Fortinet FortiOS 7.6 NSE4_FGT_AD-7.6 Static Routing Routing Table Redundancy And Load Balancing Practice Test
This Fortinet NSE4_FGT_AD-7.6 practice test focuses on static routing routing table redundancy and load balancing through original applied scenarios aligned to the current Fortinet NSE 4 – FortiOS 7.6 Administrator scope for FortiOS 7.6.0. Use the full ExamSnap NSE4_FGT_AD-7.6 collection for broader practice across all current domains. For broader exam preparation, review the Fortinet NSE4_FGT_AD-7.6 Exam Dumps page.
Question 1
Contoso Finance has validated routing and basic reachability. The remaining requirement is to send traffic for a remote network to a specific next-hop router. Which action should the team take? The change is being made during a controlled production window.
- Use supported equal-cost multipath routing with equivalent route preference
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
Correct answer: E
Explanation
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A static route adds a deterministic next hop for the matching destination network. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, configure a static route for the destination prefix with the correct outgoing interface and gateway. A static route adds a deterministic next hop for the matching destination network.
Question 2
At Litware Logistics, a network administrator is handling a FortiGate 7.6 change. The requirement is to provide a catch-all path for destinations not matched by a more specific route. What should the administrator do? The team will validate the result immediately after the change.
- Verify that a usable route exists after confirming the policy match
- Use the route with the lower administrative distance when the prefix length is the same
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Select the route with the longest matching destination prefix
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
Correct answer: C
Explanation
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- The default route matches IPv4 destinations when no more specific route is selected. This directly satisfies the stated requirement.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
Learning point: For this FortiOS 7.6 scenario, configure a default route for 0.0.0.0/0 toward the intended upstream gateway. The default route matches IPv4 destinations when no more specific route is selected.
Question 3
During a maintenance window at Wide World Importers, the team must predict which of two routes with different prefix lengths will carry a packet. Which action is the most appropriate? No unrelated security controls should be changed.
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Use the route with the lower administrative distance when the prefix length is the same
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Verify that a usable route exists after confirming the policy match
- Select the route with the longest matching destination prefix
Correct answer: E
Explanation
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, select the route with the longest matching destination prefix. IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes.
Question 4
A change review at Graphic Design Institute identifies one requirement: prefer one route when equal destination prefixes are learned from alternatives with different administrative distance. Which FortiGate action best satisfies it? The administrator wants a configuration that is easy to audit later.
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Inspect the active routing table and route details for the destination
- Use the route with the lower administrative distance when the prefix length is the same
- Use supported equal-cost multipath routing with equivalent route preference
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
Correct answer: C
Explanation
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This directly satisfies the stated requirement.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
Learning point: For this FortiOS 7.6 scenario, use the route with the lower administrative distance when the prefix length is the same. Administrative distance is used to prefer among competing routes to the same destination prefix.
Question 5
While troubleshooting at Lamna Healthcare, the SOC analyst needs to verify the route FortiGate actually installed rather than relying only on configured static entries. What is the best next step? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Inspect the active routing table and route details for the destination
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Use supported equal-cost multipath routing with equivalent route preference
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
Correct answer: A
Explanation
- The routing table shows which routes are currently installed and eligible for forwarding. This directly satisfies the stated requirement.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
Learning point: For this FortiOS 7.6 scenario, inspect the active routing table and route details for the destination. The routing table shows which routes are currently installed and eligible for forwarding.
Question 6
Tailspin Toys is standardizing its FortiGate 7.6 operations. Which approach should it use to retain a backup static path that should be used only when the preferred path is unavailable? The team wants the smallest change that directly addresses the requirement.
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Verify that a usable route exists after confirming the policy match
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
Correct answer: B
Explanation
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This directly satisfies the stated requirement.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
Learning point: For this FortiOS 7.6 scenario, configure the backup route with a less-preferred distance or priority and validate next-hop reachability. A less-preferred route can remain available as a fallback when the primary route is removed or unusable.
Question 7
A production ticket for Humongous Insurance states that administrators must share traffic across multiple equally preferred next hops to the same prefix. Which choice is correct? The choice should follow normal FortiOS administration practice.
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Verify that a usable route exists after confirming the policy match
- Use supported equal-cost multipath routing with equivalent route preference
- Select the route with the longest matching destination prefix
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
Correct answer: C
Explanation
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This directly satisfies the stated requirement.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
Learning point: For this FortiOS 7.6 scenario, use supported equal-cost multipath routing with equivalent route preference. ECMP can install multiple equal-cost routes and distribute eligible sessions across them.
Question 8
The security team at Coho Winery wants to prevent a failed narrow destination from falling back unexpectedly to a broad default route. Which FortiGate configuration or action most directly meets that goal? The solution must preserve the existing production design where possible.
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Use the route with the lower administrative distance when the prefix length is the same
Correct answer: D
Explanation
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This directly satisfies the stated requirement.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
Learning point: For this FortiOS 7.6 scenario, use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback. A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback.
Question 9
An incident at Relecloud requires the SOC analyst to troubleshoot a configured static route that does not appear active. What should be done first? The change is being made during a controlled production window.
- Verify that a usable route exists after confirming the policy match
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
Correct answer: E
Explanation
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes. A configured route may be inactive or unused because its path is unavailable or another route is preferred.
Question 10
For a FortiGate 7.6 deployment at Woodgrove Bank, which option correctly addresses the need to explain why an allowed firewall session still cannot reach its destination? The team will validate the result immediately after the change.
- Verify that a usable route exists after confirming the policy match
- Use the route with the lower administrative distance when the prefix length is the same
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Inspect the active routing table and route details for the destination
Correct answer: A
Explanation
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This directly satisfies the stated requirement.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
Learning point: For this FortiOS 7.6 scenario, verify that a usable route exists after confirming the policy match. Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path.
Question 11
Alpine Ski House has validated routing and basic reachability. The remaining requirement is to send traffic for a remote network to a specific next-hop router. Which action should the team take? No unrelated security controls should be changed.
- Verify that a usable route exists after confirming the policy match
- Select the route with the longest matching destination prefix
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Use supported equal-cost multipath routing with equivalent route preference
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
Correct answer: C
Explanation
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A static route adds a deterministic next hop for the matching destination network. This directly satisfies the stated requirement.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
Learning point: For this FortiOS 7.6 scenario, configure a static route for the destination prefix with the correct outgoing interface and gateway. A static route adds a deterministic next hop for the matching destination network.
Question 12
At Datum Corporation, a network administrator is handling a FortiGate 7.6 change. The requirement is to provide a catch-all path for destinations not matched by a more specific route. What should the administrator do? The administrator wants a configuration that is easy to audit later.
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Inspect the active routing table and route details for the destination
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
Correct answer: A
Explanation
- The default route matches IPv4 destinations when no more specific route is selected. This directly satisfies the stated requirement.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
Learning point: For this FortiOS 7.6 scenario, configure a default route for 0.0.0.0/0 toward the intended upstream gateway. The default route matches IPv4 destinations when no more specific route is selected.
Question 13
During a maintenance window at Southridge Video, the team must predict which of two routes with different prefix lengths will carry a packet. Which action is the most appropriate? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Use the route with the lower administrative distance when the prefix length is the same
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Inspect the active routing table and route details for the destination
- Select the route with the longest matching destination prefix
Correct answer: E
Explanation
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, select the route with the longest matching destination prefix. IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes.
Question 14
A change review at Fabrikam Manufacturing identifies one requirement: prefer one route when equal destination prefixes are learned from alternatives with different administrative distance. Which FortiGate action best satisfies it? The team wants the smallest change that directly addresses the requirement.
- Use the route with the lower administrative distance when the prefix length is the same
- Verify that a usable route exists after confirming the policy match
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Inspect the active routing table and route details for the destination
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
Correct answer: A
Explanation
- Administrative distance is used to prefer among competing routes to the same destination prefix. This directly satisfies the stated requirement.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
Learning point: For this FortiOS 7.6 scenario, use the route with the lower administrative distance when the prefix length is the same. Administrative distance is used to prefer among competing routes to the same destination prefix.
Question 15
While troubleshooting at Wingtip Energy, the SOC analyst needs to verify the route FortiGate actually installed rather than relying only on configured static entries. What is the best next step? The choice should follow normal FortiOS administration practice.
- Inspect the active routing table and route details for the destination
- Select the route with the longest matching destination prefix
- Use the route with the lower administrative distance when the prefix length is the same
- Verify that a usable route exists after confirming the policy match
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
Correct answer: A
Explanation
- The routing table shows which routes are currently installed and eligible for forwarding. This directly satisfies the stated requirement.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
Learning point: For this FortiOS 7.6 scenario, inspect the active routing table and route details for the destination. The routing table shows which routes are currently installed and eligible for forwarding.
Question 16
Lucerne Publishing is standardizing its FortiGate 7.6 operations. Which approach should it use to retain a backup static path that should be used only when the preferred path is unavailable? The solution must preserve the existing production design where possible.
- Inspect the active routing table and route details for the destination
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Verify that a usable route exists after confirming the policy match
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
Correct answer: D
Explanation
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This directly satisfies the stated requirement.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
Learning point: For this FortiOS 7.6 scenario, configure the backup route with a less-preferred distance or priority and validate next-hop reachability. A less-preferred route can remain available as a fallback when the primary route is removed or unusable.
Question 17
A production ticket for School of Fine Art states that administrators must share traffic across multiple equally preferred next hops to the same prefix. Which choice is correct? The change is being made during a controlled production window.
- Use supported equal-cost multipath routing with equivalent route preference
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Use the route with the lower administrative distance when the prefix length is the same
- Inspect the active routing table and route details for the destination
- Select the route with the longest matching destination prefix
Correct answer: A
Explanation
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This directly satisfies the stated requirement.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
Learning point: For this FortiOS 7.6 scenario, use supported equal-cost multipath routing with equivalent route preference. ECMP can install multiple equal-cost routes and distribute eligible sessions across them.
Question 18
The security team at Apex Retail wants to prevent a failed narrow destination from falling back unexpectedly to a broad default route. Which FortiGate configuration or action most directly meets that goal? The team will validate the result immediately after the change.
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Use supported equal-cost multipath routing with equivalent route preference
- Use the route with the lower administrative distance when the prefix length is the same
Correct answer: C
Explanation
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This directly satisfies the stated requirement.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
Learning point: For this FortiOS 7.6 scenario, use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback. A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback.
Question 19
An incident at Proseware Media requires the SOC analyst to troubleshoot a configured static route that does not appear active. What should be done first? No unrelated security controls should be changed.
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Use the route with the lower administrative distance when the prefix length is the same
- Use supported equal-cost multipath routing with equivalent route preference
Correct answer: C
Explanation
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This directly satisfies the stated requirement.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
Learning point: For this FortiOS 7.6 scenario, check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes. A configured route may be inactive or unused because its path is unavailable or another route is preferred.
Question 20
For a FortiGate 7.6 deployment at City Power & Light, which option correctly addresses the need to explain why an allowed firewall session still cannot reach its destination? The administrator wants a configuration that is easy to audit later.
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Verify that a usable route exists after confirming the policy match
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Select the route with the longest matching destination prefix
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
Correct answer: B
Explanation
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This directly satisfies the stated requirement.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
Learning point: For this FortiOS 7.6 scenario, verify that a usable route exists after confirming the policy match. Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path.
Question 21
Margie Travel has validated routing and basic reachability. The remaining requirement is to send traffic for a remote network to a specific next-hop router. Which action should the team take? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
Correct answer: C
Explanation
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A static route adds a deterministic next hop for the matching destination network. This directly satisfies the stated requirement.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
Learning point: For this FortiOS 7.6 scenario, configure a static route for the destination prefix with the correct outgoing interface and gateway. A static route adds a deterministic next hop for the matching destination network.
Question 22
At Bellows College, a network administrator is handling a FortiGate 7.6 change. The requirement is to provide a catch-all path for destinations not matched by a more specific route. What should the administrator do? The team wants the smallest change that directly addresses the requirement.
- Use supported equal-cost multipath routing with equivalent route preference
- Select the route with the longest matching destination prefix
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Verify that a usable route exists after confirming the policy match
Correct answer: D
Explanation
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- The default route matches IPv4 destinations when no more specific route is selected. This directly satisfies the stated requirement.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
Learning point: For this FortiOS 7.6 scenario, configure a default route for 0.0.0.0/0 toward the intended upstream gateway. The default route matches IPv4 destinations when no more specific route is selected.
Question 23
During a maintenance window at Adventure Works, the team must predict which of two routes with different prefix lengths will carry a packet. Which action is the most appropriate? The choice should follow normal FortiOS administration practice.
- Verify that a usable route exists after confirming the policy match
- Use the route with the lower administrative distance when the prefix length is the same
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Use supported equal-cost multipath routing with equivalent route preference
- Select the route with the longest matching destination prefix
Correct answer: E
Explanation
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, select the route with the longest matching destination prefix. IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes.
Question 24
A change review at Fourth Coffee identifies one requirement: prefer one route when equal destination prefixes are learned from alternatives with different administrative distance. Which FortiGate action best satisfies it? The solution must preserve the existing production design where possible.
- Use the route with the lower administrative distance when the prefix length is the same
- Verify that a usable route exists after confirming the policy match
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
Correct answer: A
Explanation
- Administrative distance is used to prefer among competing routes to the same destination prefix. This directly satisfies the stated requirement.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
Learning point: For this FortiOS 7.6 scenario, use the route with the lower administrative distance when the prefix length is the same. Administrative distance is used to prefer among competing routes to the same destination prefix.
Question 25
While troubleshooting at Consolidated Messenger, the SOC analyst needs to verify the route FortiGate actually installed rather than relying only on configured static entries. What is the best next step? The change is being made during a controlled production window.
- Select the route with the longest matching destination prefix
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Inspect the active routing table and route details for the destination
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Verify that a usable route exists after confirming the policy match
Correct answer: C
Explanation
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- The routing table shows which routes are currently installed and eligible for forwarding. This directly satisfies the stated requirement.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
Learning point: For this FortiOS 7.6 scenario, inspect the active routing table and route details for the destination. The routing table shows which routes are currently installed and eligible for forwarding.
Question 26
VanArsdel is standardizing its FortiGate 7.6 operations. Which approach should it use to retain a backup static path that should be used only when the preferred path is unavailable? The team will validate the result immediately after the change.
- Use supported equal-cost multipath routing with equivalent route preference
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Use the route with the lower administrative distance when the prefix length is the same
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
Correct answer: E
Explanation
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to retain a backup static path that should be used only when the preferred path is unavailable.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, configure the backup route with a less-preferred distance or priority and validate next-hop reachability. A less-preferred route can remain available as a fallback when the primary route is removed or unusable.
Question 27
A production ticket for Northwind Health states that administrators must share traffic across multiple equally preferred next hops to the same prefix. Which choice is correct? No unrelated security controls should be changed.
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Inspect the active routing table and route details for the destination
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Use supported equal-cost multipath routing with equivalent route preference
- Verify that a usable route exists after confirming the policy match
Correct answer: D
Explanation
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This directly satisfies the stated requirement.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to share traffic across multiple equally preferred next hops to the same prefix.
Learning point: For this FortiOS 7.6 scenario, use supported equal-cost multipath routing with equivalent route preference. ECMP can install multiple equal-cost routes and distribute eligible sessions across them.
Question 28
The security team at Blue Yonder Airlines wants to prevent a failed narrow destination from falling back unexpectedly to a broad default route. Which FortiGate configuration or action most directly meets that goal? The administrator wants a configuration that is easy to audit later.
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Inspect the active routing table and route details for the destination
- Verify that a usable route exists after confirming the policy match
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
Correct answer: E
Explanation
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prevent a failed narrow destination from falling back unexpectedly to a broad default route.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback. A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback.
Question 29
An incident at Trey Research requires the SOC analyst to troubleshoot a configured static route that does not appear active. What should be done first? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.
- Verify that a usable route exists after confirming the policy match
- Check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes
- Inspect the active routing table and route details for the destination
- Select the route with the longest matching destination prefix
- Use the route with the lower administrative distance when the prefix length is the same
Correct answer: B
Explanation
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- A configured route may be inactive or unused because its path is unavailable or another route is preferred. This directly satisfies the stated requirement.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot a configured static route that does not appear active.
Learning point: For this FortiOS 7.6 scenario, check interface state, gateway or next-hop reachability, route parameters, and competing more-preferred routes. A configured route may be inactive or unused because its path is unavailable or another route is preferred.
Question 30
For a FortiGate 7.6 deployment at Nod Publishers, which option correctly addresses the need to explain why an allowed firewall session still cannot reach its destination? The team wants the smallest change that directly addresses the requirement.
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Use the route with the lower administrative distance when the prefix length is the same
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Verify that a usable route exists after confirming the policy match
- Use supported equal-cost multipath routing with equivalent route preference
Correct answer: D
Explanation
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
- The default route matches IPv4 destinations when no more specific route is selected. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This directly satisfies the stated requirement.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to explain why an allowed firewall session still cannot reach its destination.
Learning point: For this FortiOS 7.6 scenario, verify that a usable route exists after confirming the policy match. Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path.
Question 31
Contoso Finance has validated routing and basic reachability. The remaining requirement is to send traffic for a remote network to a specific next-hop router. Which action should the team take? The choice should follow normal FortiOS administration practice.
- Use supported equal-cost multipath routing with equivalent route preference
- Use the route with the lower administrative distance when the prefix length is the same
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Select the route with the longest matching destination prefix
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
Correct answer: E
Explanation
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to send traffic for a remote network to a specific next-hop router.
- A static route adds a deterministic next hop for the matching destination network. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, configure a static route for the destination prefix with the correct outgoing interface and gateway. A static route adds a deterministic next hop for the matching destination network.
Question 32
At Litware Logistics, a network administrator is handling a FortiGate 7.6 change. The requirement is to provide a catch-all path for destinations not matched by a more specific route. What should the administrator do? The solution must preserve the existing production design where possible.
- Configure a default route for 0.0.0.0/0 toward the intended upstream gateway
- Use the route with the lower administrative distance when the prefix length is the same
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Verify that a usable route exists after confirming the policy match
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
Correct answer: A
Explanation
- The default route matches IPv4 destinations when no more specific route is selected. This directly satisfies the stated requirement.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to provide a catch-all path for destinations not matched by a more specific route.
Learning point: For this FortiOS 7.6 scenario, configure a default route for 0.0.0.0/0 toward the intended upstream gateway. The default route matches IPv4 destinations when no more specific route is selected.
Question 33
During a maintenance window at Wide World Importers, the team must predict which of two routes with different prefix lengths will carry a packet. Which action is the most appropriate? The change is being made during a controlled production window.
- Select the route with the longest matching destination prefix
- Use supported equal-cost multipath routing with equivalent route preference
- Use the route with the lower administrative distance when the prefix length is the same
- Verify that a usable route exists after confirming the policy match
- Inspect the active routing table and route details for the destination
Correct answer: A
Explanation
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This directly satisfies the stated requirement.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to predict which of two routes with different prefix lengths will carry a packet.
Learning point: For this FortiOS 7.6 scenario, select the route with the longest matching destination prefix. IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes.
Question 34
A change review at Graphic Design Institute identifies one requirement: prefer one route when equal destination prefixes are learned from alternatives with different administrative distance. Which FortiGate action best satisfies it? The team will validate the result immediately after the change.
- Select the route with the longest matching destination prefix
- Configure a static route for the destination prefix with the correct outgoing interface and gateway
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Inspect the active routing table and route details for the destination
- Use the route with the lower administrative distance when the prefix length is the same
Correct answer: E
Explanation
- IP forwarding prefers the most specific matching prefix before comparing route preference among equal prefixes. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- A static route adds a deterministic next hop for the matching destination network. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- The routing table shows which routes are currently installed and eligible for forwarding. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to prefer one route when equal destination prefixes are learned from alternatives with different administrative distance.
- Administrative distance is used to prefer among competing routes to the same destination prefix. This directly satisfies the stated requirement.
Learning point: For this FortiOS 7.6 scenario, use the route with the lower administrative distance when the prefix length is the same. Administrative distance is used to prefer among competing routes to the same destination prefix.
Question 35
While troubleshooting at Lamna Healthcare, the SOC analyst needs to verify the route FortiGate actually installed rather than relying only on configured static entries. What is the best next step? No unrelated security controls should be changed.
- Verify that a usable route exists after confirming the policy match
- Inspect the active routing table and route details for the destination
- Use an appropriate blackhole route for the destination when the design requires explicit discard instead of fallback
- Configure the backup route with a less-preferred distance or priority and validate next-hop reachability
- Use supported equal-cost multipath routing with equivalent route preference
Correct answer: B
Explanation
- Firewall authorization and routing are separate decisions; allowed traffic still needs a valid forwarding path. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- The routing table shows which routes are currently installed and eligible for forwarding. This directly satisfies the stated requirement.
- A blackhole route can intentionally terminate traffic for a prefix and prevent less-specific fallback. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- A less-preferred route can remain available as a fallback when the primary route is removed or unusable. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
- ECMP can install multiple equal-cost routes and distribute eligible sessions across them. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to verify the route FortiGate actually installed rather than relying only on configured static entries.
Learning point: For this FortiOS 7.6 scenario, inspect the active routing table and route details for the destination. The routing table shows which routes are currently installed and eligible for forwarding.