NSE7-PBC-7-2 Fortinet NSE 7 - Public Cloud Security 7.2 Practice Questions
Prepare for NSE7-PBC-7-2 with more than an answer.
Unlock the full exam and previous versions
- v1Public Cloud Security 7.6 157 questions Locked
- NSE7-PBC-7-2Legacy Fortinet NSE 7 - Public Cloud Security 7.2 264 questions Current
- Exam fee
- $400 USD
- Level
- Professional
- Valid for
- 2 years from exam pass date
Domains covered on the exam 3
- FortiGate Deployments in Public Cloud40%
- Automation35%
- Troubleshooting and FortiCNP25%
- 1
A consultant is using Terraform to deploy a single FortiGate-VM into an existing Azure Virtual Network (VNet). The security policy requires that the FortiGate has separate network interfaces for external (untrust) and internal (trust) traffic. Which three Azure resources must be defined in the Terraform configuration to support this two-interface setup? (Select THREE)
Show answer details
Correct answer: B, C, D
Each network interface in Azure is a distinct resource. For a two-interface setup, two separate
azurerm_network_interfaceresources must be defined in Terraform.A single
azurerm_virtual_machineresource represents the FortiGate-VM itself. The network interfaces are attached to this single VM resource.Best practice in Azure is to place each network interface in its own dedicated subnet. Therefore, you would need to define two
azurerm_subnetresources, one for the external interface and one for the internal interface, within the existing VNet. - 2
When automating the deployment of a FortiGate active-passive HA cluster in Azure, an Azure Standard Load Balancer is used to direct traffic to the active node. What is the purpose of configuring 'HA Ports' (also known as Floating IP) in the load balancer rule?
Show answer details
Correct answer: B
HA Ports with Floating IP enabled is the mechanism for Direct Server Return (DSR). It ensures that the destination IP address of the incoming packet (the load balancer's frontend IP) is preserved when it's sent to the backend FortiGate. This allows the FortiGate to process the traffic and respond directly to the client, bypassing the load balancer on the return path, which is essential for preserving session state and proper routing in HA NVA scenarios.
- 3
An administrator is configuring an SD-WAN between an on-premises FortiGate and a FortiGate-VM in AWS using TGW Connect. They notice that BGP peering is established, but routes from on-premises are not appearing in the spoke VPC route tables. The TGW route table associated with the security VPC shows the on-premises routes correctly. What is the most likely missing configuration step?
Show answer details
Correct answer: C
In AWS TGW, routes are not automatically shared between different route tables or attachments. For the spoke VPCs to learn the routes coming from the on-premises connection (via the security VPC), you must explicitly enable route propagation from the security VPC's TGW attachment into the TGW route table that is associated with the spoke VPC attachments. This missing step is a common cause for this exact symptom.
- 4
A security administrator has configured an Azure SDN connector on a FortiGate to create dynamic address objects based on Azure resource tags. A new web server VM is deployed in Azure with the tag
Role:WebServer. However, the VM's private IP address is not appearing in the corresponding dynamic address group on the FortiGate. The fabric connector status shows as connected and up-to-date. What is the most likely misconfiguration?Show answer details
Correct answer: B
The SDN connector uses filters to determine which tagged resources to import. If the dynamic address group is not being populated, it's highly probable that the filter criteria (e.g.,
Tag.Role eq 'WebServer') defined in the FortiGate's SDN connector settings are incorrect, misspelled, or do not match the exact tag applied to the Azure VM. The connector itself might be working, but it is not being instructed to import this specific resource. - 5
Case Study:
A multinational corporation, GlobalLogix, is centralizing its IT infrastructure in Azure. They have deployed an Azure Virtual WAN (vWAN) with a secured hub in their primary region. The secured hub contains a FortiGate-VM active-passive HA pair acting as the central Network Virtual Appliance (NVA) for all traffic inspection.
GlobalLogix has hundreds of branch offices connected to the vWAN via site-to-site VPNs. They also have several spoke VNets for different application environments (Prod, Dev, QA). The security policy mandates that all spoke-to-spoke VNet traffic must be inspected by the FortiGate NVA. Additionally, all traffic from branch offices destined for the Prod VNet must also be inspected by the FortiGate NVA, but traffic from branches to the Dev VNet can be routed directly.
To achieve this, the cloud team has configured custom route tables within the vWAN hub. The Prod VNet connection is associated with a route table named 'RT_INSPECT', while the Dev VNet connection is associated with the 'default' route table. The branch VPN connections are also associated with the 'default' route table.
What configuration is required in the 'RT_INSPECT' and 'default' route tables to enforce the specified traffic flows?
graph TD subgraph Azure Cloud subgraph vWAN Hub FG[FortiGate NVA HA Pair] RT_DEFAULT[Default Route Table] RT_INSPECT[RT_INSPECT Route Table] end subgraph Spoke VNets PROD[Prod VNet] DEV[Dev VNet] end end Branches[Branch Offices] -->|VPN| vWAN Hub vWAN Hub -- Association --> PROD vWAN Hub -- Association --> DEV PROD -- Association --> RT_INSPECT DEV -- Association --> RT_DEFAULT Branches -- Association --> RT_DEFAULTShow answer details
Correct answer: C
This configuration correctly enforces the policies. In 'RT_INSPECT' (used by the Prod VNet), static routes for all other destinations (other spokes, branches) pointing to the FortiGate ensure all its outbound traffic is inspected. In 'default' (used by branches and Dev), a specific static route for the Prod VNet CIDR pointing to the FortiGate ensures branch-to-prod traffic is inspected, while propagating routes from the Dev VNet allows direct branch-to-dev traffic, fulfilling all requirements.
- 6
A financial services firm is deploying a FortiGate-VM High Availability (HA) cluster in Azure using Terraform. To meet compliance requirements, all HA-related traffic, including FGCP heartbeat packets, must be isolated on a dedicated subnet. The lead architect has mandated that the Azure Load Balancer health probe must target a specific, non-standard port on the FortiGate's internal interface to monitor service health. Which Terraform resource and attribute is essential for configuring this custom health probe port?
Show answer details
Correct answer: C
The
azurerm_lb_probeTerraform resource is specifically designed to define the health probe used by an Azure Load Balancer. Theportattribute within this resource allows the administrator to specify the exact TCP or HTTP port that the probe will use to check the health of backend instances, such as the FortiGate-VMs. This is the correct way to configure a custom port for health monitoring in an Azure HA setup. - 7
A healthcare provider is automating the deployment of a multi-VPC environment in AWS using Terraform. The architecture requires a centralized security VPC with a FortiGate-VM auto-scaling group for egress traffic inspection. A critical requirement is that newly launched FortiGate instances must automatically register with a central FortiManager and retrieve their base configuration without manual intervention. How can this be achieved in the Terraform configuration?
Show answer details
Correct answer: C
The most secure and scalable method for auto-scaling groups is to use an
aws_launch_template. Theuser_datascript within the launch template can be configured to run at boot. This script should securely fetch the FortiManager IP and registration credentials from a service like AWS Secrets Manager, then use the FortiGate CLI commandexecute fgfm-regto initiate registration. This avoids hardcoding secrets and allows for dynamic, secure bootstrapping of new instances. - 8
A DevOps engineer is using an Ansible playbook to manage a fleet of FortiGate-VMs in Azure. The playbook needs to idempotently create a new firewall address object. Which combination of Ansible module and parameters is the correct approach to ensure the object is created only if it doesn't exist, and left unchanged if it already exists with the correct configuration?
Show answer details
Correct answer: A
The
fortios_firewall_addressmodule is the correct tool for managing firewall address objects. Usingstate: presentensures idempotency. If the named address object does not exist, Ansible will create it. If it already exists with the specified parameters, Ansible will report 'ok' and make no changes. If it exists but has different parameters, Ansible will update it to match the playbook definition and report 'changed'. - 9
A retail company has deployed a FortiGate-VM in AWS to inspect traffic between their on-premises data center and multiple spoke VPCs, connected via an AWS Transit Gateway (TGW). The security team observes that traffic from a specific on-premises subnet (10.10.20.0/24) to a spoke VPC (192.168.1.0/24) is being dropped. All other traffic flows correctly. A packet capture on the FortiGate shows the traffic arriving on the internal interface but not leaving the external interface. Which is the most likely cause of this issue?
Show answer details
Correct answer: B
Since the packet capture shows traffic arriving but not leaving the FortiGate, the issue is likely within the FortiGate's configuration. For the FortiGate to route traffic to the spoke VPC, it must have a route in its routing table for that destination. In a TGW environment, this route should point to the TGW as the next hop. A missing static route for 192.168.1.0/24 would cause the FortiGate to drop the packets, as it wouldn't know where to send them.
- 10
An organization is using FortiCNP to monitor its AWS environment. A security analyst receives a high-priority alert indicating a publicly accessible S3 bucket contains files with sensitive data patterns (e.g., credit card numbers). According to Fortinet best practices, what are the most effective immediate mitigation steps the analyst should take using FortiCNP's capabilities? (Select TWO)
Show answer details
Correct answer: B, D
FortiCNP provides actionable remediation guidance, often including specific CLI commands or console steps to fix misconfigurations. This is a primary feature for mitigating identified risks.
A key benefit of FortiCNP is its ability to automate remediation. Setting up a workflow to automatically correct common, high-risk misconfigurations like public S3 buckets is a best practice for immediate risk mitigation.
