NSE 7 - Public Cloud Security 6.4

Here you have the best Fortinet NSE7_PBC-6.4 practice exam questions

  • You have 30 total questions across 6 pages (5 per page)
  • These questions were last updated on March 14, 2026
  • This site is not affiliated with or endorsed by Fortinet.
Question 1 of 30

When configuring the FortiCASB policy, which three configuration options are available? (Choose three.)
Answer

Suggested Answer

The suggested answer is B, C, D.

When configuring the FortiCASB policy, three configuration options available are threat protection policies, data loss prevention policies, and compliance policies. These settings enable users to effectively manage security measures for cloud applications by taking proactive steps to prevent threats, safeguard sensitive data, and adhere to industry and regulatory compliance requirements.

Community Votes8 votes
BCDSuggested
88%
ACE
13%
Question 2 of 30

You have been tasked with deploying FortiGate VMs in a highly available topology on the Amazon Web Services (AWS) cloud. The requirements for your deployment are as follows:
* You must deploy two FortiGate VMs in a single virtual private cloud (VPC), with an external elastic load balancer which will distribute ingress traffic from the internet to both FortiGate VMs in an active-active topology.
* Each FortiGate VM must have two elastic network interfaces: one will connect to a public subnet and other will connect to a private subnet.
* To maintain high availability, you must deploy the FortiGate VMs in two different availability zones.
How many public and private subnets will you need to configure within the VPC?
Answer

Suggested Answer

The suggested answer is C.

To deploy FortiGate VMs in an active-active high availability topology on AWS, you need to ensure that each VM is placed in a different availability zone to maintain high availability. Each FortiGate VM requires two elastic network interfaces: one connected to a public subnet and one connected to a private subnet. Since the deployment spans two availability zones, each zone must have both a public and a private subnet. Therefore, you will need two public subnets and two private subnets to meet the deployment requirements.

Community Votes9 votes
CSuggested
78%
A
22%
Question 3 of 30

You are deploying Amazon Web Services (AWS) GuardDuty to monitor malicious or unauthorized behaviors related to AWS resources. You will also use the
Fortinet aws-lambda-guardduty script to translate feeds from AWS GuardDuty findings into a list of malicious IP addresses. FortiGate can then consume this list as an external threat feed.
Which Amazon AWS services must you subscribe to in order to use this feature?
Answer

Suggested Answer

The suggested answer is B.

To use this feature, you must subscribe to GuardDuty for detecting threats, CloudWatch for monitoring and triggering the lambda function, S3 for storing and accessing the list of malicious IP addresses, and DynamoDB for storing state information or any other data needed by the script. These services collectively provide the necessary infrastructure to monitor, process, and store threat data effectively.

Community Votes7 votes
BSuggested
71%
A
29%
Question 4 of 30

Exam NSE7_PBC-6.4: Question 4 - Image 1
Refer to the exhibit. A customer has deployed an environment in Amazon Web Services (AWS) and is now trying to send outbound traffic from the Web servers to the Internet. The FortiGate policies are configured to allow all outbound traffic; however, the traffic is not reaching the FortiGate internal interface.
What are two possible reasons for this behavior? (Choose two.)
Answer

Suggested Answer

The suggested answer is A, D.

The web servers might not be configured with a default gateway, which is essential for the servers to route traffic correctly to external destinations. Additionally, AWS security groups may be blocking the necessary traffic. Security groups act as virtual firewalls and if they are not properly configured to allow outbound traffic, the web servers won't be able to reach the internet. These two issues are common causes for traffic not reaching the FortiGate internal interface.

Community Votes14 votes
CDMost voted
86%
ADSuggested
14%
Question 5 of 30

Exam NSE7_PBC-6.4: Question 5 - Image 1
Refer to the exhibit. Your senior administrator successfully configured a FortiGate fabric connector with the Azure resource manager, and created a dynamic address object on the FortiGate VM to connect with a windows server in Microsoft Azure. However, there is now an error on the dynamic address object, and you must resolve the issue.
How do you resolve this issue?
Answer

Suggested Answer

The suggested answer is B.

The error on the dynamic address object likely arises because the correct tag values for the Windows server were not set in the Microsoft Azure portal. This dynamic address object is supposed to resolve dynamically based on the tags assigned to resources in Azure. If the tags are incorrect or missing, the FortiGate cannot match the address object appropriately. Therefore, setting the correct tag values for the Windows server in the Azure portal will resolve the issue, ensuring that the dynamic address object can be resolved accurately.

Community Votes8 votes
BSuggested
63%
C
25%
A
13%

About the Fortinet NSE7_PBC-6.4 Certification Exam

About the Exam

The Fortinet NSE7_PBC-6.4 (NSE 7 - Public Cloud Security 6.4) validates your knowledge and skills. Passing demonstrates proficiency and can boost your career prospects in the field.

How to Prepare

Work through all 30 practice questions across 6 pages. Focus on understanding the reasoning behind each answer rather than memorizing responses to be ready for any variation on the real exam.

Why Practice Exams?

Practice exams help you familiarize yourself with the question format, manage your time, and reduce anxiety on the test day. Our NSE7_PBC-6.4 questions are regularly updated to reflect the latest exam objectives.