Fortinet · NSE 7
Validates advanced skills in deploying, managing, and troubleshooting Fortinet security solutions in public cloud environments including AWS, Azure, and Google Cloud. Covers FortiGate VM deployment, cloud automation tools, SD-WAN in the cloud, and FortiCNP risk management.
Practice Questions
600
≈ 10 practice exams
Duration
60 minutes
Passing Score
70%
Difficulty
ProfessionalLast Updated
May 2026
Use this Fortinet NSE 7 Network Security Architect—Public Cloud Security practice exam to prepare for Fortinet NSE 7 Network Security Architect—Public Cloud Security with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for Fortinet NSE 7, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as FortiGate VM Deployment in Public Cloud, Cloud Automation and Infrastructure-as-Code, AWS Transit Gateway and SD-WAN Connect, Azure FortiGate Deployment and Troubleshooting, and FortiCNP Risk Management. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Fortinet NSE 7 – Public Cloud Security exam (NSE7_PBC-7.2 / NSE7_CDS_AR-7.6) validates advanced proficiency in deploying, administering, monitoring, and troubleshooting Fortinet security solutions within public cloud environments, specifically AWS and Azure. The exam tests applied knowledge across FortiGate VM deployment architectures, cloud-native automation using Terraform and Ansible, SD-WAN integration with AWS Transit Gateway, Azure Virtual WAN, and risk management through FortiCNP. It is part of the Fortinet Certified Solution Specialist (FCSS) – Public Cloud Security certification track.
The exam is scenario-driven, incorporating design scenarios and configuration extracts that reflect real-world enterprise cloud security deployments. Candidates are expected to demonstrate competency beyond basic firewall configuration to encompass Infrastructure-as-Code (IaC) pipelines, high-availability architectures across cloud providers, east-west and north-south traffic control, and cloud-native monitoring integration. Product coverage is anchored on FortiOS 7.6 and FortiCNAPP (formerly FortiCNP).
This certification is designed for network and security professionals who are responsible for the integration, administration, and troubleshooting of enterprise public cloud security infrastructures built on Fortinet solutions. Relevant job roles include cloud security engineers, network security architects, cloud infrastructure administrators, and senior network engineers who work across AWS and Azure environments.
Candidates typically have experience deploying multi-vendor cloud security stacks and are looking to formalize and validate their expertise in Fortinet-specific public cloud deployments. It is well-suited for professionals seeking the FCSS – Public Cloud Security designation as a step toward the NSE 8 expert-level certification.
Fortinet recommends a minimum of two years of hands-on experience with Fortinet security solutions, two years with AWS cloud infrastructure, and two years with Azure cloud infrastructure prior to attempting this exam. Candidates should be comfortable with IaaS concepts, virtual networking, routing protocols, and Linux VM administration.
Formal recommended training includes completion of the FCSS – Cloud Security for AWS and FCSS – Cloud Security for Azure courses from the Fortinet Training Institute. Candidates who attempt the exam without completing these preparatory courses should have a thorough working understanding of cloud-native constructs such as VPCs, Transit Gateways, VNets, Azure Resource Manager, IAM roles, and security groups. Prior hands-on lab experience with FortiGate VM deployments and basic Terraform usage is strongly advised.
The NSE 7 – Public Cloud Security exam consists of 35–40 questions (reported as 37 questions for the NSE7_PBC-7.2 version) with a time limit of 70–75 minutes, delivered in English through Pearson VUE test centers or via online proctoring. Question types are single-selection and multiple-selection multiple-choice. The exam is registered and delivered through Pearson VUE at a cost of approximately $400 USD.
Scoring is pass/fail based on a 70% passing threshold. All answers within a question must be fully correct to receive credit — no partial credit is awarded for partially correct multiple-select answers. A detailed score report is available through Pearson VUE following the exam. The certification earned by passing this exam is valid for two years and can be renewed by passing any current NSE 7-level exam.
Earning the FCSS – Public Cloud Security designation through the NSE 7 exam positions professionals for roles such as Cloud Security Architect, Senior Network Security Engineer, Cloud Infrastructure Security Specialist, and Security Operations Engineer in organizations running hybrid or multi-cloud environments. As enterprises increasingly migrate workloads to AWS and Azure, demand for professionals who can enforce security policy at scale using automated, cloud-native tooling continues to grow, making Fortinet's cloud security specialization directly relevant to hiring decisions at organizations standardized on FortiOS.
The NSE 7 certification is recognized within the broader Fortinet NSE Program as the professional tier, sitting above the NSE 4–6 associate/specialist levels and below the NSE 8 expert designation. It integrates into the FCSS track, which is Fortinet's current role-based certification framework. Professionals holding this certification often pursue complementary cloud provider certifications (AWS Solutions Architect, Azure Security Engineer Associate) to maximize market positioning, as the combination of vendor-specific Fortinet expertise and cloud-provider credentials is particularly sought after in regulated industries and large enterprises.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 10 full-length practice exams.
Preview — answers shown1. A branch connectivity architect at Contoso configures SD-WAN on a cloud FortiGate with two overlay tunnels to headquarters: an MPLS-backed tunnel with consistently low latency and high monthly cost, and an internet-backed tunnel with variable latency and low cost. Voice over IP traffic requires latency below 100ms and packet loss below 1%. The architect wants the internet tunnel to carry VoIP traffic when it meets the SLA thresholds, automatically failing over to the MPLS tunnel only when the internet tunnel degrades. Which SD-WAN service steering mode should be configured for the VoIP traffic rule? (Select one!)
Explanation
SLA mode evaluates each SD-WAN member against the configured SLA thresholds for latency, jitter, and packet loss, then routes traffic through qualifying members applying cost-based preference when multiple members satisfy the thresholds. This behavior allows the low-cost internet tunnel to carry VoIP traffic whenever it meets the 100ms latency and 1% packet loss thresholds, while automatically failing over to the MPLS tunnel when the internet tunnel degrades beyond the SLA limits. Manual mode uses a fixed primary and backup assignment regardless of real-time SLA compliance, always preferring the MPLS or internet tunnel regardless of current quality. Priority mode always selects the highest-priority member that meets SLA thresholds but does not optimize for cost when multiple qualifying members exist. Load-balance mode distributes sessions across members regardless of SLA compliance on a per-session basis, making it inappropriate for VoIP where each individual session must consistently remain on one path that meets quality requirements.
2. A compliance team at Litware needs to scan files stored in Microsoft SharePoint Online and Google Drive for sensitive data including PII and financial records. They require visibility into stored data without impacting user performance or requiring changes to proxy configurations. Which FortiCASB deployment mode should they use? (Select one!)
Explanation
FortiCASB API mode connects directly to SaaS provider APIs such as SharePoint Online and Google Drive to perform out-of-band, asynchronous scanning of files stored in the cloud. This mode has no latency impact on users because scanning occurs independently of the user access path, and it requires no proxy configuration changes on user devices or network infrastructure. API mode is specifically designed for auditing data at rest and compliance scanning for sensitive data like PII and financial records. Inline proxy mode would require WPAD or PAC file configuration changes and would add latency to all user SaaS access, failing both the performance and configuration change requirements. IPsec VPN mode is not a valid FortiCASB deployment option. DNS redirect is not a supported deployment mode for FortiCASB.
3. A financial services company at Tailspin Toys runs FortiGate deployments in AWS, Azure, and GCP for different business units. Workloads vary significantly with quarterly peaks requiring three times normal capacity. The licensing team needs a model that allows reallocation of licenses across cloud providers, supports pausing instances during non-peak periods, and avoids large upfront annual commitments. Which FortiGate licensing model BEST meets these requirements? (Select one!)
Explanation
FortiFlex consumption-based licensing uses a points-per-day model from a single account that manages licenses across AWS, Azure, GCP, and on-premises environments simultaneously. Tokens can be reallocated between FortiGate instances across clouds, paused during non-peak periods to stop consumption, and resized to match changing capacity requirements without forfeiting annual commitments. A single FortiFlex account provides centralized visibility and management across all cloud providers. BYOL requires upfront annual purchase and cannot be easily paused or reallocated between cloud environments — annual commitment conflicts with the variable workload and no-upfront-commitment requirement. PAYG billing occurs independently per cloud marketplace and does not offer cross-cloud reallocation or pause capability; managing separate PAYG accounts per cloud does not address centralized license management. Combining BYOL with PAYG adds administrative complexity and the BYOL component still requires annual upfront commitment.
4. A cloud engineer at Litware Inc. is deploying a FortiGate VM in AWS using BYOL licensing. The deployment must use cloud-init user data to automatically apply initial CLI configuration and activate the BYOL license file at first boot in a single payload. What format must the user data use to combine both the FortiGate configuration and the license file? (Select one!)
Explanation
FortiGate VM bootstrap via cloud-init requires MIME multipart mixed-content format when combining both a CLI configuration section and a BYOL license file in a single user data payload. The format uses Content-Type multipart/mixed with a defined boundary delimiter that separates the configuration attachment (text/plain with filename config) and the license attachment (text/plain with filename license). This structure allows the FortiGate bootstrap parser to identify and process each component independently at first boot. It is important to note that bootstrap runs only once at first boot — subsequent reboots do not re-apply the configuration. Base64-encoded JSON and XML are not recognized bootstrap formats by the FortiGate bootstrap parser. While shell scripts downloading from S3 are used in auto-scaling scenarios, they do not support the structured delivery of a BYOL license file in the required format.
5. Litware's cloud team has 20 active FortiFlex tokens deployed on AWS FortiGate instances. Five AWS instances will be decommissioned and 3 new FortiGate instances need to be deployed in Azure. The team wants to avoid purchasing additional licenses. Which statement BEST describes how FortiFlex supports this transition? (Select one!)
Explanation
FortiFlex uses a consumption-based, cloud-agnostic token pool model. Tokens are not bound to a specific cloud provider, enabling flexible deployment across AWS, Azure, GCP, and on-premises from a single FortiFlex account. When a FortiGate instance is decommissioned, its token is automatically returned to the account pool and immediately becomes available for assignment to new deployments in any supported environment. This cross-cloud reallocation is a core FortiFlex design principle differentiating it from BYOL licenses. FortiFlex tokens are not cloud-specific, no support ticket is required for reallocation between providers, and FortiFlex natively supports Azure alongside AWS and GCP.
Fortinet NSE 6 - FortiSOAR 7.3 Administrator (NSE6_FSR-7.3)
NSE6_FSR-7.3 · 600 questions
Fortinet NSE 6 - FortiVoice Administrator (NSE6_FVE-6.0)
NSE6_FVE-6.0 · 597 questions
Fortinet NSE 7 – Network Security Architect
NSE 7 · 600 questions
Fortinet NSE 7 – Network Security Architect (SASE)
NSE7_SAR · 600 questions
Fortinet NSE 7 - Security Operations 7.6 Architect (NSE7_SOC_AR-7.6)
NSE7_SOC_AR-7.6 · 600 questions
FCP - FortiManager 7.6 Administrator (FCP_FMG_AD-7.6)
FCP_FMG_AD-7.6 · 600 questions
$17.99
One-time access to this exam