exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 4 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 4
Topic #: 1
[All NSE4_FGT-7.2 Questions]

An administrator has configured a strict RPF check on FortiGate.
How does strict RPF check work?

  • A. Strict RPF allows packets back to sources with all active routes.
  • B. Strict RPF checks the best route back to the source using the incoming interface.
  • C. Strict RPF checks only for the existence of at least one active route back to the source using the incoming interface.
  • D. Strict RPF check is run on the first sent and reply packet of any new session.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
moutaz1983
Highly Voted 2 years ago
Answer should be (B), The strict RPF check ensures the best route back to the source is used as the incoming interface
upvoted 14 times
...
Wrath4980
Highly Voted 1 year, 1 month ago
Selected Answer: B
According to FortiGate_Infrastructure_7.2_Study_Guide page 40 Strict: In this mode, Fortigate also verifies that the matching route is the best route in the routing table. That is, if the route in table contains a matching route for the source address and the incoming interface, but there is a better route for the source address through another interface the the rpf check fails.
upvoted 6 times
...
yihqgzg
Most Recent 2 months, 3 weeks ago
B. Strict RPF checks the best route back to the source using the incoming interface. FortiGate Infrastructure 7.2 Study Guide (p.41): "Strict: In this mode, FortiGate also verifies that the matching route is the best route in the routing table. That is, if the routing table contains a matching route for the source address and incoming interface, but there is a better route for the source address through another interface, then, the RPF check fails."
upvoted 1 times
...
learner2024
8 months ago
Selected Answer: B
the matching route should be best route via incoming interface
upvoted 1 times
...
Jere2001
8 months, 3 weeks ago
Selected Answer: B
In strict mode Fortigate also verifies that the matching route is the best route in the routing table.
upvoted 1 times
...
MAUROBTA
9 months, 3 weeks ago
Selected Answer: B
Difference between "strict" and "feasible path" : 'strict' : a routing lookup (with best match) is made for the packet source IP. Packet is dropped if its ingressing interface does not match the interface selected by the routing lookup. 'feasible path' : not only the best match route is considered. Other routes pointing to packet ingressing interfaces are also checked. If one of them includes the packet source IP address (even if not the best match route), packet is accepted.
upvoted 1 times
...
GoodServant
9 months, 3 weeks ago
Selected Answer: B
You can lab it out yourself, or refer to the study guide on page 41. Loose or feasible path mode which is the default mode, only checks to make sure that a source address exists in the routing table with the incoming interface. But the strict mode, checks to that the source address and incoming interface match it's route table for the best route back to the source address. This could be a scenario where you have a customer with multiple connections back through your fortigate, where you may receive a packet in both interface port1 and port2 for the same source address. But your FGT prefers port1 as the best path. If you have strict mode turned on, and it receives a packet through port2 it will get dropped. Otherwise, RPF or feasible path RPF would be ok with that packet.
upvoted 1 times
...
znznzn219
12 months ago
Selected Answer: B
Correct
upvoted 1 times
...
GeniusA
1 year ago
B for the strick RPF check
upvoted 1 times
...
Ygrec
1 year, 2 months ago
Selected Answer: B
B definitely
upvoted 1 times
...
Ygrec
1 year, 2 months ago
B definitely
upvoted 1 times
...
raydel92
1 year, 4 months ago
Selected Answer: B
B. Strict RPF checks the best route back to the source using the incoming interface. FortiGate Infrastructure 7.2 Study Guide (p.41): "Strict: In this mode, FortiGate also verifies that the matching route is the best route in the routing table. That is, if the routing table contains a matching route for the source address and incoming interface, but there is a better route for the source address through another interface, then, the RPF check fails." Reference and download study guide: https://ebin.pub/fortinet-fortigate-infrastructure-study-guide-for-fortios-72.html
upvoted 2 times
...
Vic2911
1 year, 4 months ago
The right answer is C: "Strict RPF requires that the receiving interface is not only valid, but that it is also the best interface for the reply. If you have multiple routes, it must be the preferred one."
upvoted 1 times
Vic2911
1 year, 4 months ago
I meant B as the correct answer
upvoted 2 times
...
...
Slash_JM
1 year, 4 months ago
Selected Answer: B
FortiGate Infrastructure 7.2 Study Guide p.41
upvoted 1 times
...
lucas09
1 year, 4 months ago
The Correct answer is B Strict chooses best path back Loose chooses a valid path back Feasible path: Formerly known as loose, it’s the default mode. In this mode, FortiGate verifies that the routing table contains a route that matches the source address of the packet and the incoming interface. The matching route doesn’t have to be the best route in the routing table for that source address. It just has to match the source address and the incoming interface of the packet. Strict: In this mode, FortiGate also verifies that the matching route is the best route in the routing table. That is, if the routing table contains a matching route for the source address and incoming interface, but there is a better route for the source address through another interface, then, the RPF check fails. So in short if there is a best route out of its incoming interface then strict will pass. If there is a route from the incoming interface but a better route out of another Strict will deny.
upvoted 1 times
...
[Removed]
1 year, 4 months ago
Selected Answer: B
Correct answer: B
upvoted 1 times
...
AhmedZkry
1 year, 5 months ago
Selected Answer: B
Correct is B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago