{"id":12605,"date":"2026-09-15T10:52:42","date_gmt":"2026-09-15T10:52:42","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=12605"},"modified":"2026-09-15T10:52:42","modified_gmt":"2026-09-15T10:52:42","slug":"fortinet-fcss_nst_se-7-6-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcss_nst_se-7-6-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Fortinet FCSS_NST_SE-7.6 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<p><b>View Full <a href=\"https:\/\/www.examlabs.com\/fcss-nst-se-7-6-exam-dumps\">Fortinet FCSS_NST_SE-7.6 Exam Dumps<\/a> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Q181. Which BGP attribute is primarily used to influence the outbound path selection from an autonomous system?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> MED<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Local Preference<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Origin<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Next Hop<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">BGP Local Preference is used within an autonomous system to influence which exit path should be preferred for outbound traffic. A higher Local Preference value is generally preferred over a lower value. Because the attribute is propagated through iBGP, administrators can consistently influence routing decisions across the organization. MED, in contrast, is commonly used to influence how external networks enter an autonomous system. When troubleshooting BGP path selection on FortiGate, Local Preference is therefore an important attribute to inspect when multiple external routes are available and the administrator wants internal routers to favor a particular exit point.<\/span><\/p>\n<h3><b>Q182. Which BGP attribute represents the sequence of autonomous systems that a route has traversed?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Local Preference<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> MED<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> AS Path<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Weight<\/span><\/p>\n<p><b>Correct Answer: 3)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The BGP AS Path attribute records the autonomous systems through which a route advertisement has passed. It helps BGP prevent routing loops because a router can reject a route if its own autonomous system number already appears in the path. AS Path length is also an important factor in BGP best-path selection, with shorter paths generally preferred when other relevant criteria are equal. On FortiGate, administrators can inspect AS Path information when diagnosing unexpected route selection, external routing behavior, or connectivity between different autonomous systems.<\/span><\/p>\n<h3><b>Q183. What is a primary difference between iBGP and eBGP?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> iBGP operates within the same autonomous system, while eBGP operates between different autonomous systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> iBGP supports IPv4 only, while eBGP supports IPv6 only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> iBGP is used only for static routes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> eBGP cannot advertise network prefixes<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">iBGP is used to exchange BGP routing information between routers belonging to the same autonomous system, while eBGP exchanges routing information between different autonomous systems. This distinction is important when designing enterprise and service-provider routing environments. iBGP commonly distributes externally learned routes throughout an organization, whereas eBGP connects separate routing domains. On FortiGate, understanding whether a BGP neighbor is internal or external helps administrators configure appropriate neighbor relationships and troubleshoot route advertisements, next-hop behavior, and path-selection decisions.<\/span><\/p>\n<h3><b>Q184. Which BGP neighbor state indicates that the router is attempting to establish a TCP connection with the peer?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Established<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Active<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> OpenSent<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Connect<\/span><\/p>\n<p><b>Correct Answer: 4)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The BGP Connect state indicates that the router is attempting to establish a TCP connection with its configured BGP peer. BGP uses TCP port 179 for this communication. If the connection succeeds, the session progresses through subsequent BGP states toward Established. If the connection cannot be completed, troubleshooting should include checking IP reachability, firewall policies, TCP port 179 access, neighbor configuration, and routing. On FortiGate, checking the BGP neighbor status is useful for determining whether a routing problem is caused by connectivity before investigating route advertisements or path-selection attributes.<\/span><\/p>\n<h3><b>Q185. When multiple BGP routes are available for the same destination, what is the purpose of BGP best-path selection?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To advertise every route simultaneously<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To randomly select a route<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To select the preferred route for installation and advertisement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To remove all routes with different AS paths<\/span><\/p>\n<p><b>Correct Answer: 3)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">BGP best-path selection evaluates multiple candidate routes and determines which path should be preferred for a destination. The process considers several attributes and routing conditions, depending on the implementation and configuration. This allows administrators to control traffic flow when redundant connections or multiple service providers are available. On FortiGate, understanding best-path behavior is essential when diagnosing why traffic uses one WAN connection instead of another. Reviewing attributes such as Local Preference, AS Path, MED, origin, and next-hop reachability can help identify why a particular route became the preferred BGP path.<\/span><\/p>\n<h3><b>Q186. What is the primary purpose of the BGP hold timer?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To determine the maximum packet size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To detect when a BGP neighbor is no longer responding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To select the shortest AS Path<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To calculate the interface bandwidth<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The BGP hold timer helps detect failure or loss of communication with a BGP neighbor. If a router does not receive an expected BGP message within the configured hold-time period, the session can be considered unavailable and the associated routes can be withdrawn. BGP keepalive messages normally maintain the session when there is no other BGP traffic. On FortiGate, inappropriate timer values can affect how quickly routing failures are detected. Administrators should consider network stability and convergence requirements when configuring BGP timers.<\/span><\/p>\n<h3><b>Q187. What is a common purpose of using a route-map in advanced routing configuration?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To define physical interface speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To apply conditional routing policies to selected routes or traffic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To replace all firewall security policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To encrypt BGP messages<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A route-map provides a flexible mechanism for applying conditional routing policies. Administrators can use matching criteria and configured actions to influence how routes are accepted, advertised, redistributed, or modified. For example, a route-map can work with prefix lists to identify specific networks and then apply attributes or filtering actions. This makes route-maps useful in environments requiring granular routing control. On FortiGate, careful route-map configuration can help implement routing policies without unnecessarily affecting unrelated prefixes.<\/span><\/p>\n<h3><b>Q188. What is the primary purpose of a BGP prefix list?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To filter routes based on network prefixes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To encrypt routing updates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To establish an IPsec tunnel<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To monitor CPU utilization<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A prefix list is used to identify and filter network prefixes according to defined rules. Administrators can use prefix lists to permit or deny specific networks based on their prefixes and prefix lengths. This provides precise control over which routes may be advertised or accepted. Prefix lists are especially useful when combined with routing policies or route-maps. On FortiGate, effective prefix filtering can prevent unwanted routes from entering the routing table or being advertised to neighbors, improving routing security and reducing the risk of accidental route propagation.<\/span><\/p>\n<h3><b>Q189. What is the purpose of a floating static route?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To permanently override every dynamic route<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To provide a backup route with a higher administrative distance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To automatically encrypt traffic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To increase BGP Local Preference<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A floating static route is configured with a higher administrative distance than the primary route so that it remains inactive while the preferred route is available. If the primary route disappears, the floating static route can become active and provide connectivity. This technique is useful for simple route failover scenarios. On FortiGate, administrators can use backup static routes alongside dynamic routing or another static route to provide redundancy. Proper administrative-distance configuration ensures that the backup route does not unnecessarily replace the preferred path during normal operation.<\/span><\/p>\n<h3><b>Q190. What happens when a primary route is removed and a valid floating static route is available?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The firewall disables all routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The backup route can become active<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> BGP automatically stops permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The interface is deleted<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">When the preferred route is no longer present in the routing table, a valid floating static route with an appropriate administrative distance can become the active route. This provides a basic mechanism for maintaining connectivity after a primary path failure. The backup route must have valid next-hop reachability and appropriate configuration before it can be used. On FortiGate, administrators can combine static routes, interface monitoring, and dynamic routing mechanisms to create resilient routing designs. Testing failover is important to verify that traffic switches to the intended backup path.<\/span><\/p>\n<h3><b>Q191. Why is route failover important in a network with redundant WAN connections?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> It guarantees that every packet uses both links simultaneously<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> It allows traffic to use an alternate path when the preferred path fails<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> It eliminates the need for routing tables<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> It disables health monitoring<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Route failover improves network availability by allowing traffic to move to an alternate path when the preferred WAN connection becomes unavailable. Without an effective failover mechanism, users may lose connectivity even though another functional connection exists. FortiGate can support different approaches to redundancy, including static routes, dynamic routing, and SD-WAN capabilities. The selected method should match the network&#8217;s requirements. Administrators should also verify that failure detection is reliable so that traffic does not remain directed toward an unavailable path.<\/span><\/p>\n<h3><b>Q192. Why might an administrator configure a blackhole route together with a summary route?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To prevent traffic for unreachable summarized destinations from following an unintended path<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To increase interface bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To bypass all firewall inspection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To create additional VLANs<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A blackhole route can provide controlled handling for traffic destined to an address range that should not be reachable through more specific routes. When used with route summarization, it can help prevent unwanted fallback behavior or routing loops. For example, if a summary route exists but no valid specific route is available, the blackhole route can intentionally discard traffic rather than allowing it to follow an incorrect default path. On FortiGate, this technique can be useful in carefully designed routing environments, but administrators should document the purpose clearly to avoid confusing legitimate traffic drops with routing failures.<\/span><\/p>\n<h3><b>Q193. What is recursive routing used for when determining whether a static route is usable?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To resolve whether the configured next hop is reachable through another route<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To encrypt the next-hop address<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To convert IPv4 into IPv6<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To disable route lookup<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Recursive routing allows a router to determine the actual forwarding path to a configured next-hop address by performing additional route lookups. A static route may specify a next-hop IP address that is not directly connected, so the device must determine how that next hop can be reached. This process helps establish whether the route has a valid forwarding path. On FortiGate, understanding recursive next-hop resolution is useful when troubleshooting static routes that appear configured correctly but are not being installed or used because their next hop cannot be resolved.<\/span><\/p>\n<h3><b>Q194. What should an administrator verify if a configured static route is not appearing as active?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The firewall hostname only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Next-hop reachability and the route&#8217;s interface or gateway configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The administrator&#8217;s browser cache<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The device serial number<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A static route may fail to become active if its next hop cannot be resolved or if the associated interface or gateway configuration is invalid. Administrators should verify that the next-hop address is reachable and that the selected interface is operational. They should also check for conflicting routes, incorrect subnet masks, and administrative-distance settings. On FortiGate, examining the routing table and performing route lookup or connectivity tests can help determine why the configured route is not being selected. Troubleshooting should begin with basic reachability before making unnecessary routing changes.<\/span><\/p>\n<h3><b>Q195. Which FortiGate function is most useful for determining which route will be used for a particular destination?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Route lookup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Antivirus scanning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Web filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Certificate inspection<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Route lookup is useful for determining how FortiGate will forward traffic toward a specified destination. It can help identify the selected route, next hop, and interface, depending on the diagnostic method being used. This is particularly valuable when several routes overlap or when administrators suspect that traffic is taking an unexpected path. By checking the routing decision directly, administrators can distinguish routing problems from firewall-policy or application-related issues. FortiGate troubleshooting should generally include route-table and route-lookup verification when traffic is not following the expected network path.<\/span><\/p>\n<h3><b>Q196. What is an important consideration when using policy-based routing instead of normal destination-based routing?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Policy-based routing can select paths based on additional traffic characteristics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Policy-based routing automatically disables security policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Policy-based routing requires all traffic to use BGP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Policy-based routing cannot use a next hop<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Policy-based routing can make forwarding decisions using criteria beyond the destination address, allowing administrators to direct selected traffic through a particular gateway or interface. This can be useful for applications, users, source networks, or other traffic characteristics that require specialized forwarding behavior. However, policy-based routing must be carefully designed because it can override or influence normal routing decisions. On FortiGate, administrators should verify policy order, matching criteria, outgoing interface, and next-hop configuration when troubleshooting unexpected traffic paths.<\/span><\/p>\n<h3><b>Q197. What is the purpose of Reverse Path Forwarding (RPF) checking?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To verify that the source of incoming traffic is reachable through an expected routing path<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To increase DNS query speed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To select an antivirus signature<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To establish an SSL VPN portal<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Reverse Path Forwarding checking helps validate the source address of incoming traffic by examining whether the routing table provides a valid path back toward that source. This can help identify and block packets with spoofed or otherwise suspicious source addresses. RPF is particularly useful as a network security control because attackers can manipulate source addresses to disguise traffic. On FortiGate, administrators should understand how RPF interacts with routing because asymmetric routing can sometimes cause legitimate traffic to fail source-validation checks.<\/span><\/p>\n<h3><b>Q198. What is a common security benefit of Unicast Reverse Path Forwarding (uRPF)?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Protection against source-address spoofing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Automatic malware removal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Encryption of routing updates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Compression of network packets<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">uRPF helps reduce source-address spoofing by verifying whether the source address of an incoming packet has a valid return path according to the routing information. If the source fails the configured validation method, the packet may be rejected. This can make spoofing-based attacks more difficult, particularly at network boundaries. However, administrators must consider asymmetric routing before enabling strict validation because legitimate packets may arrive through an interface different from the expected reverse path. Proper FortiGate routing design and RPF configuration are therefore important for reliable operation.<\/span><\/p>\n<h3><b>Q199. Which protocol is commonly associated with Protocol Independent Multicast (PIM) routing?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> BGP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> PIM<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> FTP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> SNMP<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Protocol Independent Multicast, or PIM, is a family of multicast routing protocols used to build multicast distribution trees. PIM does not depend on a particular unicast routing protocol; instead, it uses the existing unicast routing information to determine appropriate paths. PIM modes include Sparse Mode and Dense Mode, each designed for different multicast deployment models. In FortiGate environments where multicast traffic is required, understanding PIM and the underlying unicast routing behavior is important for troubleshooting multicast forwarding, group membership, and path selection.<\/span><\/p>\n<h3><b>Q200. Why might an administrator use BGP together with SD-WAN on FortiGate?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To combine dynamic route exchange with intelligent WAN path selection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To disable all WAN health checks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To replace every firewall security policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To prevent routing information from being exchanged<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">BGP and SD-WAN can complement each other in complex WAN environments. BGP can dynamically exchange and learn network prefixes, while SD-WAN can evaluate WAN paths using performance measurements such as latency, jitter, and packet loss. This combination allows FortiGate to maintain dynamic routing information while using intelligent path-selection policies for application traffic. It is especially useful in environments with multiple WAN links, branches, or service providers. Administrators should carefully design route advertisements, SD-WAN rules, health checks, and routing priorities so that the two mechanisms work together predictably.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCSS_NST_SE-7.6 Exam Dumps and Practice Test Dumps &nbsp; Q181. Which BGP attribute is primarily used to influence the outbound path selection from an autonomous system? 1) MED 2) Local Preference 3) Origin 4) Next Hop Correct Answer: 2) Explanation: BGP Local Preference is used within an autonomous system to influence which exit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12605"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=12605"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12605\/revisions"}],"predecessor-version":[{"id":12626,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12605\/revisions\/12626"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=12605"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=12605"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=12605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}