B&D and here's why:
D is correct: In Version 6.4 FortiGuard stopped support for ports 53 and 8888, only 443 is valid now (its the whole point of this question, to differentiate between 6.2 test and 6.4 test). This is per: https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGuard-communication/ta-p/197109?externalID=FD46841
B is correct: The flags for 173.243.138.210 (a default FortiGuard Server IP) show D and I. "D" means this is a default address. "I" means it is the initial server contacted that validated the license, meaning that it didn't have to go on to another. If it had, one of the 173. servers would have a T or an F flag indicating that the connection was failing or had already failed.
This is per: https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGuard-Flags-and-Meanings/ta-p/206725
There are no private IP addresses shown, and there is no S flag, so a private FortiManager wasn't used, so A is wrong.
The Curr Lost column shows all 0s, so no packets were lost, so C is wrong.
BD
Link below shows D is correct and I agree that A and C do not make sense
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGuard-communication/ta-p/197109?externalID=FD46841
For A: It says "local FortiManager" and all the "Server List" IPs are public
For B: The letter "I" from the "Flags" section means "Contract server contacted"
For C: The "Curr Lost" and "Total Lost" sections have the value 0
This means that A & C are wrong, B is right and the only other option left is D.
* B & C can be verified @ FortiGate Security Study Guide - page 415 (Web Filtering - FortiGuard Connection)
I understand that the correct ones are B and D, see FortiGate_Security_6.4_Study_Guide page 415(about the I flag indicating contract server contacted), and 416(HTTPS port 443 enforced by default fortiguard or manager communications)
My Bad, B&D are the right choices. Based on the flag definition, DI indicates that this server was contacted. 443 is also one of the default ports. NO indicator of the Fortimanager. Also, all listed IPs are public IPs that belongs to Fortiguard servers.
Default ports for querying Fortiguard are either udp/8888 or udp/53. If Fortigate is querying by using HTTPS tcp/443, then this indicates answer A (local FortiManager is used as Fortigurad server - https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/179018/using-fortimanager-as-a-local-fortiguard-server). So, in the end A & B answers are correct
HTTPS 443 is also considered as default port for communication. If you look at a real fortigate device you will find 3 options HTTPS, UDP 8888 and udp 53
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
davidone
Highly Voted 4 years agoLionardo
Highly Voted 4 years agoJ_Olin
Most Recent 2 years, 8 months agoVancero
2 years, 9 months agoWilasky
2 years, 9 months agoJustAnotherKids
2 years, 10 months agoCornelius360
2 years, 11 months agoibos8383
3 years agoblahblah1234567890000
3 years, 3 months agoScottXYZ
3 years, 4 months agovdmi
3 years, 5 months agonimvoltage
3 years, 7 months agoAkoladet
3 years, 7 months ago2021gene
3 years, 8 months agoRHK0783
3 years, 8 months agoRHK0783
3 years, 8 months agoalkalinegp
3 years, 8 months agomoneim
3 years, 8 months ago