exam questions

Exam NSE7_EFW-7.2 All Questions

View all questions & answers for the NSE7_EFW-7.2 exam

Exam NSE7_EFW-7.2 topic 1 question 35 discussion

Actual exam question from Fortinet's NSE7_EFW-7.2
Question #: 35
Topic #: 1
[All NSE7_EFW-7.2 Questions]

Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

  • A. udp is not a protocol option.
  • B. fortiguard-anycast is set to enable.
  • C. You do not have the corresponding write access.
  • D. FortiManager provides FortiGuard.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
myrmidon3
1 month, 2 weeks ago
Selected Answer: B
Reason for the Error: When fortiguard-anycast is enabled, FortiGate automatically uses TCP as the protocol for FortiGuard communication. This is because the Anycast protocol relies on TCP for ensuring reliability and proper connection establishment with the nearest FortiGuard server. In this mode, you cannot manually set the protocol to UDP. Why the other options are incorrect: A. FortiManager provides FortiGuard: While FortiManager can act as a local FortiGuard Distribution Server, it does not influence the protocol settings for FortiGuard communication. C. You do not have the corresponding write access: If this were a permissions issue, the error would indicate an authorization problem, not a parsing error. D. udp is not a protocol option: UDP is a valid protocol option for FortiGuard communication, but it cannot be used when fortiguard-anycast is enabled.
upvoted 1 times
...
re_j0hn
5 months, 4 weeks ago
60F (fortiguard) # set fortiguard-anycast enable 60F (fortiguard) # set protocol https HTTPS for server communication (for use by FortiGuard or FortiManager). 60F (fortiguard) # set protocol https No UDP option when anycast is enabled.
upvoted 1 times
...
jddc10006
7 months, 4 weeks ago
Selected Answer: B
B its correct
upvoted 1 times
...
havokdu
9 months, 2 weeks ago
Selected Answer: B
B is correct. You can enable UDP and ports 443, 53 or 8888 only after disabling fortiguard anycast setting on CLI. Otherwise Web-filtering will use HTTPS on port 443.
upvoted 2 times
...
charruco
10 months, 2 weeks ago
Selected Answer: B
B is correct study guide page 245
upvoted 1 times
...
5deee77
1 year ago
Selected Answer: B
study guide page 245
upvoted 1 times
...
Heim_Ox
1 year ago
B is correct. fortguard-anycast must be disabled to change the protocol to UDP. in this case, error is received when trying to set UDP protocol. This can indicate fortiguard-anycast is currently enabled.
upvoted 2 times
...
MikeSco001
1 year ago
Selected Answer: B
B is correct
upvoted 1 times
...
Artbrut
1 year ago
Selected Answer: B
As per https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-UDP-protocol-for-FortiGuard-web-filter/ta-p/191920
upvoted 2 times
...
mollyk70
1 year ago
A is correct
upvoted 1 times
MikeSco001
1 year ago
answer is B
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago