FCP_FGT_AD-7.6 · Question #96
Refer to the exhibit. Which two statements about the FortiGuard connection are true? (Choose two.)
The correct answer is A. FortiGate is using the default port for FortiGuard communication. C. The weight increases as the number of failed packets rises. In the exhibit, the FortiGuard connection details reveal two key facts. First, FortiGate is communicating on the default port for FortiGuard-typically UDP/8888 or TCP/443 depending on the protocol selected (answer A). Second, the exhibit shows a 'weight' value associated with…
Question
Refer to the exhibit. Which two statements about the FortiGuard connection are true? (Choose two.)
Exhibit
Options
- AFortiGate is using the default port for FortiGuard communication.
- BFortiGate identified the FortiGuard Server using DNS lookup.
- CThe weight increases as the number of failed packets rises.
- DYou can configure unreliable protocols to communicate with FortiGuard Server.
How the community answered
(23 responses)- A87% (20)
- B4% (1)
- D9% (2)
Explanation
In the exhibit, the FortiGuard connection details reveal two key facts. First, FortiGate is communicating on the default port for FortiGuard-typically UDP/8888 or TCP/443 depending on the protocol selected (answer A). Second, the exhibit shows a 'weight' value associated with FortiGuard servers; this weight is a penalty metric that increases as the number of failed or timed-out packets to that server rises, causing FortiGate to prefer lower-weight (more reliable) servers (answer C). FortiGate uses pre-configured server IP addresses or ANYCAST addresses, not DNS lookup, for FortiGuard communication. Unreliable protocols (UDP) are already the default; reliable (TCP) can be configured but that is not what the exhibit highlights.
Topics
Community Discussion
No community discussion yet for this question.
