NSE7_PBC-7.2 Exam Details

  • Exam Code
    :NSE7_PBC-7.2
  • Exam Name
    :Fortinet NSE 7 - Public Cloud Security 7.2
  • Certification
    :Fortinet Certifications
  • Vendor
    :Fortinet
  • Total Questions
    :59 Q&As
  • Last Updated
    :May 25, 2026

Fortinet NSE7_PBC-7.2 Online Questions & Answers

  • Question 21:

    Refer to the exhibit Consider the active-active load balance sandwich scenario in Microsoft Azure.

    What are two important facts in the active-active load balance sandwich scenario? (Choose two )

    A. It uses the vdom-exception command to exclude the configuration from being synced
    B. It is recommended to enable NAT on FortiGate policies.
    C. It uses the FGCP protocol
    D. It supports session synchronization for handling asynchronous traffic.

  • Question 22:

    Refer to the exhibit.

    You deployed an HA active-active load balance sandwich with two FortiGate VMs in Microsoft Azure.

    After the deployment, you prefer to use FGSP to synchronize sessions, and allowasymmetric return traffic In the environment, FortiGate port 1 and port 2 are facing external and internal load balancers respectively

    What IP address must you use in the peerip configuration?

    A. The opposite FortiGate port 1 IP address.
    B. The public load balancer port 2 IP address
    C. The internal load balancer port 1 IP address.
    D. The opposite FortiGate port 2 IP address.

  • Question 23:

    Which two statements are true about Transit Gateway Connect peers in anlPv4 BGP configuration'? (Choose two.)

    A. The inside CIDR blocks are used for BGP peering
    B. You cannot use IPv6 addresses
    C. You must specify a /29CIDR block from the 169.254.0.0/16 range
    D. You must configure the second address from the IPv4 range on the device as the BGP IP address

  • Question 24:

    Which two Amazon Web Services (AWS) features do you use for the transit virtual private cloud (VPC) automation process to add new spoke N/PCs? (Choose two )

    A. Amazon S3 bucket
    B. AWS Security Hub
    C. AWS Transit Gateway
    D. Amazon CloudWatch

  • Question 25:

    Refer to the exhibit.

    You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP address. What could be the possible issue With this scenario?

    A. FortiGate port4 does not have internet access.
    B. A wrong client secret credential is used
    C. The error is caused by credential time expiration.
    D. The Azure service principle account must have a contributor role.

  • Question 26:

    An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure However, the SDN connector is failing on the connection What must the administrator do to correct this issue?

    A. Make sure to add the Tenant ID on FortiGate side of the configuration
    B. Make sure to set the type to system managed identity on FortiGate SDN connectorsettings
    C. Make sure to enable the system assigned managed identity on Azure
    D. Make sure to add the Client secret on FortiGate side of the configuration

  • Question 27:

    You are adding more spoke VPCs to an existing hub and spoke topology Your goal is to finish this task in the minimum amount of time without making errors.

    Which Amazon AWS services must you subscribe to accomplish your goal?

    A. GuardDuty, CloudWatch
    B. WAF, DynamoDB
    C. Inspector, S3
    D. CloudWatch, S3

  • Question 28:

    You are tasked with deploying a FortiGate HA solution in Amazon Web Services (AWS) using Terraform What are two steps you must take to complete this deployment? (Choose two.)

    A. Enable automation on the AWS portal.
    B. Create an AWS Identity and Access Management (IAM) user With permissions.
    C. Use CloudSheIl to install Terraform.
    D. Create an AWS Active Directory user with permissions.

  • Question 29:

    A customer would like to use FortiGate fabric integration With FortiCNP

    When configuring a FortiGate VM to add to FortiCNP, which three mandatory configuration steps must you follow on FortiGate? (Choose three.)

    A. Enable send logs-
    B. Create and IPS sensor and a firewall policy
    C. Create an IPsec tunnel.
    D. Create an SSL]SSH inspection profile.
    E. Enable two-factor authentication.

  • Question 30:

    You need a solution to safeguard public cloud-hosted web applications from the OWASP Top 10 vulnerabilities. The solution must support the same region in which your applications reside, with minimum traffic cost

    Which solution meets the requirements?

    A. Use FortiADC
    B. Use FortiCNP
    C. Use FortiWebCloud
    D. Use FortiGate

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your NSE7_PBC-7.2 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.