exam questions

Exam NSE7_SDW-7.2 All Questions

View all questions & answers for the NSE7_SDW-7.2 exam

Exam NSE7_SDW-7.2 topic 1 question 61 discussion

Actual exam question from Fortinet's NSE7_SDW-7.2
Question #: 61
Topic #: 1
[All NSE7_SDW-7.2 Questions]

Refer to the exhibits.


Exhibit A -




Exhibit B -



Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)

  • A. The phase 1 configuration supports the network-overlay setting.
  • B. FortiGate does not install IPsec static routes for remote protected networks in the routing table.
  • C. UDP port 4500 is used for IPsec VPN traffic (ESP).
  • D. FortiGate facilitated the negotiation of the T_INET_1_0 ADVPN shortcut over T_INET_1.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MichaelG77
4 days, 23 hours ago
Selected Answer: BD
A: Incorrect because network-overlay is not enabled B: Correct because add-route is disabled C: Incorrect because natt mode=none D: Correct because parent=T_INET_1
upvoted 1 times
...
kappa915
1 month ago
Selected Answer: AB
A & B are correct. A - claims the config is supported, not necessarily configured, thus the claim is true B - add-route is disabled, thus the claim is true C - "natt: mode=none", thus no NAT-T
upvoted 1 times
...
ccie8122
1 month, 3 weeks ago
Selected Answer: AB
D is definitely wrong. There is no indication of any spoke-spoke tunnel. This is a hub (indicated by the auto-discovery-sender command), and tunnel T_INET_1_0 is a hub-spoke tunnel, not a spoke-spoke tunnel, and therefore cannot be a shortcut. C is wrong. IPSec ESP uses UDP 500 unless traversing NAT on either or both ends--only then is UDP 4500 used. However, from Exh B: "natt: mode=none" Thus no NAT-T, therefore no UDP 4500. That leaves A - which is not in the configuration but should be, unless they just mean the config supports it even though it is not configured - which is definitely the case and part of the reference design in the recommended template, most of which is configured on this hub. And B: i think this is actually false -- it looks like we are doing ADVPN with Phase2 Selector (SG p291), in which case the phase 2 selector (i.e., IPsec static routes) *would* be installed in the routing table. This is a bad question, since definitionally, C and D *cannot* be correct based on the diag output, and it appears B is conceptually incorrect.
upvoted 2 times
...
thepresidents83
2 months, 1 week ago
Selected Answer: BD
I think A is wrong since set network overlay enable command isn't configured in Phase1 (and default value is disabled). I see that parent shortcut is T_INET_1 therefore correct answers are BD
upvoted 1 times
...
Mellon
2 months, 2 weeks ago
Selected Answer: AB
Audo discovery sender & add route disable
upvoted 1 times
...
jebusruns
2 months, 2 weeks ago
Selected Answer: AB
I can't see c being right cannot tell if 4500 is being used from the output unless I am missing something. But this is a hub config so A is true and B add route is disabled.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago