Easter Sale Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Fortinet NSE 7 - SD-WAN 7.2 Question and Answers

Fortinet NSE 7 - SD-WAN 7.2

Last Update May 20, 2024
Total Questions : 81

We are offering FREE NSE7_SDW-7.2 Fortinet exam questions. All you do is to just go and sign up. Give your details, prepare NSE7_SDW-7.2 free exam questions and then go for complete pool of Fortinet NSE 7 - SD-WAN 7.2 test questions that will help you more.

NSE7_SDW-7.2 pdf

NSE7_SDW-7.2 PDF

$35  $99.99
NSE7_SDW-7.2 Engine

NSE7_SDW-7.2 Testing Engine

$42  $119.99
NSE7_SDW-7.2 PDF + Engine

NSE7_SDW-7.2 PDF + Testing Engine

$56  $159.99
Questions 1

What are two benefits of using forward error correction (FEC) in IPsec VPNs? (Choose two.)

Options:

A.  

FEC supports hardware offloading.

B.  

FEC improves reliability of noisy links.

C.  

FEC transmits parity packets that can be used to reconstruct packet loss.

D.  

FEC can leverage multiple IPsec tunnels for parity packets transmission.

Discussion 0
Questions 2

Which two statements about the SD-WAN zone configuration are true? (Choose two.)

Options:

A.  

The service-sla-tie-break setting enables you to configure preferred member selection based on the best route to the destination.

B.  

You can delete the default zones.

C.  

The default zones are virtual-wan-link and SASE.

D.  

An SD-WAN member can belong to two or more zones.

Discussion 0
Questions 3

Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.

Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

Options:

A.  

The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.

B.  

T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.

C.  

T_INET_0_0 does not have a valid route to the destination.

D.  

T_INET_1_0 has a higher member configuration priority than T_INET_0_0.

Discussion 0
Questions 4

Which two interfaces are considered overlay links? (Choose two.)

Options:

A.  

LAG

B.  

IPsec

C.  

Physical

D.  

GRE

Discussion 0
Questions 5

What are two reasons for using FortiManager to organize and manage the network for a group of FortiGate devices?  (Choose two.)

Options:

A.  

It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.

B.  

It improves SD-WAN performance on the managed FortiGate devices.

C.  

It sends probe signals as health checks to the beacon servers on behalf of FortiGate.

D.  

It acts as a policy compliance entity to review all managed FortiGate devices.

E.  

It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.

Discussion 0
Questions 6

Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured packet loss will make T_INET_1_0 the new preferred member?

Options:

A.  

When all three members have the same packet loss.

B.  

When T_INET_0_0 has 4% packet loss.

C.  

When T_INET_0_0 has 12% packet loss.

D.  

When T_INET_1_0 has 4% packet loss.

Discussion 0
Questions 7

Refer to the exhibits.

Exhibit A shows the packet duplication rule configuration, the SD-WAN zone status output, and the sniffer output on FortiGate acting as the sender. Exhibit B shows the sniffer output on a FortiGate acting as the receiver.

The administrator configured packet duplication on both FortiGate devices. The sniffer output on the sender FortiGate shows that FortiGate forwards an ICMP echo request packet over three overlays, but it only receives one reply packet through T_INET_1_0.

Based on the output shown in the exhibits, which two reasons can cause the observed behavior? (Choose two.)

Options:

A.  

On the receiver FortiGate, packet-de-duplication is enabled.

B.  

The ICMP echo request packets sent over T_INET_0_0 and T_MPLS_0 were dropped along the way.

C.  

The ICMP echo request packets received over T_INET_0_0 and T_MPLS_0 were offloaded to NPU.

D.  

On the sender FortiGate, duplication-max-num is set to 3.

Discussion 0
Questions 8

Which diagnostic command can you use to show the configured SD-WAN zones and their assigned members?

Options:

A.  

diagnose sys sdwan zone

B.  

diagnose sys sdwan service

C.  

diagnose sys sdwan member

D.  

diagnose sys sdwan interface

Discussion 0
Questions 9

Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

Options:

A.  

When T_INET_0_0 and T_MPLS_0 have the same latency.

B.  

When T_MPLS_0 has a latency of 100 ms.

C.  

When T_INET_0_0 has a latency of 250 ms.

D.  

When T_N1PLS_0 has a latency of 80 ms.

Discussion 0
Questions 10

Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when performing IKE negotiation? (Choose two )

Options:

A.  

A peer ID is included in the first packet from the initiator, along with suggested security policies.

B.  

XAuth is enabled as an additional level of authentication, which requires a username and password.

C.  

A total of six packets are exchanged between an initiator and a responder instead of three packets.

D.  

The use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.

Discussion 0
Questions 11

What three characteristics apply to provisioning templates available on FortiManager? (Choose three.)

Options:

A.  

You can apply a system template and a CLI template to the same FortiGate device.

B.  

A CLI template can be of type CLI script or Perl script.

C.  

A template group can include a system template and an SD-WAN template.

D.  

A template group can contain CLI templates of both types.

E.  

Templates are applied in order, from top to bottom.

Discussion 0
Questions 12

What are two reasons why FortiGate would be unable to complete the zero-touch provisioning process? (Choose two.)

Options:

A.  

The FortiGate cloud key has not been added to the FortiGate cloud portal.

B.  

FortiDeploy has connected with FortiGate and provided the initial configuration to contact FortiManager

C.  

The zero-touch provisioning process has completed internally, behind FortiGate.

D.  

FortiGate has obtained a configuration from the platform template in FortiGate cloud.

E.  

A factory reset performed on FortiGate.

Discussion 0
Questions 13

Which two performance SLA protocols enable you to verify that the server response contains a specific value? (Choose two.)

Options:

A.  

http

B.  

icmp

C.  

twamp

D.  

dns

Discussion 0
Questions 14

Exhibit.

Which conclusion about the packet debug flow output is correct?

Options:

A.  

The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.

B.  

The packet size exceeded the outgoing interface MTU.

C.  

The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.

D.  

The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.

Discussion 0
Questions 15

Exhibit.

The exhibit shows the output of the command diagnose sys sdwan health-check status collected on a FortiGate device. Which two statements are correct about the health check status on this FortiGate device? (Choose two.)

Options:

A.  

The health-check VPN_PING orders the members according to the lowest jitter.

B.  

The interface T_INET_1 missed one SLA target.

C.  

There is no SLA criteria configured for the health-check Level3_DNS.

D.  

The interface T_INET_0 missed three SLA targets.

Discussion 0
Questions 16

Refer to the exhibits.

Exhibit A

Exhibit B

Exhibit A shows an SD-WAN event log and exhibit B shows the member status and the SD-WAN rule configuration.

Based on the exhibits, which two statements are correct? (Choose two.)

Options:

A.  

FortiGate updated the outgoing interface list on the rule so it prefers port2.

B.  

Port2 has the highest member priority.

C.  

Port2 has a lower latency than port1.

D.  

SD-WAN rule ID 1 is set to lowest cost (SLA) mode.

Discussion 0
Questions 17

What are two advantages of using an IPsec recommended template to configure an IPsec tunnel in a hub-and-spoke topology? (Choose two.)

Options:

A.  

VPN monitor tool provides additional statistics for tunnels defined with an IPsec recommended template.

B.  

FortiManager automatically installs IPsec tunnels to every spoke when they are added to the FortiManager ADOM.

C.  

IPsec recommended template guides the administrator to use Fortinet recommended settings.

D.  

IPsec recommended template ensures consistent settings between phase1 and phase2

Discussion 0
Questions 18

Refer to the exhibit.

Which statement about the role of the ADVPN device in handling traffic is true?

Options:

A.  

This is a spoke that has received a query from a remote hub and has forwarded the response to its hub.

B.  

Two hubs, 10.0.1.101 and 10.0.2.101, are receiving and forwarding queries between each other.

C.  

This is a hub that has received a query from a spoke and has forwarded it to another spoke.

D.  

Two spokes, 192.2.0.1 and 10.0.2.101, forward their queries to their hubs.

Discussion 0
Questions 19

Refer to the exhibit.

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate appliance that supports hardware offloading. Based on the information shown in the exhibits, which two statements about the session are true? (Choose two.)

Options:

A.  

The reply direction of the asymmetric traffic flows from port2 to port3.

B.  

The auxiliary session can be offloaded to hardware.

C.  

The original direction of the symmetric traffic flows from port3 to port2.

D.  

The main session cannot be offloaded to hardware.

Discussion 0
Questions 20

Refer to the exhibit.

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.

Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)

Options:

A.  

Set additional-path to send

B.  

Enable route-reflector-client

C.  

Set advertisement-interval to the number of additional paths to advertise

D.  

Set adv-additional-path to the number of additional paths to advertise

E.  

Enable soft-reconfiguration

Discussion 0
Questions 21

Which are two benefits of using CLI templates in FortiManager? (Choose two.)

Options:

A.  

You can reference meta fields.

B.  

You can configure interfaces as SD-WAN members without having to remove references first.

C.  

You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.

D.  

You can configure advanced CLI settings.

Discussion 0
Questions 22

Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on traffic passing through port2? (Choose two.)

Options:

A.  

FortiGate does not change the routing information on existing sessions that use a valid gateway, after a route change.

B.  

FortiGate performs routing lookups for new sessions only, after a route change.

C.  

FortiGate always blocks all traffic, after a route change.

D.  

FortiGate flushes all routing information from the session table, after a route change.

Discussion 0
Questions 23

Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.

Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

Options:

A.  

Specify a unique peer ID for each dial-up VPN interface.

B.  

Use different proposals are used between the interfaces.

C.  

Configure the IKE mode to be aggressive mode.

D.  

Use unique Diffie Hellman groups on each VPN interface.

Discussion 0
Questions 24

Refer to the exhibits.

Exhibit A -

Exhibit B -

Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.

The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator determines that FortiGate does not apply traffic shaping on YouTube traffic.

Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs traffic shaping on YouTube traffic?

Options:

A.  

Destination internet service must be enabled on the traffic shaping policy.

B.  

Application control must be enabled on the firewall policy.

C.  

Web filtering must be enabled on the firewall policy.

D.  

Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.

Discussion 0