New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_SDW_AR-7.6 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

(Refer to the exhibit.

Question # 1

You configure SD-WAN on a standalone FortiGate device.

You want to create an SD-WAN rule that steers traffic related to Facebook and LinkedIn through the less costly internet link.

What must you do to set Facebook and LinkedIn applications as destinations from the GUI? Choose one answer.)

Options:

A.

Enable the visibility of the applications field as destinations of the SD-WAN rule.


B.

In the Internet service field, select Facebook and LinkedIn.


C.

You cannot configure applications as destinations of an SD-WAN rule on a standalone FortiGate device.


D.

Install a license to allow applications as destinations of SD-WAN rules.


Expert Solution
Questions # 2:

You configured an SD-WAN rule with the best quality strategy and selected the predefined health check, Default_FortiGuard, to check the link performances against FortiGuard servers.

For the quality criteria, you selected Custom-profile-1.

Which factors does FortiGate use, and in which order. to determine the link that it should use to steer the traffic?

Options:

A.

Latency – Member configuration order – Link cost threshold


B.

Link quality index – Member configuration order – Link cost threshold


C.

Links that meet the SLA targets – Member configuration order – Member local cost


D.

Latency – Jitter - Packet loss – Bibandwidth – Member configuration order


Expert Solution
Questions # 3:

Refer to the exhibits.

Question # 3

Question # 3

The exhibits show the SD-WAN zone configuration of an SD-WAN template prepared on FortiManager and the policy package configuration.

When the administrator tries to install the configuration changes, FortiManager fails to commit.

What should the administrator do to fix the issue?

Options:

A.

Configure branch1_fgt as the installation target for policy 3.


B.

Configure HUB1 as the destination of policy 3.


C.

Configure a normalized interface for the IPsec tunnel HUB1-VPN1.


D.

Configure both HUB1-VPN1 and HUB1-VPN2 as the destination of policy 3


Expert Solution
Questions # 4:

An SD-WAN member is no longer used to steer SD-WAN traffic. The administrator updated the SD-WAN configuration and deleted the unused member. After the configuration update, users report that some destinations are unreachable. You confirm that the affected flow does not match an SD-WAN rule.

What could be a possible cause of the traffic interruption?

Options:

A.

FortiGate, with SD-WAN enabled, cannot route traffic through interfaces that are not SD-WAN members.


B.

FortiGate can remove some static routes associated with an interface when the member is removed from SD-WAN.


C.

FortiGate removes the layer 3 settings for interfaces that are removed from the SD-WAN configuration.


D.

FortiGate administratively brings down interfaces when they are removed from the SD-WAN configuration.


Expert Solution
Questions # 5:

You have a FortiGate configuration with three user-defined SD-WAN zones and two members in each of these zones. One SD-WAN member is no longer in use in health-check and SD-WAN rules. You want to delete it.

What happens if you delete the SD-WAN member from the FortiGate GUI?

Options:

A.

FodiGate accepts the deletion and removes routes as required.


B.

FortiGate displays an error message. You must use the CLI to delete an SD-WAN member.


C.

FortiGate displays an error message. SD-WAN zones must contain at least two members


D.

FortiGate accepts the deletion and places the member in the default SD-WAN zone.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate device that supports hardware offloading.

Based on the information shown in the exhibits, which two conclusions can you draw? (Choose two.)

Options:

A.

By default, FortiGate offloads symmetric and asymmetric flows.


B.

The original direction of the symmetric traffic flows from port3 to port2.


C.

The reply direction of the asymmetric traffic flows from port2 to port3.


D.

The auxiliary session can be offloaded to hardware.


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram.

When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed overT2. even though T1 is the preferred member in

the matching SD-WAN rule.

What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?

Options:

A.

Enable snat-route-change under config system global.


B.

Enable reply-session under config system sdwan.


C.

Enable auxiliary-session under config system settings.


D.

FortiGate route lookup for reply traffic only considers routes over the original ingress interface.


Expert Solution
Questions # 8:

You are tasked with configuring ADVPN 2.0 on an SD-WAN topology already configured for ADVPN. What should you do to implement ADVPN 2.0 in this scenario?

Options:

A.

Update the IPsec tunnel configurations on the hub.


B.

Update the SD-WAN configuration on the branches.


C.

Update the IPsec tunnel configuration on the branches.


D.

Delete the existing ADVPN configuration and configure ADVPN 2.0.


Expert Solution
Questions # 9:

You have configured the performance SLA with the probe mode as Prefer Passive.

What are two observable impacts of this configuration? (Choose two.)

Options:

A.

FortiGate passively monitors the member if TCP traffic is passing through the member.


B.

After FortiGate switches to active mode, the SLA performance rule falls back to passive monitoring after 3 minutes.


C.

FortiGate passively monitors the member if ICMP traffic is passing through the member.


D.

During passive monitoring, the SLA performance rule cannot detect dead members.


E.

FortiGate can offload the traffic that is subject to passive monitoring to hardware.


Expert Solution
Questions # 10:

(You are configuring SD-WAN to load balance network traffic and you want to take into account the link quality.

Which two facts should you consider? Choose two answers.)

Options:

A.

When applicable, FortiGate load balances the traffic through all members that meet the SLA target.


B.

You can select the best quality strategy and allow SD-WAN load balancing.


C.

You can select the lowest cost service level agreement (SLA) strategy and allow SD-WAN load balancing.


D.

The best quality strategy supports only the round-robin hash mode.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions