exam questions

Exam NSE5_FAZ-7.0 All Questions

View all questions & answers for the NSE5_FAZ-7.0 exam

Exam NSE5_FAZ-7.0 topic 1 question 23 discussion

Actual exam question from Fortinet's NSE5_FAZ-7.0
Question #: 23
Topic #: 1
[All NSE5_FAZ-7.0 Questions]

Refer to the exhibit.

Which image corresponds to the packet capture shown in the exhibit?

  • A.
    B.

    C.
  • D.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TheRealConJon
Highly Voted 6 months, 3 weeks ago
On the exam, option B doesn't have a lock but is green to show it is up but not using secure syslog TCP port 6514. Since we can see the port used is 514 we know the syslog is not secure and is instead using UDP port 514. So for this question you need to be looking for a green (meaning online/up) option without a lock because it isn't secure. B and C are the same answer here so one was copied incorrectly. One of those should be green without a lock and that would be the answer.
upvoted 10 times
nerostart
6 months, 1 week ago
Port UDP/514 is used for unencrypted log communication. Syslog runs on UDP, where syslog servers listen to UDP port 514 and clients (sending log messages) The default port for secure TCP syslog messages is 6514
upvoted 1 times
...
...
dede1234
Most Recent 5 months, 1 week ago
By default, syslog protocol works over UDP port 514. If you need to pass syslog packets through a firewall, you need to allow access at UDP 514. If you send syslog over the default UDP port 514, then messages are un-encrypted and can be intercepted and stolen over the network. If you want secure log messages transfer, then Syslog must work over TCP 6514 with secure TLS certificate-based authentication (RFC 5425) that means that answer is GREEN WITHOUT LOCK.
upvoted 1 times
...
k3rnelpanicpj
6 months, 2 weeks ago
It should be green with lock: log is received (green) with encryption (tcp/514 is for OFTP) https://training.fortinet.com/pluginfile.php/1245914/mod_resource/content/26/FortiAnalyzer_7.0_Study_Guide-Online.pdf?forcedownload=1 page 148 and https://docs.fortinet.com/document/fortianalyzer/7.0.0/administration-guide/781928/device-manager
upvoted 1 times
k3rnelpanicpj
6 months, 2 weeks ago
without encryption!!! so green without lock! D
upvoted 1 times
...
...
matt20491
6 months, 4 weeks ago
B Screenshot is wrong from exam, There should be a UDP connection that is successful (Green status without lock icon)
upvoted 1 times
...
ilbartonicola
7 months ago
Selected Answer: D
D is the only case for UDP connection
upvoted 1 times
...
LizanPR
7 months ago
I think it is D. It's the only one that would receive a UDP log. The lock next to the Real Time circle means reliable/secure, which requires TCP. Status is down (red) though, but that might be a red herring.
upvoted 4 times
...
wayne0926
7 months, 3 weeks ago
Correct Answer: A
upvoted 1 times
M1gu3l
7 months, 1 week ago
Why? Somebody can explain the answer please?
upvoted 3 times
pepso100
3 months ago
in capture you see port UDP 514 what means UNencrypted - without lock in capture you see SYSLOG traffic so it could be green summary => green without lock is proper answer. This pic is missing there or D has wrong color Identifies whether the device is successfully sending logs to the FortiAnalyzer unit. A green circle indicates that logs are being sent. A red circle indicates that logs are not being sent. The status indicator will turn from green to red when logs have not been sent for 15 minute or longer. A lock icon displays when a secure tunnel is being used to transfer logs from the device to the FortiAnalyzer unit. https://docs.fortinet.com/document/fortianalyzer/7.0.0/administration-guide/781928/device-manager
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago