Skip to content

NSE7-PBC-7.6 Public Cloud Security 7.6 Practice Questions

Prepare for NSE7-PBC-7.6 with more than an answer.

157 questions in the full set12 sample questionsUpdated Oct 8, 2026

Unlock the full exam and previous versions

  • v1Public Cloud Security 7.6 157 questions Current
  • NSE7-PBC-7-2Legacy Fortinet NSE 7 - Public Cloud Security 7.2 264 questions Locked
  1. 1

    In Fortinet's official repository for AWS CloudFormation templates, the template file specifically designed to deploy an autoscale cluster directly integrated with an AWS Transit Gateway in a newly created VPC is named _____.

    Show answer details

    Correct answer: D

    Fortinet publishes three main autoscale templates in the release package: 'autoscale-new-vpc.template.yaml', 'autoscale-existing-vpc.template.yaml', and 'autoscale-tgw-new-vpc.template.yaml'. The template designated for deploying a new VPC with an autoscale cluster attached to AWS Transit Gateway is 'autoscale-tgw-new-vpc.template.yaml'.

  2. 2

    An enterprise security architect is designing ingress traffic inspection for public-facing web applications in AWS. The architecture separates workloads into an Application Customer VPC and a centralized Security VPC hosting FortiGate-VM instances behind an AWS Gateway Load Balancer (GWLB). To inspect inbound traffic originating from the Internet before it reaches application workloads, how must the Customer VPC route tables be configured?

    graph TD Internet((Internet)) --> IGW[Customer VPC IGW] subgraph Customer VPC IGW -->|Edge Association| IngressRT[Edge Ingress Route Table] IngressRT -->|App Subnet CIDRs -> GWLBe| GWLBe[GWLB Endpoint] AppSubnet[Application Subnet] -->|Default Route 0.0.0.0/0| GWLBe end subgraph Security VPC GWLBe -.->|Geneve Tunnel| GWLB[Gateway Load Balancer] GWLB --> FGT[FortiGate-VM Inspection Cluster] end
    Show answer details

    Correct answer: B

    To inspect inbound traffic destined for subnets inside a Customer VPC using GWLB, AWS utilizes Ingress Routing (Edge Associations). An ingress route table is attached to the Internet Gateway, directing traffic for specific application subnet CIDRs to the local GWLB endpoints (GWLBe). In turn, the application subnet route table points its default route (0.0.0.0/0) back to the GWLBe, ensuring symmetric return path inspection through FortiGate.

  3. 3

    A network security engineer is configuring a FortiGate-VM instance to inspect packet flows forwarded by an AWS Gateway Load Balancer (GWLB). The Geneve tunnel interface is established on port2, but the GWLB target group health checks persistently report the FortiGate instance as Unhealthy. Network security groups allow TCP/HTTP traffic on all ports. Which configuration on FortiGate port2 is required to successfully respond to GWLB health checks?

    Show answer details

    Correct answer: D

    AWS GWLB sends health check probes directly to the FortiGate network interface (port2) associated with the target group. In FortiOS, interface management access must include 'probe-response' under 'allowaccess' so that the built-in HTTP health check daemon responds successfully to GWLB health probes.

  4. 4

    A cloud infrastructure engineer deploys a FortiGate-VM instance on AWS using a Bring Your Own License (BYOL) VM08 license. Due to specific memory and networking bandwidth requirements, the engineer provisions an Amazon EC2 c5.4xlarge instance type, which provides 16 vCPUs. How does FortiOS handle the compute resources on this instance?

    Show answer details

    Correct answer: A

    Under FortiOS licensing rules for FortiGate-VM, if a virtual machine instance is provisioned with more vCPUs than authorized by the installed license (such as assigning 16 vCPUs to a VM08 license), FortiOS caps its compute resource usage to the licensed limit. It actively uses only eight vCPUs for traffic inspection and management tasks while ignoring the surplus compute resources, allowing the firewall to remain fully operational without triggering license violation shutdowns.

  5. 5

    An administrator deploys an on-demand (PAYG) FortiGate-VM into an isolated management subnet in AWS that initially lacks direct outbound Internet connectivity. After updating the route table and security groups to permit outbound HTTPS connections to directregistration.fortinet.com, the instance remains in a temporary license state. Which CLI command must the administrator execute on the FortiGate to immediately contact FortiCloud and activate the official license?

    Show answer details

    Correct answer: D

    When an on-demand (PAYG) FortiGate-VM is provisioned in an environment without initial access to FortiCloud, it generates a temporary local license to allow bootstrapping. Once routing and security group rules allow connectivity to https://directregistration.fortinet.com/, running 'execute vm-license' manually initiates contact with FortiCloud to retrieve and activate the official cloud marketplace license.

  6. 6

    When integrating the FortiWeb Ingress Controller 1.0.1 with an Amazon EKS cluster to protect containerized microservices, which ingressClassName must be defined within the Kubernetes Ingress resource, and which core FortiWeb objects are automatically provisioned upon reconciliation?

    Show answer details

    Correct answer: B

    The FortiWeb Ingress Controller listens specifically for Kubernetes Ingress resources associated with the IngressClass name 'fwb-ingress-controller'. When reconciling these resources, the controller communicates with the FortiWeb appliance via REST API to automatically create and update the virtual server, content routing, and real server pool objects.

Create an account to continue.