New Year Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

FCSS - SD-WAN 7.6 Architect Question and Answers

FCSS - SD-WAN 7.6 Architect

Last Update Jan 14, 2026
Total Questions : 94

We are offering FREE FCSS_SDW_AR-7.6 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare FCSS_SDW_AR-7.6 free exam questions and then go for complete pool of FCSS - SD-WAN 7.6 Architect test questions that will help you more.

FCSS_SDW_AR-7.6 pdf

FCSS_SDW_AR-7.6 PDF

$36.75  $104.99
FCSS_SDW_AR-7.6 Engine

FCSS_SDW_AR-7.6 Testing Engine

$43.75  $124.99
FCSS_SDW_AR-7.6 PDF + Engine

FCSS_SDW_AR-7.6 PDF + Testing Engine

$57.75  $164.99
Questions 1

Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network.

The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3.

Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)

Options:

A.  

HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.

B.  

The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device

C.  

HUB1-VPN1 does not have a valid route to the destination

D.  

HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.

Discussion 0
Questions 2

Refer to the exhibits.

You use FortiManager to configure SD-WAN on three branch devices.

When you install the device settings. FortiManager prompts you with the error "Copy Failed" for the device branch1_fat When you click the log button. FortiManager displays the message shown in the exhibit.

Options:

A.  

Based on the exhibits, which statement best describes the issue and how you can resolve it?

B.  

Remove the installation target for the SD-WAN member port4. You cannot combine metadata variable and installation targets.

C.  

Gateways for all members in a zone must be defined the same way. Specify the gateway of the SD-WAN member port! without metadata variables.

D.  

Check the metadata variable definitions, and review the per-device mapping configuration.

E.  

Check the connection between branch1_fgt and FortiManager

Discussion 0
Questions 3

You configured an SD-WAN rule with the best quality strategy and selected the predefined health check, Default_FortiGuard, to check the link performances against FortiGuard servers.

For the quality criteria, you selected Custom-profile-1.

Which factors does FortiGate use, and in which order. to determine the link that it should use to steer the traffic?

Options:

A.  

Latency – Member configuration order – Link cost threshold

B.  

Link quality index – Member configuration order – Link cost threshold

C.  

Links that meet the SLA targets – Member configuration order – Member local cost

D.  

Latency – Jitter - Packet loss – Bibandwidth – Member configuration order

Discussion 0
Questions 4

Refer to the exhibits.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in the first exhibit. After generating GoToMeeting test traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in the second exhibit.

The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.

Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)

Options:

A.  

Full SSL inspection is not enabled on the matching firewall policy.

B.  

The session 3-tuple did not match any of the existing entries in the ISDB application cache.

C.  

FortiGate could not refresh the routing information on the session after the application was detected.

D.  

No configured SD-WAN rule matches the traffic related to the collaboration application GoToMeeting

Discussion 0
Questions 5

Refer to the exhibit.

The administrator configured the SD-WAN rule ID 4 with two members (port1 and port2) and strategy lowest cost (SLA).

What are the two characteristics of the session shown in the exhibit? (Choose two.)

Options:

A.  

FortiGate steered this flow according to an SD-WAN rule 4.

B.  

FortiGate will never re-evaluate this session.

C.  

FortiGate steered this flow according to the application detected and the outgoing interface is port3.

D.  

FortiGate will re-evaluate this session if the outgoing interface goes down.

Discussion 0
Questions 6

Refer to the exhibit that shows an SD-WAN zone configuration on the FortiManager GUI.

Based on the exhibit, how will the FortiGate device behave after it receives this configuration?

Options:

A.  

The configuration instructs FortiGate to choose an ADVPN shortcut based on SD-WAN information.

B.  

The configuration instructs FortiGate to allow ADVPN shortcuts for the tunnels of this SD-WAN zone.

C.  

The configuration instructs FortiGate to establish shortcuts only when at least two members meet the SLA target.

D.  

The configuration instructs FortiGate to establish shortcuts only for overlay interfaces that meet the SLA target HUB1_HC.

Discussion 0
Questions 7

Exhibit.

Which action will FortiGate take if it detects SD-WAN members as dead?

Options:

A.  

FoftiGate bounces port5 after it detects all SD-WAN members as dead.

B.  

FortiGate fails over to the secondary device after it detects port5 as dead.

C.  

FortiGate sends alert messages through poft5 when it detects all SD-WAN members as dead

D.  

FortiGate brings down port5 after it detects all SD-WAN members as dead.

Discussion 0
Questions 8

Refer to the exhibits.

The administrator configured a device blueprint and CLI scripts as shown in the exhibits, to prepare for onboarding FortiGate devices in the company’s stores. Later, a technician prepares a FortiGate 51G with a basic configuration and connects it to the network. The basic configuration contains the port1 configuration and the minimal configuration required to allow the device to connect to FortiManager.

After the device first connects to FortiManager, FortiManager updates the device configuration.

Based on the exhibits, which actions does FortiManager perform?

Options:

A.  

FortiManager updates the device configuration according to the selected templates. It applies the corp_st template first.

B.  

FortiManager does not update the port1 configuration because FortiManager does not change the configuration of interfaces with fgfm access.

C.  

FortiManager updates access rights only for port1. FortiManager cannot update the IP address because it was already set manually.

D.  

FortiManager updates the configuration of port1, port2, and port5. The three ports might get new IP addresses.

Discussion 0
Questions 9

(Refer to the exhibit.

Which statement correctly describes the role of the ADVPN device in handling traffic? Choose one answer.)

Options:

A.  

This device is a spoke that has received a direct shortcut query from a remote spoke.

B.  

This device is a hub, and two spokes, 192.2.0.1 and 10.0.3.101, established a shortcut.

C.  

This device is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.

D.  

This device is a spoke that has received a shortcut query from a remote hub.

Discussion 0
Questions 10

(Refer to the exhibits.

The SD-WAN zones and members configuration of two branch devices are shown. The two branch devices are part of the same hub-and-spoke topology and connect to the same hub. The devices are configured to allow Auto-Discovery VPN (ADVPN). The configuration on the hub allows the initial communication between the two spokes.

When traffic flows require it, between which interfaces can the devices establish shortcuts? Choose one answer.)

Options:

A.  

Any interface in the overlay zones

B.  

Interface connected to HUB only

C.  

Between T3 on Branch-A and TC on Branch-B

D.  

Between T2 on Branch-A and TA on Branch-B

Discussion 0
Questions 11

(Refer to the exhibit. The administrator configured two SD-WAN rules to load balance the traffic.

Which interfaces does FortiGate use to steer the traffic from 10.0.1.124 to 10.0.0.254? Choose one answer.)

Options:

A.  

HUB2-VPN2

B.  

HUB1-VPN2 or HUB2-VPN2

C.  

port1 or port2

D.  

Any interface in the HUB1 or HUB2 zones

Discussion 0
Questions 12

Which three characteristics apply to provisioning templates available on FortiManager? (Choose three.)

Options:

A.  

A template group can include a system template and an SD-WAN template.

B.  

Each template group can contain up to three IPsec tunnel templates.

C.  

CLI templates are applied in order, from top to bottom

D.  

A CLI template group can contain CLI templates of both types.

E.  

A CLI template can be of type CLI script or Perl script.

Discussion 0
Questions 13

You want FortiGate to use SD-WAN rules to steer local-out traffic.

Which two constraints should you consider? (Choose two.)

Options:

A.  

By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to ping and traceroute.

B.  

By default, local-out traffic does not use SD-WAN.

C.  

You can steer local-out traffic only with SD-WAN rules that use the manual strategy.

D.  

You must configure each local-out feature individually to use SD-WAN.

Discussion 0
Questions 14

Refer to the exhibit.

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate device that supports hardware offloading.

Based on the information shown in the exhibits, which two conclusions can you draw? (Choose two.)

Options:

A.  

By default, FortiGate offloads symmetric and asymmetric flows.

B.  

The original direction of the symmetric traffic flows from port3 to port2.

C.  

The reply direction of the asymmetric traffic flows from port2 to port3.

