wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

NSE7 - SD-WAN 7.0

Total questions: 63

Worksheet time: 1hrs 3mins

Name
Class
Date
1.
  1. 1. Which diagnostic command can you use to show the member utilization statistics measured by performance SLAs for the last 10 minutes?

a)
  • D. diagnose sys sdwan sla-log

b)
  • A. diagnose sys sdwan intf-sla-log

c)
  • C. diagnose sys sdwan log

d)
  • B. diagnose sys sdwan health-check

2.
  1. 2. Which two protocols in the IPsec suite are most used for authentication and encryption? (Choose two.)

a)
  • B. Secure Shell (SSH)

b)
  • C. Internet Key Exchange (IKE)

c)
  • D. Security Association (SA)

d)
  • A. Encapsulating Security Payload (ESP)

3.
  1. 3. Which two settings can you configure to speed up routing convergence in BGP? (Choose two.)

a)
  • C. holdtime-timer

b)
  • B. set-route-tag

c)
  • D. link-down-failover

d)
  • A. update-source

4.

4. Refer to the exhibits.

Exhibit A -

  • -

  • -

  • -

  • -

  • -

Exhibit B -

  • -

  • -

  • -

  • -

  • -

Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

a)
  • D. The traffic will be routed over T_INET_1_0.

b)
  • C. The traffic will be routed over T_MPLS_0.

c)
  • B. The traffic will be routed over T_INET_0_0.

d)
  • A. The traffic will be load balanced across all three overlays.

5.

5. Refer to the exhibit.
-
-
-
-
-

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2. The administrator configured ADVPN on both hub-and-spoke groups.
Which two outcomes are expected if a user in Toronto sends traffic to London? (Choose two.)

a)
  • A. London generates an IKE information message that contains the Toronto public IP address.

b)
  • D. The first packets from Toronto to London are routed through Hub 1 then to Hub 2.

c)
  • B. Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN.

d)
  • C. Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.

6.

6. Which two performance SLA protocols enable you to verify that the server response contains a specific value? (Choose two.)

a)
  • B. icmp

b)
  • D. dns

c)
  • A. http

d)
  • C. twamp

7.

7. Refer to the exhibit.
-
-
-
-
-
Which two conclusions for traffic that matches the traffic shaper are true? (Choose two.)

a)
  • C. The traffic shaper drops packets if the bandwidth exceeds 6250 KBps.

b)
  • B. The measured bandwidth is less than 100 KBps.

c)
  • A. The traffic shaper drops packets if the bandwidth is less than 2500 KBps.

d)
  • D. The traffic shaper limits the bandwidth of each source IP to a maximum of 6250 KBps.

8.

8. Refer to the exhibit.

  • -

  • -

  • -

  • -

  • -

  • Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

a)
  • B. mode-cfg must be enabled.

b)
  • D. add-route must be disabled.

c)
  • C. exchange-interface-ip must be enabled.

d)
  • A. type must be set to static.

9.
  1. 9. Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?

a)
  • B. diagnose debug application ike

b)
  • C. diagnose vpn tunnel list

c)
  • D. get ipsec tunnel list

d)
  • A. get router info routing-table all

10.
  1. 10. Refer to the exhibits.

    Exhibit A -

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Exhibit B -

  8. -

  9. -

  10. -

  11. -

  12. -

  13. Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.
    Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?

a)
  • A. port1 is assigned a manual IP address.

b)
  • D. port1 and port2 are not administratively down.

c)
  • B. port1 is referenced in a firewall policy.

d)
  • C. port2 is referenced in a static route.

11.
  1. 11. Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)

a)
  • C. Traffic does not match any of the entries in the policy route table.

b)
  • D. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.

c)
  • A. The sdwan_service_id flag in the session information is 0.

d)
  • B. All SD-WAN rules have the default setting enabled.

12.
  1. 12. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
    Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

a)
  • B. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.

b)
  • A. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.

c)
  • D. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.

d)
  • C. T_INET_0_0 does not have a valid route to the destination.

13.
  1. 13. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change? (Choose two.)

a)
  • D. FortiGate evaluates new sessions.

b)
  • C. FortiGate does not change existing sessions.

c)
  • B. FortiGate terminates the old sessions.

d)
  • A. FortiGate flushes all sessions.

14.
  1. 14. Which two statements about SD-WAN central management are true? (Choose two.)

a)
  • C. It uses templates to configure SD-WAN on managed devices.

b)
  • A. The objects are saved in the ADOM common object database.

c)
  • D. It supports normalized interfaces for SD-WAN member configuration.

d)
  • B. It does not support meta fields.

15.
  1. 15. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Which conclusion about the packet debug flow output is correct?

a)
  • D. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.

b)
  • A. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.

c)
  • C. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.

d)
  • B. The packet size exceeded the outgoing interface MTU.

16.
  1. 16. Which are two benefits of using CLI templates in FortiManager? (Choose two.)

a)
  • B. You can configure interfaces as SD-WAN members without having to remove references first.

b)
  • D. You can configure advanced CLI settings.

c)
  • C. You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.

d)
  • A. You can reference meta fields.

17.
  1. 17. Refer to the exhibits.

    Exhibit A -

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Exhibit B -

  8. -

  9. -

  10. -

  11. -

  12. -

  13. Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
    If port2 is detected dead by FortiGate, what is the expected behavior?

a)
  • C. The administrator manually restores the static routes for port2, if port2 becomes alive.

b)
  • B. FortiGate removes all static routes for port2.

c)
  • D. Host 8.8.8.8 is reachable through port1 and port2.

d)
  • A. Port2 becomes alive after three successful probes are detected.

18.
  1. 18. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. The device exchanges routes using IBGP.
    Which two statements are correct about the IBGP configuration and routing information on the device? (Choose two.)

a)
  • C. additional-path is enabled.

b)
  • A. Each BGP route is three hops away from the destination.

c)
  • D. You can run the get router info routing-table database command to display the additional paths.

d)
  • B. ibgp-multipath is disabled.

19.
  1. 19. In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)

a)
  • B. It provides direct connectivity between spokes by creating shortcuts.

b)
  • D. It enables spokes to establish shortcuts to third-party gateways.

c)
  • C. It enables spokes to bypass the hub during shortcut negotiation.

d)
  • A. It provides the benefits of a full-mesh topology in a hub-and-spoke network.

20.
  1. 20. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?

a)
  • C. All traffic from a source IP is sent to the most used interface.

b)
  • A. All traffic from a source IP to a destination IP is sent to the same interface.

c)
  • D. All traffic from a source IP to a destination IP is sent to the least used interface.

d)
  • B. All traffic from a source IP is sent to the same interface.

21.
  1. 21. Refer to the exhibits.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)

a)
  • C. FortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.

b)
  • B. The phase 1 configuration supports the network-overlay setting.

c)
  • D. Dead peer detection is disabled.

d)
  • A. FortiGate does not install IPsec static routes for remote protected networks in the routing table.

22.
  1. 22. Refer to the exhibits.

  2. Exhibit A -

  3. -

  4. -

  5. -

  6. -

  7. -

  8. Exhibit B -

  9. -

  10. -

  11. -

  12. -

  13. -

  14. Exhibit A shows the source NAT (SNAT) global setting and exhibit B shows the routing table on FortiGate.
    Based on the exhibits, which two actions does FortiGate perform on existing sessions established over port2, if the administrator increases the static route priority on port2 to 20? (Choose two.)

a)
  • B. FortiGate continues routing the sessions with no SNAT, over port2.

b)
  • C. FortiGate performs a route lookup for the original traffic only.

c)
  • A. FortiGate flags the sessions as dirty.

d)
  • D. FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.

23.
  1. 23. Refer to the exhibits.

  2. Exhibit A -

  3. -

  4. -

  5. -

  6. -

  7. -

  8. Exhibit B -

  9. -

  10. -

  11. -

  12. -

  13. -

  14. Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
    Based on the exhibits, which two statements are correct about the health and performance of port1 and port2? (Choose two.)

a)
  • C. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.

b)
  • A. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.

c)
  • D. Non-TCP Facebook and YouTube traffic are not used for performance measurement.

d)
  • B. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.

24.
  1. 24. Refer to the exhibits.

  2. Exhibit A -

  3. -

  4. -

  5. -

  6. -

  7. -

  8. Exhibit B -

  9. -

  10. -

  11. -

  12. -

  13. -

  14. Exhibit A shows an SD-WAN event log and exhibit B shows the member status and the SD-WAN rule configuration.
    Based on the exhibits, which two statements are correct? (Choose two.)

a)
  • B. Port2 has the highest member priority.

b)
  • D. SD-WAN rule ID 1 is set to lowest cost (SLA) mode.

c)
  • A. FortiGate updated the outgoing interface list on the rule so it prefers port2.

d)
  • C. Port2 has a lower latency than port1.

25.
  1. 25. Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?

a)
  • D. Per-IP shaping mode

b)
  • B. Reverse-policy shaping mode

c)
  • A. Interface-based shaping mode

d)
  • C. Shared-policy shaping mode

26.
  1. 26. Which two interfaces are considered overlay links? (Choose two.)

a)
  • B. IPsec

b)
  • D. GRE

c)
  • A. LAG

d)
  • C. Physical

27.
  1. 27. Refer to the exhibits.

  2. Exhibit A -

  3. -

  4. -

  5. -

  6. -

  7. -

  8. Exhibit B -

  9. -

  10. -

  11. -

  12. -

  13. -

  14. Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
    When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferred member in the matching SD-WAN rule.
    Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?

a)
  • C. Enable snat-route-change under config system global.

b)
  • B. Disable tсp-session-without-syn under config system settings.

c)
  • D. Disable allow-subnet-overlap under config system settings.

d)
  • A. Enable auxiliary-session under config system settings.

28.
  1. 28. What are two benefits of using the Internet service database (ISDB) in an SD-WAN rule? (Choose two.)

a)
  • B. The ISDB requires application control to maintain signatures and perform load balancing.

b)
  • D. The ISDB contains the IP addresses and port ranges of well-known internet services.

c)
  • A. The ISDB is dynamically updated and reduces administrative overhead.

d)
  • C. The ISDB applies rules to traffic from specific sources, based on application type.

29.
  1. 29. Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?

a)
  • C. You must enable auto-discovery-sender.

b)
  • B. You must enable net-device.

c)
  • D. You must disable idle-timeout.

d)
  • A. You must set ike-version to 1.

30.
  1. 30. Which statement is correct about SD-WAN and ADVPN?

a)
  • C. SD-WAN does not monitor the health and performance of ADVPN shortcuts.

b)
  • A. Routes for ADVPN shortcuts must be manually configured.


c)
  • B. SD-WAN can steer traffic to ADVPN shortcuts, established over IPsec overlays, configured as SD-WAN members.

d)
  • D. You must use IKEv2 on IPsec tunnels.

31.
  1. 31. What is the route-tag setting in an SD-WAN rule used for?

a)
  • B. To indicate the destination of a rule based on learned BGP prefixes.

b)
  • D. To indicate the members that can be used to route SD-WAN traffic.

c)
  • A. To indicate the routes for health check probes.

d)
  • C. To indicate the routes that can be used for routing SD-WAN traffic.

32.
  1. 32. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. The exhibit shows the SD-WAN rule status and configuration.
    Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

a)
  • C. When T_INET_0_0 has a latency of 250 ms.

b)
  • B. When T_MPLS_0 has a latency of 100 ms.

c)
  • D. When T_N1PLS_0 has a latency of 80 ms.

d)
  • A. When T_INET_0_0 and T_MPLS_0 have the same latency.

33.
  1. 33. Refer to the exhibits.

  2. Exhibit A -

  3. -

  4. -

  5. -

  6. -

  7. -

  8. Exhibit B -

  9. -

  10. -

  11. -

  12. -

  13. -

  14. Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
    The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator determines that FortiGate does not apply traffic shaping on YouTube traffic.
    Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs traffic shaping on YouTube traffic?

a)
  • C. Web filtering must be enabled on the firewall policy.

b)
  • A. Destination internet service must be enabled on the traffic shaping policy.

c)
  • D. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.

d)
  • B. Application control must be enabled on the firewall policy.

34.
  1. 33. Which are three key routing principles in SD-WAN? (Choose three.)

a)
  • B. Regular policy routes have precedence over SD-WAN rules.

b)
  • E. By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.

c)
  • A. FortiGate performs route lookups for new sessions only.

d)
  • C. SD-WAN rules have precedence over ISDB routes.

e)
  • D. By default, SD-WAN members are skipped if they do not have a valid route to the destination.

35.
  1. 35. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Based on the output, which two conclusions are true? (Choose two.)

a)
  • C. The all_rules rule represents the implicit SD-WAN rule.

b)
  • A. There is more than one SD-WAN rule configured.

c)
  • D. Entry 1(id=1) is a regular policy route.

d)
  • B. The SD-WAN rules take precedence over regular policy routes.

36.
  1. 36. Which two statements about SLA targets and SD-WAN rules are true? (Choose two.)

a)
  • B. SD-WAN rules use SLA targets to check if the preferred members meet the SLA requirements.

b)
  • D. Member metrics are measured only if an SLA target is configured.

c)
  • A. When configuring an SD-WAN rule, you can select multiple SLA targets of the same performance SLA.

d)
  • C. SLA targets are used only by SD-WAN rules that are configured with Lowest Cost (SLA) or Maximize Bandwidth (SLA) as strategy.

