Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Fortinet NSE7_PBC-7.2 Practice Exam with Questions & Answers

Questions 1

You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications reside, with minimum traffic cost

Which solution meets the requirements?

Options:
A.

Use FortiADC

B.

Use FortiCNP

C.

Use FortiWebCloud

D.

Use FortiGate

Fortinet NSE7_PBC-7.2 Premium Access
Questions 2

What are two main features in Amazon Web Services (AWS) network access control lists (ACLs)? (Choose two.)

Options:
A.

You cannot use Network ACL and Security Group at the same time.

B.

The default network ACL is configured to allow all traffic

C.

NetworkACLs are stateless, and inbound and outbound rules are used for traffic filtering

D.

Network ACLs are tied to an instance

Questions 3

Refer to the exhibit.

NSE7_PBC-7.2 Question 3

You are configuring a second route table on a Transit Gateway to accommodate east-west traffic inspection between two VPCs_ However, you are getting an error during the transit gateway route table association With the Connect attachment.

Which action Should you take to fulfill your requirement?

Options:
A.

Add both Associations and Propagations in the second TGW route table.

B.

Delete the both Connect and Transport attachments from the first TGW route table

C.

Add a static route in the Routes section

D.

In the second route table: create a propagation with the Connect attachment.

Questions 4

When adding the Amazon Web Services (AWS) account to the FortiCNP, which three mandatory configuration steps must you follow? (Choose three.)

Options:
A.

Add AWS accounts through FortiCNP.

B.

Enable cloud protection through AWS Guard Duty and AWS Inspector

C.

Accept FortiCNP to create CloudTrail for the account

D.

Enable cross-reg Ion aggregation

E.

Launch the CloudFormation template.

Questions 5

Refer to the exhibit.

NSE7_PBC-7.2 Question 5

NSE7_PBC-7.2 Question 5

What could be the reason that the administrator cannot access the EC2 instance?

Options:
A.

You must elevate the permissions to access the EC2 instance

B.

You must run the chmod 400 Staging-key.peracommand before accessing the instance.

C.

There is no . pem key created on in Amazon Web Services (AWS)

D.

The directory location of the . pem file is incorrect.

Questions 6

Refer to the exhibit

NSE7_PBC-7.2 Question 6

An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform However, during the configuration, the Azure client secret is no longer visible in the Azure portal.

How would the administrator obtain the Azure

client secret to configure on Terratorm?

Options:
A.

The administrator must create a new Azure account

B.

Log in to the Azure CLI with power user to obtain the client secret

C.

The administrator can create a new client secret

D.

The administrator must obtain the client secret through Azure Cloud Shell.

Questions 7

A Network security administrator is searching for a solution to secure traffic going in and out of the container infrastructure.

In which two ways can Fortinet container security help secure container infrastructure? (Choose two.)

Options:
A.

FortiGate NGFW can be placed between each application container for north-south traffic inspection

B.

FortiGate NGFW can connect to the worker node and protects the container-

C.

FortiGate NGFW can inspect north-south container traffic with label aware policies

D.

FortiGate NGFW and FortiSandbox can be used to secure container traffic

Questions 8

You have created a TGW route table to route traffic from your spoke VPC to the security VPC where two FortiGate devices are inspecting traffic. Your spoke VPC CIDR block is already propagated to the Transit Gateway (TGW) route table.

Which type of attachment should you use to advertise routes through BGP from the spoke VPC to the security VPC?

Options:
A.

Connect attachment

B.

VPC attachment

C.

Route attachment

D.

GRE attachment

Questions 9

You are asked to find a solution to replace the existing VPC peering topology to have a higher bandwidth connection from Amazon Web Services (AWS) to the on-premises data center Which two solutions will satisfy the requirement? (Choose two.)

Options:
A.

Use ECMP and VPN to achieve higher bandwidth.

B.

Use transit VPC to build multiple VPC connections to the on-premises data center

C.

Use a transit VPC with hub and spoke topology to create multiple VPN connections to the on-premises data center.

D.

Use the transit gateway attachment With VPN option to create multiple VPN connections to the on-premises data center

Questions 10

Refer to the exhibit.

NSE7_PBC-7.2 Question 10

What would be the impact of confirming to delete all the resources in Terraform?

Options:
A.

It destroys all the resources in the . tfvars file

B.

It destroys all the resources tied to the AWS Identity and Access Management (1AM) user.

C.

It destroys all the resources in the resource group

D.

It destroys all the resources in the state file.

Exam Code: NSE7_PBC-7.2
Certification Provider: Fortinet
Exam Name: Fortinet NSE 7 Public Cloud Security 7.2 (FCSS)
Last Update: Jul 15, 2025
Questions: 59
PDF + Testing Engine
$164.99
$66
Testing Engine
$124.99
$50
PDF (Q&A)
$104.99
$42