exam questions

Exam FCP_FGT_AD-7.4 All Questions

View all questions & answers for the FCP_FGT_AD-7.4 exam

Exam FCP_FGT_AD-7.4 topic 1 question 28 discussion

Actual exam question from Fortinet's FCP_FGT_AD-7.4
Question #: 28
Topic #: 1
[All FCP_FGT_AD-7.4 Questions]

Refer to the exhibit.

Why did FortiGate drop the packet?

  • A. It matched an explicitly configured firewall policy with the action DENY.
  • B. It failed the RPF check.
  • C. The next-hop IP address is unreachable.
  • D. It matched the default implicit firewall policy.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sxcap
3 weeks, 2 days ago
Selected Answer: D
Don't get confused with the word "check", the important part is (policy 0), that's the implicit policy
upvoted 1 times
...
Charly0710
1 month, 1 week ago
Selected Answer: D
D is correct. It's clear, "Denied by forward policy check (policy 0)"
upvoted 1 times
...
vuhidus
1 month, 2 weeks ago
Selected Answer: D
It's D
upvoted 1 times
...
262cfa1
2 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
s4mu3l007
2 months, 1 week ago
D is correct - traffic is denied by implicit firewall rule
upvoted 1 times
...
youla5
3 months, 1 week ago
Policy id 0 is the default drop policy. so D is correct
upvoted 1 times
...
Knocks
3 months, 3 weeks ago
Selected Answer: D
Denied by forward policy check means it matched a deny policy, in this case it has ID 0 so it is the implicit deny
upvoted 1 times
...
fab1ccb
3 months, 3 weeks ago
Selected Answer: D
D because the output shows "Denied by forward policy check (policy 0)" which is the implicit policy
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago