11.11 Special Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

NSE7_PBC-7.2 Exam Dumps - Fortinet NSE 7 Public Cloud Security 7.2 (FCSS)

Question # 4

Refer to the exhibit

Consider the active-active load balance sandwich scenario in Microsoft Azure.

What are two important facts in the active-active load balance sandwich scenario? (Choose two )

A.

It uses the vdom-exception command to exclude the configuration from being synced

B.

It is recommended to enable NAT on FortiGate policies.

C.

It uses the FGCP protocol

D.

It supports session synchronization for handling asynchronous traffic.

Full Access
Question # 5

An administrator is looking for a solution that can provide insight into users and data stored in major SaaS applications in the multicloud environment Which product should the administrator deploy to have secure access to SaaS applications?

A.

FortiProxy

B.

FortiSandbox

C.

ForliCASB

D.

FortiWeb

Full Access
Question # 6

Which two statements are true about Transit Gateway Connect peers in anlPv4 BGP configuration'? (Choose two.)

A.

The inside CIDR blocks are used for BGP peering

B.

You cannot use IPv6 addresses

C.

You must specify a /29CIDR block from the 169.254.0.0/16 range

D.

You must configure the second address from the IPv4 range on the device as the BGP IP address

Full Access
Question # 7

In an SD-WAN TGW Connect topology, which three initial steps are mandatory when routing traffic from a spoke VPC to a security VPC through a Transit Gateway? (Choose three.)

A.

From the security VPC TGW subnet routing table, point 0.0.0.0/0 traffic to the FortiGate internal port.

B.

From the security VPC FortiGate internal subnet routing table, point 0.0.0.0/0 traffic to the TGW.

C.

From the spoke VPC internal routing table, point 0.0.0.0/0 traffic to the TGW.

D.

From the security VPC TGW subnet routing table, point 0.0.0.0/0 traffic to the TGW.

E.

From both spoke VPCs, and the security VPC, point 0.0.0.0/0 traffic to the Internet Gateway.

Full Access
Question # 8

You must allow an SSH traffic rule in an Amazon Web Services (AWS) network access list (NACL) to allow SSH traffic to travel to a subnet for temporary testing purposes. When you review the current inbound network ACL rules, you notice that rule number 5 demes SSH and telnet traffic to the subnet

What can you do to allow SSH traffic?

A.

You must create a new allow SSH rule below rule number 5

B.

You must create a new allow SSH rule above rule number 5-

C.

You must create a new allow SSH rule anywhere in the network ACL rule base to allow SSH traffic.

D.

You do not have to create any NACL rules because the default security group rule automatically allows SSH traffic to the subnet.

Full Access
Question # 9

What are three important steps required to get Terraform ready using Microsoft Azure Cloud Shell? (Choose three.)

A.

Set up a storage account in Azure.

B.

use the -O command to download Terraform.

C.

Subscribe to Terraform in Azure.

D.

Move the Terraform file to the bin directory.

E.

Use the wget (te=aform vession) command to upload Terraform.

Full Access
Question # 10

Refer to the exhibit

A customer has deployed an environment in Amazon Web Services (AWS) and is now trying to send outbound traffic from the Linux1 and Linux2 instances to the internet through the security VPC (virtual private cloud). The FortiGate policies are configured to allow all outbound

traffic; however, the traffic is not reaching the FortiGate internal interface. Assume there are no issues with the Transit Gateway (TGW) configuration

Which two settings must the customer add to correct the issue? (Choose two.)

A.

Both landing subnets in the spoke VPCs must have a 0.0.0.0/0 traffic route to the Internet Gateway (IOW).

B.

Both landing subnets in the spoke VPCs must have a 0.0 00/0 traffic route to the TGW

C.

Both landing subnets in the security VPC must have a 0.0.0.0/0 traffic route to the FortiGate port2.

D.

The four landing subnets in all the VPCs must have a 0.0 0 0/0 traffic route to the TGW

Full Access
Question # 11

Refer to Exhibit:

After the initial Terraform configuration in Microsoft Azure, the terraform plan command is run Which two statements about running the plan command are true? (Choose two.)

A.

The terraform plan command will deploy the rest of the resources except the service principle details.

B.

You cannot run the terraform apply command before the terraform plan command.

C.

You must run the terraform init command once, before the terraform plan command

D.

The terraform plan command makes terraform do a dry run.

Full Access
Question # 12

Refer to the exhibit.

You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary

device does not have the previous primary device floating IP

address.

What could be the possible issue With this scenario?

A.

FortiGate port4 does not have internet access.

B.

A wrong client secret credential is used

C.

The error is caused by credential time expiration.

D.

The Azure service principle account must have a contributor role.

Full Access
Question # 13

Which two Amazon Web Services (AWS) features support east-west traffic inspection within the AWS cloud by the FortiGate VM? (Choose two.)

A.

A NAT gateway with an EIP

B.

A transit gateway with an attachment

C.

An Internet gateway with an EIP

D.

A transit VPC

Full Access
Question # 14

Refer to Exhibit:

You are troubleshooting a Microsoft Azure SDN connector issue on your FortiGate VM in Azure

Which three settings should you check while troubleshooting this problem? (Choose three.)

A.

Use the show vdom command to see hidden VDOMs.

B.

use the diag sys va command.

C.

Ensure FortiGate port4 can resolve DNS.

D.

Ensure FortiGate portl has internet access

E.

Ensure IP address 169.254.169_254 is not blocked

Full Access
Question # 15

You are troubleshooting an Azure SDN connectivity issue with your FortiGate VM

Which two queries does that SDN connector use to interact with the Azure management API? (Choose two.)

A.

The first query is targeted to a special IP address to get a token.

B.

The first query is targeted to IP address 8.8

C.

There is only one query initiating from FortiGate port1 -

D.

Some queries are made to manage public IP addresses.

Full Access
Question # 16

How does Terraform keep track of provisioned resources?

A.

It uses the terraform. tf state file

B.

Terraform does not keep the state of resources created

C.

It uses the terraform. tfvars file.

D.

It uses the database. tf file.

Full Access
Question # 17

Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?

A.

TGW can have multiple TGW route tables.

B.

Both the TGW attachment and propagation must be in the same TGW route table

C.

A TGW attachment can be associated with multiple TGW route tables.

D.

The TGW default route table cannot be disabled.

Full Access