Pass the Fortinet Fortinet Certified Solution Specialist FCSS_SDW_AR-7.4 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit.

Question # 11

Which statement best describe the role of the ADVPN device in handling traffic?

Options:

A.

This is a hub that has received a query from a spoke and has forwarded it to another spoke.


B.

This is a hub in a dual-region topology. The remote hub tunnel ID is 10.0.2.101.


C.

This is a spoke that has received a shortcut query from another spoke and has forwarded the response to its hub.


D.

This is a spoke. The kernel received a shortcut request and forwards the query to another spoke.


Expert Solution
Questions # 12:

Refer to the exhibit.

Question # 12

The administrator configured the SD-WAN rule ID 4 with two members (port1 and port2) and strategy lowest cost (SLA).

What are the two characteristics of the session shown in the exhibit? (Choose two.)

Options:

A.

FortiGate steered this flow according to an SD-WAN rule.


B.

FortiGate will never re-evaluate this session.


C.

FortiGate steered this flow according to the application detected and the outgoing interface is port3.


D.

FortiGate will re-evaluate this session if the outgoing interface goes down.


Expert Solution
Questions # 13:

Refer to the exhibit.

Question # 13

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network.

The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3.

Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)

Options:

A.

HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.


B.

The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device


C.

HUB1-VPN1 does not have a valid route to the destination


D.

HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.


Expert Solution
Questions # 14:

Refer to the exhibits.

Question # 14

You use FortiManager to manage the branch devices and configure the SD-WAN template. You have configured direct internet access (DIA) for the IT department users. Now. you must configure secure internet access (SIA) for all local LAN users and have set the firewall policies as shown in the second exhibit.

Then, when you use the install wizard to install the configuration and the policy package on the branch devices, FortiManager reports an error as shown in the third exhibit.

Which statement describes why FortiManager could not install the configuration on the branches?

Options:

A.

You must direct SIA traffic to a VPN tunnel.


B.

You cannot install firewall policies that reference an SD-WAN zone.


C.

You cannot install firewall policies that reference an SD-WAN member.


D.

You cannot install SIA and DIA rules on the same device.


Expert Solution
Questions # 15:

Exhibit.

Question # 15

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured packet loss will make HUB1-VPN3 the new preferred member?

Options:

A.

When HUB1-VPN1 has 4% packet loss


B.

When HUB1-VPN1 has 12% packet loss


C.

When HUB1-VPN3 has 4% packet loss


D.

When all three members have the same packet loss


Expert Solution
Questions # 16:

Exhibit.

Question # 16

For your ZTP deployment, you review the CSV file shown in exhibit and note that it is missing important information. Which two elements must you change before you can import it into FortiManager? (Choose two.)

Options:

A.

You must associate a device blueprint with each device


B.

You must define a name for each device


C.

You must define a value for each device and each metadata variable that defines an IP address.


D.

You must define a value for each device and each user-defined metadata variable.


Expert Solution
Questions # 17:

You are planning a large SD-WAN deployment with approximately 1000 spokes and want to allow ADVPN between the spokes. Some remote sites use FortiSASE to connect to the company's SD-WAN hub. Which overlay routing configuration should you use?

Options:

A.

BGP on loopback with dynamic BGP for ADVPN shortcut routing.


B.

BGP on loopback with IPsec phase2 selectors for ADVPN shortcut routing.


C.

BGP per overlay with dynamic BGP for ADVPN shortcut routing.


D.

BGP per overlay with BGP next-hop convergence for ADVPN shortcut routing.


Expert Solution
Questions # 18:

Refer to the exhibit.

Question # 18

The exhibit shows output of the command diagnose sys adwan aervice4 collected on a FortiGate device.

The administrator wants to know through which interface FortiGate will steer traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the social media application Facebook.

Based on the exhibits, which two statements are correct? (Choose two.)

Options:

A.

When FortiGate cannot recognize the application of the flow, it steers the traffic through the preferred member of rule 3, HQ_T1.


B.

There is no service defined for the Facebook application, so FortiGate appliesservice rule 3 and directs the traffic to headquarters.


C.

FortiGate steers traffic for social media applications according to the service rule 2 and steers traffic through port2.


D.

When FortiGate cannot recognize the application of the flow, it load balances the traffic through the tunnels HQ_T1. HQ_T2. HQ_T3.


Expert Solution
Questions # 19:

Refer to the exhibit that shows a diagnose output on FortiGate.

Question # 19

Based on the output shown in the exhibit, what can you say about the device role and how it handles health checks?

Options:

A.

The device is a spoke. It receives health-check measures for the tunnels of another spoke.


B.

The device is a hub. It receives embedded health-check measures for each tunnel from the spoke.


C.

The device is a spoke. It provides embedded health-check measures for each tunnel to the hub.


D.

The device is a hub. It receives health-check measures for the tunnels of a spoke.


Expert Solution
Questions # 20:

An SD-WAN member is no longer used to steer SD-WAN traffic. The administrator updated the SD-WAN configuration and deleted the unused member. After the configuration update, users report that some destinations are unreachable. You confirm that the affected flow does not match an SD-WAN rule.

What could be a possible cause of the traffic interruption?

Options:

A.

FortiGate, with SD-WAN enabled, cannot route traffic through interfaces that are not SD-WAN members.


B.

FortiGate can remove some static routes associated with an interface when the member is removed from SD-WAN.


C.

FortiGate removes the layer 3 settings for interfaces that are removed from the SD-WAN configuration.


D.

FortiGate administratively brings down interfaces when they are removed from the SD-WAN configuration.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions