exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 102 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 102
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibits.

Exhibit A shows a network diagram. Exhibit B shows the central SNAT policy and IP pool configuration.

The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.

A firewall policy is configured to allow all destinations from LAN (port3) to WAN (port1).

Central NAT is enabled, so NAT settings from matching central SNAT policies will be applied.





Which IP address will be used to source NAT (SNAT) the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?

  • A. 10.200.1.99
  • B. 10.200.1.1
  • C. 10.200.1.49
  • D. 10.200.1.149
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
besi05
Highly Voted 1 year, 9 months ago
Selected Answer: A
A is correct , pings is ICMP so protocol 1. Protocol 1 is enabled on access list id 2 which has destination address SNAT-remote 1
upvoted 8 times
...
Halmonte0780
Highly Voted 1 year, 9 months ago
It's A because of the protocol number. Ping = icmp Ping is ICMP protocol - protocol number = 1 => SNAT policy ID 1 is policy that used. => Translated address is "SNAT-Remote1" that 10.200.1.99
upvoted 7 times
...
darkdante24
Most Recent 1 year, 3 months ago
Selected Answer: A
A is correct, look at the pictures carefully they have made it complicated on purpose.
upvoted 1 times
...
Jumpy007
1 year, 7 months ago
Selected Answer: A
Protocol number 1 ICMP Internet Control Message Protocol https://www.fortinetguru.com/2018/12/protocol-number/
upvoted 1 times
...
raydel92
1 year, 7 months ago
Selected Answer: A
A. 10.200.1.99 Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 1 times
...
D1360_1304
1 year, 9 months ago
A. Correct - is for ICMP B. Incorrect - C. Incorrect - is for TCP protocol D. Incorrect - is for IGMP protocol
upvoted 4 times
...
Takumi
1 year, 9 months ago
Selected Answer: A
The real answer es A
upvoted 2 times
...
Takumi
1 year, 9 months ago
Selected Answer: D
The answer is D
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago