exam questions

Exam NSE7_EFW-7.0 All Questions

View all questions & answers for the NSE7_EFW-7.0 exam

Exam NSE7_EFW-7.0 topic 1 question 41 discussion

Actual exam question from Fortinet's NSE7_EFW-7.0
Question #: 41
Topic #: 1
[All NSE7_EFW-7.0 Questions]

Refer to the exhibit, which shows a session entry.

Which statement about this session is true?

  • A. It is an ICMP session from 10.1.10.10 to 10.200.1.1.
  • B. Return traffic to the initiator is sent to 10.1.0.1.
  • C. It is an ICMP session from 10.1.10.1 to 10.200.5.1.
  • D. Return traffic to the initiator is sent to 10.200.1.254.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
theklee
Highly Voted 1 year, 5 months ago
Correct answer is B. Return packet routing back to the source follows this format gwy=10.200.1.254 (this is the gateway to the dest) / 10.1.0.1 (this is the destination's gateway back to the source) Study guide P 140
upvoted 9 times
...
Seph1
Highly Voted 1 year, 4 months ago
Selected Answer: B
B - is only correct. 10.1.0.1 - is a gateway for the reply.
upvoted 5 times
...
mhd96far
Most Recent 10 months, 2 weeks ago
I've just taken the exam and I think the correct answer is indeed B for question 41, I answered with C assuming there is a typo and it should be 10.1.10.10, but I don't think there will be a typo in an official exam like this, Good luck to everyone, I've only had 2 mistakes, one in System Tshoot, and the other in VPN (I'm quite sure that was the question 56 with answer auto-discovery-sender).
upvoted 2 times
...
lucient
10 months, 2 weeks ago
Selected Answer: C
I think it's "C", but there is a typo. The session is from 10.1.10.TEN (last zero is missing) to 10.200.5.1. B is wrong, because the return traffic will come to the nated IP 10.200.1.1 as showed in the "reply" line: 10.200.5.1:60430 -> 10.200.1.1:0
upvoted 2 times
...
Bob_Oso
11 months, 1 week ago
Selected Answer: B
B Enterprise_Firewall_7.0_Study_Guide-Online.pdf page 140
upvoted 3 times
...
sbirare
1 year ago
Selected Answer: B
B is the correct answer. Go through pg. 136, 137, 138, 139 & 140 from study guide. This session entry is for ICMP echo response with gateway to source identified which is 10.1.0.1. Considering fortigate objective of keeping flow symmetric, return traffic will sent to identified gateway.
upvoted 2 times
...
sebajacaj
1 year ago
I believe B is the correct answer, based on the Source gateway. But isnt this asynchronous routing?
upvoted 1 times
...
certifi46
1 year, 3 months ago
Selected Answer: B
10.1.0.1 gt to source
upvoted 3 times
...
AdamB3
1 year, 3 months ago
Selected Answer: B
A / Eliminated (wrong destination, 10.200.1.1 = SNAT egress interface) C / Eliminated (wrong source ip) D / wrong GW for return traffic to the initiation Correct answer : B return traffic is sent to GW 10.1.10.1
upvoted 3 times
...
kambata
1 year, 3 months ago
Selected Answer: B
.It's B C - It is an ICMP session from 10.1.10.1 to 10.200.5.1 - The source is wrong
upvoted 4 times
...
TrX
1 year, 3 months ago
Selected Answer: C
proto_state = 00 (icmp) icmp session from 10.1.10.10 to 10.200.5.1
upvoted 1 times
...
mabalon
1 year, 3 months ago
Selected Answer: B
B -> its the gateway for the reply
upvoted 3 times
...
HSilver
1 year, 4 months ago
Selected Answer: C
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-session-table-information/ta-p/196988?externalId=FD30042
upvoted 1 times
...
kashir
1 year, 5 months ago
there is a typo in the choice B. It should ne 10.1.0.10. So, B is the correct answer.
upvoted 1 times
...
akukaracia
1 year, 5 months ago
There is an error in the answer. Should be: B Return traffic to the initiator is sent to 10.1.0.10
upvoted 1 times
...
Drakfeut
1 year, 6 months ago
A / Eliminated (wrong destination, 10.200.1.1 = SNAT egress interface) C / Eliminated (wrong source ip) D / wrong GW for return traffic to the initiation Correct answer : B return traffic is sent to GW 10.1.10.1
upvoted 2 times
...
djela45
1 year, 6 months ago
Selected Answer: C
I believe it is C
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...