Fortinet NSE 7 - Public Cloud Security 7.2 - NSE7_PBC-7.2 Exam Practice Test
What are three important steps required to get Terraform ready using Microsoft Azure Cloud Shell? (Choose three.)
Correct Answer: A,B,D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit. You are configuring a second route table on a Transit Gateway to accommodate east-west traffic inspection between two VPCs. However, you are getting an error during the transit gateway route table association with the Connect attachment.

Which action Should you take to fulfill your requirement?

Which action Should you take to fulfill your requirement?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit. You attempted to access the Linux1 EC2 instance directly from the internet using its public IP address in AWS.

However, your connection is not successful.
Given the network topology, what can be the issue?

However, your connection is not successful.
Given the network topology, what can be the issue?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Your administrator instructed you to deploy an Azure vWAN solution to create a connection between the main company site and branch sites to the other company VNETs.
What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)
What are the two best connection solutions available between your company headquarters, branch sites, and the Azure vWAN hub? (Choose two.)
Correct Answer: A,C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit. You are deploying two FortiGate VMS in HA active-passive mode with load balancers in Microsoft Azure.

Which two statements are true in this load balancing scenario? (Choose two.)

Which two statements are true in this load balancing scenario? (Choose two.)
Correct Answer: C,D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
You are deploying Amazon Web Services (AWS) GuardDuty to monitor malicious or unauthorized behaviors related to AWS resources. You will also use the Fortinet aws-lambda-guardduty script to translate feeds from AWS GuardDuty findings into a list of malicious IP addresses. FortiGate can then consume this list as an external threat feed.
Which Amazon AWS services must you subscribe to in order to use this feature?
Which Amazon AWS services must you subscribe to in order to use this feature?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which two statements about Amazon Web Services (AWS) networking are correct? (Choose two.)
Correct Answer: A,C
A Network security administrator is searching for a solution to secure traffic going in and out of the container infrastructure.
In which two ways can Fortinet container security help secure container infrastructure? (Choose two.)
In which two ways can Fortinet container security help secure container infrastructure? (Choose two.)
Correct Answer: B,D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Your company deploys FortiGate VM devices in high availability (HA) (active-active) mode with Microsoft Azure load balancers using the Microsoft Azure ARM template. Your senior administrator instructs you to connect to one of the FortiGate devices and configure the necessary firewall rules. However, you are not sure now to obtain the correct public IP address of the deployed FortiGate VM and identify the access ports.
How do you obtain the public IP address of the FortiGate VM and identify the correct ports to access the device?
How do you obtain the public IP address of the FortiGate VM and identify the correct ports to access the device?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Refer to the exhibit. In your Amazon Web Services (AWS) virtual private cloud (VPC), you must allow outbound access to the internet and upgrade software on an EC2 instance, without using a NAT instance. This specific EC2 instance is running in a private subnet: 10.0.1.0/24. Also, you must ensure that the EC2 instance source IP address is not exposed to the public internet. There are two subnets in this VPC in the same availability zone, named public (10.0.0.0/24) and private (10.0.1.0/24).

How do you achieve this outcome with minimum configuration?

How do you achieve this outcome with minimum configuration?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).