exam questions

Exam NSE7_EFW-6.2 All Questions

View all questions & answers for the NSE7_EFW-6.2 exam

Exam NSE7_EFW-6.2 topic 1 question 49 discussion

Actual exam question from Fortinet's NSE7_EFW-6.2
Question #: 49
Topic #: 1
[All NSE7_EFW-6.2 Questions]

Refer to the exhibits, which contain configuration on FortiGate and partial session information.


All traffic to the Internet currently egresses from port1. The exhibit shows partial session information for Internet traffic from a user on the internal network.
If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user's session?

  • A. The session would remain in the session table, but its traffic would now egress from both port1 and port2.
  • B. The session would remain in the session table, and its traffic would still egress from port1.
  • C. The session would remain in the session table, and its traffic would start to egress from port2.
  • D. The session would be deleted, so the client would need to start a new session.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pollyy
Highly Voted 4 years, 2 months ago
C - Correct - NSE7_EFW-6.2 Manual page 152
upvoted 9 times
...
anitaramirezcl
Highly Voted 3 years, 7 months ago
For me is D because snat route change is enable in this case the any session is delete.
upvoted 5 times
...
ni
Most Recent 2 years, 11 months ago
C page 151
upvoted 1 times
...
Prof3ss0r
3 years, 1 month ago
Notice the command snat-route-change enable is set which flushes routing information from existing SNAT sessions so the the existing snat sessions can use any new best route. Page 148 EFW Study Guide. Correct Answer is C.
upvoted 2 times
...
Null0
3 years, 6 months ago
Answer is B. This existing session will keep using port1 since STATE=LOG MAY DIRTY. If the STATE=DIRTY then offcourse recalculation will be pushed and then any new session will be forced to port2. I think B is correct.
upvoted 1 times
...
Ahmed_Elswify
3 years, 8 months ago
Enterprise_Firewall_6.4_Study_Guide page#150,151
upvoted 1 times
...
mai340
3 years, 10 months ago
C it´s correct
upvoted 2 times
...
vwboy
3 years, 10 months ago
A. The session would remain in the session table, and its traffic would still egress from port 1. If the administrator increases the priority for port1 to a value higher than port2, and if snat-route-change is disabled, all new sessions start using port2, because it has the lowest priority. However, all the existing sessions continue to use port1. The default route is through port1. Even though the default route is no longer the best route, it is still active and FortiGate is doing SNAT. The existing sessions will continue to use the old route until they expire. If FortiGate wasn’t doing SNAT, all the existing sessions would switch to port2 after the change
upvoted 1 times
ZOKOF
3 years, 3 months ago
The text explain the case where snat-route-change is disable . So, le correct Answer is D (because snat-route-change is enable)
upvoted 1 times
...
...
jhona_0505
3 years, 11 months ago
for me, the answer is B, because the priority in port 1 is 5, the priority in port 2 is 10, Pag 134 also Pag 151 and 152 of NSE7_EFW-6.2 Manual study guide with Snat-route-change enable
upvoted 1 times
mai340
3 years, 10 months ago
yes, B it´s correct because Snat-route-change enable
upvoted 1 times
...
...
kishocr
4 years, 2 months ago
it's the same question 5 Correct - B the session remain in the session table and traffic would still egress from port 1 until the session expire.
upvoted 1 times
Lyubo
4 years, 2 months ago
In this case, we have snat-route-change enable which differs from question 5. Pay attention to that. Correct - C
upvoted 11 times
ZOKOF
3 years, 3 months ago
So D is correct . When enable, session table and route cache are flushed and routing table is re-evaluate. But if we have a session without SNAT, C become correct
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago