FCP_FGT_AD-7.6 · Question #85
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?
The correct answer is A. It uses DNS over TLS. When FortiGate is configured to use FortiGuard DNS servers with default settings in current FortiOS versions, it uses DNS over TLS (DoT) on TCP port 853 to secure DNS queries. This prevents DNS query interception and tampering in transit. DNS over HTTPS (DoH) uses TCP port 443…
Question
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?
Options
- AIt uses DNS over TLS.
- BIt uses DNS over HTTPS.
- CIt uses UDP 8888.
- DIt uses UDP 53.
How the community answered
(19 responses)- A89% (17)
- B5% (1)
- C5% (1)
Explanation
When FortiGate is configured to use FortiGuard DNS servers with default settings in current FortiOS versions, it uses DNS over TLS (DoT) on TCP port 853 to secure DNS queries. This prevents DNS query interception and tampering in transit. DNS over HTTPS (DoH) uses TCP port 443 and is a separate protocol not used by default for FortiGuard DNS. Standard UDP port 53 and Fortinet's legacy UDP port 8888 are not the default for FortiGuard DNS in current firmware, as Fortinet has adopted encrypted DNS to improve security for DNS resolution traffic leaving the device.
Topics
Community Discussion
No community discussion yet for this question.