Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

[Nov 18, 2024] NSE7_SDW-7.2 Dumps Full Questions - Exam Study Guide [Q40-Q62]

Share

[Nov 18, 2024] NSE7_SDW-7.2 Dumps Full Questions - Exam Study Guide

NSE 7 Network Security Architect Free Certification Exam Material from ExamsTorrent with 99 Questions

NEW QUESTION # 40
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the
default implicit SD-WAN rule? (Choose two )

  • A. Matched traffic failed RPF and was caught by the rule.
  • B. The FIB lookup resolved interface was the SD-WAN interface.
  • C. Traffic has matched none of the FortiGate policy routes.
  • D. An absolute SD-WAN rule was defined and matched traffic.

Answer: B,C


NEW QUESTION # 41
Refer to the exhibit.

Based on the output, which two conclusions are true? (Choose two.)

  • A. Theall_rulesrule represents the implicit SD-WAN rule.
  • B. Entry1(id=1)is a regular policy route.
  • C. The SD-WAN rules take precedence over regular policy routes.
  • D. There is more than one SD-WAN rule configured.

Answer: B,D


NEW QUESTION # 42
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device?
(Choose two.)

  • A. You can run the get router info routing-table database command to display the additional paths.
  • B. additional-path is enabled.
  • C. Each BGP route is three hops away from the destination.
  • D. ibgp-multipath is disabled.

Answer: A,B


NEW QUESTION # 43
Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on traffic passing through port2? (Choose two.)

  • A. FortiGate does not change the routing information on existing sessions that use a valid gateway, after a route change.
  • B. FortiGate performs routing lookups for new sessions only, after a route change.
  • C. FortiGate always blocks all traffic, after a route change.
  • D. FortiGate flushes all routing information from the session table, after a route change.

Answer: A,B


NEW QUESTION # 44
Refer to the exhibit.

Which conclusion about the packet debug flow output is correct?

  • A. The original traffic exceeded the maximum packets per second of the outgoing interface, and the packet was dropped.
  • B. The original traffic exceeded the maximum bandwidth of the outgoing interface, and the packet was dropped.
  • C. The reply traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.
  • D. The original traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.

Answer: D


NEW QUESTION # 45
Refer to the exhibit.

In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling the anti-replay setting on the hubs?

  • A. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve performance.
  • B. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions originated from spokes to fail over back and forth between the hubs.
  • C. It instructs the hub to skip content inspection on TCP traffic, to improve performance.
  • D. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.

Answer: B


NEW QUESTION # 46
Refer to the exhibits.


An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)

  • A. FortiGate did not refresh the routing information on the session after the application was detected.
  • B. Full SSL inspection is not enabled on the matching firewall policy.
  • C. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
  • D. Port1 and port2 do not have a valid route to the destination.

Answer: A,C

Explanation:
Study guide 7.2 Page 191


NEW QUESTION # 47
Refer to the Exhibits:

Exhibit A, which shows the SD-WAN performance SLA and exhibit B shows the health of the participating SD-WAN members.
Based on the exhibits, which statement is correct?

  • A. FortiGate has not received three consecutive requests from the SLA server configured for port2.
  • B. Port2 needs to wait 500 milliseconds to change the status from alive to dead.
  • C. The dead member interface stays unavailable until an administrator manually brings the interface back.
  • D. Static routes using port2 are active in the routing table.

Answer: D


NEW QUESTION # 48
Refer to the exhibit.

Based on the output, which two conclusions are true? (Choose two.)

  • A. The SD-WAN rules take precedence over regular policy routes.
  • B. There is more than one SD-WAN rule configured.
  • C. The all_rules rule represents the implicit SD-WAN rule.
  • D. Entry 1(id=1) is a regular policy route.

Answer: B,D


NEW QUESTION # 49
Which statement is correct about SD-WAN and ADVPN?

  • A. SD-WAN can steer traffic to ADVPN shortcuts, established over IPsec overlays, configured as SD-WAN members.
  • B. Routes for ADVPN shortcuts must be manually configured.
  • C. SD-WAN does not monitor the health and performance of ADVPN shortcuts.
  • D. You must use IKEv2 on IPsec tunnels.

Answer: A


NEW QUESTION # 50
Refer to the exhibits.


An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B.
The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)

  • A. FortiGate did not refresh the routing information on the session after the application was detected.
  • B. Full SSL inspection is not enabled on the matching firewall policy.
  • C. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
  • D. Port1 and port2 do not have a valid route to the destination.

Answer: A,C

Explanation:
Study guide 7.2 Page 191


NEW QUESTION # 51
Which components make up the secure SD-WAN solution?

