Pass the Fortinet Fortinet Certified Solution Specialist FCSS_SDW_AR-7.4 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

When you use the command diagnose sys session list, how do you identify the sessions that correspond to traffic steered according to SD-WAN rules?

Options:

A.

You identify sessions steered according to SD-WAN rules with the flag vwl.


B.

You cannot identify SD-WAN sessions. You must use the sdwar. session filter.


C.

You identify sessions steered according to SD-WAN rules with the data vwl_mbr_seq.


D.

You identify sessions steered according to SD-WAN rules with the data 3dwan_service_id.


Expert Solution
Questions # 2:

Refer to the exhibit.

Question # 2

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network.

The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3.

Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)

Options:

A.

HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.


B.

The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device


C.

HUB1-VPN1 does not have a valid route to the destination


D.

HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.


Expert Solution
Questions # 3:

You have a FortiGate configuration with three user-defined SD-WAN zones and two members in each of these zones. One SD-WAN member is no longer in use in health-check and SD-WAN rules. You want to delete it.

What happens if you delete the SD-WAN member from the FortiGate GUI?

Options:

A.

FodiGate accepts the deletion and removes routes as required.


B.

FortiGate displays an error message. You must use the CLI to delete an SD-WAN member.


C.

FortiGate displays an error message. SD-WAN zones must contain at least two members


D.

FortiGate accepts the deletion and places the member in the default SD-WAN zone.


Expert Solution
Questions # 4:

An administrator is configuring SD-WAN to load balance their network traffic. Which two things should they consider when setting up SD-WAN? (Choose two.)

Options:

A.

You can select the outbandwidth hash mode with all strategies that allow load balancing.


B.

Only the manual and best-quality strategies allow SD-WAN load balancing.


C.

When applicable. FortiGate load balances the traffic through all members that meet the SLA target.


D.

SD-WAN load balancing is possible only using the best quality and lowest cost (SLA) strategies.


Expert Solution
Questions # 5:

Exhibit.

Question # 5

Which action will FortiGate take if it detects SD-WAN members as dead?

Options:

A.

FoftiGate bounces port5 after it detects all SD-WAN members as dead.


B.

FortiGate fails over to the secondary device after it detects port5 as dead.


C.

FortiGate sends alert messages through poft5 when it detects all SD-WAN members as dead


D.

FortiGate brings down port5 after it detects all SD-WAN members as dead.


Expert Solution
Questions # 6:

You are planning a large SD-WAN deployment with approximately 1000 spokes and want to allow ADVPN between the spokes. Some remote sites use FortiSASE to connect to the company's SD-WAN hub. Which overlay routing configuration should you use?

Options:

A.

BGP on loopback with dynamic BGP for ADVPN shortcut routing.


B.

BGP on loopback with IPsec phase2 selectors for ADVPN shortcut routing.


C.

BGP per overlay with dynamic BGP for ADVPN shortcut routing.


D.

BGP per overlay with BGP next-hop convergence for ADVPN shortcut routing.


Expert Solution
Questions # 7:

Exhibit.

Question # 7

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member?

Options:

A.

When HUB1-VPN1 has 4% packet loss


B.

When HUB1-VPN1 has 12% packet loss


C.

When HUB1-VPN3 has 4% packet loss


D.

When all three members have the same packet loss


Expert Solution
Questions # 8:

You manage an SD-WAN topology. You will soon deploy 50 new branches.

Which three tasks can you do in advance to simplify this deployment? (Choose three.)

Options:

A.

Update the DHCP server configuration.


B.

Create model devices.


C.

Create a ZTP template.


D.

Define metadata variables value for each device.


E.

Create policy blueprint.


Expert Solution
Questions # 9:

The SD-WAN overlay template helps to prepare SD-WAN deployments. To complete the tasks performed by the SD-WAN overlay template, the administrator must perform some post-run tasks. What are two mandatory post-run tasks that must be performed? (Choose two.)

Options:

A.

Configure routing through the overlay tunnels created by the SD-WAN overlay template.


B.

Create policy packages andassign them to the branch devices.


C.

Assign a hub id metadata variable to each hub device.


D.

Configure SD-WAN rules


E.

Assign ansdwan_id metadata variable to each device (branch and hub)


Expert Solution
Questions # 10:

Question # 10

Refer to the exhibit that shows event logs on FortiGate.

Based on the output shown in the exhibit, what can you say about the tunnels on this device?

Options:

A.

The master tunnel HU82-VPN3 cannot accept ADVPN shortcuts.


B.

The device steers voice traffic through the VPN tunnel HUB1-VPN3.


C.

The VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.


D.

There is one shortcut tunnel built from master tunnel VPN4.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions