Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

Get Special Discount Offer of NSE7_SDW-7.2 Certification Exam Sample Questions and Answers [Q53-Q70]

Share

Get Special Discount Offer of NSE7_SDW-7.2 Certification Exam Sample Questions and Answers

New NSE7_SDW-7.2 Dumps For Preparing NSE 7 Network Security Architect Certified Fortinet Exam Well


Fortinet NSE7_SDW-7.2 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Rules and Routing: Understanding SD-WAN Rules and Routing is crucial for directing traffic effectively. This topic of the NSE7_SDW-7.2 exam evaluates the capabilities of Fortinet network and security professionals to configure SD-WAN rules and routing.
Topic 2
  • SD-WAN Troubleshooting: Troubleshooting SD-WAN issues, including rules, routing, and ADVPN, is vital for maintaining network reliability. This section of the Fortinet NSE 7 - SD-WAN 7.2 exam tests the ability to diagnose and resolve SD-WAN problems using diagnostic commands and monitoring tools, ensuring robust and uninterrupted network operations.
Topic 3
  • SD-WAN Overlay Design and Best Practices: It focuses on the deployment of hub-and-spoke IPsec topologies and configuring ADVPN. Proficiency in this topic ensures that Fortinet network and security professionals can implement effective and reliable SD-WAN overlays tailored to organizational needs.
Topic 4
  • Centralized Management: This area focuses on deploying and managing SD-WAN through FortiManager, including using IPsec templates and SD-WAN Overlay Templates. Mastery here demonstrates the abilities of Fortinet network and security professionals to streamline SD-WAN configuration, enhance security, and maintain consistent policies across multiple sites.
Topic 5
  • SD-WAN Configuration: This topic assesses skills of Fortinet network and security professionals in setting up basic SD-WAN environments, including configuring Direct Internet Access (DIA), SD-WAN Members, and Performance Service Level Agreements (SLAs). Proficiency here ensures the ability to design efficient and resilient SD-WAN configurations.

 

NEW QUESTION # 53
Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured packet loss will make T_INET_1_0 the new preferred member?

  • A. When all three members have the same packet loss.
  • B. When T_INET_0_0 has 4% packet loss.
  • C. When T_INET_1_0 has 4% packet loss.
  • D. When T_INET_0_0 has 12% packet loss.

Answer: C


NEW QUESTION # 54
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device? (Choose two.)

  • A. additional-path is enabled.
  • B. You can run the get router info routing-table database command to display the additional paths.
  • C. ibgp-multipath is disabled.
  • D. Each BGP route is three hops away from the destination.

Answer: A,B


NEW QUESTION # 55
Which three matching traffic criteria are available in SD-WAN rules? (Choose three.)

  • A. Internet service database (ISDB) address object
  • B. Application signatures
  • C. URL categories
  • D. Source and destination IP address
  • E. Type of physical link connection

Answer: A,B,E


NEW QUESTION # 56
Refer to the exhibit.

Based on the exhibit, which two statements are correct about the health of the selected members? (Choose two.)

  • A. After FortiGate switches to active mode, FortiGate never fails back to passive monitoring.
  • B. FortiGate can offload the traffic that is subject to passive monitoring to hardware.
  • C. During passive monitoring, FortiGate can't detect dead members.
  • D. FortiGate passively monitors the member if TCP traffic is passing through the member.

Answer: C,D


NEW QUESTION # 57
Refer to the exhibit.

Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)

  • A. Set load-balance-mode source-ip-ip-based.
  • B. Set priority 10.
  • C. Set cost 15.
  • D. Set source 100.64.1.1.

Answer: B,C


NEW QUESTION # 58
Refer to the exhibit.

Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)

  • A. Priority
  • B. Cost
  • C. Gateway IP
  • D. Interface member

Answer: C,D


NEW QUESTION # 59
Exhibit.

The exhibit shows the output of the command diagnose sys sdwan health-check status collected on a FortiGate device. Which two statements are correct about the health check status on this FortiGate device? (Choose two.)

  • A. The health-check VPN_PING orders the members according to the lowest jitter.
  • B. The interface T_INET_0 missed three SLA targets.
  • C. The interface T_INET_1 missed one SLA target.
  • D. There is no SLA criteria configured for the health-check Level3_DNS.

Answer: A,D

Explanation:
According to the FortiGate / FortiOS 6.4.2 Administration Guide, the health check status command displays the status of the health check probes for each SD-WAN member interface. The output includes the following information:
* state: the current state of the interface, either alive or dead
* packet-loss: the percentage of packets lost during the health check
* latency: the average round-trip time in milliseconds
* jitter: the variation in latency
* mos: the mean opinion score, a measure of voice quality
* bandwidth: the available bandwidth in kilobits per second for each direction (up, down, bi)
* sla map: a bitmap that indicates which SLA criteria are met or failed Based on the exhibit, the following statements are correct:
* The health-check VPN_PING orders the members according to the lowest jitter. This means that the interface with the lowest jitter value is listed first, followed by the next lowest, and so on1. In the exhibit, the order is T_MPLS, T_INET_1, and T_INET_0.
* There is no SLA criteria configured for the health-check Level3_DNS. This means that the health check does not use any SLA parameters to determine the state of the interface2. In the exhibit, the sla map value is 0x0 for both port1 and port2, indicating that no SLA criteria are applied.


NEW QUESTION # 60
Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

  • A. Use different proposals are used between the interfaces.
  • B. Specify a unique peer ID for each dial-up VPN interface.
  • C. Configure the IKE mode to be aggressive mode.
  • D. Use unique Diffie Hellman groups on each VPN interface.

Answer: B,C


NEW QUESTION # 61
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?

  • A. FortiGate removes all static routes for port2.
  • B. The administrator manually restores the static routes for port2, if port2 becomes alive.
  • C. Port2 becomes alive after three successful probes are detected.
  • D. Host 8.8.8.8 is reachable through port1 and port2.

Answer: A

Explanation:
This is due to Update static route is enable which removes the static route entry referencing the interface if the interface is dead


NEW QUESTION # 62
Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.

What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?

  • A. You must disable idle-timeout.
  • B. You must enable net-device.
  • C. You must set ike-version to 1.
  • D. You must enable auto-discovery-sender.

Answer: B


NEW QUESTION # 63
Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

  • A. Use different proposals are used between the interfaces.
  • B. Specify a unique peer ID for each dial-up VPN interface.
  • C. Configure the IKE mode to be aggressive mode.
  • D. Use unique Diffie Hellman groups on each VPN interface.

Answer: B,C


NEW QUESTION # 64
Refer to the exhibit.

Based on the output, which two conclusions are true? (Choose two.)

  • A. The SD-WAN rules take precedence over regular policy routes.
  • B. Entry 1(id=1) is a regular policy route.
  • C. The all_rules rule represents the implicit SD-WAN rule.
  • D. There is more than one SD-WAN rule configured.

Answer: B,D


NEW QUESTION # 65
Which statement is correct about SD-WAN and ADVPN?

  • A. SD-WAN can steer traffic to ADVPN shortcuts, established over IPsec overlays, configured as SD-WAN members.
  • B. Routes for ADVPN shortcuts must be manually configured.
  • C. SD-WAN does not monitor the health and performance of ADVPN shortcuts.
  • D. You must use IKEv2 on IPsec tunnels.

Answer: A


NEW QUESTION # 66
Refer to the exhibit.

Based on the exhibit, which action does FortiGate take?

  • A. FortiGate bounces port5 after it detects all SD-WAN members as dead.
  • B. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
  • C. FortiGate brings up port5 after it detects all SD-WAN members as alive.
  • D. FortiGate brings down port5 after it detects all SD-WAN members as dead.

Answer: B


NEW QUESTION # 67
What is the route-tag setting in an SD-WAN rule used for?

  • A. To indicate the routes for health check probes.
  • B. To indicate the routes that can be used for routing SD-WAN traffic.
  • C. To indicate the destination of a rule based on learned BGP prefixes.
  • D. To indicate the members that can be used to route SD-WAN traffic.

Answer: C


NEW QUESTION # 68
Refer to the exhibit.

Based on the exhibit, which two statements are correct about the health of the selected members? (Choose two.)

  • A. After FortiGate switches to active mode, FortiGate never fails back to passive monitoring.
  • B. FortiGate can offload the traffic that is subject to passive monitoring to hardware.
  • C. During passive monitoring, FortiGate can't detect dead members.
  • D. FortiGate passively monitors the member if TCP traffic is passing through the member.

Answer: C,D


NEW QUESTION # 69
Refer to the exhibit.

An administrator used the SD-WAN overlay template to prepare an IPsec configuration for a hub-and-spoke SD-WAN topology. The exhibit shows the installation preview for one FortiGate device. In the exhibit, which statement best describes the configuration applied to the FortiGate device?

  • A. It is a hub device and will automatically discover the spoke devices that are in the SD-WAN topology.
  • B. It is a hub device. It can send ADVPN shortcut offers.
  • C. It is a spoke device that establishes dynamic IPsec tunnels to the hub. The subnet range is 10.10.128.0
    /23.
  • D. It is a spoke device that establishes dynamic IPsec tunnels to the hub. It can send ADVPN shortcut requests.

Answer: D

Explanation:
According to the SD-WAN 7.2 Study Guide, the SD-WAN overlay template simplifies the configuration of IPsec tunnels in a hub-and-spoke topology. The template defines the following parameters:
* type: dynamic for spokes, static for hubs
* interface: the WAN interface to use for the IPsec tunnel
* network-overlay: enable for spokes, disable for hubs
* network-id: a unique identifier for each spoke
* auto-discovery-sender: enable for hubs, disable for spokes
* auto-discovery-receiver: enable for spokes, disable for hubs
Based on the exhibit, the FortiGate device has the following configuration:
* type: dynamic
* interface: port1
* network-overlay: enable
* network-id: 5
* auto-discovery-sender: disable
* auto-discovery-receiver: enable
Therefore, the FortiGate device is a spoke that establishes dynamic IPsec tunnels to the hub. It also has the network-overlay and auto-discovery-receiver options enabled, which means it can send ADVPN shortcut requests to other spokes when it receives a shortcut offer from the hub


NEW QUESTION # 70
......

Updated NSE7_SDW-7.2 Dumps Questions Are Available For Passing Fortinet Exam: https://www.examstorrent.com/NSE7_SDW-7.2-exam-dumps-torrent.html

Free UPDATED Fortinet NSE7_SDW-7.2 Certification Exam Dumps is Online: https://drive.google.com/open?id=14iiKnbc8ySxUyRkPatKwNMQGXvFCwq2a