Pass the Fortinet NSE 7 Network Security Architect NSE7_PBC-7.2 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to Exhibit:

Question # 1

The exhibit shows the Connect Peers settings on Amazon Web Services (AWS) transit gateway attachments With two FortiGate VMS in a security VPC.

Which two statements are correct? (Choose two.)

Options:

A.

The peer GRE address is the FortiGate external interface IP address.


B.

The Transit Gateway GRE address is auto-generated


C.

The BGP inside CIDR blocks can be any CIDR block with /29


D.

The Peer GRE address is the FortiGate internal interface IP address


Expert Solution
Questions # 2:

An administrator would like to keep track of sensitive data files located in the Amazon Web Services (AWS) S3 bucket and protect it from malware. Which Fortinet product or feature should the administrator use?

Options:

A.

FortiCNP application control policies


B.

FortiCNP web sensitive polices


C.

FortiCNP DLP policies


D.

FortiCNP compliance scanning policies


Expert Solution
Questions # 3:

An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure However, the SDN connector is failing on the connection What must the administrator do to correct this issue?

Options:

A.

Make sure to add the Tenant ID on FortiGate side of the configuration


B.

Make sure to set the type to system managed identity on FortiGate SDN connector settings


C.

Make sure to enable the system assigned managed identity on Azure


D.

Make sure to add the Client secret on FortiGate side of the configuration


Expert Solution
Questions # 4:

Refer to the exhibit

Question # 4

You attempted to access the Linux1 EC2 instance directly from the internet using its public IP address in AWS.

However, your connection is not successful.

Given the network topology, what can be the issue?

Options:

A.

There is no connection between VPC A and VPC B.


B.

There is no elastic IP address attached to FortiGate in the Security VPC.


C.

The Transit Gateway BGP IP address is incorrect.


D.

There is no internet gateway attached to the Spoke VPC A.


Expert Solution
Questions # 5:

You are tasked with deploying a FortiGate HA solution in Amazon Web Services (AWS) using Terraform What are two steps you must take to complete this deployment? (Choose two.)

Options:

A.

Enable automation on the AWS portal.


B.

Create an AWS Identity and Access Management (IAM) user With permissions.


C.

Use CloudSheIl to install Terraform.


D.

Create an AWS Active Directory user with permissions.


Expert Solution
Questions # 6:

Which statement about immutable infrastructure in automation is true?

Options:

A.

It is the practice of deploying a new server for every configuration change


B.

It is the practice of modifying the existing server configuration after it is deployed


C.

It is the practice of deploying two parallel servers for high availability.


D.

It is the practice of applying hotfixes and OS patches after deployment


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

The exhibit shows an active-passive high availability FortiGate pair with external and internal Azure load balancers. There is no SDN connector used in this solution

Which configuration should the administrator implement?

Options:

A.

Lambda IP address with one static route.


B.

Probe IP address with two static routes


C.

Probe IP address with one BGP route


D.

Public load balancer IP address with two BGP routes.


Expert Solution
Questions # 8:

Refer to the exhibit.

Question # 8

What would be the impact of confirming to delete all the resources in Terraform?

Options:

A.

It destroys all the resources in the . tfvars file


B.

It destroys all the resources tied to the AWS Identity and Access Management (1AM) user.


C.

It destroys all the resources in the resource group


D.

It destroys all the resources in the state file.


Expert Solution
Questions # 9:

What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

Options:

A.

It eliminates the use of ECMP


B.

You can use GRE-based tunnel attachments


C.

You can combine it with IPsec to achieve higher bandwidth


D.

You can use BGP over IPsec for maximum throughput


Expert Solution
Questions # 10:

Your goal is to deploy resources in multiple places and regions in the public cloud using Terraform.

What is the most efficient way to deploy resources without changing much of the Terraform code?

Options:

A.

Use multiple terraform.tfvars files With a variables.tf file.


B.

Use the provider. tf file to add all the new values


C.

Install and configure two Terraform staging servers to deploy resources.


D.

Use the variable, tf file and edit its values to match multiple resources


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions