exam questions

Exam NSE4_FGT-6.4 All Questions

View all questions & answers for the NSE4_FGT-6.4 exam

Exam NSE4_FGT-6.4 topic 1 question 105 discussion

Actual exam question from Fortinet's NSE4_FGT-6.4
Question #: 105
Topic #: 1
[All NSE4_FGT-6.4 Questions]

Refer to the exhibit.

The exhibit shows a CLI output of firewall policies, proxy policies, and proxy addresses.
How does FortiGate process the traffic sent to http://www.fortinet.com?

  • A. Traffic will be redirected to the transparent proxy and it will be denied by the proxy implicit deny policy.
  • B. Traffic will be redirected to the transparent proxy and it will be allowed by proxy policy ID 3.
  • C. Traffic will not be redirected to the transparent proxy and it will be allowed by firewall policy ID 1.
  • D. Traffic will be redirected to the transparent proxy and it will be allowed by proxy policy ID 1.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
yadavarya97
Highly Voted 3 years, 8 months ago
A is correct as traffic is being sent to fortinet.com, which will not match any proxy policy as will be implicit denied.
upvoted 12 times
prenominal
3 years, 8 months ago
Agreed. http-policy-redirect validates using the proxy policies. Since proxy policy 1 does not match fortinet.com and proxy policies 2 & 3 are disabled, the implicit proxy policy (deny) will deny the traffic. https://kb.fortinet.com/kb/documentLink.do?externalID=FD40584
upvoted 10 times
...
...
NicolaeEast
Most Recent 2 years, 8 months ago
Selected Answer: A
Host regex match - Once created, the hostname address can be selected as a destination of a proxy policy. This means that a policy will only allow or block requests that match the regular expression. So because both of the other proxy-policies are set to disable, only proxy-policy 1 is applicable. https://docs.fortinet.com/document/fortigate/7.0.1/administration-guide/720455/proxy-policy-addresses
upvoted 1 times
...
SandroAlex
3 years, 1 month ago
Selected Answer: A
A é a verdadeira
upvoted 1 times
...
Wachiturro
3 years, 1 month ago
By discarding the answers, the one that best satisfies the question is A
upvoted 1 times
...
Miguex125
3 years, 4 months ago
This sort of questions can be overwhelmed, however the key is read carefully each line, in this way you narrow the options. A is correct.
upvoted 3 times
...
jarz
3 years, 9 months ago
I don't get this question / answer either. Policy ID 3 has its status disabled and so shouldn't be passing traffic? I did spin this up in a lab and confirmed the configuration, but after disabling the allow all policy I could still reach the internet, which makes me think that policy id 1 was passing the traffic.
upvoted 1 times
MrSaintz
3 years, 4 months ago
In your lab you must have set your explicit proxy default firewall policy to accept. if you had it in deny it will block all http/https traffic but the matching EICAR.
upvoted 1 times
...
MrSaintz
3 years, 4 months ago
In your lab you must have set your explicit proxy default firewall policy to accept. if you had it in deny it will block all traffic, but eicar
upvoted 1 times
MrSaintz
3 years, 4 months ago
deny is default by the way, this not explicitly shown in any screenshot, so you must assume default, if default was accept, your answer would be true.
upvoted 1 times
...
...
...
G33
3 years, 9 months ago
A - if traffic is redirected to web proxy then srcintf port3, dstintf port1 and this matches proxy policy 3 (fortinet.com -dst all) but is disabled so it is implicitly denied
upvoted 4 times
...
Gape4
3 years, 9 months ago
B. Because in transparent Proxy, the client send requests to the web server and the web proxy intercepts the client's requests transparently.
upvoted 1 times
xela2005
3 years, 9 months ago
B not is correct. police id 3 ---> set status disable . i think is A correct.
upvoted 1 times
...
...
fihocoy633
3 years, 9 months ago
Can someone explain please ? I don't get it
upvoted 3 times
...
Jancy_111
3 years, 10 months ago
why not D?
upvoted 1 times
thissiteisgreat
3 years, 10 months ago
because the proxy policy 2 & 3 has status set to disabled
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago