Sign In
Home/Fortinet/Cloud Security 26 Architect/Free questions

Fortinet NSE 7 - Cloud Security 26 Architect — Free Practice Questions

10 free sample questions from a bank of 38, with the correct answers and explanations. No signup required — start practising right now.

1An administrator decides to use the Use managed identity option on the FortiGate SDN connector with Microsoft Azure. However, the SDN connector is failing on the connection. What must the administrator do to correct this issue?
  • Make sure to set the type to system managed identity on FortiGate SDN connector settings.
  • Make sure to add the Tenant ID on the FortiGate side of the configuration.
  • Make sure to enable the system-assigned managed identity on Azure.
  • Make sure to add the Client Secret on the FortiGate side of the configuration.
Answer: C

The short version

C — managed identity fails until Azure has a system-assigned identity to present. Enable it on the Azure side first.

Key concepts in this question

  • System-assigned managed identity is created and toggled on the Azure resource.
  • FortiGate merely references it; it cannot conjure the identity itself.

Why C is correct

A failing managed-identity connector with correct FortiGate settings points at the missing Azure-side enablement.

Why the others are wrong

  • A. The type selection matters only after the identity exists.
  • B. Tenant IDs belong to service-principal auth, not managed identity.
  • D. Client secrets belong to service principals, not managed identities.

Cloud exam tip

Managed identity fails = enable it in Azure first.

2Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP address.What could be the possible issue with this scenario?
  • FortiGate port4 does not have internet access.
  • A wrong client secret credential is used.
  • The Azure service principal account must have a contributor role.
  • The error is caused by credential time expiration.
Answer: C

The short version

C — floating IPs move only if the service principal can rewrite them: Contributor role required. Failover without permission strands the address.

Key concepts in this question

  • Azure floating-IP failover is an API rewrite of the LB frontend mapping.
  • The service principal needs Contributor rights to perform that rewrite.

Why C is correct

Post-failover IP stickiness is the classic symptom of an under-privileged service principal.

Why the others are wrong

  • A. Port4 internet access does not gate API-driven IP moves.
  • B. Wrong secrets break all API calls, not just IP moves.
  • D. Credential expiry breaks everything, not selectively failover.

Cloud exam tip

Floating IP stuck after failover = Contributor role.

3Refer to the exhibit. An administrator deployed an HA active-active load balance sandwich in Microsoft Azure. The setup requires configuration synchronization between devices.What can you conclude from the configured settings shown in the exhibit? (Choose two.)
  • FortiGate A and FortiGate B are two independent devices.
  • By default, FortiGate uses FGCP.
  • It does not synchronize the FortiGate hostname.
  • FortiGate-VM instances are scaled out automatically according to predefined workload levels.
Answer: B, C

The short version

B and C — cloud HA speaks FGCP by default, and FGCP never syncs hostnames. Protocol plus its famous exception.

Key concepts in this question

  • FGCP is FortiGate's HA clustering protocol in every deployment including cloud.
  • Hostnames stay node-unique by design so admins can tell members apart.

Why B and C are correct

FGCP-by-default (B) with hostname exclusion (C) are both documented FGCP facts.

Why the others are wrong

  • A. A-A sandwich members are one cluster, not independent devices.
  • D. Autoscaling is an orchestration feature, not an HA-sync conclusion.

Cloud exam tip

FGCP syncs everything except the hostname.

4A DevOps team is using Terraform to manage their infrastructure across multiple environments.Currently, the Terraform state file is stored locally on a developer's machine. The team decides to migrate the state file to a remote back-end machine.Why is storing the Terraform state file in a remote location considered a best practice in this scenario?
  • It ensures that the state file is encrypted.
  • It eliminates the need to define provider configurations in the state file.
  • It enables collaboration among multiple team members.
  • It prevents the accidental deletion of the state file.
Answer: C

The short version

C — remote state exists so teams can collaborate. One shared truth instead of N laptops.

Key concepts in this question

  • Remote backends share state across developers and CI runners.
  • Locking plus sharing prevent the overwrite chaos of local files.

Why C is correct

Multi-environment teamwork is the primary documented motive for remote state.

Why the others are wrong

  • A. Backends can encrypt, but that is not the migration motive here.
  • B. Provider blocks remain required regardless of backend.
  • D. Versioned backends help recovery, but collaboration is the best-practice driver.

Cloud exam tip

Remote state = teamwork. Always.

5Refer to the exhibit. An administrator installed a FortiWeb ingress controller to protect a containerized web application.What is the reason for the status shown in FortiView?
  • The manifest file deployed is configured with the wrong node IP addresses.
  • The FortiWeb VM is missing a route to the node subnet.
  • The load balancing type is not set to round-robin.
  • The SDN connector is not authenticated correctly.
Answer: B

The short version

The banked answer B is kept because the reconstructed FortiView exhibit shows unreachable nodes consistent with the FortiWeb VM missing a route to the node subnet, so exhibit missing is resolved by reconstruction.

Key concepts in this question

This question tests FortiWeb ingress controller connectivity and why protected container nodes appear with failure status in FortiView.

Why B is correct

The reconstructed exhibit shows a FortiView topology where the FortiWeb VM cannot reach the Kubernetes node subnet, so a missing route to the node subnet explains the status, which makes B consistent with the stem options and banked answer.

Why the others are wrong

Wrong node IPs in the manifest, round robin load balancing type, and SDN connector authentication all describe different failure modes than the unreachable node subnet in the reconstructed exhibit, so A and C and D are wrong.

NSE7_CLS_AR-26 exam tip

Remember to verify FortiWeb to node subnet routing first when FortiView shows ingress nodes as down.

6Refer to the exhibit. Your team notices an unusually high volume of traffic sourced at one of the organizations FortiGate EC2 instances. They create a flow log to obtain and analyze detailed information about this traffic. However, when they checked the log, they found that it included traffic that was not associated with the FortiGate instance in question.What can they do to obtain the correct logs?
  • Change the maximum aggregation time to 1 minute.
  • Send the logs to Amazon Data Firehose instead to get more granular information.
  • Ensure that the flow log data is not mixed with the rest of the traffic.
  • Create a new flow log at the interface level.
Answer: D

The short version

D — approved. A VPC-level flow log mixes traffic from every ENI, so scoping a new log to the FortiGate network interface isolates the correct logs.

Key concepts in this question

  • Flow log scope: logs can target a VPC, a subnet, or a single network interface with narrower scopes containing only that resource traffic.
  • NetworkInterface resource type: the ENI-level flow log records only traffic to and from that FortiGate instance interface.
  • Aggregation vs scope: aggregation interval and Firehose destination change timing and delivery, not which instances are included.

Why D is correct

AWS documents NetworkInterface as a flow-log resource type alongside VPC and Subnet, so creating the log at the interface level for the FortiGate ENI removes the unrelated traffic seen in the VPC-wide log.

Why the others are wrong

  • A. Changing maximum aggregation to 1 minute only shortens the capture window; it does not filter out other instances.
  • B. Sending logs to Amazon Data Firehose only changes the delivery destination, not the scope of monitored interfaces.
  • C. Ensuring data is not mixed restates the symptom without selecting the narrower VPC, subnet, or interface scope that fixes it.

NSE7_CLS_AR-26 exam tip

Mixed-instance flow log = drop scope from VPC to the FortiGate ENI.

7You are automating configuration changes on one of the FortiGate VMs using Linux Red Hat Ansible.How does Linux Red Hat Ansible connect to FortiGate to make the configuration change?
  • It uses a YAML file.
  • It uses a FortiGate VIP.
  • It uses an API.
  • It uses SSH.
Answer: C

The short version

C — Ansible drives FortiGate over its API. Modules speak HTTPS, playbooks declare intent.

Key concepts in this question

  • The fortios Ansible collection issues API calls to FortiGate.
  • YAML describes the play; SSH is not the transport.

Why C is correct

API transport is the documented Ansible-to-FortiGate connection method.

Why the others are wrong

  • A. YAML is the playbook language, not the connection.
  • B. VIPs are traffic destinations, not management channels.
  • D. SSH ad-hoc commands bypass the module framework.

Cloud exam tip

Ansible + FortiGate = API transport.

8An administrator would like to use FortiCNP to keep track of sensitive data files located in the Amazon Web Services (AWS) S3 bucket and protect it from malware. Which FortiCNP feature should the administrator use?
  • FortiCNP Threat Detection policies
  • FortiCNP Risk Management policies
  • FortiCNP Data Scan policies
  • FortiCNP Compliance policies
Answer: C

The short version

C — S3 files plus malware equals Data Scan policies. Content inspection for stored objects.

Key concepts in this question

  • FortiCNP Data Scan inspects bucket content including malware.
  • Threat, risk, and compliance policies cover other dimensions.

Why C is correct

File-content malware scanning in S3 is the documented Data Scan use.

Why the others are wrong

  • A. Threat Detection watches runtime threats, not stored files.
  • B. Risk Management scores posture, not file content.
  • D. Compliance checks baselines, not malware.

Cloud exam tip

S3 malware = Data Scan.

9Which statement about Amazon Web Services (AWS) Transit Gateway is true for SD-WAN transit gateway (TGW) Connect with FortiGate?
  • The TGW plugin must be used with a VPN to achieve higher bandwidth.
  • Attaching a virtual private cloud (VPC) to the TGW automatically adds new routes to the subnet route table.
  • The Generic Routing Encapsulation (GRE)-based tunnel attachments are slower than IPsec tunnels.
  • TGW supports BGP to share routes with FortiGate.
Answer: B

The short version

B — TGW Connect trades IPsec for GRE attachments. The protocol swap is the headline.

Key concepts in this question

  • TGW Connect uses GRE-based tunnel attachments to FortiGate.
  • Traditional SD-WAN transit rides IPsec overlays.

Why B is correct

GRE-instead-of-IPsec is the documented TGW Connect differentiator (Q16 D confirms the same fact).

Why the others are wrong

  • A. No VPN plugin is required for the bandwidth story.
  • C. GRE is not slower here; speed is not the comparison point.
  • D. Route sharing runs over the Connect peering, not classic BGP-to-TGW as framed.

Cloud exam tip

TGW Connect = GRE attachments.

10A customer would like to use FortiGate fabric integration with FortiCNP.When adding a FortiGate VM to FortiCNP, which three mandatory configuration steps must you follow on FortiGate? (Choose three.)
  • Create an SSL/SSH inspection profile.
  • Configure FortiGate to send logs to FortiCNP.
  • Import the FortiGate certificate into FortiCNP.
  • Enable pre-shared key on both sides.
  • Create and IPS sensor and a firewall policy.
Answer: B, C, D

The short version

B, C, D — FortiGate joins FortiCNP via log feed, certificate trust, and a shared PSK. Telemetry, identity, secret.

Key concepts in this question

  • Logs to FortiCNP feed the CNAPP analytics.
  • Certificate import plus pre-shared key mutually authenticate the pair.

Why B, C and D are correct

The three documented mandatory fabric-integration steps.

Why the others are wrong

  • A. Inspection profiles shape traffic, not onboarding.
  • E. IPS sensors and policies are traffic controls, not integration steps.

Cloud exam tip

FortiGate-to-FortiCNP = logs + cert + PSK.

Want the full bank of 38 questions for Fortinet NSE 7 - Cloud Security 26 Architect? See all practice exams.