Free NSE7-PBC-64 Fortinet NSE7-PBC-64 Practice Test Question

Loading demo links...

Showing 1–3 of 3 questions

Question 1 (Topic 1)

Which two statements about the Amazon Cloud Services (AWS) network access control lists (ACLs) are true? (Choose two.)

Select an option, then click Submit answer.

  • Network ACLs are stateless, and inbound and outbound rules are used for traffic filtering.
  • Network ACLs are stateful, and inbound and outbound rules are used for traffic filtering.
  • Network ACLs must be manually applied to virtual network interfaces.
  • Network ACLs support allow rules and deny rules.
Question 2 (Topic 1)

Refer to the exhibit. In your Amazon Web Services (AWS) virtual private cloud (VPC), you must allow outbound access to the internet and upgrade software on an EC2 instance, without using a NAT instance. This specific EC2 instance is running in a private subnet: 10.0.1.0/24. Also, you must ensure that the EC2 instance source IP address is not exposed to the public internet. There are two subnets in this VPC in the same availability zone, named public (10.0.0.0/24) and private (10.0.1.0/24). How do you achieve this outcome with minimum configuration?

Select an option, then click Submit answer.

  • Deploy a NAT gateway with an EIP in the private subnet, edit the public main routing table, and change the destination route 0.0.0.0/0 to the target NAT gateway.
  • Deploy a NAT gateway with an EIP in the public subnet, edit route tables, select Public-route, and delete the route destination 10.0.0.0/16 to target local.
  • Deploy a NAT gateway with an EIP in the private subnet, edit route tables, select Private-route, and add a new route destination 0.0.0.0/0 to the target internet gateway.
  • Deploy a NAT gateway with an EIP in the public subnet, edit route tables, select Private-route and add a new route destination 0.0.0.0/0 to target the NAT gateway.
Question 3 (Topic 1)

Customer XYZ has an ExpressRoute connection from Microsoft Azure to a data center. They want to secure communication over ExpressRoute, and to install an in-line FortiGate to perform intrusion prevention system (IPS) and antivirus scanning. Which three methods can the customer use to ensure that all traffic from the data center is sent through FortiGate over ExpressRoute? (Choose three.)

Select an option, then click Submit answer.

  • Install FortiGate in Azure and build a VPN tunnel to the data center over ExpressRoute
  • Configure a user-defined route table
  • Enable the redirect option in ExpressRoute to send data center traffic to a user-defined route table
  • Configure the gateway subnet as the subnet in the user-defined route table
  • Define a default route where the next hop IP is the FortiGate WAN interface