exam questions

Exam NSE7_EFW-6.2 All Questions

View all questions & answers for the NSE7_EFW-6.2 exam

Exam NSE7_EFW-6.2 topic 1 question 48 discussion

Actual exam question from Fortinet's NSE7_EFW-6.2
Question #: 48
Topic #: 1
[All NSE7_EFW-6.2 Questions]


Refer to the exhibit, which contains the output of a diagnose command.
Which two statements about the output are true? (Choose two.)

  • A. This is an expected session created by a session helper.
  • B. This is an expected session created by an application control profile.
  • C. Traffic in the original direction (coming from the IP address 10.171.121.38) will be routed to the next-hop IP address 10.0.1.10.
  • D. Traffic in the original direction (coming from the IP address 10.171.121.38) will be routed to the next-hop IP address 10.200.1.1.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kishocr
Highly Voted 4 years, 2 months ago
A is correct ------ source ip: 10.171.121.38 destination ip: 10.200.1.1 Gateway: 10.0.1.10 If the question is about the destination IP D is correct But it says "will be routed" I think it is about the gateway and C is correct
upvoted 10 times
...
pollyy
Highly Voted 4 years, 2 months ago
Correct A & C
upvoted 8 times
...
professa
Most Recent 2 years, 11 months ago
Its simple when doing routing, you define the destination network through the next hope gateway or the address behind it????? its the gateway which is 10.0.1.10 correct answer A,C
upvoted 1 times
...
FortiSherlock
3 years, 7 months ago
Output means that traffic from 10.171.121.38 to 10.200.1.1 will use destination NAT and the destination IP will be replaced by 10.0.1.10. This means that 10.200.1.1 is the gateway. When my home routers IP address is X and my laptops IP is 192.168.0.100 then traffic from internet to my laptop is destined to X (gateway IP, my router). On the router DNAT replaces X by 192.168.0.100. Same principle here. So traffic from some host 10.171.121.38 has destination IP 10.200.1.1 (gateway) and on the GW DNAT replaces 10.200.1.1 by 10.0.1.10 which is the final destination. Now the questions asks about traffic COMING FROM 10.171.121.38. So it asks to which point is it routed when it initiates from this IP. As explained above, it is routed to 10.200.1.1 where the destination NAT to the final destination 10.0.1.10 happens, so from 10.171.121.38s perspective, and that is what the questions asks for, 10.200.1.1 is the next-hop.
upvoted 4 times
...
mai340
3 years, 10 months ago
A & C it´s correct
upvoted 1 times
...
ItalyFortinet91
4 years ago
I think A and C, because this is a session with helper and after the destination nat the traffic is routed to the 10.0.1.10
upvoted 5 times
...
fmokdelv
4 years, 2 months ago
NSE7_EFW6.2 Manual page p 118 source ip: 10.171.121.38 destination ip: 10.0.1.10 Gateway: 10.200.1.1 Correct A & D
upvoted 6 times
Bobsinclar06
3 years, 11 months ago
10.200.1.1 is the destination, not the gateway
upvoted 2 times
ni
2 years, 11 months ago
policy_dir=1 means is not the original, so in order to find the GW we must think reverse
upvoted 2 times
...
...
...
Lyubo
4 years, 2 months ago
For me A and D are correct
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago