Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE6_SDW_AD-7.6 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

The exhibit shows the health-check configuration on a FortiGate device used as a spoke. You notice that the hub FortiGate doesn’t prioritize the traffic as expected.

Which two configuration elements should you check on the hub? (Choose two.)

Options:

A.

The performance SLA has the parameter priority-out-sla configured.


B.

This performance SLA uses the same members.


C.

The performance SLA uses the same criteria.


D.

The performance SLA is configured with set embedded-measure accept.


Expert Solution
Questions # 2:

Refer to the exhibit.

Question # 2

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network.

The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over HUB1-VPN1. However, the traffic is routed over HUB1-VPN3.

Based on the output shown in the exhibit, which two reasons, individually or together, could explain the observed behavior? (Choose two.)

Options:

A.

HUB1-VPN3 has a higher member configuration priority than HUB1-VPN1.


B.

The traffic matches a regular policy route configured with HUB1-VPN3 as the outgoing device


C.

HUB1-VPN1 does not have a valid route to the destination


D.

HUB1-VPN3 has a lower route priority value (higher priority) than HUB1-VPN1.


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

Which statement best describe the role of the ADVPN device in handling traffic?

Options:

A.

This is a spoke that has received a direct shortcut query from a remote spoke.


B.

This is a hub, and two spokes, 192.2.0.1 and 10.0.3.101, establish a shortcut.


C.

This is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.


D.

This is a spoke that has received a shortcut query from a remote hub.


Expert Solution
Questions # 4:

You are planning a new SD-WAN deployment with the following criteria:

- Two regions

- Most of the traffic is expected to remain within its region

- No requirement for inter-region ADVPN

To remain within the recommended best practices, which routing protocol should you select for the overlays?

Options:

A.

OSPF for the routing within ea raffic will be routed over HUB1-V ns.


B.

IBGP with BGP on loopback within each region and EBGP between the regions.


C.

IBGP with BGP per overlays within each region and IBGP with BGP on loopback between the regions.


D.

IBGP within each region and between the regions.


Expert Solution
Questions # 5:

You want FortiGate to use SD-WAN rules to steer ping local-out traffic .

Which two constraints should you consider? Choose two answers.

Options:

A.

You can steer local-out traffic only with SD-WAN rules that use the manual strategy.


B.

By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to ping and traceroute.


C.

By default, local-out traffic does not use SD-WAN.


D.

You must configure each local-out feature individually to use SD-WAN.


Expert Solution
Questions # 6:

The administrator uses the FortiManager SD-WAN overlay template to prepare an SD-WAN deployment. Using information provided through the SD-WAN overlay template wizard, FortiManager creates templates ready to install on the spoke and hub devices.

What are the three templates created by the SD-WAN overlay template for a spoke device? (Choose three.)

Options:

A.

Static route template


B.

Rules template


C.

CLI template


D.

BGP template


E.

IPsec tunnel template


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

The administrator configured the SD-WAN rule ID 4 with two members (port1 and port2) and strategy lowest cost (SLA).

What are the two characteristics of the session shown in the exhibit? (Choose two.)

Options:

A.

FortiGate steered this flow according to an SD-WAN rule 4.


B.

FortiGate will never re-evaluate this session.


C.

FortiGate steered this flow according to the application detected and the outgoing interface is port3.


D.

FortiGate will re-evaluate this session if the outgoing interface goes down.


Expert Solution
Questions # 8:

Refer to the exhibit.

Question # 8

An administrator checks the status of an SD-WAN topology using the FortiManager SD-WAN monitor menus. All members are configured with one or two SLAs.

Which two conclusions can you draw from the output shown? (Choose two.)

Options:

A.

The template view should be used to see the hub devices.


B.

One member of branch2_fgt is missing the SLAs.


C.

branch2_fgt establishes six tunnels to the hubs and they are all up.


D.

This SD-WAN topology contains only two branch devices.


Expert Solution
Questions # 9:

To secure your enterprise network traffic, which step does FortiGate perform first, when handling the first packets of a session? (Choose one answer)

Options:

A.

Installation of the session key in the network processor (NP)


B.

Decryption


C.

A reverse path forwarding (RPF) check


D.

IP integrity header checking


Expert Solution
Questions # 10:

Your FortiGate is in production. To optimize WAN link use and improve redundancy, you enable and configure SD-WAN.

What must you do as part of this configuration update process?

Options:

A.

Replace references to interfaces used as SD-WAN members in the routing configuration.


B.

Purchase and install the SD-WAN license, and reboot the FortiGate device.


C.

Replace references to interfaces used as SD-WAN members in the firewall policies.


D.

Disable the interface that you want to use as an SD-WAN member.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions