nerdexam
Fortinet

FCP_FGT_AD-7.4 · Question #3

Refer to the exhibit. Why did FortiGate drop the packet?

The correct answer is D. It matched the default implicit firewall policy. The debug trace output shows that the packet was "Denied by forward policy check (policy 0)." In FortiGate, policy ID 0 corresponds to the default implicit deny policy. This means that if a packet does not match any configured firewall policies, it is denied by the default…

Logging and Monitoring

Question

Refer to the exhibit. Why did FortiGate drop the packet?

Exhibit

FCP_FGT_AD-7.4 question #3 exhibit

Options

  • AIt matched an explicitly configured firewall policy with the action DENY.
  • BIt failed the RPF check.
  • CThe next-hop IP address is unreachable.
  • DIt matched the default implicit firewall policy.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    8% (3)
  • D
    83% (33)

Explanation

The debug trace output shows that the packet was "Denied by forward policy check (policy 0)." In FortiGate, policy ID 0 corresponds to the default implicit deny policy. This means that if a packet does not match any configured firewall policies, it is denied by the default implicit policy.

Topics

#packet drop#implicit deny#firewall policy#traffic analysis

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.4 Practice