Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Fortinet > Fortinet Network Security Expert > NSE7_CDS_AR-7.6

NSE7_CDS_AR-7.6 Fortinet NSE 7 - Public Cloud Security 7.6.4 Architect Question and Answers

Question # 4

Refer to the exhibit.

An administrator deployed a FortiGate-VM in a high availability (HA) (active/passive) architecture in Amazon Web Services (AWS) using Terraform for testing purposes. At the same time, the administrator deployed a single Linux server using AWS Marketplace.

Which two options are available for the administrator to delete all the resources created in this test? (Choose two.)

A.

The administrator must manually delete the Linux server.

B.

Use the terraform destroy all command.

C.

Use the terraform destroy command.

D.

Use the terraform validate command.

Full Access
Question # 5

How does an administrator secure container environments in Amazon AWS from newly emerged security threats? (Choose one answer)

A.

Using Docker-related application control signatures.

B.

Using Amazon AWS-related application control signatures.

C.

Using distributed network-related application control signatures.

D.

Using Amazon AWS_S3-related application control signatures.

Full Access
Question # 6

How can the FortiCNAPP SmartFix feature assist security teams in handling vulnerabilities and code security?

A.

SmartFix can directly apply fixes to supported code repositories using APIs.

B.

SmartFix can suggest automated remediation steps for identified misconfigurations and vulnerabilities.

C.

SmartFix can aggregate multiple alerts into a single, prioritized view to reduce alert fatigue.

D.

SmartFix can list all possible versions with their known security issues and recommend the closest version that is free of vulnerabilities.

Full Access
Question # 7

Refer to the exhibit.

You are tasked to deploy a FortiGate VM with private and public subnets in Amazon Web Services (AWS). You examined the variables.tf file. Assume that all the other terraform files are in place. What will be the final result after running the terraform init and terraform apply commands? (Choose one answer)

A.

Terraform will not deploy a FortiGate VM.

B.

Terraform will deploy a FortiGate VM in the eu-West-1a availability zone without any subnets.

C.

Terraform will deploy a FortiGate VM in the eu-West-1 region with private and public subnets.

D.

Terraform will deploy a FortiGate VM in the eu-West-1a availability zone with two subnets and BYOL license.

Full Access
Question # 8

Refer to the exhibit.

In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet. However, your HTTPS connection to the FortiGate VM in the Customer VPC is not successful.

Also, you must ensure that the Customer VPC FortiGate VM sends all the outbound Internet traffic through the Security VPC.

How do you correct this issue with minimal configuration changes? (Choose three.)

A.

Add a route with your local internet public IP address as the destination and the internet gateway as the target.

B.

Add a route with your local internet public IP address as the destination and the transit gateway as the target.

C.

Add a route to the destination 0.0.0.0/0 with the transit gateway as the target.

D.

Deploy an internet gateway, associate an EIP with the Customer VPC private subnet, and then add a new route with destination 0.0.0.0/0 with the internet gateway as the target.

E.

Deploy an internet gateway, attach it to the Customer VPC, and then associate an EIP with the port1 of the FortiGate in the Customer VPC.

Full Access
Question # 9

Refer to the exhibit.

A team of AWS administrators is in the process of installing a FortiWeb ingress controller to protect containerized web applications in an Amazon Elastic Kubernetes Service (EKS) cluster. While customizing the manifest file shown in the exhibit, they realize that they do not know the correct value to enter in the fortiweb-login field.

How can they determine the correct value for this field?

A.

The correct value is the password of the FortiWeb admin account.

B.

They can find the expected value in the manifest file used to deploy the pods.

C.

They must create a Kubernetes secret with the kubectl command.

D.

They can refer to the output of the EKS cluster deployment.

Full Access
Question # 10

Refer to the exhibit.

An administrator used the what-if tool to preview the changes to an Azure Bicep file. What will happen if the administrator applies these changes in Azure? (Choose one answer)

A.

A new subnet will be added to vnet-002.

B.

The vnet-002 VNet will be renamed Production.

C.

The resulting VNet will have a single subnet.

D.

The VNet address space will be updated.

Full Access
Question # 11

Refer to the exhibit.

A senior administrator in a multinational organization needs to include a comment in the template shown in the exhibit to ensure that administrators from other regions change the EC2 instance size value to one that meets the requirements in their local deployments. How can the administrator add the comment in that section of the file? (Choose one answer)

A.

The administrator can run the aws cloudformation update-stack and include the comment.

B.

The administrator must update the AWSTemplateFormatVersion to a more current version.

C.

The administrator must convert the template to JSON format before adding the comment.

D.

The administrator can add the comment with the # character next to the InstanceType section.

Full Access
Question # 12

A customer would like to use FortiGate fabric integration with FortiCNP. When adding a FortiGate VM to FortiCNP, which three mandatory configuration steps must you follow on FortiGate? (Choose three answers)

A.

Enable pre-shared key on both sides.

B.

Import the FortiGate certificate into FortiCNP.

C.

Configure FortiGate to send logs to FortiCNP.

D.

Create an IPS sensor and a firewall policy.

E.

Create an SSL/SSH inspection profile.

Full Access
Question # 13

Refer to the exhibit.

You have deployed a Linux EC2 instance in Amazon Web Services (AWS) with the settings shown on the exhibit.

What next step must the administrator take to access this instance from the internet?

A.

Allocate an Elastic IP address and assign it to the instance.

B.

Create a VIP on FortiGate to allow access.

C.

Enable SSH and allocate it to the device.

D.

Configure the user name and password.

Full Access
Question # 14

Refer to the exhibit.

A FortiCNAPP administrator used the FortiCNAPP Explorer to reveal all hosts exposed to the internet that are running active packages with vulnerabilities of all severity levels. Why do only the first two results have an attack path? (Choose one answer)

A.

Attack paths are available only for AWS resources with public IP addresses.

B.

Attack paths are available only for AWS resources with high impact scores.

C.

Attack paths are available only for resources with potential multi-hop exposure.

D.

Attack paths are available only for resources that have critical vulnerabilities.

Full Access
Question # 15

You are automating configuration changes on one of the FortiGate VMs using Red Hat Ansible.

How does Red Hat Ansible connect to FortiGate to make the configuration change?

A.

It uses a FortiGate VIP.

B.

It uses an API.

C.

It uses SSH.

D.

It uses a YAML file.

Full Access
Question # 16

What is the main advantage of using SD-WAN Transit Gateway Connect over traditional SD-WAN?

A.

You can use BGP over IPsec for maximum throughput.

B.

You can combine it with IPsec to achieve higher bandwidth.

C.

It eliminates the use of ECMP.

D.

You can use GRE-based tunnel attachments.

Full Access
Question # 17

What are two main features in Amazon Web Services (AWS) network access control lists (NACLs)? (Choose two answers)

A.

NACLs are stateless, and inbound and outbound rules are used for traffic filtering.

B.

NACLs are tied to an instance.

C.

The default NACL is configured to allow all traffic.

D.

You cannot use NACLs and Security Groups at the same time.

Full Access
Question # 18

Refer to the exhibit.

An administrator is trying to deploy a FortiGate VM in Microsoft Azure using Terraform. However, during the configuration, the Azure client secret is no longer visible in the Azure portal.

How would the administrator obtain the Azure client secret to configure in Terraform?

A.

Log in to the Azure CLI as a power user to obtain the client secret.

B.

Create a new Azure account and assign it the Administrator role.

C.

Use the Terraform output file values to obtain the client secret.

D.

Create a new client secret and take note of it.

Full Access
Question # 19

Refer to the exhibit.

An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer. However, the connection is not successful, and at the same time FortiGate is not receiving any HTTPS or SSH traffic on its external interface.

What should the administrator check for a possible issue?

A.

Check the FortiGate instance ID.

B.

Check the FortiGate firewall policies.

C.

Check the debug flow for any network ACLs.

D.

Check the inbound rules of the security groups.

Full Access
Question # 20

An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure. However, the SDN connector is failing on the connection.

What must the administrator do to correct this issue?

A.

Make sure to add the Client secret on FortiGate side of the configuration.

B.

Make sure to add the Tenant ID on FortiGate side of the configuration.

C.

Make sure to enable the system assigned managed identity on Azure.

D.

Make sure to set the type to system managed identity on FortiGate SDN connector settings.

Full Access