View all questions & answers for the NSE 4 - FortiOS 7.6 Administrator Exam Materials exam
Comments
Selected Answers: A, C
Selected Answers: B, C
Selected Answers: B, C
defencedev.com
. For a source of 10.10.10.10, the routing table shows the return path is via the 10.10.10.0/24 route on port 3. If such a packet arrives on port 2, the return path doesn’t match and strict RPF drops it.
Option A is not considered correct in the exam, even though it can appear reasonable. When strict RPF is disabled, FortiGate uses loose RPF, which permits a packet as long as there is a route back to the source
defencedev.com
. In this case the only route back to 10.100.110.10 is the default route via port 2, not the incoming port 3. Exam guidance takes a conservative view that, without a more specific route to the source (and with no RPF enabled on that interface), such a packet would not be accepted. Hence, the exam omits Option A and selects only B and C as the correct answers.
Selected Answers: B, C
A) is incorrect because RPF looks for route back to the source IP using the same port, as in pg 130 of the study guide: "Feasible path: Formerly known as loose, it’s the default mode. In this mode, FortiGate verifies that the
routing table contains a route that matches the source address of the packet and the incoming interface.
The matching route doesn’t have to be the best route in the routing table for that source address. It just has
to match the source address and the incoming interface of the packet."
When the packet 10.100.110.10 arrives at port 3, the only route back available is the default route on port 2, it is dropped because the ports don't match.
Selected Answers: A, C
Selected Answers: B, C
C is true because when strict RPF is disabled, the firewall accepts the packet as long as a valid routing path back to the source exists on port2
Based on the routing table shown in the exhibit, which two statements are true? (Choose two answers)
Brave-Dump Clients Votes