exam questions

Exam NSE4_FGT-6.0 All Questions

View all questions & answers for the NSE4_FGT-6.0 exam

Exam NSE4_FGT-6.0 topic 1 question 122 discussion

Actual exam question from Fortinet's NSE4_FGT-6.0
Question #: 122
Topic #: 1
[All NSE4_FGT-6.0 Questions]

View the exhibit.

VDOM1 is operating in transparent mode VDOM2 is operating in NAT Route mode. There is an inteface VDOM link between both VDOMs. A client workstation with the IP address 10.0.1.10/24 is connected to port2. A web server with the IP address 10.200.1.2/24 is connected to port1.
What is required in the FortiGate configuration to route and allow connections from the client workstation to the web server? (Choose two.)

  • A. A static or dynamic route in VDOM2 with the subnet 10.0.1.0/24 as the destination.
  • B. A static or dynamic route in VDOM1 with the subnet 10.200.1.0/24 as the destination.
  • C. One firewall policy in VDOM1 with port2 as the source interface and InterVDOM0 as the destination interface.
  • D. One firewall policy in VDOM2 with InterVDOM1 as the source interface and port1 as the destination interface.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
montonearm
Highly Voted 5 years, 2 months ago
C & D are chouse two i think is correct
upvoted 7 times
...
Levis
Highly Voted 4 years, 10 months ago
no routing needed, C and D are answer,
upvoted 5 times
...
ramiropalm
Most Recent 4 years, 5 months ago
I think A & D, since in the Forti Infra 6.2 says that routes are required to route packets between two VDOMs.
upvoted 1 times
farmez
4 years, 4 months ago
routes are required if both VDOMs are in NAT mode (which is not the case here). VDOM1 is working in transparent mode. meaning that, VDOM2 is directly connected to both Subnets. Therefore, no need for routing
upvoted 1 times
...
...
ramzie
4 years, 6 months ago
Answer is C&D
upvoted 1 times
...
Raul_Omar
4 years, 7 months ago
C and D are correct.
upvoted 1 times
...
Rondo
4 years, 9 months ago
C & D are correct. No routes need be configured because both networks are directly connected. Also because vdom1 is transparent all that is needed is a firewall policy as the client will have link1 IP as the gateway. vdom2 also needs a firewall policy to allow the traffic to reach destination interface.
upvoted 2 times
...
jbernard
4 years, 10 months ago
C and D are correct... (Question says "choose two") A is NOT correct cause you need to allow traffic from 10.0.1.10 to 10.200.1.2, so the destination is 10.200.1.0/24 subnet B is not correct cause the static route must be configured in VDOM2
upvoted 4 times
...
Fr4nx
4 years, 11 months ago
A and C
upvoted 1 times
...
esh1
5 years ago
A and D.
upvoted 2 times
...
alex_iec
5 years, 5 months ago
A & C are correct.
upvoted 3 times
esh1
5 years ago
I Agree , only the fact that VDOM1 is transparent directs on answers A and C.
upvoted 1 times
esh1
5 years ago
sorry I mean A and D.
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago