Exam NSE4-5.4 All QuestionsBrowse all questions from this exam
Question 24

View the exhibit.

In this scenario, FGT1 has the following routing table:

S* 0. 0. 0. 0/0 [10/0] via 10. 40. 72. 2, port1

C 172. 16. 32. 0/24 is directly connected, port2

C 10. 40. 72. 0/30 is directly connected, port1

A user at 192.168.32.15 is trying to access the web server at 172.16.32.254. Which of the following statements best describe how the FortiGate will perform reverse path forwarding checks on this traffic? (Choose two.)

    Correct Answer: A, C

    In this scenario, the FortiGate unit evaluates whether the incoming traffic from 192.168.32.15 to the web server at 172.16.32.254 will pass a reverse path forwarding (RPF) check. With strict RPF, FortiGate requires that the return route for the packet to the source is available via the same interface the packet was received. Given that the source IP 192.168.32.15 is not in the routing table, the strict RPF check will deny the traffic. Loose RPF, on the other hand, only requires the existence of a return route to the source IP without mandating the same interface. Since the routing table contains a route for 172.16.32.0/24, the loose RPF check will allow the traffic.

Discussion
Kyoraku715Options: BC

the correct answer is B and C

hiberusOptions: BC

correct answer is B & C Reference: Fortinet Training Institute. FCP - Fortigate 7.4 Administrator Sample Questions.

vervvsdvOptions: BC

B and C. https://extreme-networks.my.site.com/ExtrArticleDetail?an=000086726