Q: 5
An administrator is checking an enterprise network and sees a suspicious packet with the MAC
address e0:23:ff:fc:00:86.
What two conclusions can the administrator draw? (Choose two.)
Options
Discussion
A and C here. The MAC prefix is unique to HA with VDOMs, and decoding the group-id lands under 255. Disagree?
B and D maybe? That MAC could look like it's tied to FGSP setups (B) and something port specific (D) if you don't pay attention to the octet breakdown. I think FortiGate clustering protocols can get confusing with these addresses. Not totally sure, feel free to show me where I'm off.
A and C imo. That MAC prefix (e0:23:ff) is FortiGate HA with VDOMs, pretty standard in cluster setups. For C, the math on the group-id works out to less than 255 after decoding the last three octets. Not 100% on D because port mapping via MAC isn't really a thing here. Let me know if someone interprets it differently.
A and C. Pretty sure official Fortinet docs and HA cluster practice labs back this up, seen similar logic in exam sets.
Option B and D
A and C tbh. That MAC prefix is all about HA clusters with VDOMs on, and group-ids less than 255 fits the format. The rest don't line up from what I know but if I'm missing anything, let me know.
Why not B? FGSP protocol doesn't use that MAC prefix, it's all about HA clusters with VDOMs. Am I missing something?
A and C. No extra info needed here.
Option A and C
A and C imo
Be respectful. No spam.