D.  

The auxiliary session can be offloaded to hardware.

Discussion 0
Questions 15

Refer to the exhibit.

You want to configure SD-WAN on a network as shown in the exhibit.

The network contains many FortiGate devices. Some are used as NGFW, and some are installed with extensions such as FortiSwitch. FortiAP. or Forti Ex tender.

What should you consider when planning your deployment?

Options:

A.  

You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with Forti Extender.

B.  

You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.

C.  

You must use FortiManager to manage your SD-WAN topology.

D.  

You must build multiple SD-WAN topologies. Each topology must contain only one type of extension.

Discussion 0
Questions 16

Refer to the exhibit.

Which SD-WAN rule and interface uses FortiGate to steer the traffic from the LAN subnet 10.0.1.0/24 to the corporate server 10.2.5.254?

Options:

A.  

SD-WAN service rule 3 and interface HUB1-VPN2.

B.  

SD-WAN service rule 3 and interface HUB1-VPN3.

C.  

SD-WAN service rule 4 and port1 or port2.

D.  

SD-WAN service rule 4 and interface port2.

Discussion 0
Questions 17

(You are using the FortiManager SD-WAN monitor menus to check the status of an SD-WAN topology. When you place the mouse next to branch1_fgt, you receive the output shown in the exhibit.

Which two conclusions can you draw from the output shown in the exhibit? Choose two answers.)

Options:

A.  

Three spokes have tunnels that are out of SL

A.  

B.  

The template Corp-SOT defines a dual-hub topology.

C.  

branch3_fgt is configured with three SD-WAN overlay tunnels and one is down.

D.  

branch1_fgt is configured with six SD-WAN overlay tunnels and three are down.

Discussion 0
Questions 18

The SD-WAN overlay template helps to prepare SD-WAN deployments. To complete the tasks performed by the SD-WAN overlay template, the administrator must perform some post-run tasks. What are two mandatory post-run tasks that must be performed? (Choose two.)

Options:

A.  

Configure routing through the overlay tunnels created by the SD-WAN overlay template.

B.  

Create policy packages and assign them to the branch devices.

C.  

Assign a hub id metadata variable to each hub device.

D.  

Configure SD-WAN rules

E.  

Assign an sdwan_id metadata variable to each device (branch and hub)

Discussion 0
Questions 19

Refer to the exhibits.

The exhibits show two IPsec templates to define Branch IPsec 1 and Branch_IPsec_2. Each template defines a VPN tunnel. The error message that FortiManager displayed when the administrator tried to assign the second template to the FortiGate device is also shown.

Which statement best describes the cause of the issue?

Options:

A.  

You can assign only one template with a tunnel type of static to each FortiGate device.

B.  

You can assign only one IPsec template to each FortiGate device.

C.  

You should review the branch1_fgt configuration for configured tunnels in the rootVDOM.

D.  

You should use the same outgoing interface of both templates.

Discussion 0
Questions 20

Refer to the exhibits.

The first exhibit shows the SD-WAN zone HUB1 and SD-WAN member configuration from an SD-WAN template, and the second exhibit shows the output of command diagnose sys sdwan member collected on a FortiGate device.

Which statement best describes what the diagnose output shows?

Options:

A.  

The diagnose output shows that HUB1-VPN1 and all HUBx-VPNy members are dead.

B.  

The diagnose output does not correspond to a device configured with the SD-WAN template shown in the exhibit.

C.  

The diagnose output was collected on the device branch2_fgt.

D.  

The diagnose output was collected on the device branch1_fgt

Discussion 0
Questions 21

(You want FortiGate to use SD-WAN rules to steer ping local-out traffic.

Which two constraints should you consider? Choose two answers.)

Options:

A.  

You can steer local-out traffic only with SD-WAN rules that use the manual strategy.

B.  

By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to ping and traceroute.

C.  

By default, local-out traffic does not use SD-WAN.

D.  

You must configure each local-out feature individually to use SD-WAN.

Discussion 0
Questions 22

Which statement describes FortiGate behavior when you reference a zone in a static route?

