New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE6_SDW_AD-7.6 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibits.

Question # 1

To prepare to onboard FortiGate devices to your company's stores, you configure the device blueprint and CLI scripts shown in the exhibit. Then, a technician prepares a FortiGate 90G with a basic configuration and connects it to the network. The basic configuration contains the port1 configuration and the minimal configuration required to allow the device to connect to FortiManager.

After the device initially connects to FortiManager, FortiManager updates the device configuration.

Based on what is shown in the exhibits, which statement about the actions taken by FortiManager is true?

Options:

A.

FortiManager updates the configuration of port1, port2, and port5. The three ports might get new IP addresses


B.

FortiManager updates access rights only for port1. FortiManager cannot update the IP address because it was already set manually


C.

FortiManager updates the device configuration according to the selected templates and it applies the corp_st template first


D.

FortiManager does not update the port1 configuration because FortiManager does not change the configuration of interfaces with FortiGate-FortiManager communication protocol (FGFM) access


Expert Solution
Questions # 2:

When a customer delegate the installation and management of its SD-WAN infrastructure to an MSSP, the MSSP usually keeps the hub within its infrastructure for ease of management and to share costly resources.

In which two situations will the MSSP install the hub in customer premises? (Choose two.)

Options:

A.

The customer requires SIA with centralized breakout.


B.

The administrator expects a large volume of traffic between the branches.


C.

The customer expects a large amount of VoIP traffic.


D.

The majority of the branch traffic is directed to a corporate data center.


Expert Solution
Questions # 3:

(Refer to the exhibit.

Question # 3

Based on the output shown in the exhibit, what can you conclude about the device role and how it handles health checks? Choose one answer.)

Options:

A.

The device is a spoke and it provides embedded health-check measures for each tunnel to the hub.


B.

The device is a spoke and it receives health-check measures for the tunnels of another spoke.


C.

The device is a hub and it receives embedded health-check measures for each tunnel from the spoke.


D.

The device is a hub and it receives health-check measures for the tunnels of a spoke.


Expert Solution
Questions # 4:

Refer to the exhibits.

Question # 4

The exhibits show the source NAT (SNAT) global setting. port2 interface settings, and the routing table on FortiGate.

The administrator increases the member priority on port2 to 20.

Upon configuration changes and the receipt of new packets, which two actions does FortiGate perform on existing sessions established over port2? (Choose two.)

Options:

A.

FortiGate continues routing all existing sessions over port2.


B.

FortiGate routes only new sessions over port2.


C.

FortiGate flags the SNAT session as dirty only if the administrator has assigned an IP pool to the firewall policies with NAT.


D.

FortiGate flags the sessions as dirty.


E.

FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.


Expert Solution
Questions # 5:

Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two.)

Options:

A.

The session information output displays no SD-WAN service id.


B.

Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.


C.

The traffic is distributed, regardless of weight, through all available static routes.


D.

Traffic does not match any of the entries in the policy route table.


E.

FortiGate flags the session with may_dirty and vwl_def ault.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

An administrator configures SD-WAN rules for a DIA setup using the FortiGate GUI. The page to configure the source and destination part of the rule looks as shown in the exhibit. The GUI page shows no option to configure an application as the destination of the SD-WAN rule Why?

Options:

A.

You cannot use applications as the destination when FortiGate is used for a DIA setup.


B.

FortiGate allows the configuration of applications as the destination of SD-WAN rules only on the CLI.


C.

You must enable the feature on the CLI.


D.

You must enable the feature first using the GUI menu System > Feature Visibility.


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

The administrator used the SD-WAN overlay template to prepare an IPsec tunnels configuration for a hub-and-spoke SD-WAN topology. The exhibit shows the FortiManager installation preview for one FortiGate device.

Based on the exhibit, which statement best describes the configuration applied to the FortiGate device?

Options:

A.

It is a spoke device that establishes dynamic IPsec tunnels to the hub. The local subnet range is 10.10.128.0/23.


B.

It is a hub device. It can send ADVPN shortcut offers.


C.

It is a hub device. It will automatically discover the spoke devices and add them to the SD-WAN topology.


D.

It is a spoke device that establishes dynamic IPsec tunnels to the hub It can send ADVPN shortcut requests.


Expert Solution
Questions # 8:

Exhibit.

Question # 8

Two hub-and-spoke groups are connected through redundant site-to-site IPsec VPNs between Hub 1 and Hub 2

Which two configuration settings are required for the spoke A1 to establish an ADVPN shortcut with the spoke B2? (Choose two.)

Options:

A.

On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to hubs.


B.

On hubs, auto-discovery-receiver must be enabled on the IPsec VPNs to spokes.


C.

On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to spokes.


D.

On hubs, auto-diacovery-sender must be enabled on the IPsec VPNs to spokes


Expert Solution
Questions # 9:

The SD-WAN overlay template helps to prepare SD-WAN deployments. To complete the tasks performed by the SD-WAN overlay template, the administrator must perform some post-run tasks. What are two mandatory post-run tasks that must be performed? (Choose two.)

Options:

A.

Configure routing through the overlay tunnels created by the SD-WAN overlay template.


B.

Create policy packages and assign them to the branch devices.


C.

Assign a hub id metadata variable to each hub device.


D.

Configure SD-WAN rules


E.

Assign an sdwan_id metadata variable to each device (branch and hub)


Expert Solution
Questions # 10:

You want FortiGate to use SD-WAN rules to steer local-out traffic.

Which two constraints should you consider? (Choose two.)

Options:

A.

By default, FortiGate uses SD-WAN rules only for local-out traffic that corresponds to ping and traceroute.


B.

By default, local-out traffic does not use SD-WAN.


C.

You can steer local-out traffic only with SD-WAN rules that use the manual strategy.


D.

You must configure each local-out feature individually to use SD-WAN.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions