exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 21 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 21
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Which three criteria can FortiGate use to look for a matching firewall policy to process traffic? (Choose three.)

  • A. Services defined in the firewall policy
  • B. Highest to lowest priority defined in the firewall policy
  • C. Destination defined as Internet Services in the firewall policy
  • D. Lowest to highest policy ID number
  • E. Source defined as Internet Services in the firewall policy
Show Suggested Answer Hide Answer
Suggested Answer: ACE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
raydel92
Highly Voted 1 year, 8 months ago
Selected Answer: ACE
Correct: A. Services defined in the firewall policy C. Destination defined as Internet Services in the firewall policy E. Source defined as Internet Services in the firewall policy FortiGate Security 7.2 Study Guide (p.52): "When a packet arrives, how does FortiGate find a matching policy? Each policy has match criteria, which you can define using the following objects: • Incoming Interface • Outgoing Interface • Source: IP address, user, internet services • Destination: IP address or internet services • Service: IP protocol and port number • Schedule: Specific times to apply policy" Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 11 times
...
Slash_JM
Highly Voted 1 year, 8 months ago
Selected Answer: ACE
FortiGate Security 7.2 Study Guide p.52 The policies are consulted from top to bottom, regardless of the Policy ID #. The first rule that matches is applied and subsequent rules are not evaluated. FortiGate matches the traffic using the following criteria: - Incoming Interface - Outgoing Interface - Source (IP Address, User, Internet Services) - Destination (IP Address or Internet Services) - Service (IP Protocol and Port number) - Schedule (Time that the packet connected to the FortiGate)
upvoted 6 times
...
Cisco_SE_765
Most Recent 11 months, 1 week ago
Selected Answer: ACE
The correct ones are A,C,E
upvoted 1 times
...
[Removed]
1 year, 8 months ago
Selected Answer: ACE
ACE is correct
upvoted 1 times
...
Danny_B
1 year, 11 months ago
Selected Answer: ACE
7.2 SEC 52
upvoted 2 times
...
geroboamo
1 year, 12 months ago
Selected Answer: ACE
there is no priority to be defined in security policies, and the policy id is just for reference
upvoted 3 times
...
PaulGo
2 years, 1 month ago
Selected Answer: ACE
Correct A, C, E
upvoted 1 times
...
Equiano
2 years, 1 month ago
Selected Answer: ACE
ACE is correct!
upvoted 1 times
...
DriftandLuna
2 years, 2 months ago
ACE, firewall policy will match on services, source & destinaiton
upvoted 1 times
...
leadac
2 years, 3 months ago
Selected Answer: ACE
ACE - Policy ID does not define a matching criteria, it´s just for editing purposes, and there is no priority in the policies, only their order will affect the matching process.
upvoted 3 times
...
Rich_Man_Rich
2 years, 4 months ago
ACE is correct
upvoted 2 times
...
indunil75
2 years, 4 months ago
ACE is correct
upvoted 3 times
...
chiheb
2 years, 4 months ago
Selected Answer: ACE
the correct answers are ACE.
upvoted 3 times
...
jberol
2 years, 4 months ago
ACE is correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago