[Jul 23, 2022] NSE7_PBC-6.4 Exam Brain Dumps – Study Notes and Theory [Q12-Q27]

Rate this post

[Jul 23, 2022] NSE7_PBC-6.4 Exam Brain Dumps – Study Notes and Theory

Pass Fortinet NSE7_PBC-6.4 Test Practice Test Questions Exam Dumps

Q12. Refer to the exhibit.

A customer has deployed an environment in Amazon Web Services (AWS) and is now trying to send outbound traffic from the Web servers to the Internet. The FortiGate policies are configured to allow all outbound traffic; however, the traffic is not reaching the FortiGate internal interface.
What are two possible reasons for this behavior? (Choose two.)

 
 
 
 

Q13. An organization deployed a FortiGate-VM in the Google Cloud Platform and initially configured it with two vNICs. Now, the same organization wants to add additional vNICs to this existing FortiGate-VM to support different workloads in their environment.
How can they do this?

 
 
 
 

Q14.

Refer to the exhibit. The exhibit shows a topology where multiple connections from clients to the same FortiGate-VM instance, regardless of the protocol being used, are required.
Which two statements are correct? (Choose two.)

 
 
 
 

Q15.

Refer to the exhibit. Your senior administrator successfully configured a FortiGate fabric connector with the Azure resource manager, and created a dynamic address object on the FortiGate VM to connect with a windows server in Microsoft Azure. However, there is now an error on the dynamic address object, and you must resolve the issue.
How do you resolve this issue?

 
 
 
 

Q16. Refer to the exhibit.

Consider an active-passive HA deployment in Microsoft Azure. The exhibit shows an excerpt from the passive FortiGate-VM node.
If the active FortiGate-VM fails, what are the results of the API calls made by the FortiGate named SSTENTAZFGT-0302? (Choose two.)

 
 
 
 

Q17. Which three properties are configurable Microsoft Azure network security group rule settings? (Choose three.)

 
 
 
 
 

Q18. Which statement about FortiSandbox in Amazon Web Services (AWS) is true?

 
 
 
 

Q19. You have been asked to secure your organization’s salesforce application that is running on Microsoft Azure, and find an effective method for inspecting shadow IT activities in the organization. After an initial investigation, you find that many users access the salesforce application remotely as well as on-premises.
Your goal is to find a way to get more visibility, control over shadow IT-related activities, and identify any data leaks in the salesforce application.
Which three steps should you take to achieve your goal? (Choose three.)

 
 
 
 
 

Q20. Which two statements about Amazon Web Services (AWS) networking are correct? (Choose two.)

 
 
 
 

Q21. You have been tasked with deploying FortiGate VMs in a highly available topology on the Amazon Web Services (AWS) cloud. The requirements for your deployment are as follows:
* You must deploy two FortiGate VMs in a single virtual private cloud (VPC), with an external elastic load balancer which will distribute ingress traffic from the internet to both FortiGate VMs in an active-active topology.
* Each FortiGate VM must have two elastic network interfaces: one will connect to a public subnet and other will connect to a private subnet.
* To maintain high availability, you must deploy the FortiGate VMs in two different availability zones.
How many public and private subnets will you need to configure within the VPC?

 
 
 
 

Q22. Customer XYZ has an ExpressRoute connection from Microsoft Azure to a data center. They want to secure communication over ExpressRoute, and to install an in-line FortiGate to perform intrusion prevention system (IPS) and antivirus scanning.
Which three methods can the customer use to ensure that all traffic from the data center is sent through FortiGate over ExpressRoute? (Choose three.)

 
 
 
 
 

Q23. You have previously deployed an Amazon Web Services (AWS) transit virtual private cloud (VPC) with a pair of FortiGate firewalls (VM04 / c4.xlarge) as your security perimeter. You are beginning to see high CPU usage on the FortiGate instances.
Which action will fix this issue?

 
 
 
 

Q24. Which three properties are configurable Microsoft Azure network security group rule settings? (Choose three.)

 
 
 
 
 

Q25. When configuring the FortiCASB policy, which three configuration options are available? (Choose three.)

 
 
 
 
 

Q26. When an organization deploys a FortiGate-VM in a high availability (HA) (active/active) architecture in Microsoft Azure, they need to determine the default timeout values of the load balancer probes.
In the event of failure, how long will Azure take to mark a FortiGate-VM as unhealthy, considering the default timeout values?

 
 
 
 

Q27.

Refer to the exhibit. Consider an active-passive HA deployment in Microsoft Azure. The exhibit shows an excerpt from the passive FortiGate-VM node.
If the active FortiGate-VM fails, what are the results of the API calls made by the FortiGate named SSTENTAZFGT-0302? (Choose two.)

 
 
 
 

Verified NSE7_PBC-6.4 dumps Q&As – NSE7_PBC-6.4 dumps with Correct Answers: https://www.real4dumps.com/NSE7_PBC-6.4_examcollection.html

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter the text from the image below