Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtreat

NSE7_PBC-7.2 Fortinet NSE 7 - Public Cloud Security 7.2 Questions and Answers

Questions 4

Your goal is to deploy resources in multiple places and regions in the public cloud using Terraform.

What is the most efficient way to deploy resources without changing much of the Terraform code?

Options:

A.

Use multiple terraform.tfvars files With a variables.tf file.

B.

Use the provider. tf file to add all the new values

C.

Install and configure two Terraform staging servers to deploy resources.

D.

Use the variable, tf file and edit its values to match multiple resources

Buy Now
Questions 5

Refer to the exhibit

You are deploying two FortiGate VMS in HA active-passive mode with load balancers in Microsoft Azure

Which two statements are true in this load balancing scenario? (Choose two.)

Options:

A.

The FortiGate public IP is the next-hop for all the traffic.

B.

An internal load balancer listener is the next-hop for outgoing traffic.

C.

You must add a route to the Microsoft VIP used for the health check.

D.

A dedicated management interface can be used for load balancing.

Buy Now
Questions 6

Which two statements are true about Transit Gateway Connect peers in anlPv4 BGP configuration'? (Choose two.)

Options:

A.

The inside CIDR blocks are used for BGP peering

B.

You cannot use IPv6 addresses

C.

You must specify a /29CIDR block from the 169.254.0.0/16 range

D.

You must configure the second address from the IPv4 range on the device as the BGP IP address

Buy Now
Questions 7

Refer to the exhibit.

The exhibit shows an active-passive high availability FortiGate pair with external and internal Azure load balancers. There is no SDN connector used in this solution

Which configuration should the administrator implement?

Options:

A.

Lambda IP address with one static route.

B.

Probe IP address with two static routes

C.

Probe IP address with one BGP route

D.

Public load balancer IP address with two BGP routes.

Buy Now
Questions 8

An administrator is looking for a solution that can provide insight into users and data stored in major SaaS applications in the multicloud environment Which product should the administrator deploy to have secure access to SaaS applications?

Options:

A.

FortiProxy

B.

FortiSandbox

C.

ForliCASB

D.

FortiWeb

Buy Now
Questions 9

Refer to the exhibit

You are tasked to deploy a FortiGate VM with private and public subnets in Amazon Web Services (AWS).

You examined the variables.tf file.

What will be the final result after running the terraform init and terraform apply commands?

Options:

A.

Terraform will not deploy a FortiGate VM

B.

Terraform will deploy a FortiGate VM in the eu-West-Ia region with private and public subnets.

C.

Terraform will deploy a FortiGate VM in the eu-West-1a region with two subnets and byol license.

D.

Terraform will deploy a FortiGate VM in the eu-West-Ia region without any subnets.

Buy Now
Questions 10

Refer to the exhibit.

What would be the impact of confirming to delete all the resources in Terraform?

Options:

A.

It destroys all the resources in the . tfvars file

B.

It destroys all the resources tied to the AWS Identity and Access Management (1AM) user.

C.

It destroys all the resources in the resource group

D.

It destroys all the resources in the state file.

Buy Now
Questions 11

In an SD-WAN TGW Connect topology, which three initial steps are mandatory when routing traffic from a spoke VPC to a security VPC through a Transit Gateway? (Choose three.)

Options:

A.

From the spoke VPC internal routing table, point 0.0.0.0/0 traffic to the TGW

B.

From the security VPC TGW subnet routing table: point 0.0.0.0/0 traffic to theFortiGate internal port

C.

From the security VPC TGW subnet routing table: point 0.0.0.0/0 traffic to the TGW

D.

From the security VPC FortiGate internal subnet routing table, point 0.0.0.0/0 traffic to the TGW

E.

From both spoke VPCs and the security VPC, point 0.0.0.0/0 traffic to the Internet Gateway

Buy Now
Questions 12

Refer to the exhibit

An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform However, during the configuration, the Azure client secret is no longer visible in the Azure portal.

How would the administrator obtain the Azure

client secret to configure on Terratorm?

Options:

A.

The administrator must create a new Azure account

B.

Log in to the Azure CLI with power user to obtain the client secret

C.

The administrator can create a new client secret

D.

The administrator must obtain the client secret through Azure Cloud Shell.

Buy Now
Questions 13

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.

What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)

Options:

A.

ExpressRoute

B.

GRE tunnels

C.

SSL VPN connections

D.

An L2TP connection

E.

VPN Gateway

Buy Now
Questions 14

Refer to the exhibit.

You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary

device does not have the previous primary device floating IP

address.

What could be the possible issue With this scenario?

Options:

A.

FortiGate port4 does not have internet access.

B.

A wrong client secret credential is used

C.

The error is caused by credential time expiration.

D.

The Azure service principle account must have a contributor role.

Buy Now
Questions 15

What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

Options:

A.

It eliminates the use of ECMP

B.

You can use GRE-based tunnel attachments

C.

You can combine it with IPsec to achieve higher bandwidth

D.

You can use BGP over IPsec for maximum throughput

Buy Now
Questions 16

An administrator would like to keep track of sensitive data files located in the Amazon Web Services (AWS) S3 bucket and protect it from malware. Which Fortinet product or feature should the administrator use?

Options:

A.

FortiCNP application control policies

B.

FortiCNP web sensitive polices

C.

FortiCNP DLP policies

D.

FortiCNP compliance scanning policies

Buy Now
Questions 17

Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?

Options:

A.

TGW can have multiple TGW route tables.

B.

Both the TGW attachment and propagation must be in the same TGW route table

C.

A TGW attachment can be associated with multiple TGW route tables.

D.

The TGW default route table cannot be disabled.

Buy Now
Exam Code: NSE7_PBC-7.2
Exam Name: Fortinet NSE 7 - Public Cloud Security 7.2
Last Update: May 5, 2024
Questions: 59
NSE7_PBC-7.2 pdf

NSE7_PBC-7.2 PDF

$28  $80
NSE7_PBC-7.2 Engine

NSE7_PBC-7.2 Testing Engine

$33.25  $95
NSE7_PBC-7.2 PDF + Engine

NSE7_PBC-7.2 PDF + Testing Engine

$45.5  $130