exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 56 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 56
Topic #: 1
[All NSE4_FGT-7.0 Questions]

Refer to the exhibits.
The exhibits contain a network diagram, virtual IP, IP pool, and firewall policies configuration.
Exhibit A.

Exhibit B.

The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
The first firewall policy has NAT enabled using IP Pool.
The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the internet traffic coming from a workstation with the IP address 10.0.1.10?

  • A. 10.200.1.100
  • B. 10.200.1.10
  • C. 10.200.1.1
  • D. 10.200.3.1
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JT20
Highly Voted 8 months ago
Selected Answer: A
Policy 1 is applied on outbound (LAN-WAN) and policy 2 is applied on inbound (WAN-LAN). question is asking SNAT for outbound traffic so policy 1 will take place and NAT overload is in effect.
upvoted 6 times
...
doncacciato62
Most Recent 6 months, 1 week ago
Is it correct to say that if you had the REAL (Mapped IP) of 10.0.1.10 as the source in the first rule instead of "all" the SNAT would use te VIPs address of 10.200.1.10 ?
upvoted 2 times
Dylon
4 months, 3 weeks ago
No because it is outbound traffic. If it was inbound traffic then it would us the VIPs address.
upvoted 1 times
...
...
Kutchek
10 months ago
Selected Answer: A
traffic coming from a workstation has unspecified target (not the Webserver) so- policy 1 and ip overload matches
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago