New Year Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator Question and Answers

Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator

Last Update Jan 14, 2026
Total Questions : 95

We are offering FREE NSE6_SDW_AD-7.6 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE6_SDW_AD-7.6 free exam questions and then go for complete pool of Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator test questions that will help you more.

NSE6_SDW_AD-7.6 pdf

NSE6_SDW_AD-7.6 PDF

$36.75  $104.99
NSE6_SDW_AD-7.6 Engine

NSE6_SDW_AD-7.6 Testing Engine

$43.75  $124.99
NSE6_SDW_AD-7.6 PDF + Engine

NSE6_SDW_AD-7.6 PDF + Testing Engine

$57.75  $164.99
Questions 1

Refer to the exhibits.

The exhibits show two IPsec templates to define Branch IPsec 1 and Branch_IPsec_2. Each template defines a VPN tunnel. The error message that FortiManager displayed when the administrator tried to assign the second template to the FortiGate device is also shown.

Which statement best describes the cause of the issue?

Options:

A.  

You can assign only one template with a tunnel type of static to each FortiGate device.

B.  

You can assign only one IPsec template to each FortiGate device.

C.  

You should review the branch1_fgt configuration for configured tunnels in the rootVDOM.

D.  

You should use the same outgoing interface of both templates.

Discussion 0
Questions 2

Refer to the exhibit.

The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram.

When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed overT2. even though T1 is the preferred member in

the matching SD-WAN rule.

What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?

Options:

A.  

Enable snat-route-change under config system global.

B.  

Enable reply-session under config system sdwan.

C.  

Enable auxiliary-session under config system settings.

D.  

FortiGate route lookup for reply traffic only considers routes over the original ingress interface.

Discussion 0
Questions 3

Refer to the exhibits.

The exhibits show the source NAT (SNAT) global setting. port2 interface settings, and the routing table on FortiGate.

The administrator increases the member priority on port2 to 20.

Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)

Options:

A.  

FortiGate continues routing all existing sessions over port2.

B.  

FortiGate routes only new sessions over port2.

C.  

FortiGate flags the SNAT session as dirty only if the administrator has assigned an IP pool to the firewall policies with NAT.

D.  

FortiGate flags the sessions as dirty.

E.  

FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.

Discussion 0
Questions 4

Refer to the exhibits.

The administrator configured a device blueprint and CLI scripts as shown in the exhibits, to prepare for onboarding FortiGate devices in the company’s stores. Later, a technician prepares a FortiGate 51G with a basic configuration and connects it to the network. The basic configuration contains the port1 configuration and the minimal configuration required to allow the device to connect to FortiManager.

After the device first connects to FortiManager, FortiManager updates the device configuration.

Based on the exhibits, which actions does FortiManager perform?

Options:

A.  

FortiManager updates the device configuration according to the selected templates. It applies the corp_st template first.

B.  

FortiManager does not update the port1 configuration because FortiManager does not change the configuration of interfaces with fgfm access.

C.  

FortiManager updates access rights only for port1. FortiManager cannot update the IP address because it was already set manually.

D.  

FortiManager updates the configuration of port1, port2, and port5. The three ports might get new IP addresses.

Discussion 0
Questions 5

You are tasked with configuring ADVPN 2.0 on an SD-WAN topology already configured for ADVPN. What should you do to implement ADVPN 2.0 in this scenario?

Options:

A.  

Update the IPsec tunnel configurations on the hub.

B.  

Update the SD-WAN configuration on the branches.

C.  

Update the IPsec tunnel configuration on the branches.

D.  

Delete the existing ADVPN configuration and configure ADVPN 2.0.

Discussion 0
Questions 6

Refer to the exhibit.

The administrator used the SD-WAN overlay template to prepare an IPsec tunnels configuration for a hub-and-spoke SD-WAN topology. The exhibit shows the FortiManager installation preview for one FortiGate device.

Based on the exhibit, which statement best describes the configuration applied to the FortiGate device?

Options:

A.  

It is a spoke device that establishes dynamic IPsec tunnels to the hub. The local subnet range is 10.10.128.0/23.

B.  

It is a hub device. It can send ADVPN shortcut offers.

C.  

It is a hub device. It will automatically discover the spoke devices and add them to the SD-WAN topology.

D.  

It is a spoke device that establishes dynamic IPsec tunnels to the hub It can send ADVPN shortcut requests.

Discussion 0
Questions 7

(You want to configure two static routes: one that references an SD-WAN zone and a second one that references an SD-WAN member that belongs to that zone.

Which statement about this scenario is true? Choose one answer.)

Options:

A.  

You cannot create static routes for individual SD-WAN members.

B.  

You cannot create static routes that reference an SD-WAN zone.

C.  

The destination subnets must be different.

D.  

The source subnets must be different.

Discussion 0
Questions 8

Refer to the exhibits.

The first exhibit shows the SD-WAN zone HUB1 and SD-WAN member configuration from an SD-WAN template, and the second exhibit shows the output of command diagnose sys sdwan member collected on a FortiGate device.

Which statement best describes what the diagnose output shows?

Options:

A.  

The diagnose output shows that HUB1-VPN1 and all HUBx-VPNy members are dead.

B.  

The diagnose output does not correspond to a device configured with the SD-WAN template shown in the exhibit.

C.  

The diagnose output was collected on the device branch2_fgt.

D.  

The diagnose output was collected on the device branch1_fgt

Discussion 0
Questions 9

Refer to the exhibit.

You want to configure SD-WAN on a network as shown in the exhibit.

The network contains many FortiGate devices. Some are used as NGFW, and some are installed with extensions such as FortiSwitch. FortiAP. or Forti Ex tender.

What should you consider when planning your deployment?

Options:

A.  

You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with Forti Extender.

B.  

You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.

C.  

You must use FortiManager to manage your SD-WAN topology.

D.  

You must build multiple SD-WAN topologies. Each topology must contain only one type of extension.

Discussion 0
Questions 10

Which three characteristics apply to provisioning templates available on FortiManager? (Choose three.)

Options:

A.  

A template group can include a system template and an SD-WAN template.

B.  

Each template group can contain up to three IPsec tunnel templates.

C.  

CLI templates are applied in order, from top to bottom

D.  

A CLI template group can contain CLI templates of both types.

E.  

A CLI template can be of type CLI script or Perl script.

Discussion 0
Questions 11

Refer to the exhibit that shows a diagnose output on FortiGate.

Based on the output shown in the exhibit, what can you say about the device role and how it handles health checks?

Options:

A.  

The device is a spoke. It receives health-check measures for the tunnels of another spoke.

B.  

The device is a hub. It receives embedded health-check measures for each tunnel from the spoke.

C.  

The device is a spoke. It provides embedded health-check measures for each tunnel to the hub.

D.  

The device is a hub. It receives health-check measures for the tunnels of a spoke.

Discussion 0
Questions 12

As an MSSP administrator, you are asked to configure ADVPN on an existing SD-WAN topology. FortiManager manages the customer devices in a dedicated ADOM. The previous administrator used the SD-WAN overlay topology.

Which two statements apply to this scenario? (Choose two.)

Options:

A.  

You can activate auto-discovery VPN in the SD-WAN overlay template only if it is a single hub topology.

B.  

When auto-discovery VPN is enabled, FortiManager updates the IPsec and BGP templates in the hub.

C.  

After you enable auto-discovery VPN in the overlay template, you must select between ADVPN 2.0 and ADVPN 1.0.

D.  

You can activate auto-discovery VPN in the SD-WAN overlay template for any type of topology, including a primary-primary dual-hub topology.

Discussion 0
Questions 13

(In the context of SD-WAN, the terms underlay and overlay are commonly used to categorize links.

Which two statements about underlay and overlay links are correct? Choose two answers.)

Options:

A.  

A VLAN is a type of overlay link.

B.  

Overlay links provide routing flexibility.

C.  

FortiLink interface is considered an underlay link.

D.  

Wireless connections can be used to build overlay links.

E.  

Only wired connections can be used as underlay links.

Discussion 0
Questions 14

(As an IT manager, you want to delegate the installation and management of your SD-WAN deployment to a managed security service provider (MSSP). Each site must maintain direct internet access and be secure. You expect significant traffic flow between the sites and want to delegate as much of the network administration and management as possible to the MSSP.

Which two MSSP deployment blueprints address your requirements? Choose two answers.)

Options:

A.  

Use a shared hub on the MSSP premises and a dedicated hub on the customer premises, and install the spokes on the customer premises.

B.  

Install a dedicated hub on the MSSP premises for the customer, and install the spokes on the customer premises.

C.  

Install the hub and spokes on the customer premises, and enable the MSSP to manage the SD-WAN deployment using FortiManager with a dedicated ADOM.

D.  

Use a shared hub on the MSSP premises with a dedicated VDOM for the customer, and install the spokes on the customer premises.

Discussion 0
Questions 15

(Refer to the exhibit.

Which statement correctly describes the role of the ADVPN device in handling traffic? Choose one answer.)

Options:

A.  

This device is a spoke that has received a direct shortcut query from a remote spoke.

B.  

This device is a hub, and two spokes, 192.2.0.1 and 10.0.3.101, established a shortcut.

C.  

This device is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.

D.  

This device is a spoke that has received a shortcut query from a remote hub.

Discussion 0
Questions 16

(Refer to the exhibits.

The SD-WAN zones and members configuration of two branch devices are shown. The two branch devices are part of the same hub-and-spoke topology and connect to the same hub. The devices are configured to allow Auto-Discovery VPN (ADVPN). The configuration on the hub allows the initial communication between the two spokes.

When traffic flows require it, between which interfaces can the devices establish shortcuts? Choose one answer.)

Options:

A.  

Any interface in the overlay zones

B.  

Interface connected to HUB only

C.  

Between T3 on Branch-A and TC on Branch-B

D.  

Between T2 on Branch-A and TA on Branch-B

Discussion 0
Questions 17

You have a FortiGate configuration with three user-defined SD-WAN zones and two members in each of these zones. One SD-WAN member is no longer in use in health-check and SD-WAN rules. You want to delete it.

What happens if you delete the SD-WAN member from the FortiGate GUI?

Options:

A.  

FodiGate accepts the deletion and removes routes as required.

B.  

FortiGate displays an error message. You must use the CLI to delete an SD-WAN member.

C.  

FortiGate displays an error message. SD-WAN zones must contain at least two members

D.  

FortiGate accepts the deletion and places the member in the default SD-WAN zone.

Discussion 0
Questions 18

When you use the command diagnose sys session list, how do you identify the sessions that correspond to traffic steered according to SD-WAN rules?

Options:

A.  

You identify sessions steered according to SD-WAN rules with the flag vwl.

B.  

You cannot identify SD-WAN sessions. You must use the sdwar. session filter.

C.  

You identify sessions steered according to SD-WAN rules with the data vwl_mbr_seq.

D.  

You identify sessions steered according to SD-WAN rules with the data 3dwan_service_id.

Discussion 0
Questions 19

Refer to the exhibits.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in the first exhibit. After generating GoToMeeting test traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in the second exhibit.

The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.

Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)

Options:

A.  

Full SSL inspection is not enabled on the matching firewall policy.

B.  

The session 3-tuple did not match any of the existing entries in the ISDB application cache.

C.  

FortiGate could not refresh the routing information on the session after the application was detected.

D.  

No configured SD-WAN rule matches the traffic related to the collaboration application GoToMeeting

Discussion 0
Questions 20

Refer to the exhibit.

What conclusions can you draw about the traffic received by FortiGate originating from the source LAN device 10.0.1.133 and destined for the company’s SMTP mail server at 10.66.0.125?

Options:

A.  

FortiGate steers the traffic from the LAN device 10.0.1.133 to the company SMTP mail server 10.66 0.125 through port3.

B.  

ForliGate steers the traffic from the LAN device 10.0.1.133 to the company SMTP mail server 10.66.0.125 through port2.

C.  

FortiGate steers the traffic from the LAN device 10.0.1.133 to the company SMTP mail server 10.66.0.125 through the SD-WAN member ID 4.

D.  

FortiGate steers the traffic from the LAN device 10.0.1.133 to the SMTP mail server 10.66.0.125 through the SD-WAN member ID 1 or 2.

Discussion 0
Questions 21

(Refer to the exhibits. You collected the output shown in the exhibits and want to know which interface TCP traffic will flow through from the user device 10.0.1.101 to the corporate file server 10.0.0.125. All SD-WAN links are stable.

Which interface will FortiGate use to steer the traffic? Choose one answer.)

Options:

A.  

Only HUB1-VPN1

B.  

Either HUB1-VPN1 or HUB1-VPN2

C.  

Only HUB1-VPN2

D.  

Either HUB1-VPN1, HUB1-VPN2, or HUB1-VPN3

Discussion 0
Questions 22

(Refer to the exhibit.

You update the spokes configuration of an existing auto-discovery VPN (ADVPN) topology by adding the parameters shown in the exhibit.

Which is a valid objective of those settings? Choose one answer.)

Options:

A.  

Enable the tunnels as overlay links.

B.  

Convert the configuration from ADVPN to ADVPN 2.0.

C.  

Prevent cross-overlay shortcuts.

D.  

Prevent multiple shortcuts from being established over the same overlay.

Discussion 0
Questions 23

What are three key routing principles of SD-WAN? (Choose three.)

Options:

A.  

Directly connected routes have precedence over SD-WAN rules.

B.  

Policy routes have precedence over SD-WAN rules.

C.  

SD-WAN rules are skipped if the best route to the destination is a static route

D.  

SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.

E.  

SD-WAN members are skipped if they do not have a valid route to the destination.

Discussion 0
Questions 24

(Refer to the exhibit.

You configure SD-WAN on a standalone FortiGate device.

You want to create an SD-WAN rule that steers traffic related to Facebook and LinkedIn through the less costly internet link.

What must you do to set Facebook and LinkedIn applications as destinations from the GUI? Choose one answer.)

Options:

A.  

Enable the visibility of the applications field as destinations of the SD-WAN rule.

B.  

In the Internet service field, select Facebook and LinkedIn.

C.  

You cannot configure applications as destinations of an SD-WAN rule on a standalone FortiGate device.

D.  

Install a license to allow applications as destinations of SD-WAN rules.

Discussion 0
Questions 25

(You are using the FortiManager SD-WAN monitor menus to check the status of an SD-WAN topology. When you place the mouse next to branch1_fgt, you receive the output shown in the exhibit.

Which two conclusions can you draw from the output shown in the exhibit? Choose two answers.)

Options:

A.  

Three spokes have tunnels that are out of SL

A.  

B.  

The template Corp-SOT defines a dual-hub topology.

C.  

branch3_fgt is configured with three SD-WAN overlay tunnels and one is down.

D.  

branch1_fgt is configured with six SD-WAN overlay tunnels and three are down.

Discussion 0
Questions 26

(In which order does FortiGate consider the following elements during the route lookup process? Choose one answer.)

Options:

A.  

SD-WAN rules, ISDB routes, policy routes, BGP routes

B.  

Policy routes, SD-WAN rules, Internet Service Database (ISDB) routes, BGP routes

C.  

SD-WAN rules, policy routes, static routes, ISDB routes

D.  

Policy routes, ISDB routes, SD-WAN rules, static routes

Discussion 0
Questions 27

Refer to the exhibit.

Which two conclusions can you draw from the output shown? (Choose two.)

Options:

A.  

One SD-WAN rule is defined with application categories as the destination.

B.  

UDP traffic destined to the subnet 10.22.0.0/24 matches a manual SD-WAN rule.

C.  

One SD-WAN rule allows traffic load balancing.

D.  

UDP traffic destined to the subnet 10.22.0.0/24 matches a policy route.

Discussion 0
Questions 28

(Which two features must you configure before FortiGate can steer traffic according to SD-WAN rules? Choose two answers.)

Options:

A.  

Security profiles

B.  

Underlay links

C.  

Overlay links

D.  

Traffic shaping

E.  

Firewall policies

Discussion 0