Weekend Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: netbudy65

NSE7_PBC-7.2 Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Questions and Answers

Questions 4

Refer to the exhibit

NSE7_PBC-7.2 Question 4

The exhibit shows the results of a FortiCNP registry scan

Which two statements are correct? (Choose two )

Options:

A.

When adding a repository, you can leave the Tag section blank to scan all images-

B.

The registry scan is part of the FortiCNP cloud protection.

C.

The registry scan is part of the FortiCNP container protection.

D.

When adding a repository, you can add a minimum number of images to be imported through the CAP section.

Buy Now
Questions 5

When adding the Amazon Web Services (AWS) account to the FortiCNP, which three mandatory configuration steps must you follow? (Choose three.)

Options:

A.

Add AWS accounts through FortiCNP.

B.

Enable cloud protection through AWS Guard Duty and AWS Inspector

C.

Accept FortiCNP to create CloudTrail for the account

D.

Enable cross-reg Ion aggregation

E.

Launch the CloudFormation template.

Buy Now
Questions 6

Refer to the exhibit

NSE7_PBC-7.2 Question 6

You are deploying two FortiGate VMS in HA active-passive mode with load balancers in Microsoft Azure

Which two statements are true in this load balancing scenario? (Choose two.)

Options:

A.

The FortiGate public IP is the next-hop for all the traffic.

B.

An internal load balancer listener is the next-hop for outgoing traffic.

C.

You must add a route to the Microsoft VIP used for the health check.

D.

A dedicated management interface can be used for load balancing.

Buy Now
Questions 7

An administrator is looking for a solution that can provide insight into users and data stored in major SaaS applications in the multicloud environment Which product should the administrator deploy to have secure access to SaaS applications?

Options:

A.

FortiProxy

B.

FortiSandbox

C.

ForliCASB

D.

FortiWeb

Buy Now
Questions 8

An administrator would like to keep track of sensitive data files located in the Amazon Web Services (AWS) S3 bucket and protect it from malware. Which Fortinet product or feature should the administrator use?

Options:

A.

FortiCNP application control policies

B.

FortiCNP web sensitive polices

C.

FortiCNP DLP policies

D.

FortiCNP compliance scanning policies

Buy Now
Questions 9

Refer to Exhibit:

NSE7_PBC-7.2 Question 9

The exhibit shows the Connect Peers settings on Amazon Web Services (AWS) transit gateway attachments With two FortiGate VMS in a security VPC.

Which two statements are correct? (Choose two.)

Options:

A.

The peer GRE address is the FortiGate external interface IP address.

B.

The Transit Gateway GRE address is auto-generated

C.

The BGP inside CIDR blocks can be any CIDR block with /29

D.

The Peer GRE address is the FortiGate internal interface IP address

Buy Now
Questions 10

Refer to the exhibit.

NSE7_PBC-7.2 Question 10

What would be the impact of confirming to delete all the resources in Terraform?

Options:

A.

It destroys all the resources in the . tfvars file

B.

It destroys all the resources tied to the AWS Identity and Access Management (1AM) user.

C.

It destroys all the resources in the resource group

D.

It destroys all the resources in the state file.

Buy Now
Questions 11

An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure However, the SDN connector is failing on the connection What must the administrator do to correct this issue?

Options:

A.

Make sure to add the Tenant ID on FortiGate side of the configuration

B.

Make sure to set the type to system managed identity on FortiGate SDN connector settings

C.

Make sure to enable the system assigned managed identity on Azure

D.

Make sure to add the Client secret on FortiGate side of the configuration

Buy Now
Questions 12

Refer to the exhibit.

NSE7_PBC-7.2 Question 12

The exhibit shows an active-passive high availability FortiGate pair with external and internal Azure load balancers. There is no SDN connector used in this solution

Which configuration should the administrator implement?

Options:

A.

Lambda IP address with one static route.

B.

Probe IP address with two static routes

C.

Probe IP address with one BGP route

D.

Public load balancer IP address with two BGP routes.

Buy Now
Questions 13

You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications reside, with minimum traffic cost

Which solution meets the requirements?

Options:

A.

Use FortiADC

B.

Use FortiCNP

C.

Use FortiWebCloud

D.

Use FortiGate

Buy Now
Questions 14

You must allow an SSH traffic rule in an Amazon Web Services (AWS) network access list (NACL) to allow SSH traffic to travel to a subnet for temporary testing purposes. When you review the current inbound network ACL rules, you notice that rule number 5 demes SSH and telnet traffic to the subnet

What can you do to allow SSH traffic?

Options:

A.

You must create a new allow SSH rule below rule number 5

B.

You must create a new allow SSH rule above rule number 5-

C.

You must create a new allow SSH rule anywhere in the network ACL rule base to allow SSH traffic.

D.

You do not have to create any NACL rules because the default security group rule automatically allows SSH traffic to the subnet.

Buy Now
Questions 15

Refer to the exhibit.

NSE7_PBC-7.2 Question 15

An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer However, the connection is not successful and at the same time FortiGate is not receiving any HTTPS or SSH traffic to its external interface

What should the administrator check for possible issue?

Options:

A.

Run a debug flow to check any network ACLs

B.

Check the FortiGate firewall policies

C.

Check the FortiGate instance ID

D.

Check the inbound network security group rules

Buy Now
Questions 16

How does an administrator secure container environments from newly emerged security threats?

Options:

A.

Use distributed network-related application control signatures.

B.

Use Amazon AWS-related application control signatures

C.

Use Amazon AWS_S3-related application control signatures

D.

Use Docker-related application control signatures

Buy Now
Questions 17

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.

What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)

Options:

A.

ExpressRoute

B.

GRE tunnels

C.

SSL VPN connections

D.

An L2TP connection

E.

VPN Gateway

Buy Now
Exam Code: NSE7_PBC-7.2
Exam Name: Fortinet NSE 7 Public Cloud Security 7.2 (FCSS)
Last Update: Sep 23, 2025
Questions: 59

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99