Pass the Fortinet NSE 7 Network Security Architect NSE7_SDW-7.2 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

Options:

A.

type must be set to static.


B.

mode-cfg must be enabled.


C.

exchange-interface-ip must be enabled.


D.

add-route must be disabled.


Expert Solution
Questions # 2:

Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?

Options:

A.

Interface-based shaping mode


B.

Reverse-policy shaping mode


C.

Shared-policy shaping mode


D.

Per-IP shaping mode


Expert Solution
Questions # 3:

Which statement about using BGP for ADVPN is true?

Options:

A.

You must use BGP to route traffic for both overlay and underlay links.


B.

You must configure AS path prepending.


C.

You must configure BGP communities.


D.

IBGP is preferred over EBGP, because IBGP preserves next hop information.


Expert Solution
Questions # 4:

Refer to the exhibit.

Question # 4

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.

Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

Options:

A.

Specify a unique peer ID for each dial-up VPN interface.


B.

Use different proposals are used between the interfaces.


C.

Configure the IKE mode to be aggressive mode.


D.

Use unique Diffie Hellman groups on each VPN interface.


Expert Solution
Questions # 5:

Which are two benefits of using CLI templates in FortiManager? (Choose two.)

Options:

A.

You can reference meta fields.


B.

You can configure interfaces as SD-WAN members without having to remove references first.


C.

You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.


D.

You can configure advanced CLI settings.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)

Options:

A.

Cost


B.

Interface member


C.

Priority


D.

Gateway IP


Expert Solution
Questions # 7:

The administrator uses the FortiManager SD-WAN overlay template to prepare an SD-WAN deployment. With information provided through the SD-WAN overlay template wizard, FortiManager creates templates ready to install on spoke and hub devices.

Select three templates created by the SD-WAN overlay template for a spoke device. (Choose three.)

Options:

A.

System template


B.

BGP template


C.

IPsec tunnel template


D.

CLI template


E.

Overlay template


Expert Solution
Questions # 8:

Question # 8

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2. The administrator configured ADVPN on both hub-and-spoke groups.

Which two outcomes are expected if a user in Toronto sends traffic to London? (Choose two.)

Options:

A.

London generates an IKE information message that contains the Toronto public IP address.


B.

Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN.


C.

Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.


D.

The first packets from Toronto to London are routed through Hub 1 then to Hub 2.


Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate appliance that supports hardware offloading. Based on the information shown in the exhibits, which two statements about the session are true? (Choose two.)

Options:

A.

The reply direction of the asymmetric traffic flows from port2 to port3.


B.

The auxiliary session can be offloaded to hardware.


C.

The original direction of the symmetric traffic flows from port3 to port2.


D.

The main session cannot be offloaded to hardware.


Expert Solution
Questions # 10:

What three characteristics apply to provisioning templates available on FortiManager? (Choose three.)

Options:

A.

You can apply a system template and a CLI template to the same FortiGate device.


B.

A CLI template can be of type CLI script or Perl script.


C.

A template group can include a system template and an SD-WAN template.


D.

A template group can contain CLI templates of both types.


E.

Templates are applied in order, from top to bottom.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions