nse4_fgt-72 Exam QuestionsBrowse all questions from this exam

nse4_fgt-72 Exam - Question 57


An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings.

What is true about the DNS connection to a FortiGuard server?

Show Answer
Correct Answer: BD

When an administrator configures FortiGuard servers as DNS servers on FortiGate using default settings, the DNS connection to a FortiGuard server uses DNS over TLS (DoT). This is the default protocol to secure DNS traffic when using FortiGuard servers, ensuring that the connections are encrypted and secure.

Discussion

17 comments
Sign in to comment
EggrollsOption: D
Jun 22, 2023

FortiGate_Security_7.2_Study_Guide page 15

Senox999Option: D
May 15, 2023

Study Guide Page 15 - By default, uses DNS over TLS DoT to secure DNS traffic - FortiOS uses Fortiguard server for DNS requests

RabbitBOption: D
Jun 21, 2023

FortiGate Security 7.2 Study Guide P.15 When using FortiGuard servers for DNS, FortiOS uses DNS over TLS (DoT) by default to secure the DNS traffic. New FortiGuard DNS servers have been added as primary and secondary servers.

RabbitB
Jun 21, 2023

B is correct

RabbitB
Jun 21, 2023

Apologize correct is D (DNS over TLS)

bgodOption: D
Aug 7, 2023

ref security 7.2, page 15, last paragraph.

efotOption: D
Jan 19, 2023

Correct answer is D https://docs.fortinet.com/document/fortigate/7.0.0/new-features/92199/use-dns-over-tls-for-default-fortiguard-dns-servers-7-0-4

Poseidon458Option: D
Jan 25, 2023

Answer is D: https://docs.fortinet.com/document/FortiProxy/7.2.0/administration-guide/710207/use-dns-over-tls-for-default-fortiguard-dns-servers

GCISystemIntegratorOption: D
Mar 12, 2023

For DNS servers, select Use FortiGuard Servers. The Primary DNS server is 96.45.45.45, and the Secondary DNS server is 96.45.46.46. DNS Protocols is set to TLS and cannot be modified.

EquianoOption: D
Mar 23, 2023

I’m going with answer D if this exam is focused on FortiOS 7.2.3 and lower. From 7.2.4 the default setting is set to DNS (UDP/53) and TLS (TCP/853) is optional.

EmmaWOption: D
May 4, 2023

When using FortiGuard servers for DNS, FortiOS defaults to using DNS over TLS (DoT) to secure the DNS traffic. So answer D is correct. It will be using not UDP port 53 but port 853.

raydel92Option: D
Sep 13, 2023

D. It uses DNS over TLS. FortiGate Security 7.2 Study Guide (p.15): "When using FortiGuard servers for DNS, FortiOS uses DNS over TLS (DoT) by default to secure the DNS traffic." Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html

Jumpy007Option: D
Sep 16, 2023

When using fortiguard servers for DNS? FortiOS uses DNS over TLS by default to secure the DNS traffic. Answer D is correct. FortiGate_Security_7.2_Study_Guide page 15

Spyder_ByteOption: D
Jan 14, 2023

DNS over TLS

lelacoolOption: B
Jan 16, 2023

B CORRECT. https://docs.fortinet.com/document/fortigate/7.0.0/new-features/92199/use-dns-over-tls-for-default-fortiguard-dns-servers-7-0-4 Debido a que los servidores DNS probablemente no admiten DES de bajo cifrado, los dispositivos de bajo cifrado no tienen la opción de seleccionar DoT o DoH. En su lugar, los dispositivos utilizan de forma predeterminada texto no cifrado (UDP/53).

DalikOption: B
Apr 28, 2023

B is correct According to FortiOS 7.2.0 Administration Guide: The following DNS protocols can be enabled: - cleartext: Enable clear text DNS over port 53 (default). - dot: Enable DNS over TLS. - doh: Enable DNS over HTTPS.

Dalik
Apr 28, 2023

Correction: D is the right answer. 'When using FortiGuard servers for DNS, FortiOS defaults to using DNS over TLS (DoT) to secure the DNS traffic. New FortiGuard DNS servers are added as primary and secondary servers.'

rian00z_
Aug 19, 2023

I didn't find this reference on Admin Guide, but on FortiGate Security 7.2 Study Guide P.15 When using FortiGuard servers for DNS, FortiOS uses DNS over TLS (DoT) by default to secure the DNS traffic. New FortiGuard DNS servers have been added as primary and secondary servers. I've tested on lab and the result was the same of the Study Guide.

rian00z_Option: D
Aug 19, 2023

Correct answer: D

GeniusAOption: D
Dec 22, 2023

Correct answer: D

millerryOption: D
Jan 9, 2024

FortiGate_Security_7.2_Study_Guide page 15. "When using FortiGuard servers for DNS, FortiOS uses DNS over TLS by default to secure the DNS traffic."