Pass the Fortinet Fortinet Certified Solution Specialist FCSS_SDW_AR-7.4 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibits.

You use FortiManager to configure SD-WAN on three branch devices.

Question # 1

Question # 1

Question # 1

When you install the device settings, FortiManager prompts you with the error “Copy Failed” for the device branch1_fgt. When you click the log button, FortiManager displays the message shown in the exhibit.

There are two different ways to resolve this issue. Based on the exhibits, which methods could you use? (Choose two.)

Options:

A.

Update the management IP address of branch1_fgt.


B.

Specify the gateway of the SD-WAN member port1 with an IP address or use the default value.


C.

Do not define installation targets for SD-WAN members.


D.

Review the per-device mapping configuration for metadata variables


Expert Solution
Questions # 2:

Refer to the exhibit.

Question # 2

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate device that supports hardware offloading.

Based on the information shown in the exhibits, which two conclusions can you draw? (Choose two.)

Options:

A.

By default, FortiGate offloads symmetric and asymmetric flows.


B.

The original direction of the symmetric traffic flows from port3 to port2.


C.

The reply direction of the asymmetric traffic flows from port2 to port3.


D.

The auxiliary session can be offloaded to hardware.


Expert Solution
Questions # 3:

Refer to the exhibits.

Question # 3

You use FortiManager to configure SD-WAN on three branch devices.

When you install the device settings. FortiManager prompts you with the error "Copy Failed" for the device branch1_fat When you click the log button. FortiManager displays the message shown in the exhibit.

Options:

A.

Based on the exhibits, which statement best describes the issue and how you can resolve it?


B.

Remove the installation target for the SD-WAN member port4. You cannot combine metadata variable and installation targets.


C.

Gateways for all members in a zone must be defined the same way. Specify the gateway of the SD-WAN member port! without metadata variables.


D.

Check the metadata variable definitions, and review the per-device mapping configuration.


E.

Check the connection between branch1_fgt and FortiManager


Expert Solution
Questions # 4:

SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.

Which three configuration elements that you must configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)

Options:

A.

Firewall policies


B.

Interfaces


C.

Security profiles


D.

Traffic shaping


E.

Routing


Expert Solution
Questions # 5:

Which three characteristics apply to provisioning templates available on FortiManager? (Choose three.)

Options:

A.

A template group can include a system template and an SD-WAN template.


B.

Each template group can contain up to three IPsec tunnel templates.


C.

CLI templates are applied in order, from top to bottom


D.

A CLI template group can contain CLI templates of both types.


E.

A CLI template can be of type CLI script or Perl script.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

The exhibit shows the health-check configuration on a FortiGate device used as a spoke. You notice that the hub FortiGate doesn’t prioritize the traffic as expected.

Which two configuration elements should you check on the hub? (Choose two.)

Options:

A.

The performance SLA has the parameter priority-out-sla configured.


B.

This performance SLA uses the same members.


C.

The performance SLA uses the same criteria.


D.

The performance SLA is configured with set embedded-measure accept.


Expert Solution
Questions # 7:

An administrator is configuring SD-WAN to load balance their network traffic. Which two things should they consider when setting up SD-WAN? (Choose two.)

Options:

A.

You can select the outbandwidth hash mode with all strategies that allow load balancing.


B.

Only the manual and best-quality strategies allow SD-WAN load balancing.


C.

When applicable. FortiGate load balances the traffic through all members that meet the SLA target.


D.

SD-WAN load balancing is possible only using the best quality and lowest cost (SLA) strategies.


Expert Solution
Questions # 8:

Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two.)

Options:

A.

The session information output displays no SD-WAN service id.


B.

Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.


C.

The traffic is distributed, regardless of weight, through all available static routes.


D.

Traffic does not match any of the entries in the policy route table.


E.

FortiGate flags the session with may_dirty and vwl_def ault.


Expert Solution
Questions # 9:

Exhibit.

Question # 9

Which action will FortiGate take if it detects SD-WAN members as dead?

Options:

A.

FoftiGate bounces port5 after it detects all SD-WAN members as dead.


B.

FortiGate fails over to the secondary device after it detects port5 as dead.


C.

FortiGate sends alert messages through poft5 when it detects all SD-WAN members as dead


D.

FortiGate brings down port5 after it detects all SD-WAN members as dead.


Expert Solution
Questions # 10:

Refer to the exhibit.

Question # 10

Which SD-WAN rule and interface uses FortiGate to steer the traffic from the LAN subnet 10.0.1.0/24 to the corporate server 10.2.5.254?

Options:

A.

SD-WAN service rule 3 and interface HUB1-VPN2.


B.

SD-WAN service rule 3 and interface HUB1-VPN3.


C.

SD-WAN service rule 4 and port1 or port2.


D.

SD-WAN service rule 4 and interface port2.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions