New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE6_SDW_AD-7.6 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

(Refer to the exhibit.

Question # 21

You configure SD-WAN on a standalone FortiGate device.

You want to create an SD-WAN rule that steers traffic related to Facebook and LinkedIn through the less costly internet link.

What must you do to set Facebook and LinkedIn applications as destinations from the GUI? Choose one answer.)

Options:

A.

Enable the visibility of the applications field as destinations of the SD-WAN rule.


B.

In the Internet service field, select Facebook and LinkedIn.


C.

You cannot configure applications as destinations of an SD-WAN rule on a standalone FortiGate device.


D.

Install a license to allow applications as destinations of SD-WAN rules.


Expert Solution
Questions # 22:

An administrator is configuring SD-WAN to load balance their network traffic. Which two things should they consider when setting up SD-WAN? (Choose two.)

Options:

A.

You can select the outbandwidth hash mode with all strategies that allow load balancing.


B.

Only the manual and best-quality strategies allow SD-WAN load balancing.


C.

When applicable. FortiGate load balances the traffic through all members that meet the SLA target.


D.

SD-WAN load balancing is possible only using the best quality and lowest cost (SLA) strategies.


Expert Solution
Questions # 23:

Refer to the exhibits.

Question # 23

Question # 23

The administrator configured a device blueprint and CLI scripts as shown in the exhibits, to prepare for onboarding FortiGate devices in the company’s stores. Later, a technician prepares a FortiGate 51G with a basic configuration and connects it to the network. The basic configuration contains the port1 configuration and the minimal configuration required to allow the device to connect to FortiManager.

After the device first connects to FortiManager, FortiManager updates the device configuration.

Based on the exhibits, which actions does FortiManager perform?

Options:

A.

FortiManager updates the device configuration according to the selected templates. It applies the corp_st template first.


B.

FortiManager does not update the port1 configuration because FortiManager does not change the configuration of interfaces with fgfm access.


C.

FortiManager updates access rights only for port1. FortiManager cannot update the IP address because it was already set manually.


D.

FortiManager updates the configuration of port1, port2, and port5. The three ports might get new IP addresses.


Expert Solution
Questions # 24:

(Refer to the exhibit. You noticed that one SD-WAN member went down and you immediately collected the session output shown in the exhibit. What can you conclude from this output? Choose one answer.)

Question # 24

Options:

A.

FortiGate didn’t receive any traffic related to this session after the interface went down.


B.

FortiGate flushed the gateway for the session.


C.

FortiGate cannot reevaluate the session.


D.

FortiGate already reevaluated this session.


Expert Solution
Questions # 25:

Refer to the exhibits.

Question # 25

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in the first exhibit. After generating GoToMeeting test traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in the second exhibit.

The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.

Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)

Options:

A.

Full SSL inspection is not enabled on the matching firewall policy.


B.

The session 3-tuple did not match any of the existing entries in the ISDB application cache.


C.

FortiGate could not refresh the routing information on the session after the application was detected.


D.

No configured SD-WAN rule matches the traffic related to the collaboration application GoToMeeting


Expert Solution
Questions # 26:

(In which order does FortiGate consider the following elements during the route lookup process? Choose one answer.)

Options:

A.

SD-WAN rules, ISDB routes, policy routes, BGP routes


B.

Policy routes, SD-WAN rules, Internet Service Database (ISDB) routes, BGP routes


C.

SD-WAN rules, policy routes, static routes, ISDB routes


D.

Policy routes, ISDB routes, SD-WAN rules, static routes


Expert Solution
Questions # 27:

Refer to the exhibit.

Question # 27

The exhibit shows the health-check configuration on a FortiGate device used as a spoke. You notice that the hub FortiGate doesn’t prioritize the traffic as expected.

Which two configuration elements should you check on the hub? (Choose two.)

Options:

A.

The performance SLA has the parameter priority-out-sla configured.


B.

This performance SLA uses the same members.


C.

The performance SLA uses the same criteria.


D.

The performance SLA is configured with set embedded-measure accept.


Expert Solution
Questions # 28:

(Refer to the exhibit.

Question # 28

You update the spokes configuration of an existing auto-discovery VPN (ADVPN) topology by adding the parameters shown in the exhibit.

Which is a valid objective of those settings? Choose one answer.)

Options:

A.

Enable the tunnels as overlay links.


B.

Convert the configuration from ADVPN to ADVPN 2.0.


C.

Prevent cross-overlay shortcuts.


D.

Prevent multiple shortcuts from being established over the same overlay.


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions