Fortinet NSE7_PBC-7.2 - Fortinet NSE 7 - Public Cloud Security 7.2 Exam
Page: 3 / 11
Total 53 questions
Question #11 (Topic: Exam A)
Which two statements are true about Transit Gateway Connect peers in aniPv4 BGP configuration? (Choose two.)
A. You cannot use IPv6 addresses.
B. The inside CIDR blocks are used for BGP peering.
C. You must configure the second address from the IPv4 range on the device as the BGP IP address.
D. You must specify a /29 CIDR block from the 169.254.0.0/16 range.
Answer: AD
Question #12 (Topic: Exam A)
Which statement about immutable infrastructure in automation is true?
A. It is the practice of deploying a new server for every configuration change.
B. It is the practice of deploying two parallel servers for high availability.
C. It is the practice of applying hotfixes and OS patches after deployment.
D. It is the practice of modifying the existing server configuration after it is deployed.
Answer: A
Question #13 (Topic: Exam A)
Refer to the exhibit.

You deployed an HA active-passive FortiGate VM in Microsoft Azure.
Which two statements regarding this particular deployment are true? (Choose two.)

You deployed an HA active-passive FortiGate VM in Microsoft Azure.
Which two statements regarding this particular deployment are true? (Choose two.)
A. Use the vdom-exception command to synchronize the configuration.
B. In this example, the configuration does not synchronize between the primary and secondary devices.
C. During the failover, the passive FortiGate issues API calls to Azure.
D. There is no SLA for API calls from Microsoft Azure.
Answer: BC
Question #14 (Topic: Exam A)
Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?
A. TGW can have multiple TGW route tables.
B. Both the TGW attachment and propagation must be in the same TGW route table.
C. The TGW default route table cannot be disabled.
D. A TGW attachment can be associated with multiple TGW route tables.
Answer: A
Question #15 (Topic: Exam A)
Refer to the exhibit.

You are deploying two FortiGate VMs in HA active-passive mode with load balancers in Microsoft Azure.
Which two statements are true in this load balancing scenario? (Choose two.)

You are deploying two FortiGate VMs in HA active-passive mode with load balancers in Microsoft Azure.
Which two statements are true in this load balancing scenario? (Choose two.)
A. A dedicated management interface can be used for load balancing.
B. The FortiGate public IP is the next-hop for all the traffic.
C. You must add a route to the Microsoft VIP used for the health check.
D. An internal load balancer listener is the next-hop for outgoing traffic.
Answer: CD