NSE7-PBC-7.6 Sample Questions & Answers
Free Public Cloud Security 7.6 practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full NSE7-PBC-7.6 simulator →Showing 6 of 12 free samples.
- Question 1Beginner
Security solutions deployment · Deploy Fortinet solutions to protect CaaS
True or False: The FortiWeb Ingress Controller version 1.0.0 exclusively manages and provides security inspection for HTTP and HTTPS routes within Kubernetes environments.
Show answer & explanation
Correct answer: B
FortiWeb Ingress Controller version 1.0.0 is dedicated strictly to Layer 7 web traffic and exclusively services HTTP and HTTPS ingress routes. Raw TCP/UDP stream proxying or non-HTTP application ingress is not supported by version 1.0.0.
- Question 2Advanced
Security solutions deployment · Deploy Fortinet solutions to protect CaaS
A multinational financial services enterprise is modernizing its application tier by migrating containerized microservices to Amazon Elastic Kubernetes Service (EKS). The security architecture mandates a dedicated FortiWeb-VM cluster deployed in a central inspection VPC, managed via Helm and Kubernetes API integrations through the FortiWeb Ingress Controller (version 1.0.1).
The platform engineering team must ensure that the ingress controller pod possesses granular role-based access control (RBAC) permissions across the cluster without granting unrestricted cluster-admin privileges. Additionally, developers deploy ingress manifests that utilize host-based and path-based routing targeting microservices across multiple distinct namespaces.
During initial testing, the controller pod enters a running state, but changes to Kubernetes Ingress definitions fail to register on the FortiWeb appliances. The DevOps team verifies that the API version used for Ingress resources is networking.k8s.io/v1.
Which Kubernetes RBAC configuration and Ingress definition must be validated to ensure the FortiWeb Ingress Controller properly discovers and reconciles ingress events across all target namespaces?
flowchart LR Dev[DevOps / Helm] -->|Deploy Ingress| K8sAPI[K8s API Server] K8sAPI -->|Watch Events| FWIC[FortiWeb Ingress Controller Pod] FWIC -->|REST API Calls| FWB[FortiWeb-VM Cluster] FWB -->|WAF Inspection| Pods[Application Pods]Show answer & explanation
Correct answer: A
To discover Ingress resources across multiple namespaces, the FortiWeb Ingress Controller requires a ClusterRole and ClusterRoleBinding targeting the 'networking.k8s.io/v1' API group for 'ingresses' and 'ingressclasses'. Furthermore, FortiWeb Ingress Controller exclusively processes ingress resources that explicitly designate 'fwb-ingress-controller' as their ingressClassName.
- Question 3Intermediate
Automation tools · Deploy Fortinet solutions using Azure Bicep
An automation specialist is configuring parameters for an Azure FortiGate autoscale deployment using custom ARM/Bicep templates. The enterprise requires that all dynamic instances in the autoscale group utilize Marketplace Pay-As-You-Go (PAYG) on-demand billing, and that administrative access to the underlying deployment Function App and Cosmos DB backend is restricted to the internal network. How should the BYOL Instance Count and Access Restriction IP Range template parameters be set?
Show answer & explanation
Correct answer: D
In Fortinet Azure autoscale templates, setting 'BYOL Instance Count' to 0 designates the autoscale set as purely PAYG (on-demand), preventing the autoscale handler from provisioning or expecting BYOL license files. Setting 'Access Restriction IP Range' to the corporate management CIDR explicitly restricts inbound access to the Function App and Cosmos DB backend, rather than leaving it open to 0.0.0.0/0.
- Question 4AdvancedSelect 2
Automation tools · Deploy Fortinet solutions using Azure Bicep
A cloud engineer is defining a custom FortiGate-VM image definition in the Azure Compute Gallery using Bicep/ARM templates for standardized corporate deployment. Which TWO configuration parameter values are required according to Fortinet standards for Azure Linux-based VM image definitions? (Select TWO)
Show answer & explanation
Correct answers: A, D
In Azure Compute Gallery definitions for FortiGate-VM, the publisher parameter must be set to 'Fortinet', and hyper-v-generation must be set to 'V2'. os-type must be set to 'linux' (not windows), and os-state must be 'Generalized' (not Specialized).
Hyper-V generation V2 is required for contemporary FortiGate-VM deployments on Azure to support advanced networking and UEFI boot architectures.
- Question 5Intermediate
Automation tools · Deploy Fortinet solutions using AWS CloudFormation
When deploying a FortiGate autoscale cluster integrated with an AWS Transit Gateway using the official autoscale-tgw-new-vpc.template.yaml CloudFormation template, what is the default value assigned to the BGP Autonomous System Number (BgpAsn) parameter, and what is its valid configurable range?
Show answer & explanation
Correct answer: B
In Fortinet's AWS CloudFormation autoscale templates supporting Transit Gateway peering, the BgpAsn parameter defaults to 65000. The valid allowable range for private 2-byte BGP ASNs in the template validation schema is 64512 to 65534.
- Question 6Intermediate
Automation tools · Deploy Fortinet solutions using AWS CloudFormation
While provisioning a FortiGate autoscale cluster using Fortinet AWS CloudFormation templates, an engineer attempts to set the LoadBalancingTrafficPort parameter to handle administrative web traffic. The stack creation validation fails with an error indicating a reserved port conflict. Which set of ports is reserved by the autoscale solution architecture and cannot be used for application traffic load balancing?
Show answer & explanation
Correct answer: B
In the Fortinet AWS autoscale architecture, ports 443 (HTTPS administration/sync), 541 (FortiManager FGFM), 514 (Syslog/FortiAnalyzer logging), and 703 (Autoscale cluster heartbeat and synchronization) are reserved administrative ports and cannot be configured as the LoadBalancingTrafficPort.
Ready for the real thing?
The full NSE7-PBC-7.6 simulator has every exam-style question, timed mode, and instant scoring.