Fortinet NSE 7 - Public Cloud Security 7.2 Free Sample Questions

20 free sample questions264 in the full practice test Other version: NSE7-PBC-7.6

Try simulator

NSE7-PBC-7-2 Sample Questions

  1. Question 1

    A financial services firm is deploying a FortiGate-VM High Availability (HA) cluster in Azure using Terraform. To meet compliance requirements, all HA-related traffic, including FGCP heartbeat packets, must be isolated on a dedicated subnet. The lead architect has mandated that the Azure Load Balancer health probe must target a specific, non-standard port on the FortiGate's internal interface to monitor service health. Which Terraform resource and attribute is essential for configuring this custom health probe port?

    Answer and explanation

    Correct answer: C

    The azurerm_lb_probe Terraform resource is specifically designed to define the health probe used by an Azure Load Balancer. The port attribute within this resource allows the administrator to specify the exact TCP or HTTP port that the probe will use to check the health of backend instances, such as the FortiGate-VMs. This is the correct way to configure a custom port for health monitoring in an Azure HA setup.

  2. Question 2

    A healthcare provider is automating the deployment of a multi-VPC environment in AWS using Terraform. The architecture requires a centralized security VPC with a FortiGate-VM auto-scaling group for egress traffic inspection. A critical requirement is that newly launched FortiGate instances must automatically register with a central FortiManager and retrieve their base configuration without manual intervention. How can this be achieved in the Terraform configuration?

    Answer and explanation

    Correct answer: C

    The most secure and scalable method for auto-scaling groups is to use an aws_launch_template. The user_data script within the launch template can be configured to run at boot. This script should securely fetch the FortiManager IP and registration credentials from a service like AWS Secrets Manager, then use the FortiGate CLI command execute fgfm-reg to initiate registration. This avoids hardcoding secrets and allows for dynamic, secure bootstrapping of new instances.

  3. Question 3

    A DevOps engineer is using an Ansible playbook to manage a fleet of FortiGate-VMs in Azure. The playbook needs to idempotently create a new firewall address object. Which combination of Ansible module and parameters is the correct approach to ensure the object is created only if it doesn't exist, and left unchanged if it already exists with the correct configuration?

    Answer and explanation

    Correct answer: A

    The fortios_firewall_address module is the correct tool for managing firewall address objects. Using state: present ensures idempotency. If the named address object does not exist, Ansible will create it. If it already exists with the specified parameters, Ansible will report 'ok' and make no changes. If it exists but has different parameters, Ansible will update it to match the playbook definition and report 'changed'.

  4. Question 4

    A retail company has deployed a FortiGate-VM in AWS to inspect traffic between their on-premises data center and multiple spoke VPCs, connected via an AWS Transit Gateway (TGW). The security team observes that traffic from a specific on-premises subnet (10.10.20.0/24) to a spoke VPC (192.168.1.0/24) is being dropped. All other traffic flows correctly. A packet capture on the FortiGate shows the traffic arriving on the internal interface but not leaving the external interface. Which is the most likely cause of this issue?

    Answer and explanation

    Correct answer: B

    Since the packet capture shows traffic arriving but not leaving the FortiGate, the issue is likely within the FortiGate's configuration. For the FortiGate to route traffic to the spoke VPC, it must have a route in its routing table for that destination. In a TGW environment, this route should point to the TGW as the next hop. A missing static route for 192.168.1.0/24 would cause the FortiGate to drop the packets, as it wouldn't know where to send them.

  5. Question 5

    Multiple answers

    An organization is using FortiCNP to monitor its AWS environment. A security analyst receives a high-priority alert indicating a publicly accessible S3 bucket contains files with sensitive data patterns (e.g., credit card numbers). According to Fortinet best practices, what are the most effective immediate mitigation steps the analyst should take using FortiCNP's capabilities? (Select TWO)

    Answer and explanation

    Correct answers: B, D

    FortiCNP provides actionable remediation guidance, often including specific CLI commands or console steps to fix misconfigurations. This is a primary feature for mitigating identified risks.

    A key benefit of FortiCNP is its ability to automate remediation. Setting up a workflow to automatically correct common, high-risk misconfigurations like public S3 buckets is a best practice for immediate risk mitigation.

  6. Question 6

    True or False: When using the Azure SDN Connector on a FortiGate-VM, it is mandatory to assign an Azure AD Managed Identity to the VM for the connector to dynamically pull metadata about Azure resources.

    Answer and explanation

    Correct answer: B

    While using a Managed Identity is the recommended and most secure method, the Azure SDN Connector also supports authentication using a Service Principal with a client ID and secret. Therefore, it is not mandatory to use a Managed Identity, although it is a best practice.

  7. Question 7

    Multiple answers

    A global logistics company is designing a secure network architecture in AWS. They are using an AWS Transit Gateway (TGW) to connect hundreds of VPCs across multiple regions. They plan to deploy a centralized security VPC in each region, containing a FortiGate-VM HA pair to inspect all inter-VPC and VPC-to-internet traffic. To maintain traffic isolation between different business units (e.g., Shipping, Warehousing, Finance), which two TGW features are essential to implement? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    Multiple TGW route tables are fundamental to creating separate routing domains. Each business unit's VPC attachments can be associated with a specific route table, and propagation can be controlled to ensure traffic is isolated and only routed where intended (e.g., to the security VPC).

    Controlling route table association (which route table an attachment uses) and propagation (which attachments dynamically propagate their routes into a route table) is the core mechanism for enforcing traffic isolation and directing traffic flows within the TGW.

  8. Question 8

    A media streaming company is deploying a containerized application on Azure Kubernetes Service (AKS). To secure east-west traffic between pods, they have deployed FortiGate CNF. A security requirement states that all traffic from pods in the 'frontend' namespace to pods in the 'database' namespace must be inspected for SQL injection attacks. Which FortiGate CNF feature should be used to achieve this specific requirement?

    Answer and explanation

    Correct answer: B

    FortiGate CNF integrates with the Kubernetes API to understand its objects. The correct way to enforce this policy is to create a firewall policy within FortiGate CNF that uses Kubernetes labels or service objects to define the 'frontend' namespace as the source and the 'database' namespace as the destination. Applying an Intrusion Prevention System (IPS) profile to this policy will enable the inspection for SQL injection attacks.

  9. Question 9

    When configuring an SD-WAN using AWS Transit Gateway (TGW) Connect, what is the primary purpose of the GRE tunnel that is established between the FortiGate-VM and the TGW?

    Answer and explanation

    Correct answer: B

    The GRE (Generic Routing Encapsulation) tunnel in a TGW Connect setup serves as a transport layer. Its primary function is to encapsulate and carry the packets of a dynamic routing protocol, specifically BGP, between the customer's SD-WAN appliance (FortiGate) and the Transit Gateway. This allows for dynamic exchange of routes, which is a core benefit of TGW Connect over static TGW attachments. GRE itself does not provide encryption.

  10. Question 10

    A large enterprise has established a global network using Azure Virtual WAN (vWAN). They have deployed a FortiGate-VM as a Network Virtual Appliance (NVA) in the vWAN hub for centralized security inspection. An architect needs to ensure that all traffic from a spoke VNet destined for the internet is routed through the FortiGate NVA. What is the correct way to configure this routing in Azure?

    Answer and explanation

    Correct answer: B

    In an Azure Virtual WAN architecture, routing for spoke VNets is controlled by the hub's route tables. To force internet-bound traffic through the NVA, you must edit the effective route table associated with the spoke VNet connection (often the 'default' route table). You would add a static route for 0.0.0.0/0 and set the next hop to the specific vWAN connection corresponding to the FortiGate NVA. UDRs in the spoke VNet are not the primary mechanism for this in a vWAN hub scenario.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 264 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon