View all questions & answers for the NSE 7 - Enterprise Firewall 7.6 Administrator Exam Materials exam


Question 18 Discussion

To secure your enterprise network traffic, which step does FortiGate perform first, when handling the first packets of a session? (Choose one answer)

  • A. Installation of the session key in the network processor (NP)
  • B. Decryption
  • C. A reverse path forwarding (RPF) check
  • D. IP integrity header checking
Correct Answer: D

Brave-Dump Clients Votes

D 75%
C 25%

Comments



Brave-Dumps Admin 2025-09-16 19:59:00

Selected Answers: D


EFW 7.6 page 289


thaer saadi 2025-12-18 20:09:24

Selected Answers: C


First the firtigate will check the RPF C is coorect


Anonymous User 2025-12-20 01:31:27

Selected Answers: D


EFW 7.6 page 18 & Page 289.


Adam 2026-01-18 10:26:26

Selected Answers: D


From Study Guide:
# Life of a Packet—Initial Session Packets
Network Interface -> mandatory
---
Access Control List (ACL) -> optional/configurable
Host Protection Engine (HPE) -> optional/configurable
IP integrity header checking -> mandatory -------------------------> D is right
IPsec VPN decryption -> optional/configurable --------------------> B is wrong
---
Quarantine -> optional/configurable
FortiTelemetry -> optional/configurable
User authentication (captive portal) -> optional/configurable
---
Kernel -> mandatory
1. Destination NAT
2. Routing, RPF check, and SD-WAN --------------------------------> C is wrong
3. Stateful inspection/policy lookup/session management
4. Session helpers
5. User authentication
6. Device identification
7. SSL VPN
8. Local management traffic
---
UTM/NGFW -> optional/configurable
1. Flow-based inspection
2. Proxy-based inspection
3. Explicit web proxy
4. Botnet check
---
Kernel -> mandatory
1. Forwarding
2. Source NAT
---
IPsec VPN encryption -> optional/configurable
---
Traffic shaping -> optional/configurable
---
WAN optimization -> optional/configurable
---
Network interface -> mandatory

-----------------------------------------------------------------------------------

From Study Guide:
The FortiGate CPU always processes the first part of traffic:
-> TCP traffic: the first three-way handshake
-> UDP traffic: the first packet
So A is wrong