nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #85

An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?

The correct answer is A. It uses DNS over TLS. When FortiGate is configured to use FortiGuard DNS servers with default settings in current FortiOS versions, it uses DNS over TLS (DoT) on TCP port 853 to secure DNS queries. This prevents DNS query interception and tampering in transit. DNS over HTTPS (DoH) uses TCP port 443…

Submitted by naveen.iyer· Apr 18, 2026Deployment and system configuration

Question

An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?

Options

  • AIt uses DNS over TLS.
  • BIt uses DNS over HTTPS.
  • CIt uses UDP 8888.
  • DIt uses UDP 53.

How the community answered

(19 responses)
  • A
    89% (17)
  • B
    5% (1)
  • C
    5% (1)

Explanation

When FortiGate is configured to use FortiGuard DNS servers with default settings in current FortiOS versions, it uses DNS over TLS (DoT) on TCP port 853 to secure DNS queries. This prevents DNS query interception and tampering in transit. DNS over HTTPS (DoH) uses TCP port 443 and is a separate protocol not used by default for FortiGuard DNS. Standard UDP port 53 and Fortinet's legacy UDP port 8888 are not the default for FortiGuard DNS in current firmware, as Fortinet has adopted encrypted DNS to improve security for DNS resolution traffic leaving the device.

Topics

#DNS#FortiGuard#DNS over TLS#Default Settings

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice