NSE 7 - Public Cloud Security 6.4

Here you have the best Fortinet NSE7_PBC-6.4 practice exam questions

  • You have 30 total questions to study from
  • Each page has 5 questions, making a total of 6 pages
  • You can navigate through the pages using the buttons at the bottom
  • This questions were last updated on November 14, 2024
Question 1 of 30

When configuring the FortiCASB policy, which three configuration options are available? (Choose three.)

    Correct Answer: B, C, D

    When configuring the FortiCASB policy, three configuration options available are threat protection policies, data loss prevention policies, and compliance policies. These settings enable users to effectively manage security measures for cloud applications by taking proactive steps to prevent threats, safeguard sensitive data, and adhere to industry and regulatory compliance requirements.

Question 2 of 30

You have been tasked with deploying FortiGate VMs in a highly available topology on the Amazon Web Services (AWS) cloud. The requirements for your deployment are as follows:

* You must deploy two FortiGate VMs in a single virtual private cloud (VPC), with an external elastic load balancer which will distribute ingress traffic from the internet to both FortiGate VMs in an active-active topology.

* Each FortiGate VM must have two elastic network interfaces: one will connect to a public subnet and other will connect to a private subnet.

* To maintain high availability, you must deploy the FortiGate VMs in two different availability zones.

How many public and private subnets will you need to configure within the VPC?

    Correct Answer: C

    To deploy FortiGate VMs in an active-active high availability topology on AWS, you need to ensure that each VM is placed in a different availability zone to maintain high availability. Each FortiGate VM requires two elastic network interfaces: one connected to a public subnet and one connected to a private subnet. Since the deployment spans two availability zones, each zone must have both a public and a private subnet. Therefore, you will need two public subnets and two private subnets to meet the deployment requirements.

Question 3 of 30

You are deploying Amazon Web Services (AWS) GuardDuty to monitor malicious or unauthorized behaviors related to AWS resources. You will also use the

Fortinet aws-lambda-guardduty script to translate feeds from AWS GuardDuty findings into a list of malicious IP addresses. FortiGate can then consume this list as an external threat feed.

Which Amazon AWS services must you subscribe to in order to use this feature?

    Correct Answer: B

    To use this feature, you must subscribe to GuardDuty for detecting threats, CloudWatch for monitoring and triggering the lambda function, S3 for storing and accessing the list of malicious IP addresses, and DynamoDB for storing state information or any other data needed by the script. These services collectively provide the necessary infrastructure to monitor, process, and store threat data effectively.

Question 4 of 30

Refer to the exhibit. A customer has deployed an environment in Amazon Web Services (AWS) and is now trying to send outbound traffic from the Web servers to the Internet. The FortiGate policies are configured to allow all outbound traffic; however, the traffic is not reaching the FortiGate internal interface.

What are two possible reasons for this behavior? (Choose two.)

    Correct Answer: A, D

    The web servers might not be configured with a default gateway, which is essential for the servers to route traffic correctly to external destinations. Additionally, AWS security groups may be blocking the necessary traffic. Security groups act as virtual firewalls and if they are not properly configured to allow outbound traffic, the web servers won't be able to reach the internet. These two issues are common causes for traffic not reaching the FortiGate internal interface.

Question 5 of 30

Refer to the exhibit. Your senior administrator successfully configured a FortiGate fabric connector with the Azure resource manager, and created a dynamic address object on the FortiGate VM to connect with a windows server in Microsoft Azure. However, there is now an error on the dynamic address object, and you must resolve the issue.

How do you resolve this issue?

    Correct Answer: B

    The error on the dynamic address object likely arises because the correct tag values for the Windows server were not set in the Microsoft Azure portal. This dynamic address object is supposed to resolve dynamically based on the tags assigned to resources in Azure. If the tags are incorrect or missing, the FortiGate cannot match the address object appropriately. Therefore, setting the correct tag values for the Windows server in the Azure portal will resolve the issue, ensuring that the dynamic address object can be resolved accurately.