Options:

A.  

FoftiGate installs ECMP static routes for the first two members of the zone.

B.  

FortiGate ignores the static routes defined through members referenced in the zone.

C.  

FortiGate routes the traffic through the best performing member of the zone.

D.  

FortiGate installs a static route for each member in the zone.

Discussion 0
Questions 23

As an MSSP administrator, you are asked to configure ADVPN on an existing SD-WAN topology. FortiManager manages the customer devices in a dedicated ADOM. The previous administrator used the SD-WAN overlay topology.

Which two statements apply to this scenario? (Choose two.)

Options:

A.  

You can activate auto-discovery VPN in the SD-WAN overlay template only if it is a single hub topology.

B.  

When auto-discovery VPN is enabled, FortiManager updates the IPsec and BGP templates in the hub.

C.  

After you enable auto-discovery VPN in the overlay template, you must select between ADVPN 2.0 and ADVPN 1.0.

D.  

You can activate auto-discovery VPN in the SD-WAN overlay template for any type of topology, including a primary-primary dual-hub topology.

Discussion 0
Questions 24

Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two.)

Options:

A.  

The session information output displays no SD-WAN service id.

B.  

Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.

C.  

The traffic is distributed, regardless of weight, through all available static routes.

D.  

Traffic does not match any of the entries in the policy route table.

E.  

FortiGate flags the session with may_dirty and vwl_def ault.

Discussion 0
Questions 25

You have configured the performance SLA with the probe mode as Prefer Passive.

What are two observable impacts of this configuration? (Choose two.)

Options:

A.  

FortiGate passively monitors the member if TCP traffic is passing through the member.

B.  

After FortiGate switches to active mode, the SLA performance rule falls back to passive monitoring after 3 minutes.

C.  

FortiGate passively monitors the member if ICMP traffic is passing through the member.

D.  

During passive monitoring, the SLA performance rule cannot detect dead members.

E.  

FortiGate can offload the traffic that is subject to passive monitoring to hardware.

Discussion 0
Questions 26

An administrator is configuring SD-WAN to load balance their network traffic. Which two things should they consider when setting up SD-WAN? (Choose two.)

Options:

A.  

You can select the outbandwidth hash mode with all strategies that allow load balancing.

B.  

Only the manual and best-quality strategies allow SD-WAN load balancing.

C.  

When applicable. FortiGate load balances the traffic through all members that meet the SLA target.

D.  

SD-WAN load balancing is possible only using the best quality and lowest cost (SLA) strategies.

Discussion 0
Questions 27

Refer to the exhibits.

You use FortiManager to configure SD-WAN on three branch devices.

When you install the device settings, FortiManager prompts you with the error “Copy Failed” for the device branch1_fgt. When you click the log button, FortiManager displays the message shown in the exhibit.

There are two different ways to resolve this issue. Based on the exhibits, which methods could you use? (Choose two.)

Options:

A.  

Update the management IP address of branch1_fgt.

B.  

Specify the gateway of the SD-WAN member port1 with an IP address or use the default value.

C.  

Do not define installation targets for SD-WAN members.

D.  

Review the per-device mapping configuration for metadata variables

Discussion 0
Questions 28

You used the HUB IPsec_Recommended and the BRANCH IPsec_Recommended templates to define the overlay topology. Then, you used the SD-WAN template to define the SD- WAN members, rules, and performance SLAs.

You applied the changes to the devices and want to use the FortiManager monitors menu to get a graphical view that shows the status of each SD-WAN member.

Which statement best explains how to obtain this graphical view?

Options:

A.  

Use the SD-WAN monitor template view to get a map view of the branches, hub, and tunnel status, including the SLA pass or missed status.

B.  

Use the SD-WAN monitor table view to get a donut view and a table view that shows the status of each SD-WAN member, including the SLA pass or missed status.

C.  

Use the VPN monitor map view to get a map view of the branches, hub, and tunnel status, including the SLA pass or missed status.

D.  

Use the SD-WAN monitor asset view to get a donut view and a table view that shows the status of each device and the SLA status of each SD-WAN member.

Discussion 0