1. Fortinet Training Institute
FortiGate Security 7.2 Study Guide
2022.
Page 268
"Hub-and-Spoke" section: "The main advantage of this topology is scalability. You don't need to create a full mesh of tunnels between all the remote locations. Also
the configuration on the spoke devices is simple. They just need to build a single tunnel to the hub and route all the traffic for the remote subnets through it." This statement directly supports the correctness of options B and D.
2. Fortinet Training Institute
FortiGate Infrastructure 7.2 Study Guide
2022.
Page 298
"Hub-and-Spoke" section: This section reiterates the same points: "The main advantage of this topology is scalability. You don't need to create a full mesh of tunnels between all the remote locations. Also
the configuration on the spoke devices is simple." This confirms that fewer tunnels lead to simpler configuration (Option B) and routing (Option D).
3. Fortinet Document Library
IPsec VPN for FortiOS 7.4.0
2023.
Section: "Hub-and-spoke": "In a hub-and-spoke configuration
spokes only need to establish one IPsec tunnel to the hub to communicate with all other spokes. This simplifies the configuration on the spokes." This directly validates option B. The document also implicitly supports option D by describing how spokes route traffic via the central hub
simplifying their routing tables.