NSE7_PBC-7.2 Exam Details

  • Exam Code
    :NSE7_PBC-7.2
  • Exam Name
    :Fortinet NSE 7 - Public Cloud Security 7.2
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :59 Q&As
  • Last Updated
    :Jan 13, 2026

Fortinet NSE7_PBC-7.2 Online Questions & Answers

  • Question 1:

    Refer to Exhibit: The exhibit shows the Connect Peers settings on Amazon Web Services (AWS) transit gateway attachments With two FortiGate VMS in a security VPC.

    Which two statements are correct? (Choose two.)

    A. The peer GRE address is the FortiGate external interface IP address.
    B. The Transit Gateway GRE address is auto-generated
    C. The BGP inside CIDR blocks can be any CIDR block with /29
    D. The Peer GRE address is the FortiGate internal interface IP address

  • Question 2:

    Refer to the exhibit

    An administrator deployed a FortiGate-VM in a high availability (HA)

    (active/passive) architecture in Amazon Web Services (AWS) using Terraform

    for testing purposes. At the same time, the administrator deployed a single

    Linux server using AWS Marketplace

    Which two options are available for the administrator to delete all the resources

    created in this test? (Choose two.)

    A. Use the terraform destroy command
    B. Use the terraform validate command.
    C. Use the terraform destroy all command.
    D. The administrator must manually delete the Linux server.

  • Question 3:

    You are asked to find a solution to replace the existing VPC peering topology to have a higher bandwidth connection from Amazon Web Services (AWS) to the on-premises data center Which two solutions will satisfy the requirement? (Choose two.)

    A. Use ECMP and VPN to achieve higher bandwidth.
    B. Use transit VPC to build multiple VPC connections to the on-premises data center
    C. Use a transit VPC with hub and spoke topology to create multiple VPN connections to the on-premises data center.
    D. Use the transit gateway attachment With VPN option to create multiple VPN connections to the on-premises data center

  • Question 4:

    You are tasked with deploying a FortiGate HA solution in Amazon Web Services (AWS) using Terraform What are two steps you must take to complete this deployment? (Choose two.)

    A. Enable automation on the AWS portal.
    B. Create an AWS Identity and Access Management (IAM) user With permissions.
    C. Use CloudSheIl to install Terraform.
    D. Create an AWS Active Directory user with permissions.

  • Question 5:

    Which two Amazon Web Services (AWS) features support east-west traffic inspection within the AWS cloud by the FortiGate VM? (Choose two.)

    A. A NAT gateway with an EIP
    B. A transit gateway with an attachment
    C. An Internet gateway with an EIP
    D. A transit VPC

  • Question 6:

    Refer to the exhibit

    You attempted to access the Linux1 EC2 instance directly from the internet using its public IP address in AWS.

    However, your connection is not successful.

    Given the network topology, what can be the issue?

    A. There is no connection between VPC A and VPC
    B. There is no elastic IP address attached to FortiGate in the Security VPC.
    C. The Transit Gateway BGP IP address is incorrect.
    D. There is no internet gateway attached to the Spoke VPC A.

  • Question 7:

    A Network security administrator is searching for a solution to secure traffic going in and out of the container infrastructure.

    In which two ways can Fortinet container security help secure container infrastructure?(Choose two.)

    A. FortiGate NGFW can be placed between each application container for north-south traffic inspection
    B. FortiGate NGFW can connect to the worker node and protects the container-
    C. FortiGate NGFW can inspect north-south container traffic with label aware policies
    D. FortiGate NGFW and FortiSandbox can be used to secure container traffic

  • Question 8:

    What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

    A. It eliminates the use of ECMP
    B. You can use GRE-based tunnel attachments
    C. You can combine it with IPsec to achieve higher bandwidth
    D. You can use BGP over IPsec for maximum throughput

  • Question 9:

    You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications reside, with minimum traffic cost

    Which solution meets the requirements?

    A. Use FortiADC
    B. Use FortiCNP
    C. Use FortiWebCloud
    D. Use FortiGate

  • Question 10:

    How does the immutable infrastructure strategy work in automation?

    A. It runs a single live environment for configuration changes.
    B. It runs one idle and a single live environment for configuration changes.
    C. It runs two live environments for configuration changes.
    D. It runs one idle and two live environments for configuration changes.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your NSE7_PBC-7.2 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.