exam questions

Exam NSE7_NST-7.2 All Questions

View all questions & answers for the NSE7_NST-7.2 exam

Exam NSE7_NST-7.2 topic 1 question 39 discussion

Actual exam question from Fortinet's NSE7_NST-7.2
Question #: 39
Topic #: 1
[All NSE7_NST-7.2 Questions]

Refer to the exhibit, which contains the partial output of a diagnose command.

Based on the output, which two statements are correct? (Choose two.)

  • A. The remote gateway IP is 10.200.5.1.
  • B. The remote gateway has quick mode selectors containing a destination subnet of 10.1.2.0/24.
  • C. DPD is disabled.
  • D. Anti-replay is enabled.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ic3Box
1 month ago
Selected Answer: BD
Correct answer is BD! From the snippet we can see that DPD is turned on (dpd: mode=on-demand on=1…) and that the IPsec SA is using a 2048‐entry replay window (replaywin=2048), which implies anti‐replay is enabled. So, C is incorrect (DPD is enabled, not disabled) and D is correct (anti‐replay is enabled). For the quick‐mode selectors, FortiGate labels the local subnet as src and the remote subnet as dst from its own perspective. Here, src=0:10.1.2.0/255.255.255.0 and dst=0:10.1.1.0/255.255.255.0 indicates the other side (the remote FortiGate) sees its “destination” as `10.1.2.0/24.” That makes B correct. Conversely, the tunnel ID and arrow notation show that 10.200.4.1 is the remote gateway IP, so A is not correct.
upvoted 1 times
...
TrX
3 months, 1 week ago
Selected Answer: AD
The correct statements are: A. The remote gateway IP is 10.200.5.1. You can see this in the "serial-1 10.200.5.1:0->10.200.4.1:0" portion of the output. D. Anti-replay is enabled. The output shows "replaywin-2048", which indicates that anti-replay is enabled with a replay window of 2048 packets.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago