Certification Training for NSE7_PBC-6.4 Exam Dumps Test Engine [2021]
Oct 06, 2021 Step by Step Guide to Prepare for NSE7_PBC-6.4 Exam
NEW QUESTION 17
Refer to the exhibit.
The exhibit shows a topology where multiple connections from clients to the same FortiGate-VM instance, regardless of the protocol being used, are required.
Which two statements are correct? (Choose two.)
- A. The design shows an active-active FortiGate-VM architecture.
- B. The Cloud Load Balancer Session Affinity setting should be changed to CLIENT_IP.
- C. The Cloud Load Balancer Session Affinity setting should use the default value.
- D. The design shows an active-passive FortiGate-VM architecture.
Answer: A,B
NEW QUESTION 18
When configuring the FortiCASB policy, which three configuration options are available? (Choose three.)
- A. Data loss prevention policies
- B. Antivirus policies
- C. Compliance policies
- D. Threat protection policies
- E. Intrusion prevention policies
Answer: A,C,D
NEW QUESTION 19
Which two Amazon Web Services (AWS) topologies support east-west traffic inspection within the AWS cloud by the FortiGate VM? (Choose two.)
- A. A multiple VPC deployment utilizing a transit VPC topology
- B. A single VPC deployment with multiple subnets and a NAT gateway
- C. A multiple VPC deployment utilizing a transit gateway
- D. A single VPC deployment with multiple subnets
Answer: A,D
Explanation:
Explanation/Reference: https://www.fortinet.com/content/dam/fortinet/assets/white-papers/wp-aws-reference- architecture.pdf
NEW QUESTION 20
What is the bandwidth limitation of an Amazon Web Services (AWS) transit gateway VPC attachment?
- A. Up to 50 Gbps per attachment
- B. Up to 1 Gbps per attachment
- C. Up to 10 Gbps per attachment
- D. Up to 1.25 Gbps per attachment
Answer: D
NEW QUESTION 21
A company deployed a FortiGate-VM with an on-demand license using Amazon Web Services (AWS) Market Place Cloud Formation template. After deployment, the administrator cannot remember the default admin password.
What is the default admin password for the FortiGate-VM instance?
- A. The instance-ID value
- B. <blank>
- C. The admin password cannot be recovered and the customer needs to deploy the FortiGate-VM again.
- D. admin
Answer: A
NEW QUESTION 22
An Amazon Web Services (AWS) auto-scale FortiGate cluster has just experienced a scale-down event, terminating a FortiGate in availability zone C.
This has now black-holed the private subnet in this availability zone.
What action will the worker node automatically perform to restore access to the black-holed subnet?
- A. The worker node moves the virtual IP of the terminated FortiGate to a running FortiGate on the worker node's private subnet interface.
- B. The worker node modifies the route table applied to the black-holed subnet changing its default route to point to a running FortiGate on the worker node's private subnet interface.
- C. The worker node migrates the subnet to a different availability zone.
- D. The worker node applies a route table from a non-black-holed subnet to the black-holed subnet.
Answer: C
NEW QUESTION 23
You are deploying Amazon Web Services (AWS) GuardDuty to monitor malicious or unauthorized behaviors related to AWS resources. You will also use the Fortinet aws-lambda-guarddutyscript to translate feeds from AWS GuardDuty findings into a list of malicious IP addresses. FortiGate can then consume this list as an external threat feed.
Which Amazon AWS services must you subscribe to in order to use this feature?
- A. Inspector, Shield, GuardDuty, S3, and DynamoDB.
- B. WAF, Shield, GuardDuty, S3, and DynamoDB.
- C. GuardDuty, CloudWatch, S3, and DynamoDB.
- D. GuardDuty, CloudWatch, S3, Inspector, WAF, and Shield.
Answer: D
Explanation:
Explanation/Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/ed901ad2-4424-11e9-
94bf-00505692583a/FortiOS_6.2.0_AWS_Cookbook.pdf
NEW QUESTION 24 
Refer to the exhibit. Your senior administrator successfully configured a FortiGate fabric connector with the Azure resource manager, and created a dynamic address object on the FortiGate VM to connect with a windows server in Microsoft Azure. However, there is now an error on the dynamic address object, and you must resolve the issue.
How do you resolve this issue?
- A. In the Microsoft Azure portal, set the correct tag values for the windows server.
- B. In the Microsoft Azure portal, access the windows server, obtain the private IP address, and assign the IP address under the FortiGate-VM AzureLab address object.
- C. Delete the address object and recreate a new address object with the type set to FQDN.
- D. Run diagnose debug application azd -lon FortiGate.
Answer: B
Explanation:
Explanation
NEW QUESTION 25 
Refer to the exhibit. The exhibit shows a topology where multiple connections from clients to the same FortiGate-VM instance, regardless of the protocol being used, are required.
Which two statements are correct? (Choose two.)
- A. The design shows an active-active FortiGate-VM architecture.
- B. The Cloud Load Balancer Session Affinity setting should be changed to CLIENT_IP.
- C. The Cloud Load Balancer Session Affinity setting should use the default value.
- D. The design shows an active-passive FortiGate-VM architecture.
