Pre-Winter Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

NSE7_CDS_AR-7.6 Fortinet NSE 7 - Public Cloud Security 7.6.4 Architect Questions and Answers

Questions 4

You are using Ansible to modify the configuration of several FortiGate VMs. What is the minimum number of files you need to create, and in which file should you configure the target FortiGate IP addresses?

Options:

A.

One playbook file for each target and the required tasks, and one inventory file.

B.

One .yaml file with the targets IP addresses, and one playbook file with the tasks.

C.

One inventory file for each target device, and one playbook file.

D.

One text file for all target devices, and one playbook file.

Buy Now
Questions 5

Refer to the exhibit.

NSE7_CDS_AR-7.6 Question 5

You are troubleshooting a Microsoft Azure SDN connector issue on your FortiGate VM in Azure.

Which command can you use to examine details about API calls sent by the connector?

Options:

A.

diag debug application cloud-connector -1

B.

diag test application azd 1

C.

diag debug application azd -1

D.

get system sdn-connector

Buy Now
Questions 6

Refer to the exhibit.

NSE7_CDS_AR-7.6 Question 6

A managed security service provider (MSSP) administration team is trying to deploy a new HA cluster in Azure to filter traffic to and from a client that is also using Azure. However, every deployment attempt fails, and only some of the resources are deployed successfully. While troubleshooting this issue, the team runs the command shown in the exhibit.

What are the implications of the output of the command?

Options:

A.

The team will not be able to deploy an A-P FortiGate HA cluster with Azure gateway load balancer.

B.

The team will not be able to deploy an A-P FortiGate HA cluster with Azure load balancer.

C.

The team will not be able to deploy an active-passive (A-P) FortiGate high availability (HA) cluster with SDN connector.

D.

The team will not be able to deploy an active-active (A-P) FortiGate HA cluster with Azure load balancer.

Buy Now
Questions 7

Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?

Options:

A.

Both the TGW attachment and propagation must be in the same TGW route table.

B.

TGW can have multiple TGW route tables.

C.

A TGW attachment can be associated with multiple TGW route tables.

D.

The TGW default route table cannot be disabled.

Buy Now
Questions 8

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs. What is the best connection solution available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose one answer)

Options:

A.

An L2TP connection

B.

SSL VPN connections

C.

GRE tunnels

D.

ExpressRoute

Buy Now
Questions 9

Refer to the exhibit.

NSE7_CDS_AR-7.6 Question 9

You are managing an active-passive FortiGate HA cluster in AWS that was deployed using CloudFormation. You have created a change set to examine the effects of some proposed changes to the current infrastructure. The exhibit shows some sections of the change set.

What will happen if you apply these changes?

Options:

A.

This deployment can be done without any traffic interruption.

B.

Both FortiGate VMs will get a new PhysicalResourceId.

C.

The updated FortiGate VMs will not have the latest configuration changes.

D.

CloudFormation checks if you will surpass your account quota.

Buy Now
Questions 10

The cloud administration team is reviewing an AWS deployment that was done using CloudFormation.

The deployment includes six FortiGate instances that required custom configuration changes after being deployed. The team notices that unwanted traffic is reaching some of the FortiGate instances because the template is missing a security group.

To resolve this issue, the team decides to update the JSON template with the missing security group and then apply the updated template directly, without using a change set.

What is the result of following this approach?

Options:

A.

If new FortiGate instances are deployed later they will include the updated changes.

B.

Some of the FortiGate instances may be deleted and replaced with new copies.

C.

The update is applied, and the security group is added to all instances without interruption.

D.

CloudFormation rejects the update and warns that a new full stack is required.

Buy Now
Questions 11

An AWS administrator must ensure that each member of the cloud deployment team has the correct permissions to deploy and manage resources using CloudFormation. The administrator is researching which tasks must be executed with CloudFormation and therefore require CloudFormation permissions.

Which task is run using CloudFormation?

Options:

A.

Deploying a new pod with a service in an Elastic Kubernetes Service (EKS) cluster using the kubectl command

B.

Installing a Helm chart to deploy a FortiWeb ingress controller in an EKS cluster

C.

Creating an EKS cluster with the eksctl create cluster command

D.

Changing the number of nodes in a EKS cluster from AWS CloudShell

Buy Now
Questions 12

What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

Options:

A.

