Labour Day Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet NSE7_PBC-7.2 Fortinet NSE 7 - Public Cloud Security 7.2 Exam Practice Test

Demo: 17 questions
Total 59 questions

Fortinet NSE 7 - Public Cloud Security 7.2 Questions and Answers

Question 1

You must allow an SSH traffic rule in an Amazon Web Services (AWS) network access list (NACL) to allow SSH traffic to travel to a subnet for temporary testing purposes. When you review the current inbound network ACL rules, you notice that rule number 5 demes SSH and telnet traffic to the subnet

What can you do to allow SSH traffic?

Options:

A.

You must create a new allow SSH rule below rule number 5

B.

You must create a new allow SSH rule above rule number 5-

C.

You must create a new allow SSH rule anywhere in the network ACL rule base to allow SSH traffic.

D.

You do not have to create any NACL rules because the default security group rule automatically allows SSH traffic to the subnet.

Question 2

Which two statements are true about Transit Gateway Connect peers in anlPv4 BGP configuration'? (Choose two.)

Options:

A.

The inside CIDR blocks are used for BGP peering

B.

You cannot use IPv6 addresses

C.

You must specify a /29CIDR block from the 169.254.0.0/16 range

D.

You must configure the second address from the IPv4 range on the device as the BGP IP address

Question 3

Refer to the exhibit.

What would be the impact of confirming to delete all the resources in Terraform?

Options:

A.

It destroys all the resources in the . tfvars file

B.

It destroys all the resources tied to the AWS Identity and Access Management (1AM) user.

C.

It destroys all the resources in the resource group

D.

It destroys all the resources in the state file.

Question 4

Which two attachments are necessary to connect a transit gateway to an existing VPC with BGP? (Choose two )

Options:

A.

A transport attachment

B.

A BGP attachment

C.

A connect attachment

D.

A GRE attachment

Question 5

A customer would like to use FortiGate fabric integration With FortiCNP

When configuring a FortiGate VM to add to FortiCNP, which three mandatory configuration steps must you follow on FortiGate? (Choose three.)

Options:

A.

Enable send logs-

B.

Create and IPS sensor and a firewall policy

C.

Create an IPsec tunnel.

D.

Create an SSL]SSH inspection profile.

E.

Enable two-factor authentication.

Question 6

Refer to the exhibit

The exhibit shows the results of a FortiCNP registry scan

Which two statements are correct? (Choose two )

Options:

A.

When adding a repository, you can leave the Tag section blank to scan all images-

B.

The registry scan is part of the FortiCNP cloud protection.

C.

The registry scan is part of the FortiCNP container protection.

D.

When adding a repository, you can add a minimum number of images to be imported through the CAP section.

Question 7

Which two Amazon Web Services (AWS) features do you use for the transit virtual private cloud (VPC) automation process to add new spoke N/PCs? (Choose two )

Options:

A.

Amazon S3 bucket

B.

AWS Security Hub

C.

AWS Transit Gateway

D.

Amazon CloudWatch

Question 8

You are configuring the failover settings on a FortiGate active-passive SDN connector solution in Microsoft Azure. Which two mandatory settings are required after the initial deployment? (Choose two)

Options:

A.

Subscription-id

B.

FortiGate license file

C.

Active FortiGate serial number

D.

Resource group name

Question 9

How does an administrator secure container environments from newly emerged security threats?

Options:

A.

Use distributed network-related application control signatures.

B.

Use Amazon AWS-related application control signatures

C.

Use Amazon AWS_S3-related application control signatures

D.

Use Docker-related application control signatures

Question 10

How does Terraform keep track of provisioned resources?

Options:

A.

It uses the terraform. tf state file

B.

Terraform does not keep the state of resources created

C.

It uses the terraform. tfvars file.

D.

It uses the database. tf file.

Question 11

Refer to the exhibit

You deployed an HA active-passive FortiGate VM in Microsoft Azure.

Which two statements regarding this particular deployment are true? (Choose two.)

Options:

A.

During the failover, the passive FortiGate issues API calls to Azure

B.

Use the vdom-excepticn command to synchronize the configuration.

C.

There is no SLA for API calls from Microsoft Azure.

D.

By default, the configuration does not synchromze between the primary and secondary devices.

Question 12

You have created a TGW route table to route traffic from your spoke VPC to the security VPC where two FortiGate devices are inspecting traffic. Your spoke VPC CIDR block is already propagated to the Transit Gateway (TGW) route table.

Which type of attachment should you use to advertise routes through BGP from the spoke VPC to the security VPC?

Options:

A.

Connect attachment

B.

VPC attachment

C.

Route attachment

D.

GRE attachment

Question 13

You are adding a new spoke to the existing transit VPC environment using the AWS Cloud Formation template. Which two components must you use for this deployment? (Choose two.)

Options:

A.

The OSPF AS value used for the hub.

B.

The Amazon CloudWatch tag value.

C.

The BGPASN value used for the transit VPC.

D.

The tag value of the spoke

Question 14

Refer to the exhibit

You are tasked to deploy a FortiGate VM with private and public subnets in Amazon Web Services (AWS).

You examined the variables.tf file.

What will be the final result after running the terraform init and terraform apply commands?

Options:

A.

Terraform will not deploy a FortiGate VM

B.

Terraform will deploy a FortiGate VM in the eu-West-Ia region with private and public subnets.

C.

Terraform will deploy a FortiGate VM in the eu-West-1a region with two subnets and byol license.

D.

Terraform will deploy a FortiGate VM in the eu-West-Ia region without any subnets.

Question 15

Refer to the exhibit.

What value or values must the administrator use in the SSH Key section to deploy a FortiGate VM using Terraform in Amazon Web Services (AWS)?

Options:

A.

Use the Name and ID values of the key pair

B.

Use the Name of the key pair

C.

Use the ID value of the key pair.

D.

Use the Fingerprint value of the key pair

Question 16

How does the immutable infrastructure strategy work in automation?

Options:

A.

It runs a single live environment for configuration changes.

B.

It runs one idle and a single live environment for configuration changes.

C.

It runs two live environments for configuration changes.

D.

It runs one idle and two live environments for configuration changes.

Question 17

Refer to the exhibit

The exhibit shows a customer deployment of two Linux instances and their main routing table in Amazon Web Services (AWS). The customer also created a Transit Gateway (TGW) and two attachments

Which two steps are required to route traffic from Linux instances to the TGWQ (Choose two.)

Options:

A.

In the TGW route table, add route propagation to 192.168.0 0/16

B.

In the main subnet routing table in VPC A and B, add a new route with destination 0_0.0.0/0, next hop Internet gateway(IGW).

C.

In the TGW route table, associate two attachments.

D.

In the main subnet routing table in VPC A and B, add a new route with destination 0_0.0.0/0, next hop TGW.

Demo: 17 questions
Total 59 questions