Câu 19: NSE5_FSW_AD-7.6: Fortinet NSE 5 - FortiSwitch 7.6 Administrator
Refer to the exhibits. Network Topology - DHCP Snooping database - All three FortiSwitch-connected ports are configured in VLAN 10.FortiGate acts as the Dynamic Host Configuration Protocol (DHCP) server and is connected to a DHCP snooping trusted trunk port. PC1 and PC2 are connected to ports configured as untrusted f…
Nội dung câu hỏi
Refer to the exhibits. Network Topology - DHCP Snooping database - All three FortiSwitch-connected ports are configured in VLAN 10.FortiGate acts as the Dynamic Host Configuration Protocol (DHCP) server and is connected to a DHCP snooping trusted trunk port. PC1 and PC2 are connected to ports configured as untrusted for DAI, and no static bindings are configured in the IP source guard (IPSG) database.PC2 is compromised and attempts to spoof the FortiGate IP address by sending forged Address Resolution Protocol (ARP) replies with its own MAC address. What will FortiSwitch do with the ARP packets from PC2?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Forward the ARP replies because there are no IPSG bindings blocking them.
- B. Accept the ARP replies because the VLAN has DAI enabled and FortiGate is a trusted DHCP server.
- C. Forward the ARP replies to all VLAN 10 ports because DAI is only active on trusted ports.
- D. Drop the ARP replies because they fail DAI validation against the DHCP snooping database. — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.