NSE4-5.4 Exam QuestionsBrowse all questions from this exam

NSE4-5.4 Exam - Question 24


View the exhibit.

In this scenario, FGT1 has the following routing table:

S* 0. 0. 0. 0/0 [10/0] via 10. 40. 72. 2, port1

C 172. 16. 32. 0/24 is directly connected, port2

C 10. 40. 72. 0/30 is directly connected, port1

A user at 192.168.32.15 is trying to access the web server at 172.16.32.254. Which of the following statements best describe how the FortiGate will perform reverse path forwarding checks on this traffic? (Choose two.)

Show Answer
Correct Answer: ABCD

In this scenario, the FortiGate unit evaluates whether the incoming traffic from 192.168.32.15 to the web server at 172.16.32.254 will pass a reverse path forwarding (RPF) check. With strict RPF, FortiGate requires that the return route for the packet to the source is available via the same interface the packet was received. Given that the source IP 192.168.32.15 is not in the routing table, the strict RPF check will deny the traffic. Loose RPF, on the other hand, only requires the existence of a return route to the source IP without mandating the same interface. Since the routing table contains a route for 172.16.32.0/24, the loose RPF check will allow the traffic.

Discussion

3 comments
Sign in to comment
Kyoraku715Options: BC
Oct 20, 2022

the correct answer is B and C

vervvsdvOptions: BC
Jun 3, 2023

B and C. https://extreme-networks.my.site.com/ExtrArticleDetail?an=000086726

hiberusOptions: BC
Jun 15, 2024

correct answer is B & C Reference: Fortinet Training Institute. FCP - Fortigate 7.4 Administrator Sample Questions.