NSE7-PBC-7-2 Sample Questions & Answers
Deploying FortiGate through a transit VPC and gateway, plus container-security solutions, carries the biggest weight, alongside Terraform and Ansible automation with Azure concepts, and fixing AWS EC2, SD-WAN, or Azure SDN connectivity problems.
Launch the full NSE7-PBC-7-2 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Troubleshooting and FortiCNP · Troubleshoot Azure SDN connectors
True or False: When using the Azure SDN Connector on a FortiGate-VM, it is mandatory to assign an Azure AD Managed Identity to the VM for the connector to dynamically pull metadata about Azure resources.
Show answer & explanation
Correct answer: B
While using a Managed Identity is the recommended and most secure method, the Azure SDN Connector also supports authentication using a Service Principal with a client ID and secret. Therefore, it is not mandatory to use a Managed Identity, although it is a best practice.
- Question 2IntermediateSelect 2
FortiGate Deployments in Public Cloud · Deploy transit VPC and transit gateway
A global logistics company is designing a secure network architecture in AWS. They are using an AWS Transit Gateway (TGW) to connect hundreds of VPCs across multiple regions. They plan to deploy a centralized security VPC in each region, containing a FortiGate-VM HA pair to inspect all inter-VPC and VPC-to-internet traffic. To maintain traffic isolation between different business units (e.g., Shipping, Warehousing, Finance), which two TGW features are essential to implement? (Select TWO)
Show answer & explanation
Correct answers: B, C
Multiple TGW route tables are fundamental to creating separate routing domains. Each business unit's VPC attachments can be associated with a specific route table, and propagation can be controlled to ensure traffic is isolated and only routed where intended (e.g., to the security VPC).
Controlling route table association (which route table an attachment uses) and propagation (which attachments dynamically propagate their routes into a route table) is the core mechanism for enforcing traffic isolation and directing traffic flows within the TGW.
- Question 3Advanced
FortiGate Deployments in Public Cloud · Explain Fortinet container security solutions
A media streaming company is deploying a containerized application on Azure Kubernetes Service (AKS). To secure east-west traffic between pods, they have deployed FortiGate CNF. A security requirement states that all traffic from pods in the 'frontend' namespace to pods in the 'database' namespace must be inspected for SQL injection attacks. Which FortiGate CNF feature should be used to achieve this specific requirement?
Show answer & explanation
Correct answer: B
FortiGate CNF integrates with the Kubernetes API to understand its objects. The correct way to enforce this policy is to create a firewall policy within FortiGate CNF that uses Kubernetes labels or service objects to define the 'frontend' namespace as the source and the 'database' namespace as the destination. Applying an Intrusion Prevention System (IPS) profile to this policy will enable the inspection for SQL injection attacks.
- Question 4Beginner
FortiGate Deployments in Public Cloud · Configure SD-WAN transit gateway connect
When configuring an SD-WAN using AWS Transit Gateway (TGW) Connect, what is the primary purpose of the GRE tunnel that is established between the FortiGate-VM and the TGW?
Show answer & explanation
Correct answer: B
The GRE (Generic Routing Encapsulation) tunnel in a TGW Connect setup serves as a transport layer. Its primary function is to encapsulate and carry the packets of a dynamic routing protocol, specifically BGP, between the customer's SD-WAN appliance (FortiGate) and the Transit Gateway. This allows for dynamic exchange of routes, which is a core benefit of TGW Connect over static TGW attachments. GRE itself does not provide encryption.
- Question 5Advanced
FortiGate Deployments in Public Cloud · Integrate FortiGate with Azure Vwan
A large enterprise has established a global network using Azure Virtual WAN (vWAN). They have deployed a FortiGate-VM as a Network Virtual Appliance (NVA) in the vWAN hub for centralized security inspection. An architect needs to ensure that all traffic from a spoke VNet destined for the internet is routed through the FortiGate NVA. What is the correct way to configure this routing in Azure?
Show answer & explanation
Correct answer: B
In an Azure Virtual WAN architecture, routing for spoke VNets is controlled by the hub's route tables. To force internet-bound traffic through the NVA, you must edit the effective route table associated with the spoke VNet connection (often the 'default' route table). You would add a static route for 0.0.0.0/0 and set the next hop to the specific vWAN connection corresponding to the FortiGate NVA. UDRs in the spoke VNet are not the primary mechanism for this in a vWAN hub scenario.
- Question 6Beginner
Automation · Describe automation infrastructure
A cloud architect is designing an Infrastructure as Code (IaC) strategy for a multi-cloud environment using Fortinet products. The goal is to provision the underlying network infrastructure (VPCs, subnets, etc.) and then, in a separate process, configure the already-running FortiGate instances. Which combination of tools aligns best with this two-phase approach?
Show answer & explanation
Correct answer: B
This is a widely-accepted best practice. Terraform excels at declarative infrastructure provisioning and managing the state of cloud resources (the 'what'). Ansible is a procedural configuration management tool that excels at configuring software and devices once they are running (the 'how'). Using Terraform for the initial build-out and Ansible for the detailed configuration of the FortiGates leverages the core strengths of each tool.
- Question 7Beginner
Automation · Explain Azure security concepts
When defining an Azure Network Security Group (NSG) in a Terraform configuration to be associated with a FortiGate-VM's network interface, what is the primary difference between an
inbound_ruleand anoutbound_rule?Show answer & explanation
Correct answer: A
Azure NSGs are stateful firewalls that filter traffic at the network interface or subnet level. An
inbound_ruledefines the permissions for traffic arriving at the network interface from external sources. Anoutbound_ruledefines permissions for traffic leaving the network interface, initiated from the VM itself. Both are crucial for controlling access to and from the FortiGate. - Question 8Intermediate
Automation · Explain routing and restrictions in public cloud
True or False: In both AWS and Azure, the longest prefix match is the rule used to determine which route in a route table is used to forward a packet.
Show answer & explanation
Correct answer: A
This statement is true. Both AWS VPC route tables and Azure VNet route tables use the principle of longest prefix match. When a packet's destination IP address matches multiple route entries, the cloud platform will always choose the route with the most specific (longest) CIDR prefix. For example, a route to 10.0.1.0/24 will be preferred over a route to 10.0.0.0/16 for a packet destined to 10.0.1.5.
- Question 9Intermediate
Automation · Deploying FortiGate-VM with automation tools
A systems administrator is troubleshooting a newly deployed FortiGate-VM in AWS. The instance was deployed using a standard Terraform script. The administrator can connect to the public IP via SSH but cannot access the HTTPS management GUI. All other instances in the same public subnet are accessible via HTTPS. What is the most likely reason for this issue?
Show answer & explanation
Correct answer: C
Since SSH (port 22) is working, basic connectivity to the instance exists. The issue is specific to the HTTPS protocol (port 443). The most common cause for this is a missing inbound rule in the instance's security group. Security groups are stateful firewalls that control traffic at the ENI level, and by default, they deny all inbound traffic unless explicitly allowed.
- Question 10Advanced
Automation · Deploy Fortinet solutions in AWS using Terraform
An engineer is writing a Terraform plan to deploy an active-passive FortiGate HA pair in AWS. To enable the failover mechanism, a secondary private IP address must be assigned to the primary FortiGate's external network interface. This IP will be moved to the secondary instance upon failover. Which Terraform resource and argument should be used to assign this secondary IP?
Show answer & explanation
Correct answer: C
In AWS, secondary private IPs are properties of the Elastic Network Interface (ENI), not the EC2 instance itself. The correct approach in Terraform is to define an
aws_network_interfaceresource and use theprivate_ipsargument (which accepts a list of strings) to specify one or more secondary private IP addresses. This ENI is then attached to the primary FortiGate instance.
Ready for the real thing?
The full NSE7-PBC-7-2 simulator has every exam-style question, timed mode, and instant scoring.