Fortinet · NSE 7
Validates advanced skills in deploying, managing, and troubleshooting Fortinet security solutions in public cloud environments including AWS, Azure, and Google Cloud. Covers FortiGate VM deployment, cloud automation tools, SD-WAN in the cloud, and FortiCNP risk management.
Practice Questions
600
≈ 10 practice exams
Duration
60 minutes
Passing Score
70%
Difficulty
ProfessionalLast Updated
May 2026
Use this Fortinet NSE 7 Network Security Architect—Public Cloud Security practice exam to prepare for Fortinet NSE 7 Network Security Architect—Public Cloud Security with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for Fortinet NSE 7, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as FortiGate VM Deployment in Public Cloud, Cloud Automation and Infrastructure-as-Code, AWS Transit Gateway and SD-WAN Connect, Azure FortiGate Deployment and Troubleshooting, and FortiCNP Risk Management. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Fortinet NSE 7 – Public Cloud Security exam (NSE7_PBC-7.2 / NSE7_CDS_AR-7.6) validates advanced proficiency in deploying, administering, monitoring, and troubleshooting Fortinet security solutions within public cloud environments, specifically AWS and Azure. The exam tests applied knowledge across FortiGate VM deployment architectures, cloud-native automation using Terraform and Ansible, SD-WAN integration with AWS Transit Gateway, Azure Virtual WAN, and risk management through FortiCNP. It is part of the Fortinet Certified Solution Specialist (FCSS) – Public Cloud Security certification track.
The exam is scenario-driven, incorporating design scenarios and configuration extracts that reflect real-world enterprise cloud security deployments. Candidates are expected to demonstrate competency beyond basic firewall configuration to encompass Infrastructure-as-Code (IaC) pipelines, high-availability architectures across cloud providers, east-west and north-south traffic control, and cloud-native monitoring integration. Product coverage is anchored on FortiOS 7.6 and FortiCNAPP (formerly FortiCNP).
This certification is designed for network and security professionals who are responsible for the integration, administration, and troubleshooting of enterprise public cloud security infrastructures built on Fortinet solutions. Relevant job roles include cloud security engineers, network security architects, cloud infrastructure administrators, and senior network engineers who work across AWS and Azure environments.
Candidates typically have experience deploying multi-vendor cloud security stacks and are looking to formalize and validate their expertise in Fortinet-specific public cloud deployments. It is well-suited for professionals seeking the FCSS – Public Cloud Security designation as a step toward the NSE 8 expert-level certification.
Fortinet recommends a minimum of two years of hands-on experience with Fortinet security solutions, two years with AWS cloud infrastructure, and two years with Azure cloud infrastructure prior to attempting this exam. Candidates should be comfortable with IaaS concepts, virtual networking, routing protocols, and Linux VM administration.
Formal recommended training includes completion of the FCSS – Cloud Security for AWS and FCSS – Cloud Security for Azure courses from the Fortinet Training Institute. Candidates who attempt the exam without completing these preparatory courses should have a thorough working understanding of cloud-native constructs such as VPCs, Transit Gateways, VNets, Azure Resource Manager, IAM roles, and security groups. Prior hands-on lab experience with FortiGate VM deployments and basic Terraform usage is strongly advised.
The NSE 7 – Public Cloud Security exam consists of 35–40 questions (reported as 37 questions for the NSE7_PBC-7.2 version) with a time limit of 70–75 minutes, delivered in English through Pearson VUE test centers or via online proctoring. Question types are single-selection and multiple-selection multiple-choice. The exam is registered and delivered through Pearson VUE at a cost of approximately $400 USD.
Scoring is pass/fail based on a 70% passing threshold. All answers within a question must be fully correct to receive credit — no partial credit is awarded for partially correct multiple-select answers. A detailed score report is available through Pearson VUE following the exam. The certification earned by passing this exam is valid for two years and can be renewed by passing any current NSE 7-level exam.
Earning the FCSS – Public Cloud Security designation through the NSE 7 exam positions professionals for roles such as Cloud Security Architect, Senior Network Security Engineer, Cloud Infrastructure Security Specialist, and Security Operations Engineer in organizations running hybrid or multi-cloud environments. As enterprises increasingly migrate workloads to AWS and Azure, demand for professionals who can enforce security policy at scale using automated, cloud-native tooling continues to grow, making Fortinet's cloud security specialization directly relevant to hiring decisions at organizations standardized on FortiOS.
The NSE 7 certification is recognized within the broader Fortinet NSE Program as the professional tier, sitting above the NSE 4–6 associate/specialist levels and below the NSE 8 expert designation. It integrates into the FCSS track, which is Fortinet's current role-based certification framework. Professionals holding this certification often pursue complementary cloud provider certifications (AWS Solutions Architect, Azure Security Engineer Associate) to maximize market positioning, as the combination of vendor-specific Fortinet expertise and cloud-provider credentials is particularly sought after in regulated industries and large enterprises.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 10 full-length practice exams.
Preview — answers shown1. An administrator deploys FortiGate VMs as targets behind an AWS Gateway Load Balancer to inspect traffic between spoke VPCs. The applications being protected require support for packets up to 8,500 bytes in size. What is the MINIMUM MTU that must be configured to prevent packet fragmentation when using GWLB? (Select one!)
Explanation
AWS Gateway Load Balancer encapsulates traffic using GENEVE (Generic Network Virtualization Encapsulation) protocol on UDP port 6081 before forwarding packets to FortiGate targets. GENEVE encapsulation adds a fixed overhead of 68 bytes to each original packet. To support application packets of up to 8,500 bytes without fragmentation, the MTU must accommodate the original payload plus the GENEVE header: 8,500 bytes plus 68 bytes equals 8,568 bytes as the minimum required MTU. If MTU is configured at 8,500 bytes, encapsulated packets would be fragmented at 8,568 bytes, requiring FortiGate to reassemble fragments which increases processing latency and CPU utilization. Setting MTU to 9,000 bytes (jumbo frames) would also prevent fragmentation but requires jumbo frame support across all network components in the traffic path and exceeds the minimum necessary. The standard 1,500-byte MTU would cause fragmentation of virtually all application traffic given the 8,500-byte maximum packet size requirement.
2. A security engineer at Contoso configures a FortiGate Active-Passive HA pair in Azure. The operations team requires an automatic notification whenever an HA failover event occurs so they can investigate the root cause. Which automation stitch trigger type should be configured to detect HA failover events specifically? (Select one!)
Explanation
The ha-failover trigger type in FortiOS automation stitches fires specifically when the HA cluster undergoes a failover event, meaning the standby unit transitions to become the active unit. This dedicated trigger provides the most direct and reliable detection of HA state changes without requiring knowledge of specific log IDs or event matching patterns. The event-log trigger fires when specific log entries match configured criteria by log ID number and could theoretically detect an HA event by matching the correct log ID, but ha-failover is the designated and recommended mechanism for this exact scenario. The fabric-event trigger responds to Security Fabric topology changes such as connected device state transitions within the Security Fabric, not specifically to HA cluster failover events. The security-rating trigger fires when the FortiGate security posture rating score changes, which represents a configuration best-practice compliance deviation and is unrelated to HA cluster status. After configuring the ha-failover trigger, an appropriate paired action would be a webhook to a messaging platform such as Slack or PagerDuty, or an email notification to the operations team.
3. A compliance officer at Adatum Healthcare requires that no security logs be lost during network interruptions between FortiGate and FortiAnalyzer. The current deployment uses the default logging transport. Which FortiAnalyzer logging configuration parameter ensures reliable log delivery? (Select one!)
Explanation
The set reliable enable command in the FortiGate FortiAnalyzer logging configuration changes the log transport protocol from connectionless UDP to TCP-based OFTP (Optimized Fabric Transfer Protocol). UDP does not guarantee delivery — logs sent over UDP may be silently dropped during network congestion or interruptions without any retransmission. When reliable is set to enable, FortiGate uses TCP with acknowledgment and retransmission to confirm every log message is received by FortiAnalyzer, ensuring no audit trail gaps during network disturbances. This is critical for HIPAA compliance which requires complete and tamper-evident audit logging of all network access. Setting enc-algorithm to high enables AES-256 encryption for log confidentiality during transmission but does not change the transport protocol or prevent log loss. Setting severity to debug would capture all events including verbose debug messages, dramatically increasing log volume and storage consumption without addressing reliability. Setting upload-option to realtime controls how quickly logs are forwarded after generation but does not change the transport protocol or guarantee delivery during network interruptions.
4. A cloud architect at Northwind configures ADVPN on a hub FortiGate deployed in AWS to enable direct spoke-to-spoke VPN tunnels without routing all traffic through the hub. Which TWO Phase 1 interface configuration parameters are REQUIRED on the hub for ADVPN to function correctly? (Select two!)
Multiple correct answersExplanation
ADVPN hub configuration requires two specific Phase 1 interface settings. Setting type to dynamic configures the hub IPsec interface to accept tunnel connections from any spoke dynamically rather than requiring a pre-defined static list of remote endpoints, which allows new spokes to connect without reconfiguring the hub and enables the hub to serve multiple spokes simultaneously. Setting auto-discovery-sender to enable activates the ADVPN hub role, causing the hub to send IKEv2 shortcut notifications informing spokes of direct paths to each other, enabling spoke-to-spoke tunnels to be established without traversing the hub. The add-route parameter should be set to disable on the ADVPN hub, not enabled, because ADVPN relies on dynamic routing protocols such as BGP to distribute spoke prefix reachability rather than static routes auto-added by tunnel establishment. Setting net-device should also be disabled on the hub to prevent unintended routing table modifications. Setting peertype to dialup would restrict peer authentication to a specific connection type and is not an ADVPN requirement; peertype any is the appropriate configuration for accepting diverse spoke FortiGate connections.
5. Contoso is migrating a web application workload from AWS EC2 instances to AWS Elastic Beanstalk. After the migration, which security responsibility shifts from Contoso to the cloud provider? (Select one!)
Explanation
When migrating from IaaS (EC2) to PaaS (Elastic Beanstalk), the operating system layer shifts from customer to cloud provider responsibility. In IaaS, the customer manages OS patching, security hardening, and runtime configuration. In PaaS, the cloud provider manages the OS, runtime, and middleware. Data classification and governance, identity and access management for application users, and client-side encryption remain the customer's responsibility in both IaaS and PaaS models. The customer always retains responsibility for their data, IAM, and client endpoints regardless of which service model is used.
Fortinet NSE 6 - FortiSOAR 7.3 Administrator (NSE6_FSR-7.3)
NSE6_FSR-7.3 · 600 questions
Fortinet NSE 6 - FortiVoice Administrator (NSE6_FVE-6.0)
NSE6_FVE-6.0 · 597 questions
Fortinet NSE 7 – Network Security Architect
NSE 7 · 600 questions
Fortinet NSE 7 – Network Security Architect (SASE)
NSE7_SAR · 600 questions
Fortinet NSE 7 - Security Operations 7.6 Architect (NSE7_SOC_AR-7.6)
NSE7_SOC_AR-7.6 · 600 questions
FCP - FortiManager 7.6 Administrator (FCP_FMG_AD-7.6)
FCP_FMG_AD-7.6 · 600 questions
$17.99
One-time access to this exam