exam questions

Exam NSE4_FGT-6.4 All Questions

View all questions & answers for the NSE4_FGT-6.4 exam

Exam NSE4_FGT-6.4 topic 1 question 33 discussion

Actual exam question from Fortinet's NSE4_FGT-6.4
Question #: 33
Topic #: 1
[All NSE4_FGT-6.4 Questions]

Refer to the exhibit.

Given the interfaces shown in the exhibit, which two statements are true? (Choose two.)

  • A. Traffic between port2 and port2-vlan1 is allowed by default.
  • B. port1-vlan10 and port2-vlan10 are part of the same broadcast domain.
  • C. port1 is a native VLAN.
  • D. port1-vlan1 and port2-vlan1 can be assigned in the same VDOM or to different VDOMs.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
aads
Highly Voted 4 years ago
The answer must be C and D. For A - traffic between interfaces is not allowed by default. For B - Port1-vlan10 and port-2vlan10 are not in the same broadcast domain since the subnet is different.
upvoted 26 times
...
Lionardo
Highly Voted 4 years ago
B & D is correct. FortiGate_Infrastructure_6.4 page 127 for "D" and page 154 for "B"
upvoted 6 times
murathtp
4 years ago
fortigate ports are in different broadcast domains. so how port1 and port 2 are in same broadcast domains? ı am not sure abot the answer, but B seems incorrect to me.
upvoted 4 times
gianmarco
4 years ago
each VLAN forms a separate broadcast domain | Pag 154
upvoted 2 times
...
...
NSE421
3 years, 12 months ago
B & D seems to me the correct answers
upvoted 1 times
...
MrSaintz
3 years, 4 months ago
broadcast domains are discussed in transparent-mode, no IP is assigned to the interfaces in this mode, much less considering that 10.1.10.1/24 is in the same broadcast domain as 10.0.10.1/24 B is surely incorrect.
upvoted 5 times
...
...
NicolaeEast
Most Recent 2 years, 8 months ago
A. WRONG Because they are different subnets, this will not work work. B. WRONG The interfaces can only be a part of the same broadcast domain if the Fortigate is in Transparent mode. If the Fortigate was in transpararent mode, however, the interfaces would not be assigned IP addresses. C. CORRECT Physical interface is native VLAN. D. CORRECT In NAT mode, which this obviously is, interfaces can be moved around. And even multi-VDOM VLAN sub-interfaces can belong in different VDOMs. Fortigate Infrastructure 7.0 Pg 121: Fortigate Infrastructure 7.0 Pg 134: Fortigate Infrastructure 7.0 Pg 156 Fortigate Infrastructure 7.0 Pg 160:
upvoted 1 times
NicolaeEast
2 years, 8 months ago
A wrong most of all because traffic between interfaces not allowed by default. And D is correct for the sake of the answer... But in reality, the two vlans couldn't exist on the same vdom unless the subnets matched.
upvoted 2 times
...
...
JuanTrabal
2 years, 9 months ago
So many people here commenting and nobody knows the correct answer yet.
upvoted 2 times
...
MetDaci
3 years, 1 month ago
Selected Answer: CD
C&D is correct.javascript:void(0)
upvoted 1 times
...
SandroAlex
3 years, 1 month ago
Selected Answer: CD
C e D são verdadeiras
upvoted 1 times
...
AJDLM
3 years, 1 month ago
Answer B and C A and d are wrong: For A - traffic between interfaces is not allowed by default. For D - "Each interface (physical or VLAN) can belong to ONLY ONE VDOM." (FortiGate Infrastructure 6.4 page 127
upvoted 1 times
AJDLM
2 years, 7 months ago
Only to confirm that B and C is correct, verified in FortiGate with 6.4.6
upvoted 1 times
...
...
MOSTAFAMETWALLY
3 years, 1 month ago
C and D.
upvoted 1 times
...
mario156090
3 years, 2 months ago
Selected Answer: CD
C and D.
upvoted 1 times
...
lrosadini
3 years, 3 months ago
C-D: B is wrong because a brodcast domain is a datalink layer [Level2], here we are working in NAT mode A is wrong because traffic between different interface aren't allowed
upvoted 4 times
...
RatheeshRavindran
3 years, 3 months ago
Selected Answer: CD
C and D is correct
upvoted 2 times
...
MrSaintz
3 years, 4 months ago
Selected Answer: CD
I agree with aads... "For A - traffic between interfaces is not allowed by default. For B - Port1-vlan10 and port-2vlan10 are not in the same broadcast domain since the subnet is different."
upvoted 1 times
Stitch2020
3 years, 3 months ago
Broadcast domain is a layer 2 concept, nothing to do with subnets.
upvoted 1 times
blahblah1234567890000
3 years, 2 months ago
vlans form a separate broadcast domain though.
upvoted 1 times
...
...
...
ScottXYZ
3 years, 4 months ago
CD is correct A is wrong, different interfaces are not allowed by default B is wrong, because physical interfaces with SAME VLAN do not have to belong to the same broadcast domain. We don't know if they connect to the same switch. Also the IP subnet is different another clue
upvoted 1 times
...
Ali1982
3 years, 5 months ago
B & D ----Creating VLAN subinterfaces with the same VLAN ID doesn’t create an internal connection between them. For example, a VLAN ID of 300 on port1 and VLAN ID of 300 on port2 are allowed, but they aren’t connected. Their relationship is the same as between any two FortiGate network interfaces. FortiGate interfaces can’t have overlapping IP addresses, the IP addresses of all interfaces must be on different subnets. This rule applies to both physical interfaces and to virtual interfaces, such as VLAN subinterfaces.
upvoted 1 times
...
damcol
3 years, 5 months ago
C and D https://community.fortinet.com/t5/FortiGate/Technical-Tip-rules-about-VLAN-configuration-and-VDOM-interface/ta-p/197640?externalID=FD31639
upvoted 2 times
...
funirka
3 years, 6 months ago
D: https://kb.fortinet.com/kb/documentLink.do?externalID=FD31639 Example of VLAN setting and VDOM assignment. The same VLANs from another ports at the same VDOM. Answer B is OK only for transparent mode, not NAT mode (IP addresses = NAT mode for this question). FG Infra 7.0 page 171
upvoted 3 times
...
forti_Ctes
3 years, 7 months ago
A: wrong B: correct. same vlan ID = same broadcast domain C: correct: Port1 = Vlan0 = Native Vlan D: Wrong: cant have 2 vlanID interface in the same VDOM
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago