Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Fortinet NSE 7 - SD-WAN 7.2 Question and Answers

Fortinet NSE 7 - SD-WAN 7.2

Last Update Oct 4, 2025
Total Questions : 99

We are offering FREE NSE7_SDW-7.2 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE7_SDW-7.2 free exam questions and then go for complete pool of Fortinet NSE 7 - SD-WAN 7.2 test questions that will help you more.

NSE7_SDW-7.2 pdf

NSE7_SDW-7.2 PDF

$36.75  $104.99
NSE7_SDW-7.2 Engine

NSE7_SDW-7.2 Testing Engine

$43.75  $124.99
NSE7_SDW-7.2 PDF + Engine

NSE7_SDW-7.2 PDF + Testing Engine

$57.75  $164.99
Questions 1

Which two statements describe how IPsec phase 1 main mode id different from aggressive mode when performing IKE negotiation? (Choose two.)

Options:

A.  

A peer ID is included in the first packet from the initiator, along with suggested security policies.

B.  

XAuth is enabled as an additional level of authentication, which requires a username and password.

C.  

Three packets are exchanged between an initiator and a responder instead of six packets.

D.  

The use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.

Discussion 0
Questions 2

Refer to the exhibit.

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.

Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)

Options:

A.  

Setadditional-pathtosend

B.  

Enableroute-reflector-client

C.  

Setadvertisement-intervalto the number of additional paths to advertise

D.  

Setadv-additional-pathto the number of additional paths to advertise

E.  

Enablesoft-reconfiguration

Discussion 0
Questions 3

What are two benefits of using the Internet service database (ISDB) in an SD-WAN rule? (Choose two.)

Options:

A.  

The ISDB is dynamically updated and reduces administrative overhead.

B.  

The ISDB requires application control to maintain signatures and perform load balancing.

C.  

The ISDB applies rules to traffic from specific sources, based on application type.

D.  

The ISDB contains the IP addresses and port ranges of well-known internet services.

Discussion 0
Questions 4

Exhibit A shows the firewall policy and exhibit B shows the traffic shaping policy.

The traffic shaping policy is being applied to all outbound traffic; however, inbound traffic is not being evaluated by the shaping policy.

Based on the exhibits, what configuration change must be made in which policy so that traffic shaping can be applied to inbound traffic?

Options:

A.  

Create a new firewall policy, and the select the SD-WAN zone as Incoming Interface.

B.  

In the traffic shaping policy, select Assign Shaping Class ID as Action.

C.  

In the firewall policy, select Proxy-based as Inspection Mode.

D.  

In the traffic shaping policy, enable Reverse shaper, and then select the traffic shaper to use.

Discussion 0
Questions 5

Which two conclusions for traffic that matches the traffic shaper are true? (Choose two.)

Options:

A.  

The traffic shaper drops packets if the bandwidth is less than 2500 KBps.

B.  

The measured bandwidth is less than 100 KBps.

C.  

The traffic shaper drops packets if the bandwidth exceeds 6250 KBps.

D.  

The traffic shaper limits the bandwidth of each source IP to a maximum of 6250 KBps.

Discussion 0
Questions 6

What are two benefits of using forward error correction (FEC) in IPsec VPNs? (Choose two.)

Options:

A.  

FEC supports hardware offloading.

B.  

FEC improves reliability of noisy links.

C.  

FEC transmits parity packets that can be used to reconstruct packet loss.

D.  

FEC can leverage multiple IPsec tunnels for parity packets transmission.

Discussion 0
Questions 7

Refer to the exhibits.

Exhibit A shows the SD-WAN rule status and the learned BGP routes with community 65000:10.

Exhibit B shows the SD-WAN rule configuration, the BGP neighbor configuration, and the route map configuration.

The administrator wants to steer corporate traffic using routes tags in the SD-WAN rule ID 1.

However, the administrator observes that the corporate traffic does not match the SD-WAN rule ID 1.

Based on the exhibits, which configuration change is required to fix issue?

Options:

A.  

In the dc1-lan-rm route map configuration, set set-route-tag to 10.

B.  

In SD-WAN rule ID 1, change the destination to use ISDB entries.

C.  

In the dc1-lan-rm route map configuration, unset match-community.

D.  

In the BGP neighbor configuration, apply the route map dc1-lan-rm in the outbound direction.

Discussion 0
Questions 8

Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI.

Based on the exhibit, which statement is true?

Options:

A.  

You can delete the virtual-wan-link zone because it contains no member.

B.  

The corporate zone contains no member.

C.  

You can move port1 from the underlay zone to the overlay zone.

D.  

The overlay zone contains four members.

Discussion 0
Questions 9

Exhibit B –

Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.

Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?

Options:

A.  

port1 is assigned a manual IP address.

B.  

port1 is referenced in a firewall policy.

C.  

port2 is referenced in a static route.

D.  

port1 and port2 are not administratively down.

Discussion 0
Questions 10

Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change? (Choose two.)

Options:

A.  

FortiGate flushes all sessions.

B.  

FortiGate terminates the old sessions.

C.  

FortiGate does not change existing sessions.

D.  

FortiGate evaluates new sessions.

Discussion 0
Questions 11

Which statement is correct about SD-WAN and ADVPN?

Options:

A.  

Routes for ADVPN shortcuts must be manually configured.

B.  

SD-WAN can steer traffic to ADVPN shortcuts, established over IPsec overlays, configured as SD-WAN members.

C.  

SD-WAN does not monitor the health and performance of ADVPN shortcuts.

D.  

You must use IKEv2 on IPsec tunnels.

Discussion 0
Questions 12

Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?

Options:

A.  

Interface-based shaping mode

B.  

Reverse-policy shaping mode

C.  

Shared-policy shaping mode

D.  

Per-IP shaping mode

Discussion 0
Questions 13

Refer to the exhibit.

Based on the exhibit, which statement about FortiGate re-evaluating traffic is true?

Options:

A.  

The type of traffic defined and allowed on firewall policy ID 1 is UDP.

B.  

FortiGate has terminated the session after a change on policy ID 1.

C.  

Changes have been made on firewall policy ID 1 on FortiGate.

D.  

Firewall policy ID 1 has source NAT disabled.

Discussion 0
Questions 14

Which SD-WAN setting enables FortiGate to delay the recovery of ADVPN shortcuts?

Options:

A.  

hold-down-time

B.  

link-down-failover

C.  

auto-discovery-shortcuts

D.  

idle-timeout

Discussion 0
Questions 15

Refer to the exhibit.

Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)

Options:

A.  

FortiGate does not install IPsec static routes for remote protected networks in the routing table.

B.  

The phase 1 configuration supports the network-overlay setting.

C.  

FortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.

D.  

Dead peer detection is disabled.

Discussion 0
Questions 16

Refer to the exhibits.

Exhibit A -

Exhibit B -

Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.

The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator determines that FortiGate does not apply traffic shaping on YouTube traffic.

Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs traffic shaping on YouTube traffic?

Options:

A.  

Destination internet service must be enabled on the traffic shaping policy.

B.  

Application control must be enabled on the firewall policy.

C.  

Web filtering must be enabled on the firewall policy.

D.  

Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.

Discussion 0
Questions 17

What does enabling theexchange-interface-ipsetting enable FortiGate devices to exchange?

Options:

A.  

The gateway address of their IPsec interfaces

B.  

The tunnel ID of their IPsec interfaces

C.  

The IP address of their IPsec interfaces

D.  

The name of their IPsec interfaces

Discussion 0
Questions 18

Refer to the Exhibits:

Exhibit A, which shows the SD-WAN performance SLA and exhibit B shows the health of the participating SD-WAN members.

Based on the exhibits, which statement is correct?

Options:

A.  

The dead member interface stays unavailable until an administrator manually brings the interface back.

B.  

Port2 needs to wait 500 milliseconds to change the status from alive to dead.

C.  

Static routes using port2 are active in the routing table.

D.  

FortiGate has not received three consecutive requests from the SLA server configured for port2.

Discussion 0
Questions 19

Refer to the exhibit.

The exhibit shows output of the command diagnose 3vg sdwan service collected on a FortiGate device.

The administrator wants to know through which interface FortiGate will steer the traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the business application Salesforce located on HO servers 10.0.0.1.

Based on the exhibits, which two statements are correct? (Choose two.)

Options:

A.  

When FortiGate cannot recognize the application of the flow it steers the traffic destined to server 10.0.0.1 according to service rule 3.

B.  

FortiGate steers traffic to HO servers according to service rule 1 and it uses port1 or port2 because both interfaces are selected.

C.  

There is no service defined for the Salesforce application, so FortiGate will use the service rule 3 and steer the traffic through interface T_HQ1.

D.  

FortiGate steers traffic for business application according to service rule 2 and steers traffic through port2.

Discussion 0
Questions 20

The administrator uses the FortiManager SD-WAN overlay template to prepare an SD-WAN deployment. With information provided through the SD-WAN overlay template wizard, FortiManager creates templates ready to install on spoke and hub devices.

Select three templates created by the SD-WAN overlay template for a spoke device. (Choose three.)

Options:

A.  

System template

B.  

BGP template

C.  

IPsec tunnel template

D.  

CLI template

E.  

Overlay template

Discussion 0
Questions 21

Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.

Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

Options:

A.  

Specify a unique peer ID for each dial-up VPN interface.

B.  

Use different proposals are used between the interfaces.

C.  

Configure the IKE mode to be aggressive mode.

D.  

Use unique Diffie Hellman groups on each VPN interface.

Discussion 0
Questions 22

Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on traffic passing through port2? (Choose two.)

Options:

A.  

FortiGate does not change the routing information on existing sessions that use a valid gateway, after a route change.

B.  

FortiGate performs routing lookups for new sessions only, after a route change.

C.  

FortiGate always blocks all traffic, after a route change.

D.  

FortiGate flushes all routing information from the session table, after a route change.

Discussion 0
Questions 23

Refer to the exhibit.

Which are two expected behaviors of the traffic that matches the traffic shaper? (Choose two.)

Options:

A.  

The number of simultaneous connections among all source IP addresses cannot exceed five connections.

B.  

The traffic shaper limits the combined bandwidth of all connections to a maximum of 5 MB/sec.

C.  

The number of simultaneous connections allowed for each source IP address cannot exceed five connections.

D.  

The traffic shaper limits the bandwidth of each source IP address to a maximum of 625 KB/sec.

Discussion 0
Questions 24

Refer to the exhibits.

Exhibit A shows a policy package definition Exhibit B shows the install log that the administrator received when he tried to install the policy package on FortiGate devices.

Based on the output shown in the exhibits, what can the administrator do to solve the Issue?

Options:

A.  

Create dynamic mapping for the LAN interface for all devices in the installation target list.

B.  

Use a metadata variable instead of a dynamic interface to define the firewall policy.

C.  

Dynamic mapping should be done automatically. Review the LAN interface configuration for branch2_fgt.

D.  

Policies can refer to only one LAN source interface. Keep only the D-LAN, which is the dynamic LAN interface.

Discussion 0
Questions 25

Which diagnostic command can you use to show the configured SD-WAN zones and their assigned members?

Options:

A.  

diagnose sys sdwan zone

B.  

diagnose sys sdwan service

C.  

diagnose sys sdwan member

D.  

diagnose sys sdwan interface

Discussion 0
Questions 26

Refer to the exhibits.

Exhibit A shows two IPsec templates to define Branch_IPsec_1 and Branch_IPsec_2. Each template defines a VPN tunnel.

Exhibit B shows the error message that FortiManager displayed when the administrator tried to assign the second template to the FortiGate device.

Which statement best explain the cause for this issue?

Options:

A.  

You can assign only one template with a tunnel of fype static to each FortiGate device

B.  

You can define only one IPsec tunnel from branch devices to HUB1.

C.  

You can assign only one IPsec template to each FortiGate device.

D.  

You should review the branch1_fgt configuration for the already configured tunnel with the name HUB1-VPN2.

Discussion 0
Questions 27

Refer to the exhibits.

Exhibit A

Exhibit B

Exhibit A shows an SD-WAN event log and exhibit B shows the member status and the SD-WAN rule configuration.

Based on the exhibits, which two statements are correct? (Choose two.)

Options:

A.  

FortiGate updated the outgoing interface list on the rule so it prefers port2.

B.  

Port2 has the highest member priority.

C.  

Port2 has a lower latency than port1.

D.  

SD-WAN rule ID 1 is set to lowest cost (SLA) mode.

Discussion 0
Questions 28

Refer to the exhibits.

Exhibit A -

Exhibit B -

Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.

When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferred member in the matching SD-WAN rule.

Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?

Options:

A.  

Enable auxiliary-session under config system settings.

B.  

Disable tсp-session-without-syn under config system settings.

C.  

Enable snat-route-change under config system global.

D.  

Disable allow-subnet-overlap under config system settings.

Discussion 0
Questions 29

Refer to the exhibit.

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

Options:

A.  

type must be set to static.

B.  

mode-cfg must be enabled.

C.  

exchange-interface-ip must be enabled.

D.  

add-route must be disabled.

Discussion 0