Answer: A,B
NEW QUESTION 26
Which two statements about Amazon Web Services (AWS) networking are correct? (Choose two.)
- A. Multicast traffic is not allowed.
- B. AWS DNS reserves the first host IP address of each subnet.
- C. 802.1q VLAN tags are allowed inside the same virtual private cloud.
- D. Proxy ARP entries are disregarded.
Answer: A,B
NEW QUESTION 27
You have been asked to secure your organization's salesforce application that is running on Microsoft Azure, and find an effective method for inspecting shadow IT activities in the organization. After an initial investigation, you find that many users access the salesforce application remotely as well as on-premises.
Your goal is to find a way to get more visibility, control over shadow IT-related activities, and identify any data leaks in the salesforce application.
Which three steps should you take to achieve your goal? (Choose three.)
- A. Use FortiGate, FortiGuard, and FortiAnalyzer solutions.
- B. Deploy and configure FortiCASB with a Fortinet FortiCASB subscription license.
- C. Deploy and configure FortiGate with Security Fabric solutions, and FortiCWP with a storage guardian advance license.
- D. Deploy and configure FortiCWP with a workload guardian license.
- E. Configure FortiCASB and set up access rights, privileges, and data protection policies.
Answer: A,B,E
NEW QUESTION 28
Which two statements about the Amazon Cloud Services (AWS) network access control lists (ACLs) are true? (Choose two.)
- A. Network ACLs support allow rules and deny rules.
- B. Network ACLs are stateful, and inbound and outbound rules are used for traffic filtering.
- C. Network ACLs must be manually applied to virtual network interfaces.
- D. Network ACLs are stateless, and inbound and outbound rules are used for traffic filtering.
Answer: A,D
NEW QUESTION 29
When an organization deploys a FortiGate-VM in a high availability (HA) (active/active) architecture in Microsoft Azure, they need to determine the default timeout values of the load balancer probes.
In the event of failure, how long will Azure take to mark a FortiGate-VM as unhealthy, considering the default timeout values?
- A. 20 seconds
- B. 16 seconds
- C. 30 seconds
- D. Less than 10 seconds
Answer: C
NEW QUESTION 30
An organization deployed a FortiGate-VM in the Google Cloud Platform and initially configured it with two vNICs. Now, the same organization wants to add additional vNICs to this existing FortiGate-VM to support different workloads in their environment.
How can they do this?
- A. They can use the Compute Engine API Explorer.
- B. They cannot create and add additional vNICs to an existing FortiGate-VM.
- C. They can create additional vNICs using the Cloud Shell.
- D. They can create additional vNICs in the UI console.
Answer: A
Explanation:
Explanation/Reference: https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/62d32ecf-687f-11ea-
9384-00505692583a/FortiOS-6.4-GCP_Cookbook.pdf
NEW QUESTION 31 
Refer to the exhibit. Consider an active-passive HA deployment in Microsoft Azure. The exhibit shows an excerpt from the passive FortiGate-VM node.
If the active FortiGate-VM fails, what are the results of the API calls made by the FortiGate named SSTENTAZFGT-0302? (Choose two.)
- A. 172.29.32.71is set as a next hop IP for all routes under FortigateUDR-01
- B. The network interface of the active unit moves to itself
- C. SSTENTAZFGT-03-FloatingPIP is assigned to the IP configuration with the name SSTENTAZFGT-
0302-Nic-01, under the network interface SSTENTAZFGT-0302-Nic-01 - D. SSTENTAZFGT-03-FloatingPIP public IP is assigned to NIC SSTENTAZFGT-0302-Nic-01
Answer: A,C
NEW QUESTION 32
Refer to the exhibit.
Your senior administrator successfully configured a FortiGate fabric connector with the Azure resource manager, and created a dynamic address object on the FortiGate VM to connect with a windows server in Microsoft Azure. However, there is now an error on the dynamic address object, and you must resolve the issue.
How do you resolve this issue?
- A. In the Microsoft Azure portal, set the correct tag values for the windows server.
- B. In the Microsoft Azure portal, access the windows server, obtain the private IP address, and assign the IP address under the FortiGate-VM AzureLab address object.
- C. Delete the address object and recreate a new address object with the type set to FQDN.
- D. Run diagnose debug application azd -l on FortiGate.
Answer: B
NEW QUESTION 33
Which three properties are configurable Microsoft Azure network security group rule settings? (Choose three.)
- A. Destination port ranges
- B. Source and destination IP ranges
- C. Source port ranges
- D. Action
- E. Sequence number
Answer: A,C,D
Explanation:
Explanation/Reference: https://docs.microsoft.com/en-us/azure/virtual-network/network-security-groups-overview
NEW QUESTION 34
......
Ultimate Guide to Prepare NSE7_PBC-6.4 Certification Exam for NSE 7 Network Security Architect: https://www.realvce.com/NSE7_PBC-6.4_free-dumps.html
NSE 7 Network Security Architect NSE7_PBC-6.4 Real Exam Questions and Answers FREE Updated: https://drive.google.com/open?id=14KLDSTK29meuOSQ2mdMhVvx-PHEIpdYf