New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE6_SDW_AD-7.6 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Exhibit.

Question # 11

Which action will FortiGate take if it detects SD-WAN members as dead?

Options:

A.

FoftiGate bounces port5 after it detects all SD-WAN members as dead.


B.

FortiGate fails over to the secondary device after it detects port5 as dead.


C.

FortiGate sends alert messages through poft5 when it detects all SD-WAN members as dead


D.

FortiGate brings down port5 after it detects all SD-WAN members as dead.


Expert Solution
Questions # 12:

Refer to the exhibit.

Question # 12

Which statement best describe the role of the ADVPN device in handling traffic?

Options:

A.

This is a spoke that has received a direct shortcut query from a remote spoke.


B.

This is a hub, and two spokes, 192.2.0.1 and 10.0.3.101, establish a shortcut.


C.

This is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.


D.

This is a spoke that has received a shortcut query from a remote hub.


Expert Solution
Questions # 13:

You are tasked with configuring ADVPN 2.0 on an SD-WAN topology already configured for ADVPN. What should you do to implement ADVPN 2.0 in this scenario?

Options:

A.

Update the IPsec tunnel configurations on the hub.


B.

Update the SD-WAN configuration on the branches.


C.

Update the IPsec tunnel configuration on the branches.


D.

Delete the existing ADVPN configuration and configure ADVPN 2.0.


Expert Solution
Questions # 14:

Question # 14

Refer to the exhibit that shows event logs on FortiGate.

Based on the output shown in the exhibit, what can you say about the tunnels on this device?

Options:

A.

The master tunnel HU82-VPN3 cannot accept ADVPN shortcuts.


B.

The device steers voice traffic through the VPN tunnel HUB1-VPN3.


C.

The VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.


D.

There is one shortcut tunnel built from master tunnel VPN4.


Expert Solution
Questions # 15:

(Refer to the exhibits.

Question # 15

Two SD-WAN event logs, the member status, the SD-WAN rule configuration, and the health-check configuration for a FortiGate device are shown.

Immediately after the log messages are displayed, how will the FortiGate steer the traffic based on the information shown in the exhibits? Choose one answer.)

Options:

A.

FortiGate skips SD-WAN rule ID 1.


B.

FortiGate uses port2 to steer the traffic for SD-WAN rule ID 1.


C.

FortiGate uses port1 to steer the traffic for SD-WAN rule ID 1.


D.

FortiGate uses port1 or port2 to steer the traffic for SD-WAN rule ID 1.


Expert Solution
Questions # 16:

You manage an SD-WAN topology. You will soon deploy 50 new branches.

Which three tasks can you do in advance to simplify this deployment? (Choose three.)

Options:

A.

Update the DHCP server configuration.


B.

Create model devices.


C.

Create a ZTP template.


D.

Define metadata variables value for each device.


E.

Create policy blueprint.


Expert Solution
Questions # 17:

Refer to the exhibits.

Question # 17

The exhibits show the configuration for SD-WAN performance. SD-WAN rule, the application IDs of Facebook and YouTube along with the firewall policy configuration and the underlay zone status.

Which two statements are true about the health and performance of SD-WAN members 3 and 4? (Choose two.)

Options:

A.

Only related TCP traffic is used for performance measurement.


B.

The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.


C.

Encrypted traffic is not used for the performance measurement.


D.

FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.


Expert Solution
Questions # 18:

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Question # 18

Based on the exhibit, which change in the measured latency will first make HUB1-VPN3 the new preferred member?

Options:

A.

When HUB1-VPN3 has a lower latency than HUB1-VPN1 and HUB1-VPN2


B.

When HUB1-VPN3 has a latency of 80 ms


C.

When HUB1-VPN3 has a latency of 90 ms


D.

When HUB1-VPN1 has a latency of 200 ms


Expert Solution
Questions # 19:

Question # 19

Refer to the exhibit.

You want to configure SD-WAN on a network as shown in the exhibit.

The network contains many FortiGate devices. Some are used as NGFW, and some are installed with extensions such as FortiSwitch. FortiAP. or Forti Ex tender.

What should you consider when planning your deployment?

Options:

A.

You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with Forti Extender.


B.

You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.


C.

You must use FortiManager to manage your SD-WAN topology.


D.

You must build multiple SD-WAN topologies. Each topology must contain only one type of extension.


Expert Solution
Questions # 20:

Refer to the exhibit.

Question # 20

How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0 125?

Options:

A.

FortiGate drops the traffic flow.


B.

FortiGate routes the traffic flow according to the forwarding information base (FIB).


C.

FortiGate load balances the traffic flow through port7 and port8.


D.

FortiGate steers the traffic flow through port7.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions