New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet NSE7_CDS_AR-7.6 Exam - Topic 2 Question 3 Discussion

Actual exam question for Fortinet's NSE7_CDS_AR-7.6 exam
Question #: 3
Topic #: 2
[All NSE7_CDS_AR-7.6 Questions]

Refer to the exhibit.

The exhibit shows a customer deployment of two Linux instances and their main routing table in Amazon Web Services (AWS). The customer also created a Transit Gateway (TGW) and two attachments. Which two steps are required to route traffic from Linux instances to the TGW? (Choose two answers)

Show Suggested Answer Hide Answer
Suggested Answer: A, B

Comprehensive and Detailed Explanation From FortiOS 7.6, FortiWeb 7.4 Exact Extract study guide:

Based on the FortiOS 7.6 Cloud Security Study Guide regarding AWS Transit Gateway (TGW) integration and VPC routing, the following steps are mandatory to establish connectivity between Spoke VPCs via a TGW:

VPC Route Table Configuration (Option A): For traffic to leave a VPC and reach the Transit Gateway, the VPC's subnet route table must have a specific entry. While the exhibit shows local routes for internal VPC traffic (192.168.50.0/24 and 192.168.100.0/24), any traffic destined for 'outside' the local VPC (such as the other Spoke VPC) must be directed to the TGW. Adding a default route (0.0.0.0/0) with the TGW ID as the next hop ensures that all non-local traffic is forwarded to the Transit Gateway for processing.

TGW Association (Option B): Within the Transit Gateway itself, connectivity is managed through Associations and Propagations. An 'Association' links a specific VPC attachment to a TGW route table. Without associating the two attachments (for Spoke VPC A and Spoke VPC B) to a TGW route table, the TGW will not know which route table to use to make forwarding decisions for packets arriving from those VPCs.

Why Option C is incorrect: Route propagation is used to automatically populate the TGW route table with the CIDR blocks of the attached VPCs. While propagation is a valid step for dynamic routing, Option C specifically mentions propagating a static summary range (192.168.0.0/16) which is not the standard automated mechanism; usually, you propagate the specific VPC CIDRs. Furthermore, without the Association (Option B), propagation alone does not allow the TGW to process incoming traffic from the attachment.

Why Option D is incorrect: Directing traffic to an Internet Gateway (IGW) would send the traffic to the public internet. This would not facilitate internal routing between the two Spoke VPCs via the Transit Gateway.


Contribute your Thoughts:

0/2000 characters
Jospeh
5 days ago
I remember practicing a similar question where we had to add routes in the main subnet routing table. I think option A might be correct, but I’m not entirely confident.
upvoted 0 times
...
Shannan
10 days ago
I think we need to associate the TGW attachments in the TGW route table, but I'm not sure about the specifics of route propagation.
upvoted 0 times
...
Sang
15 days ago
This seems straightforward. The key is to route the traffic from the Linux instances to the TGW, so I'll need to add a route in the subnet routing tables pointing to the TGW. And then I'll need to associate the attachments in the TGW route table to complete the connectivity.
upvoted 0 times
...
Jaleesa
20 days ago
I'm a bit confused by the answer choices. Option D mentions routing to an Internet gateway, but the question is specifically about routing to the TGW. I'll need to carefully analyze each option to determine which two steps are the correct ones.
upvoted 0 times
...
Jacqueline
25 days ago
Okay, I think I've got this. The question is asking for the two steps required to route traffic from the Linux instances to the TGW. Based on the answer choices, it seems like I need to add a route in the subnet routing tables to point to the TGW, and then associate the attachments in the TGW route table.
upvoted 0 times
...
Lisbeth
1 month ago
Hmm, the exhibit shows two Linux instances and a Transit Gateway, so I'm guessing the key is to properly configure the routing between the instances and the TGW. I'll need to think through the different routing table options.
upvoted 0 times
...
Adell
1 month ago
This looks like a networking question related to routing in AWS. I'll need to carefully review the exhibit and the answer choices to understand the setup and determine the correct steps.
upvoted 0 times
...

Save Cancel