You can use BGP over IPsec for maximum throughput.

B.

You can combine it with IPsec to achieve higher bandwidth.

C.

It eliminates the use of ECMP.

D.

You can use GRE-based tunnel attachments.

Buy Now
Questions 13

What are two main features in Amazon Web Services (AWS) network access control lists (NACLs)? (Choose two answers)

Options:

A.

NACLs are stateless, and inbound and outbound rules are used for traffic filtering.

B.

NACLs are tied to an instance.

C.

The default NACL is configured to allow all traffic.

D.

You cannot use NACLs and Security Groups at the same time.

Buy Now
Questions 14

Refer to the exhibit.

NSE7_CDS_AR-7.6 Question 14

An administrator used the what-if tool to preview the changes to an Azure Bicep file. What will happen if the administrator applies these changes in Azure? (Choose one answer)

Options:

A.

A new subnet will be added to vnet-002.

B.

The vnet-002 VNet will be renamed Production.

C.

The resulting VNet will have a single subnet.

D.

The VNet address space will be updated.

Buy Now
Questions 15

Refer to the exhibit.

NSE7_CDS_AR-7.6 Question 15

A team of AWS administrators is in the process of installing a FortiWeb ingress controller to protect containerized web applications in an Amazon Elastic Kubernetes Service (EKS) cluster. While customizing the manifest file shown in the exhibit, they realize that they do not know the correct value to enter in the fortiweb-login field.

How can they determine the correct value for this field?

Options:

A.

The correct value is the password of the FortiWeb admin account.

B.

They can find the expected value in the manifest file used to deploy the pods.

C.

They must create a Kubernetes secret with the kubectl command.

D.

They can refer to the output of the EKS cluster deployment.

Buy Now
Questions 16

Refer to the exhibit.

NSE7_CDS_AR-7.6 Question 16

An administrator deployed an HA active-active load balance sandwich in Microsoft Azure. The setup requires configuration synchronization between devices.

What can you conclude from the configured settings shown in the exhibit? (Choose two.)

Options:

A.

By default, FortiGate uses FGCP.

B.

FortiGate-VM instances are scaled out automatically according to predefined workload levels.

C.

FortiGate A and FortiGate B are two independent devices.

D.

It does not synchronize the FortiGate hostname.

Buy Now
Questions 17

You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications reside, with minimum traffic cost.

Which solution meets the requirements?

Options:

A.

Use FortiGate

B.

Use FortiCNP

C.

Use FortiWeb

D.

Use FortiADC

Buy Now
Questions 18

Refer to the exhibit.

NSE7_CDS_AR-7.6 Question 18

An experienced AWS administrator is creating a new virtual public cloud (VPC) flow log with the settings shown in the exhibit.

What is the purpose of this configuration?

Options:

A.

To maximize the number of logs saved

B.

To monitor logs in real time

C.

To retain logs for a long term

D.

To troubleshoot a log flow issue

Buy Now
Questions 19

An organization is deploying FortiDevSec to enhance security for containerized applications, and they need to ensure containers are monitored for suspicious behavior at runtime.

Which FortiDevSec feature is best for detecting runtime threats?

Options:

A.

FortiDevSec software composition analysis (SCA)

B.

FortiDevSec static application security testing (SAST)

C.

FortiDevSec dynamic application security testing (DAST)

D.

FortiDevSec container scanner

Buy Now
Questions 20

Refer to the exhibit.

NSE7_CDS_AR-7.6 Question 20

You are tasked to deploy a FortiGate VM with private and public subnets in Amazon Web Services (AWS). You examined the variables.tf file. Assume that all the other terraform files are in place. What will be the final result after running the terraform init and terraform apply commands? (Choose one answer)

Options:

A.

Terraform will not deploy a FortiGate VM.

B.

Terraform will deploy a FortiGate VM in the eu-West-1a availability zone without any subnets.

C.

Terraform will deploy a FortiGate VM in the eu-West-1 region with private and public subnets.

D.

Terraform will deploy a FortiGate VM in the eu-West-1a availability zone with two subnets and BYOL license.

Buy Now
Exam Code: NSE7_CDS_AR-7.6
Exam Name: Fortinet NSE 7 - Public Cloud Security 7.6.4 Architect
Last Update: Sep 17, 2026
Questions: 67

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99