  • A. Application, antivirus, and URL, and SSL inspection
  • B. Datacenter, branch offices, and public cloud
  • C. FortiGate, FortiManager, FortiAnalyzer, and FortiDeploy
  • D. Telephone, ISDN, and telecom network.

Answer: C


NEW QUESTION # 52
Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.

What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?

  • A. You must disable idle-timeout.
  • B. You must enable net-device.
  • C. You must enable auto-discovery-sender.
  • D. You must set ike-version to 1.

Answer: B


NEW QUESTION # 53
What are two reasons why FortiGate would be unable to complete the zero-touch provisioning process? (Choose two.)

  • A. FortiDeploy has connected with FortiGate and provided the initial configuration to contact FortiManager
  • B. The FortiGate cloud key has not been added to the FortiGate cloud portal.
  • C. The zero-touch provisioning process has completed internally, behind FortiGate.
  • D. FortiGate has obtained a configuration from the platform template in FortiGate cloud.
  • E. A factory reset performed on FortiGate.

Answer: B,C


NEW QUESTION # 54
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)

  • A. Traffic does not match any of the entries in the policy route table.
  • B. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
  • C. The sdwan_service_id flag in the session information is 0.
  • D. All SD-WAN rules have the default setting enabled.

Answer: A,C

Explanation:
Explanation
sdwan_service_id is 0 = match SD-WAN implicit rule, study guide 7.0 page 120, 7.2 page 149 SD-WAN rules
internally are interpreted as a Policy route, so when the traffic doesn't match with any policy route, it will be
flowing by implict policy.


NEW QUESTION # 55
Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)

  • A. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for local-out traffic.
  • B. By default, local-out traffic does not use SD-WAN.
  • C. By default, FortiGate does not check if the selected member has a valid route to the destination.
  • D. You must configure each local-out feature individually, to use SD-WAN.

Answer: B,D


NEW QUESTION # 56
Which two settings can you configure to speed up routing convergence in BGP? (Choose two.)

  • A. update-source
  • B. set-route-tag
  • C. link-down-failover
  • D. holdtime-timer

Answer: C,D


NEW QUESTION # 57
Which two tasks are part of using central VPN management? (Choose two.)

  • A. FortiManager installs VPN settings on both managed and external gateways.
  • B. You can configure full mesh, star, and dial-up VPN topologies.
  • C. You must enable VPN zones for SD-WAN deployments.
  • D. You configure VPN communities to define common IPsec settings shared by all VPN gateways.

Answer: B,D


NEW QUESTION # 58
Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on traffic passing through port2? (Choose
two.)

  • A. FortiGate does not change the routing information on existing sessions that use a valid gateway, after a
    route change.
  • B. FortiGate performs routing lookups for new sessions only, after a route change.
  • C. FortiGate always blocks all traffic, after a route change.
  • D. FortiGate flushes all routing information from the session table, after a route change.

Answer: A,B


NEW QUESTION # 59
Refer to the exhibit.

Exhibit B -

Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.
Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?

  • A. port1 is referenced in a firewall policy.
  • B. port1 and port2 are not administratively down.
  • C. port2 is referenced in a static route.
  • D. port1 is assigned a manual IP address.

Answer: A


NEW QUESTION # 60
Which are two benefits of using CLI templates in FortiManager? (Choose two.)

  • A. You can configure advanced CLI settings.
  • B. You can configure FortiManager to sync local configuration changes made on the managed device, to
    the CLI template.
  • C. You can configure interfaces as SD-WAN members without having to remove references first.
  • D. You can reference meta fields.

Answer: A,D


NEW QUESTION # 61
Refer to the exhibit.

Which are two expected behaviors of the traffic that matches the traffic shaper? (Choose two.)

  • A. The traffic shaper limits the bandwidth of each source IP address to a maximum of 625 KB/sec.
  • B. The number of simultaneous connections among all source IP addresses cannot exceed five connections.
  • C. The traffic shaper limits the combined bandwidth of all connections to a maximum of 5 MB/sec.
  • D. The number of simultaneous connections allowed for each source IP address cannot exceed five connections.

Answer: A,D


NEW QUESTION # 62
......

Dumps Brief Outline Of The NSE7_SDW-7.2 Exam: https://www.examstorrent.com/NSE7_SDW-7.2-exam-dumps-torrent.html

Use Real NSE7_SDW-7.2 - 100% Cover Real Exam Questions: https://drive.google.com/open?id=1B06p0FrgQHGoXOQqxJTf_xqEUlN2Ad6G