Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

NSE7_PBC-7.2 Fortinet NSE 7 Public Cloud Security 7.2 (FCSS) Questions and Answers

Questions 4

Refer to the exhibit.

NSE7_PBC-7.2 Question 4

You have deployed a Linux EC2 instance in Amazon Web Services (AWS) with the settings shown on the exhibit

What next step must the administrator take to access this instance from the internet?

Options:

A.

Configure the user name and password.

B.

Enable source and destination checks on the instance

C.

Enable SSH and allocate it to the device

D.

Allocate an Elastic IP address and assign it to the instance

Buy Now
Questions 5

An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure However, the SDN connector is failing on the connection What must the administrator do to correct this issue?

Options:

A.

Make sure to add the Tenant ID on FortiGate side of the configuration

B.

Make sure to set the type to system managed identity on FortiGate SDN connector settings

C.

Make sure to enable the system assigned managed identity on Azure

D.

Make sure to add the Client secret on FortiGate side of the configuration

Buy Now
Questions 6

Refer to the exhibit

NSE7_PBC-7.2 Question 6

Consider the active-active load balance sandwich scenario in Microsoft Azure.

What are two important facts in the active-active load balance sandwich scenario? (Choose two )

Options:

A.

It uses the vdom-exception command to exclude the configuration from being synced

B.

It is recommended to enable NAT on FortiGate policies.

C.

It uses the FGCP protocol

D.

It supports session synchronization for handling asynchronous traffic.

Buy Now
Questions 7

In an SD-WAN TGW Connect topology, which three initial steps are mandatory when routing traffic from a spoke VPC to a security VPC through a Transit Gateway? (Choose three.)

Options:

A.

From the security VPC TGW subnet routing table, point 0.0.0.0/0 traffic to the FortiGate internal port.

B.

From the security VPC FortiGate internal subnet routing table, point 0.0.0.0/0 traffic to the TGW.

C.

From the spoke VPC internal routing table, point 0.0.0.0/0 traffic to the TGW.

D.

From the security VPC TGW subnet routing table, point 0.0.0.0/0 traffic to the TGW.

E.

From both spoke VPCs, and the security VPC, point 0.0.0.0/0 traffic to the Internet Gateway.

Buy Now
Questions 8

Refer to the exhibit.

NSE7_PBC-7.2 Question 8

You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary

device does not have the previous primary device floating IP

address.

What could be the possible issue With this scenario?

Options:

A.

FortiGate port4 does not have internet access.

B.

A wrong client secret credential is used

C.

The error is caused by credential time expiration.

D.

The Azure service principle account must have a contributor role.

Buy Now
Questions 9

Refer to the exhibit

NSE7_PBC-7.2 Question 9

An administrator deployed a FortiGate-VM in a high availability (HA)

(active/passive) architecture in Amazon Web Services (AWS) using Terraform

for testing purposes. At the same time, the administrator deployed a single

Linux server using AWS Marketplace

Which two options are available for the administrator to delete all the resources

created in this test? (Choose two.)

Options:

A.

Use the terraform destroy command

B.

Use the terraform validate command.

C.

Use the terraform destroy all command.

D.

The administrator must manually delete the Linux server.

Buy Now
Questions 10

Which statement about immutable infrastructure in automation is true?

Options:

A.

It is the practice of deploying a new server for every configuration change

B.

It is the practice of modifying the existing server configuration after it is deployed

C.

It is the practice of deploying two parallel servers for high availability.

D.

It is the practice of applying hotfixes and OS patches after deployment

Buy Now
Questions 11

Refer to the exhibit

NSE7_PBC-7.2 Question 11

An administrator deployed an HA active-active load balance sandwich in Microsoft Azure. The setup requires configuration synchronization between devices-

What are two outcomes from the configured settings? (Choose two.)

Options:

A.

FortiGate-VM instances are scaled out automatically according to predefined workload levels.

B.

FortiGate A and FortiGate B are two independent devices.

C.

By default, FortiGate uses FGCP

D.

It does not synchronize the FortiGate hostname

Buy Now
Questions 12

Which two attachments are necessary to connect a transit gateway to an existing VPC with BGP? (Choose two )

Options:

A.

A transport attachment

B.

A BGP attachment

C.

A connect attachment

D.

A GRE attachment

Buy Now
Questions 13

How does the immutable infrastructure strategy work in automation?

Options:

A.

It runs a single live environment for configuration changes.

B.

It runs one idle and a single live environment for configuration changes.

C.

It runs two live environments for configuration changes.

D.

It runs one idle and two live environments for configuration changes.

Buy Now
Questions 14

You are configuring the failover settings on a FortiGate active-passive SDN connector solution in Microsoft Azure. Which two mandatory settings are required after the initial deployment? (Choose two)

Options:

A.

Subscription-id

B.

FortiGate license file

C.

Active FortiGate serial number

D.

Resource group name

Buy Now
Questions 15

Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?

Options:

A.

TGW can have multiple TGW route tables.

B.

Both the TGW attachment and propagation must be in the same TGW route table

C.

A TGW attachment can be associated with multiple TGW route tables.

D.

The TGW default route table cannot be disabled.

Buy Now
Questions 16

You are using Red Hat Ansible to change the FortiGate VM configuration.

What is the minimum number of files you must create and which file must you use to configure the target FortiGate IP address?

Options:

A.

Create two files and use the .yami file.

B.

Create two files and use the hosts file

C.

Create one file and use the variable file

D.

Create three files and use the .yaml file.

Buy Now
Questions 17

Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.

What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)

Options:

A.

ExpressRoute

B.

GRE tunnels

C.

SSL VPN connections

D.

An L2TP connection

E.

VPN Gateway

Buy Now
Exam Code: NSE7_PBC-7.2
Exam Name: Fortinet NSE 7 Public Cloud Security 7.2 (FCSS)
Last Update: May 19, 2026
Questions: 59

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11