Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Fortinet NSE 7 Network Security Architect NSE7_PBC-7.2 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam NSE7_PBC-7.2 Premium Access

View all detail and faqs for the NSE7_PBC-7.2 exam


529 Students Passed

90% Average Score

92% Same Questions
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

When adding the Amazon Web Services (AWS) account to the FortiCNP, which three mandatory configuration steps must you follow? (Choose three.)

Options:

A.

Add AWS accounts through FortiCNP.

B.

Enable cloud protection through AWS Guard Duty and AWS Inspector

C.

Accept FortiCNP to create CloudTrail for the account

D.

Enable cross-reg Ion aggregation

E.

Launch the CloudFormation template.

Questions # 2:

What are two main features in Amazon Web Services (AWS) network access control lists (ACLs)? (Choose two.)

Options:

A.

You cannot use Network ACL and Security Group at the same time.

B.

The default network ACL is configured to allow all traffic

C.

NetworkACLs are stateless, and inbound and outbound rules are used for traffic filtering

D.

Network ACLs are tied to an instance

Questions # 3:

Refer to the exhibit

Question # 3

You are tasked with deploying FortiGate using Terraform. When you run the terraform version command during the Terraform installation, you get an error message.

What could be the reason that you are getting the command not found error?

Options:

A.

You must move the binary file to the bin directory.

B.

You must change the directory location to the root directory

C.

You must assign correct permissions to the ec2-user.

D.

You must reinstall Terraform

Questions # 4:

Which two Amazon Web Services (AWS) features do you use for the transit virtual private cloud (VPC) automation process to add new spoke N/PCs? (Choose two )

Options:

A.

Amazon S3 bucket

B.

AWS Security Hub

C.

AWS Transit Gateway

D.

Amazon CloudWatch

Questions # 5:

What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

Options:

A.

It eliminates the use of ECMP

B.

You can use GRE-based tunnel attachments

C.

You can combine it with IPsec to achieve higher bandwidth

D.

You can use BGP over IPsec for maximum throughput

Questions # 6:

How does Terraform keep track of provisioned resources?

Options:

A.

It uses the terraform. tf state file

B.

Terraform does not keep the state of resources created

C.

It uses the terraform. tfvars file.

D.

It uses the database. tf file.

Questions # 7:

You have created a TGW route table to route traffic from your spoke VPC to the security VPC where two FortiGate devices are inspecting traffic. Your spoke VPC CIDR block is already propagated to the Transit Gateway (TGW) route table.

Which type of attachment should you use to advertise routes through BGP from the spoke VPC to the security VPC?

Options:

A.

Connect attachment

B.

VPC attachment

C.

Route attachment

D.

GRE attachment

Questions # 8:

Refer to the exhibit

Question # 8

The exhibit shows the results of a FortiCNP registry scan

Which two statements are correct? (Choose two )

Options:

A.

When adding a repository, you can leave the Tag section blank to scan all images-

B.

The registry scan is part of the FortiCNP cloud protection.

C.

The registry scan is part of the FortiCNP container protection.

D.

When adding a repository, you can add a minimum number of images to be imported through the CAP section.

Questions # 9:

Refer to Exhibit:

Question # 9

The exhibit shows the Connect Peers settings on Amazon Web Services (AWS) transit gateway attachments With two FortiGate VMS in a security VPC.

Which two statements are correct? (Choose two.)

Options:

A.

The peer GRE address is the FortiGate external interface IP address.

B.

The Transit Gateway GRE address is auto-generated

C.

The BGP inside CIDR blocks can be any CIDR block with /29

D.

The Peer GRE address is the FortiGate internal interface IP address

Questions # 10:

Refer to the exhibit

Question # 10

Consider the active-active load balance sandwich scenario in Microsoft Azure.

What are two important facts in the active-active load balance sandwich scenario? (Choose two )

Options:

A.

It uses the vdom-exception command to exclude the configuration from being synced

B.

It is recommended to enable NAT on FortiGate policies.

C.

It uses the FGCP protocol

D.

It supports session synchronization for handling asynchronous traffic.

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.