are three important steps required to get Terraform ready using Microsoft Azure Cloud Shell? (Choose three.)

Options:

A.

Set up a storage account in Azure.

B.

use the -O command to download Terraform.

C.

Subscribe to Terraform in Azure.

D.

Move the Terraform file to the bin directory.

E.

Use the wget (te=aform vession) command to upload Terraform.

Buy Now
Questions 13

A customer would like to use FortiGate fabric integration With FortiCNP

When configuring a FortiGate VM to add to FortiCNP, which three mandatory configuration steps must you follow on FortiGate? (Choose three.)

Options:

A.

Enable send logs-

B.

Create and IPS sensor and a firewall policy

C.

Create an IPsec tunnel.

D.

Create an SSL]SSH inspection profile.

E.

Enable two-factor authentication.

Buy Now
Questions 14

Refer to the exhibit

NSE7_PBC-7.2 Question 14

In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet However, your HTTPS connection to the FortiGate VM in the Customer VPC is not successful.

Also, you must ensure that the Customer VPC FortiGate VM sends all the outbound Internet traffic through the Security VPC How do you correct this Issue with minimal configuration changes?

(Choose three.)

Options:

A.

Add a route With your local internet public IP address as thedestination and target transit gateway

B.

Add route destination 0 0.0 0/0 to target the transit gateway

C.

Add a route With your local internet public IP address as the destination and target internet gateway

D.

Deploy an internet gateway, associate an EIP in the private subnet, edit route tables, and add a new route destination0.0.0.0/0 to the target internet gateway

E.

Deploy an internet gateway, associate an EIP in the public subnet, and attach the internet gateway to the Customer VPC,

Buy Now
Questions 15

You are troubleshooting an Azure SDN connectivity issue with your FortiGate VM

Which two queries does that SDN connector use to interact with the Azure management API? (Choose two.)

Options:

A.

The first query is targeted to a special IP address to get a token.

B.

The first query is targeted to IP address 8.8

C.

There is only one query initiating from FortiGate port1 -

D.

Some queries are made to manage public IP addresses.

Buy Now
Questions 16

Which statement about immutable infrastructure in automation is true?

Options:

A.

It is the practice of deploying a new server for every configuration change

B.

It is the practice of modifying the existing server configuration after it is deployed

C.

It is the practice of deploying two parallel servers for high availability.

D.

It is the practice of applying hotfixes and OS patches after deployment

Buy Now
Questions 17

You must allow an SSH traffic rule in an Amazon Web Services (AWS) network access list (NACL) to allow SSH traffic to travel to a subnet for temporary testing purposes. When you review the current inbound network ACL rules, you notice that rule number 5 demes SSH and telnet traffic to the subnet

What can you do to allow SSH traffic?

Options:

A.

You must create a new allow SSH rule below rule number 5

B.

You must create a new allow SSH rule above rule number 5-

C.

You must create a new allow SSH rule anywhere in the network ACL rule base to allow SSH traffic.

D.

You do not have to create any NACL rules because the default security group rule automatically allows SSH traffic to the subnet.

Buy Now
Exam Code: NSE7_PBC-7.2
Exam Name: Fortinet NSE 7 Public Cloud Security 7.2 (FCSS)
Last Update: May 13, 2024
Questions: 59

PDF + Testing Engine

$56  $159.99

Testing Engine

$42  $119.99
buy now NSE7_PBC-7.2 testing engine

PDF (Q&A)

$35  $99.99
buy now NSE7_PBC-7.2 pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 15 May 2024