Free NSE7_PBC-6.4: Fortinet NSE 7 - Public Cloud Security 6.4 Exam Questions and Answers
21 verified practice questions for NSE7_PBC-6.4.
The first 10 questions on this page are free to read, answers included — no account and no card. A plan opens the rest of the bank, the full timed practice test and your weak-topic reporting.
Last updated: September 19, 2026
- Provider
- Fortinet
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Our test mode duration & pass mark
- 130 mins · 70%
- Verified answers
- Reviewed weekly
- Practice format
- Multiple choice
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #1
You have been asked to secure your organization’s salesforce application that is running on Microsoft Azure, and find an effective method for inspecting shadow IT activities in the organization. After an initial investigation, you find that many users access the salesforce application remotely as well as on-premises. Your goal is to find a way to get more visibility, control over shadow IT-related activities, and identify any data leaks in the salesforce application. Which three steps should you take to achieve your goal? (Choose three.)
Select 3 answers.
Please select an optionIncorrectCorrect answer: A, B, C
FortiCASB with its subscription license gives API-based visibility and DLP inside the SaaS application, its policies control access rights and data protection, and FortiGate with FortiGuard and FortiAnalyzer supplies inline shadow IT discovery and reporting for on-premises users.
Was this answer correct?Question #2
Refer to the exhibit. Which two conditions will enable you to segregate and secure the traffic between the hub and the spokes in Microsoft Azure? (Choose two.)

Select 2 answers.
Please select an optionIncorrectCorrect answer: A, D
Placing the FortiGate-VM as an NVA in the hub and adding user-defined routes on the spokes forces spoke traffic through the firewall. The VNet peering between hub and spokes provides the underlying connectivity. ExpressRoute and spoke-only peering do not steer traffic through FortiGate.
Was this answer correct?Question #3
An organization deployed a FortiGate-VM in the Google Cloud Platform and initially configured it with two vNICs. Now, the same organization wants to add additional vNICs to this existing FortiGate-VM to support different workloads in their environment. How can they do this?
Please select an optionIncorrectCorrect answer: D
Was this answer correct?Question #4
Refer to the exhibit. Your senior administrator successfully configured a FortiGate fabric connector with the Azure resource manager, and created a dynamic address object on the FortiGate VM to connect with a windows server in Microsoft Azure. However, there is now an error on the dynamic address object, and you must resolve the issue. How do you resolve this issue?
Please select an optionIncorrectCorrect answer: B
Was this answer correct?Question #5
Refer to the exhibit. In your Amazon Web Services (AWS) virtual private cloud (VPC), you must allow outbound access to the internet and upgrade software on an EC2 instance, without using a NAT instance. This specific EC2 instance is running in a private subnet: 10.0.1.0/24. Also, you must ensure that the EC2 instance source IP address is not exposed to the public internet. There are two subnets in this VPC in the same availability zone, named public (10.0.0.0/24) and private (10.0.1.0/24). How do you achieve this outcome with minimum configuration?
Please select an optionIncorrectCorrect answer: D
The NAT gateway must live in the public subnet and hold an elastic IP, and the private subnet route table must send 0.0.0.0/0 to that NAT gateway. Outbound traffic then appears to come from the NAT gateway, hiding the instance source IP.
Was this answer correct?Question #6
When an organization deploys a FortiGate-VM in a high availability (HA) (active/active) architecture in Microsoft Azure, they need to determine the default timeout values of the load balancer probes. In the event of failure, how long will Azure take to mark a FortiGate-VM as unhealthy, considering the default timeout values?
Please select an optionIncorrectCorrect answer: B
With the default probe settings the Azure load balancer waits about 30 seconds, an interval of 15 seconds times two failed probes, before it marks the FortiGate-VM unhealthy and stops sending it traffic.
Was this answer correct?Question #7
You need to deploy FortiGate VM devices in a highly available topology in the Microsoft Azure cloud. The following are the requirements of your deployment: •Two FortiGate devices must be deployed; each in a different availability zone. •Each FortiGate requires two virtual network interfaces: one will connect to a public subnet and the other will connect to a private subnet. •An external Microsoft Azure load balancer will distribute ingress traffic to both FortiGate devices in an active- active topology. •An internal Microsoft Azure load balancer will distribute egress traffic from protected virtual machines to both FortiGate devices in an active-active topology. •Traffic should be accepted or denied by a firewall policy in the same way by either FortiGate device in this topology. Which FortiOS CLI configuration can help reduce the administrative effort required to maintain the FortiGate devices, by synchronizing firewall policy and object configuration between the FortiGate devices?
Please select an optionIncorrectCorrect answer: B
Configuring FortiOS HA (unicast HA in Azure) synchronizes firewall policies and objects between the two units, so policy changes only need to be made once while the Azure load balancers still distribute traffic active-active.
Was this answer correct?Question #8
Which statement about FortiSandbox in Amazon Web Services (AWS) is true?
Please select an optionIncorrectCorrect answer: C
In AWS the FortiSandbox inspection VMs are EC2 instances that stay powered on continuously, unlike appliance VMs that are reverted after each job, so scanning capacity is always available and billed while running.
Was this answer correct?Question #9
Which two statements about the Amazon Cloud Services (AWS) network access control lists (ACLs) are true? (Choose two.)
Select 2 answers.
Please select an optionIncorrectCorrect answer: A, D
AWS network ACLs are stateless, so return traffic must be permitted by an explicit rule in the opposite direction, and unlike security groups they support both allow and deny rules. They attach to subnets, not to network interfaces.
Was this answer correct?Question #10
An organization deploys a FortiGate-VM (VM04 / c4.xlarge) in Amazon Web Services (AWS) and configures two elastic network interfaces (ENIs). Now, the same organization wants to add additional ENIs to support different workloads in their environment. Which action can you take to accomplish this?
Please select an optionIncorrectCorrect answer: B
Additional ENIs can be created and attached, but FortiGate only detects the new interfaces after a power cycle, so the instance must be stopped, the ENI attached, and the instance started again.
Was this answer correct?
Continue with NSE7_PBC-6.4: Fortinet NSE 7 - Public Cloud Security 6.4
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in NSE7_PBC-6.4: Fortinet NSE 7 - Public Cloud Security 6.4, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Other Fortinet certifications
- NSE4-5.4: Fortinet Network Security Expert - FortiOS 5.4 (opens in a new tab)
- NSE4_FGT-7.0: Fortinet NSE 4 - FortiOS 7.0 (opens in a new tab)
- NSE5_FMG-7.2: Fortinet NSE 5 - FortiManager 7.2 (opens in a new tab)
- NSE6_FML-6.2: Fortinet NSE 6 - FortiMail 6.2 (opens in a new tab)
- NSE7 Enterprise Firewall - FortiOS 5.4 (opens in a new tab)
- NSE7_EFW-6.2: Fortinet NSE 7 - Enterprise Firewall 6.2 (opens in a new tab)
Reviews
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah Smith
USA
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar Nyström
Sweden
★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit Sharma
India
FAQ
Learn More: https://www.fortinet.com/training-certification
- Q1: What are Fortinet Certification Exams?
- A: Fortinet Certification Exams validate your expertise in using and managing Fortinet’s network security solutions, including FortiGate firewalls, FortiAnalyzer, and other Fortinet security products. These certifications demonstrate your proficiency in deploying, configuring, and troubleshooting Fortinet security technologies to protect networks from cyber threats.
- Q2: Why should I pursue Fortinet Certification?
- A: Fortinet Certification enhances your professional credibility, showcasing your skills and knowledge in network security. This can lead to better job opportunities, higher salaries, and career advancement in cybersecurity and IT infrastructure roles.
- Q3: What are the benefits of Fortinet Certification?
- A: Benefits include recognition as a certified Fortinet professional, improved job performance, access to exclusive resources, continuing education opportunities, and staying current with the latest Fortinet technologies and best practices.
- Q4: Who should take Fortinet Certification Exams?
- A: Network engineers, system administrators, security analysts, and IT professionals involved in designing, implementing, and managing network security solutions using Fortinet products should consider these certifications to validate their expertise and advance their careers.
- Q5: What types of Fortinet Certification Exams are available?
- A: Fortinet offers various certification paths under the Network Security Expert (NSE) program, including:
- Q6: How do I prepare for Fortinet Certification Exams?
- A: Preparation can include official Fortinet training courses, study guides, practice exams, online tutorials, and hands-on experience with Fortinet security products and solutions.
- Q7: Where can I take Fortinet Certification Exams?
- A: Fortinet Certification Exams can be taken at authorized Pearson VUE testing centers worldwide or online, providing flexibility to fit your schedule and location.
- Q8: How do Fortinet Certifications impact my career?
- A: Fortinet Certifications significantly boost your career by demonstrating your expertise to employers, making you a more competitive candidate for advanced roles and promotions in network security and IT infrastructure.
- Q9: Are there any prerequisites for Fortinet Certification Exams?
- A: Some exams may have prerequisites, such as foundational knowledge or prior certifications. Check the specific requirements for each certification path on the Fortinet website.
- Q10: How often do I need to recertify for Fortinet Certifications?
- A: Fortinet Certifications typically require recertification every two years to ensure that certified professionals stay updated with the latest cybersecurity technologies and industry practices.



