exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 19 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 19
Topic #: 1
[All NSE4_FGT-7.0 Questions]

Refer to the exhibit.

The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are configured in transparent mode.
The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access the internet. The To_Internet VDOM is the only VDOM with internet access and is directly connected to ISP modem.
With this configuration, which statement is true?

  • A. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs.
  • B. A default static route is not required on the To_Internet VDOM to allow LAN users to access the internet.
  • C. Inter-VDOM links are required to allow traffic between the Local and DMZ VDOMs.
  • D. Inter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Poebla
Highly Voted 1 year, 9 months ago
Selected Answer: A
B is not true, a defaut static route is needed.
upvoted 13 times
bozky
1 year, 8 months ago
No, FG can get dynamic default route from ISP.
upvoted 4 times
warlusontheweb
9 months, 2 weeks ago
How? with the help of magic?? it should be necessary a routing protocol in case but nothing is specified, any assumption can lead an error. It is reported which statement is true? It is not plural. Only A.
upvoted 1 times
...
...
...
bccabrera
Highly Voted 1 year, 8 months ago
Selected Answer: A
A. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs. B. A default static route is not required on the To_Internet VDOM to allow LAN users to access the internet./ Basic routing. C. Inter-VDOM links are required to allow traffic between the Local and DMZ VDOMs. / At least one of the VDOMs must be operating in NAT mode. This, among other benefits, prevents potential Layer 2 loops. D. Inter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM./ Similar to FG w/o VDOMs enabled, the admin VDOM should have outgoing Internet access. Otherwise, features such as scheduled FortiGuard updates will fail.
upvoted 7 times
...
darkdante24
Most Recent 5 months, 1 week ago
Selected Answer: A
The question does not say choose 2. So why choose 2 answers, correct answer is A
upvoted 1 times
...
raydel92
9 months, 3 weeks ago
Selected Answer: A
Correct: A. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs. Incorrect: B. A default static route is not required on the To_Internet VDOM to allow LAN users to access the internet. C. Inter-VDOM links are required to allow traffic between the Local and DMZ VDOMs. (transparent-transparent) D. Inter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM. FortiGate Infrastructure 7.2 Study Guide: "Each VDOM has independent security policies and routing tables. Also, and by default, traffic from one VDOM cannot go to a different VDOM" (p.71) "...you cannot create an inter-VDOM link between Layer 2 transparent mode VDOMs. At least one of the VDOMs must be operating in NAT mode" (p.101) "Similar to FortiGate without VDOMs enabled, the management VDOM should have outgoing internet access. Otherwise, features such as scheduled FortiGuard updates, fail" (p.73) Reference and download study guide: https://ebin.pub/fortinet-fortigate-infrastructure-study-guide-for-fortios-72.html
upvoted 3 times
...
Z13G3
1 year, 3 months ago
The question doesn't ask for multiple correct statements or am i missing anything? bccabrera's & Poeblas statements are correct, why are so many people selecting two answers?
upvoted 1 times
...
missaw84
1 year, 4 months ago
Selected Answer: AD
upvoted 1 times
...
alexeid72
1 year, 4 months ago
Root vdom is used only as management Vdom and not required inter links, correct answers are A and C
upvoted 1 times
...
dosoriomartins
1 year, 5 months ago
Selected Answer: B
We can use cables to interconnect VDOMs so Inter-VDOM link is not a requirement, but a feature. Inter-VDOM link does not allow traffic, it creates a path. The security policy can allow the traffic. A static default route is not needed, a route or multiple routes to the internet are needed, static or not.
upvoted 1 times
...
The_Aurora
1 year, 7 months ago
Pretty bad question in my opinion. It should provide more information, does the fortigate get route to the internet through a dynamic route protocol/is dhcp enabled on ISP router? Inter-vdom links are technically required for communication but alone won't cause the traffic to pass. While the management vdom should have internet access, it is TECHNICALLY not required. If it said "It's best practice to.." it would be a different story.
upvoted 4 times
...
iseeusee
1 year, 7 months ago
Selected Answer: A
only A
upvoted 2 times
...
lregu82
1 year, 8 months ago
Selected Answer: A
Is A for sure, and only 1 Answer is required
upvoted 3 times
...
Daniel_Dimatel
1 year, 9 months ago
Selected Answer: A
You need a static route on the To_Internet VDOM
upvoted 1 times
...
Power_Shell
1 year, 9 months ago
Selected Answer: A
I would say only A because most of the time company will use Static public IP, but think about it, if the ISP provides a dynamic public IP to the Fortigate, will it have a dynamic route?
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago