exam questions

Exam NSE4_FGT-6.0 All Questions

View all questions & answers for the NSE4_FGT-6.0 exam

Exam NSE4_FGT-6.0 topic 1 question 75 discussion

Actual exam question from Fortinet's NSE4_FGT-6.0
Question #: 75
Topic #: 1
[All NSE4_FGT-6.0 Questions]

Examine this output from a debug flow:

Which statements about the output are correct? (Choose two.)

  • A. FortiGate received a TCP SYN/ACK packet.
  • B. The source IP address of the packet was translated to 10.0.1.10.
  • C. FortiGate routed the packet through port 3.
  • D. The packet was allowed by the firewall policy with the ID 00007fc0.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
EvanABS
Highly Voted 5 years, 1 month ago
AC is correct, B is gateway IP, D is session ID not policy ID.
upvoted 7 times
...
mark05
Highly Voted 4 years, 10 months ago
AC should be correct , if you see the source port of the packet , it is an answer from 62.x.x.x then the Flag is [S.] are Syn Set and ACK set. as last the packet will be routed by port 3 ( Answer C)
upvoted 5 times
...
farmez
Most Recent 4 years, 4 months ago
Answer A is correct. Flag [S] means SYN flag is raised. Thus, first interpretation, it is a SYN or SYN/ACK packet. As the session already exists (msg="find an existing session") => it is a SYN/ACK packet. (If the msg= "allocate new session" => SYN packet) Answer C is correct. last line in the debug flow "find a route ... via port3")
upvoted 1 times
...
HazemBadr
4 years, 10 months ago
FW received TCP SYN from a client and if connection is allowed FW will send SYN/ACK to the client, therefore answer "A" definitely is not correct and "D" is session ID not policy ID. Answer: BC
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago