Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam NSE4_FGT-7.2 topic 1 question 53 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 53
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibit.
The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are configured in transparent mode.
The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access the internet. The To_Internet VDOM is the only VDOM with internet access and is directly connected to the ISP modem.

What can you conclude about this configuration?

  • A. Inter-VDOM links are not required between the Root and To_Internet VDOMs because the Root VDOM is used only as a management VDOM.
  • B. A default static route is not required on the To_Internet VDOM to allow LAN users to access the internet.
  • C. Inter-VDOM links are required to allow traffic between the Local and DMZ VDOMs.
  • D. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
erawemk
Highly Voted 1 year, 2 months ago
Selected Answer: D
A. Management VDOM ALWAYS need access to internet B. Is not true, you ALWAYS need a default route to access the internet, despite is set manually or via DHCP C. Static routes are not needed for subnets to which Fortigate has derect layer 2 connectivity (FortiGate_Infrastructure_7.2_Study_guide page 11) D. Correct
upvoted 6 times
...
Ozzygate
Most Recent 1 month ago
I do not like this question. You DO NOT need a static default route, BGP exists. I almost never use static defaults.
upvoted 1 times
...
Tuxzinator
1 month, 1 week ago
A. Management VDOM ALWAYS need access to internet Incorrect, it does not need internet. for example: Fortiguard connection can also be achieved via FMG.
upvoted 1 times
Tuxzinator
1 month, 1 week ago
Anwser is D
upvoted 1 times
...
...
GeniusA
8 months, 2 weeks ago
Selected Answer: D A Static route is ALWAYS required to access internet. B conclusion is false. FortiGate_Infrastructure_7.2_Study_Guide page 11.
upvoted 1 times
...
Jumpy007
11 months, 3 weeks ago
Selected Answer: D
FortiGate_Infrastructure_7.2 page 101 You cannot create an inter-VDOM link between layer 2 transparent VDOMs (C is wrong). At least on of the VDOMs must be operating in NAT mode.
upvoted 4 times
...
raydel92
12 months ago
Selected Answer: D
D. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs. Reference and download study guide: https://ebin.pub/fortinet-fortigate-infrastructure-study-guide-for-fortios-72.html
upvoted 2 times
...
darkstar15
1 year, 1 month ago
es D la respuesta: FortiGate_Infrastructure_7.2 pag 101 Transparent to transparent beacuse, no layer 3; potential Layer 2 loops.
upvoted 2 times
...
clrf26
1 year, 2 months ago
A. "Correct". B. "False". When you create a new VDOM you don't have any route defined, usually one define 0.0.0.0/0.0.0.0 as a default static route to the internet. C. "Wrong" Both VDOMS are in Transparent Mode at least one must be In NAT Mode, a VLINK will potentially create a Layer 2 loop. D. "Not Wrong, but unnecessary" In the exhibit the Root VDOM is used only as a management VDOM, as a best practice a VLINK is not required to allow traffic between the Local and Root VDOMs. FG Infrastructure 7.2 Study Guide Online Page 100.
upvoted 3 times
clrf26
1 year, 2 months ago
Correction!!!! The correct one is "D". "A" is false as the management VDOM Root needs to reach the internet.
upvoted 3 times
...
...
Eggrolls
1 year, 2 months ago
Selected Answer: D
A Static route is ALWAYS required to access internet. B conclusion is false. FortiGate_Infrastructure_7.2_Study_Guide page 11.
upvoted 2 times
...
cisco1750
1 year, 2 months ago
Selected Answer: B
B makes more sense than others for me since the default gateway can be learned via DHCP, no static route is really needed.
upvoted 1 times
...
cisco1750
1 year, 2 months ago
B makes more sense for me since the default gateway can be learned via DHCP, no static route is really needed. The question does not describe any traffic that would require any inter-vdom link, for example I dont see any requirement for connecting root vdom to anywhere - via inter-vdom link.
upvoted 1 times
...
leocopek
1 year, 3 months ago
Selected Answer: D
D is correct. local and dmz are in transparent mode
upvoted 3 times
...
Schwartzden
1 year, 6 months ago
Selected Answer: A
You would need inter vdom links to the local and DMZ frm the internet vdom to get out on the internet. You do not need a link between the rot and the internet since it is used for managment. Thats under the section of inter vdom links.
upvoted 1 times
Schwartzden
1 year, 6 months ago
I take that back. Went back over material. Root VDOM should have internet access in case something breaks. I agree answer is D
upvoted 6 times
...
...
efot
1 year, 7 months ago
Answer is D. Before configuring inter-VDOM routing: You must have at least two virtual domains configured. The virtual domains must all be in NAT mode. Each virtual domain to be linked must have at least one interface or subinterface assigned to it.
upvoted 4 times
...
efot
1 year, 7 months ago
Selected Answer: D
Correct Answer is D
upvoted 2 times
...
Spyder_Byte
1 year, 7 months ago
Selected Answer: D
C: wrong because one of the vdoms has to be in nat mode to create a link.
upvoted 2 times
...
Ney_mediana
1 year, 7 months ago
D. Inter-VDOM links are required to allow traffic between the Local and Root VDOMs.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...