exam questions

Exam NSE4_FGT-6.4 All Questions

View all questions & answers for the NSE4_FGT-6.4 exam

Exam NSE4_FGT-6.4 topic 1 question 28 discussion

Actual exam question from Fortinet's NSE4_FGT-6.4
Question #: 28
Topic #: 1
[All NSE4_FGT-6.4 Questions]

Refer to the FortiGuard connection debug output.

Based on the output shown in the exhibit, which two statements are correct? (Choose two.)

  • A. A local FortiManager is one of the servers FortiGate communicates with.
  • B. One server was contacted to retrieve the contract information.
  • C. There is at least one server that lost packets consecutively.
  • D. FortiGate is using default FortiGuard communication settings.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
davidone
Highly Voted 4 years ago
It could be B and D. Those IPs starting with 173.243 are for fortiguard services, addind that uses port 443 to update.
upvoted 14 times
...
Lionardo
Highly Voted 4 years ago
B & D is correct. FortiGate_Security_6.4 page 415 (not sure about D)
upvoted 10 times
...
J_Olin
Most Recent 2 years, 8 months ago
Selected Answer: BD
B&D and here's why: D is correct: In Version 6.4 FortiGuard stopped support for ports 53 and 8888, only 443 is valid now (its the whole point of this question, to differentiate between 6.2 test and 6.4 test). This is per: https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGuard-communication/ta-p/197109?externalID=FD46841 B is correct: The flags for 173.243.138.210 (a default FortiGuard Server IP) show D and I. "D" means this is a default address. "I" means it is the initial server contacted that validated the license, meaning that it didn't have to go on to another. If it had, one of the 173. servers would have a T or an F flag indicating that the connection was failing or had already failed. This is per: https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGuard-Flags-and-Meanings/ta-p/206725 There are no private IP addresses shown, and there is no S flag, so a private FortiManager wasn't used, so A is wrong. The Curr Lost column shows all 0s, so no packets were lost, so C is wrong.
upvoted 4 times
...
Vancero
2 years, 9 months ago
Selected Answer: BD
B&D correct
upvoted 2 times
...
Wilasky
2 years, 9 months ago
They do not correct the answers, there are many wrong, how do you want us to pay for Contribution Access? B & D
upvoted 1 times
...
JustAnotherKids
2 years, 10 months ago
I think B D is correct answer. You should aware anycast is enable
upvoted 1 times
...
Cornelius360
2 years, 11 months ago
B and D are correct
upvoted 2 times
...
ibos8383
3 years ago
Selected Answer: BD
I think it is B and D
upvoted 1 times
...
blahblah1234567890000
3 years, 3 months ago
Selected Answer: BD
Answer is B,D
upvoted 2 times
...
ScottXYZ
3 years, 4 months ago
BD Link below shows D is correct and I agree that A and C do not make sense https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGuard-communication/ta-p/197109?externalID=FD46841
upvoted 1 times
...
vdmi
3 years, 5 months ago
For A: It says "local FortiManager" and all the "Server List" IPs are public For B: The letter "I" from the "Flags" section means "Contract server contacted" For C: The "Curr Lost" and "Total Lost" sections have the value 0 This means that A & C are wrong, B is right and the only other option left is D. * B & C can be verified @ FortiGate Security Study Guide - page 415 (Web Filtering - FortiGuard Connection)
upvoted 2 times
...
nimvoltage
3 years, 7 months ago
This has the answer https://kb.fortinet.com/kb/documentLink.do?externalID=FD46841
upvoted 2 times
...
Akoladet
3 years, 7 months ago
The right answer is B and D
upvoted 1 times
...
2021gene
3 years, 8 months ago
I understand that the correct ones are B and D, see FortiGate_Security_6.4_Study_Guide page 415(about the I flag indicating contract server contacted), and 416(HTTPS port 443 enforced by default fortiguard or manager communications)
upvoted 3 times
...
RHK0783
3 years, 8 months ago
A & B are correct ... Default port is 8888 Also No packet drop
upvoted 1 times
RHK0783
3 years, 8 months ago
My Bad, B&D are the right choices. Based on the flag definition, DI indicates that this server was contacted. 443 is also one of the default ports. NO indicator of the Fortimanager. Also, all listed IPs are public IPs that belongs to Fortiguard servers.
upvoted 2 times
...
...
alkalinegp
3 years, 8 months ago
Default ports for querying Fortiguard are either udp/8888 or udp/53. If Fortigate is querying by using HTTPS tcp/443, then this indicates answer A (local FortiManager is used as Fortigurad server - https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/179018/using-fortimanager-as-a-local-fortiguard-server). So, in the end A & B answers are correct
upvoted 1 times
...
moneim
3 years, 8 months ago
HTTPS 443 is also considered as default port for communication. If you look at a real fortigate device you will find 3 options HTTPS, UDP 8888 and udp 53
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago