{"id":12606,"date":"2026-09-15T10:51:52","date_gmt":"2026-09-15T10:51:52","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=12606"},"modified":"2026-09-15T10:51:52","modified_gmt":"2026-09-15T10:51:52","slug":"fortinet-fcss_nst_se-7-6-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-fcss_nst_se-7-6-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"Fortinet FCSS_NST_SE-7.6 Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<p><b>View Full <a href=\"https:\/\/www.examlabs.com\/fcss-nst-se-7-6-exam-dumps\">Fortinet FCSS_NST_SE-7.6 Exam Dumps<\/a> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Q201. Which BGP attribute is commonly used to influence the preferred inbound path into an autonomous system?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> MED<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Local Preference<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> AS Path<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Next Hop<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The Multi-Exit Discriminator (MED) is a BGP attribute commonly used to influence how an external autonomous system selects an entry point into the advertising autonomous system. A lower MED is generally preferred when comparing routes from the same neighboring autonomous system. MED is therefore useful when an organization has multiple connections to another autonomous system and wants to suggest a preferred ingress path. On FortiGate, administrators can inspect MED values when troubleshooting why inbound traffic appears to favor one external connection over another.<\/span><\/p>\n<h3><b>Q202. How does BGP AS Path prepending typically influence route selection?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> It increases the Local Preference<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> It makes a route appear to have a longer AS path<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> It disables route advertisements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> It changes the interface IP address<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">AS Path prepending intentionally adds additional copies of an autonomous system number to a route&#8217;s AS Path. Because BGP generally prefers a shorter AS Path when other relevant factors are equal, prepending can make a route less attractive to external peers. This technique is commonly used to influence inbound traffic without changing the physical topology. On FortiGate, administrators can use routing policies to control route advertisements and apply path manipulation where appropriate. Careful testing is important because BGP decisions depend on multiple attributes, not AS Path length alone.<\/span><\/p>\n<h3><b>Q203. Which statement correctly describes iBGP route exchange?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> It exchanges routes only between different autonomous systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> It is used between BGP routers within the same autonomous system<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> It requires multicast communication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> It replaces the IP routing table<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">iBGP is designed to exchange BGP routing information between routers that belong to the same autonomous system. It is commonly used after an organization learns external routes through eBGP and needs to distribute those routes internally. iBGP has specific design considerations, including route-reflector use in larger environments. On FortiGate, understanding the distinction between iBGP and eBGP helps administrators troubleshoot missing routes and unexpected path selection. Incorrect neighbor relationships or incomplete route propagation can prevent internal devices from learning the routes required to reach external destinations.<\/span><\/p>\n<h3><b>Q204. What does the BGP Established state indicate?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The neighbor relationship is successfully established and BGP updates can be exchanged<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The TCP connection has never been attempted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The neighbor configuration is disabled<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The route table contains no entries<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">The BGP Established state indicates that the BGP session has successfully progressed through the negotiation process and is ready to exchange routing information. Once established, the peers can send BGP updates, keepalive messages, and notifications as required. If a session repeatedly fails to reach Established, administrators should investigate IP connectivity, TCP port 179, authentication, autonomous system configuration, timers, and neighbor addresses. On FortiGate, checking BGP neighbor status is an important first step when diagnosing dynamic-routing problems between sites or external routing peers.<\/span><\/p>\n<h3><b>Q205. Which BGP characteristic helps prevent routing loops between autonomous systems?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> AS Path information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> DNS filtering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> VLAN tagging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> TCP window scaling<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">BGP uses AS Path information as an important mechanism for preventing routing loops between autonomous systems. When a BGP route is advertised across autonomous systems, the AS numbers traversed by that route are recorded. If a router receives a route advertisement containing its own autonomous system number, it can reject the route because accepting it could create a loop. This mechanism is fundamental to inter-domain routing. On FortiGate, examining the AS Path can help administrators identify rejected routes, unexpected advertisements, or routing behavior involving multiple external autonomous systems.<\/span><\/p>\n<h3><b>Q206. What is the purpose of BGP keepalive messages?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To maintain the BGP session and confirm peer availability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To advertise DNS records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To increase packet size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To configure firewall policies<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">BGP keepalive messages are periodically exchanged between established peers to maintain the session and demonstrate that the neighbor remains responsive. They are particularly important when no other BGP messages are being exchanged. If the hold timer expires without receiving an appropriate BGP message, the session can be considered failed and routes learned from that peer may be withdrawn. On FortiGate, keepalive and hold-time behavior can affect routing convergence. Administrators should select timer values that provide suitable failure detection without creating unnecessary session instability.<\/span><\/p>\n<h3><b>Q207. Which configuration is commonly used to permit or deny specific BGP prefixes based on their network address and prefix length?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Prefix list<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> DNS server<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Application sensor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Traffic shaper<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Prefix lists provide precise control over network prefixes by matching both the prefix and, when configured, its prefix length. They can be used to permit or deny selected routes during route advertisement or reception. This makes them valuable for controlling which networks are exchanged with BGP peers. On FortiGate, prefix filtering can help prevent accidental advertisement of internal networks or acceptance of unwanted routes. Administrators should carefully define prefix-list entries because an overly restrictive rule can unintentionally prevent legitimate routes from entering or leaving the routing domain.<\/span><\/p>\n<h3><b>Q208. What is a key advantage of using route-maps with BGP policies?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> They allow conditional modification or filtering of selected routes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> They automatically create physical interfaces<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> They disable routing protocols<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> They encrypt all BGP traffic<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Route-maps allow administrators to apply conditional actions to routes that match specific criteria. They can work with prefix lists and other matching mechanisms to create granular routing policies. For example, a route-map can identify selected prefixes and modify routing attributes before routes are advertised or accepted. This provides considerably more flexibility than applying one general policy to every route. On FortiGate, route-map configuration should be reviewed carefully because matching conditions, sequence order, and actions can significantly affect route propagation and the resulting traffic path.<\/span><\/p>\n<h3><b>Q209. What is the main purpose of a route reflector in an iBGP environment?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To reduce the need for a full mesh of iBGP sessions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To encrypt BGP updates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To replace all eBGP connections<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To perform antivirus inspection<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A BGP route reflector reduces the requirement for every iBGP router in an autonomous system to establish a direct session with every other iBGP router. Instead, selected routers can act as route reflectors and distribute routes to their clients. This simplifies BGP topology and makes large deployments easier to manage. Without route reflection or another scaling mechanism, a full-mesh iBGP design can become difficult to maintain as the number of routers increases. In larger FortiGate deployments, route-reflector designs can help simplify internal BGP connectivity.<\/span><\/p>\n<h3><b>Q210. Which routing concept determines that a more specific prefix is preferred over a less specific matching prefix?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Administrative distance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Longest-prefix match<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> MED<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> AS Path prepending<\/span><\/p>\n<p><b>Correct Answer: 2)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Longest-prefix match means that when multiple routes match a destination, the route with the most specific network prefix is generally selected. For example, a route for a smaller subnet can take precedence over a broader summary route covering the same destination. This fundamental routing behavior is important when troubleshooting overlapping routes. On FortiGate, administrators should inspect the routing table and prefix lengths when traffic unexpectedly follows a particular path. Understanding longest-prefix matching can quickly explain why a more specific route is being selected instead of a broader network route.<\/span><\/p>\n<h3><b>Q211. What is administrative distance primarily used for?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Comparing the trustworthiness of routes learned from different routing sources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Measuring packet latency<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Determining application bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Encrypting routing updates<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Administrative distance, also called route preference in some contexts, helps a routing device select between routes to the same destination learned from different routing sources. A route source with a more preferred administrative distance can be selected over another source. This is particularly useful when static and dynamic routing protocols coexist. On FortiGate, administrators may use route preference values to control which routing source becomes active. However, administrative distance is different from metrics used within a routing protocol, so both should be considered when troubleshooting route selection.<\/span><\/p>\n<h3><b>Q212. Why might an administrator configure different route preferences for redundant routes?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To establish a preferred route and a backup route<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To increase DNS cache duration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To disable route lookup<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To force all applications through one firewall policy<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Different route preferences can establish which route should normally be active and which should serve as a backup. The preferred route is selected while it remains valid, while a less-preferred route can become active if the primary route is removed or becomes unavailable. This approach is useful for basic network redundancy. On FortiGate, administrators should verify that the backup route has valid next-hop reachability and that failure detection actually removes or invalidates the primary path. Proper testing ensures failover occurs as intended without unnecessary route changes.<\/span><\/p>\n<h3><b>Q213. What is recursive next-hop resolution important for?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Determining whether a configured next-hop address can be reached through the routing table<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Creating a new security profile<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Identifying applications by protocol<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Inspecting encrypted files<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Recursive next-hop resolution determines how a router can reach a next-hop address when that next hop is not directly connected. The device performs additional route lookups to identify a usable forwarding path. If the next hop cannot be resolved, the associated route may not become active. This is an important troubleshooting concept on FortiGate because a static route can appear correctly configured while still being unusable. Administrators should verify both the destination route and the route required to reach its configured next-hop address.<\/span><\/p>\n<h3><b>Q214. Which condition can cause strict reverse-path validation to drop legitimate traffic?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Asymmetric routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Correct DNS resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Low CPU utilization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Successful authentication<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Asymmetric routing occurs when traffic travels toward a destination through one path but returns through a different path. Strict reverse-path validation may consider such traffic invalid if the incoming interface does not match the expected reverse route to the source. As a result, legitimate packets can potentially be dropped even though connectivity exists. On FortiGate, administrators should consider network topology and routing symmetry before enabling strict RPF controls. In environments with multiple WAN links, carefully designed routing and validation settings are especially important.<\/span><\/p>\n<h3><b>Q215. What is the primary purpose of route redistribution?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To exchange routes between different routing protocols or routing sources<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To increase Ethernet frame size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To disable dynamic routing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To encrypt network prefixes<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Route redistribution allows routes learned from one routing source to be introduced into another routing protocol or routing domain. For example, routes learned through a static configuration may be redistributed into a dynamic routing protocol. Redistribution can improve connectivity between networks using different routing mechanisms, but it must be carefully controlled. Without filtering or appropriate policies, it can introduce unnecessary routes or create routing loops. On FortiGate, administrators should use route policies, prefix filtering, and careful redistribution rules to ensure only the intended networks are exchanged.<\/span><\/p>\n<h3><b>Q216. What is a major risk of poorly designed route redistribution?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Routing loops or excessive route propagation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Automatic password expiration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Reduced monitor brightness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Loss of DNS records only<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Poorly designed route redistribution can introduce routing loops, duplicate paths, or unnecessary routes between routing domains. When routes are redistributed in multiple directions without proper filtering, a network may repeatedly advertise information that it originally learned from another protocol. This can make routing unpredictable and increase troubleshooting complexity. On FortiGate, administrators should carefully control redistribution using route policies, prefix lists, tags, or other appropriate mechanisms. Monitoring routing tables and learned routes after configuration changes is important to verify that only intended prefixes are being exchanged.<\/span><\/p>\n<h3><b>Q217. What does route tagging help administrators accomplish during routing policy design?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Identify routes for later filtering or policy decisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Encrypt route advertisements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Increase WAN bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Replace BGP neighbors<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">Route tagging allows administrators to associate identifying information with routes so that those routes can later be matched by routing policies. This can be particularly useful in redistribution scenarios where routes need to be distinguished based on where they originated. By identifying routes before applying subsequent policies, administrators can reduce the risk of redistributing the same routes repeatedly. In FortiGate routing environments, route tags can therefore support more controlled and predictable policy design. They should be documented clearly so future administrators understand why particular routes receive specific treatment.<\/span><\/p>\n<h3><b>Q218. What should an administrator check first when a BGP neighbor repeatedly transitions between Established and other states?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Peer connectivity and BGP session parameters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Web-filter categories<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Antivirus exclusions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> DHCP lease duration only<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">A BGP neighbor repeatedly moving out of Established often indicates instability in connectivity or session configuration. Administrators should first verify IP reachability between peers, TCP port 179 access, neighbor addresses, autonomous system numbers, authentication settings, and timer configuration. Interface errors or packet loss should also be considered. On FortiGate, reviewing BGP neighbor status and relevant routing or system logs can help identify whether the problem is network-related or configuration-related. Stable underlying connectivity is essential because repeated BGP session resets can cause route withdrawals and unnecessary routing convergence.<\/span><\/p>\n<h3><b>Q219. Why is BGP route filtering important at an external network boundary?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> It helps prevent unauthorized or unintended prefixes from being advertised or accepted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> It guarantees unlimited bandwidth<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> It disables all routing updates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> It replaces firewall inspection<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">BGP route filtering is an important control at external network boundaries because it limits which prefixes an organization advertises or accepts. Without filtering, an accidental configuration could expose internal routes to an external peer or allow unwanted routes into the network. Prefix lists, route-maps, and other routing policies can be used to implement appropriate controls. On FortiGate, administrators should explicitly define expected prefixes and regularly review routing policies. Good filtering practices improve routing stability and reduce the risk of accidental route leakage between autonomous systems.<\/span><\/p>\n<h3><b>Q220. Which approach best helps troubleshoot a FortiGate BGP route that is not being installed in the routing table?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Check neighbor status, received route information, route attributes, filtering, and next-hop reachability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Restart every network device immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Disable all security profiles permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Replace the firewall hardware first<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400;\">When a BGP route is not installed, administrators should systematically determine whether the route was received, whether it passed configured filters, and whether its attributes allow it to become the preferred path. Next-hop reachability is also important because an unresolved next hop can prevent route installation. Checking the BGP neighbor state, routing information, prefix filters, route policies, and routing table provides a structured troubleshooting process. On FortiGate, this approach helps isolate the problem without making unnecessary configuration changes or disrupting unrelated network services.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet FCSS_NST_SE-7.6 Exam Dumps and Practice Test Dumps &nbsp; Q201. Which BGP attribute is commonly used to influence the preferred inbound path into an autonomous system? 1) MED 2) Local Preference 3) AS Path 4) Next Hop Correct Answer: 1) Explanation: The Multi-Exit Discriminator (MED) is a BGP attribute commonly used to influence [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12606"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=12606"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12606\/revisions"}],"predecessor-version":[{"id":12625,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12606\/revisions\/12625"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=12606"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=12606"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=12606"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}