37.
  1. 37. What does enabling the exchange-interface-ip setting enable FortiGate devices to exchange?

a)
  • C. The IP address of their IPsec interfaces

b)
  • B. The tunnel ID of their IPsec interfaces

c)
  • D. The name of their IPsec interfaces

d)
  • A. The gateway address of their IPsec interfaces

38.
  1. 38. Which diagnostic command can you use to show the configured SD-WAN zones and their assigned members?

a)
  • B. diagnose sys sdwan service

b)
  • D. diagnose sys sdwan interface

c)
  • A. diagnose sys sdwan zone

d)
  • C. diagnose sys sdwan member

39.
  1. 39. Refer to the exhibits.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Exhibit A shows the packet duplication rule configuration, the SD-WAN zone status output, and the sniffer output on FortiGate acting as the sender. Exhibit B shows the sniffer output on a FortiGate acting as the receiver.

  8. The administrator configured packet duplication on both FortiGate devices. The sniffer output on the sender FortiGate shows that FortiGate forwards an ICMP echo request packet over three overlays, but it only receives one reply packet through T_INET_1_0.

  9. Based on the output shown in the exhibits, which two reasons can cause the observed behavior? (Choose two.)

a)
  • D. On the sender FortiGate, duplication-max-num is set to 3.

b)
  • B. The ICMP echo request packets sent over T_INET_0_0 and T_MPLS_0 were dropped along the way.

c)
  • C. The ICMP echo request packets received over T_INET_0_0 and T_MPLS_0 were offloaded to NPU.

d)
  • A. On the receiver FortiGate, packet-de-duplication is enabled.

40.
  1. 40. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)

a)
  • B. Interface member

b)
  • C. Priority

c)
  • A. Cost

d)
  • D. Gateway IP

41.
  1. 41. Which statement about using BGP for ADVPN is true?

a)
  • B. You must use BGP to route traffic for both overlay and underlay links.

b)
  • D. You must configure AS path prepending.

c)
  • A. IBGP is preferred over EBGP, because IBGP preserves next hop information.

d)
  • C. You must configure BGP communities.

42.
  1. 42. Refer to the exhibits.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.

    After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.

    Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)

a)
  • B. Port1 and port2 do not have a valid route to the destination.

b)
  • D. The session 3-tuple did not match any of the existing entries in the ISDB application cache.

c)
  • C. Full SSL inspection is not enabled on the matching firewall policy.

d)
  • A. FortiGate did not refresh the routing information on the session after the application was detected.

43.
  1. 43. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Which are two expected behaviors of the traffic that matches the traffic shaper? (Choose two.)

a)
  • C. The number of simultaneous connections allowed for each source IP address cannot exceed five connections.

b)
  • A. The number of simultaneous connections among all source IP addresses cannot exceed five connections.

c)
  • B. The traffic shaper limits the combined bandwidth of all connections to a maximum of 5 MB/sec.

d)
  • D. The traffic shaper limits the bandwidth of each source IP address to a maximum of 625 KB/sec.

44.
  1. 44. Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)

a)
  • B. By default, local-out traffic does not use SD-WAN.

b)
  • C. By default, FortiGate does not check if the selected member has a valid route to the destination.

c)
  • A. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for local-out traffic.

d)
  • D. You must configure each local-out feature individually, to use SD-WAN.

45.
  1. 45. Which three matching traffic criteria are available in SD-WAN rules? (Choose three.)

a)
  • B. Internet service database (ISDB) address object

b)
  • E. Application signatures

c)
  • A. Type of physical link connection

d)
  • C. Source and destination IP address

e)
  • D. URL categories

46.
  1. 46. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Which conclusion about the packet debug flow output is correct?

a)
  • D. The original traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.

b)
  • C. The original traffic exceeded the maximum bandwidth of the outgoing interface, and the packet was dropped.

c)
  • A. The original traffic exceeded the maximum packets per second of the outgoing interface, and the packet was dropped.

d)
  • B. The reply traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.

47.
  1. 47. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.

    Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)

a)
  • B. Enable route-reflector-client

b)
  • E. Enable soft-reconfiguration

c)
  • A. Set additional-path to send

d)
  • C. Set advertisement-interval to the number of additional paths to advertise

e)
  • D. Set adv-additional-path to the number of additional paths to advertise

48.
  1. 48. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Which statement explains the output shown in the exhibit?

a)
  • D. FortiGate must re-evaluate the session due to routing change.

b)
  • B. FortiGate will not re-evaluate the session following a firewall policy change.

c)
  • A. FortiGate performed standard FIB routing on the session.

d)
  • C. FortiGate used 192.2.0.1 as the gateway for the original direction of the traffic.

49.
  1. 49. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate appliance that supports hardware offloading. Based on the information shown in the exhibits, which two statements about the session are true? (Choose two.)

a)
  • C. The original direction of the symmetric traffic flows from port3 to port2.

b)
  • D. The main session cannot be offloaded to hardware.

c)
  • B. The auxiliary session can be offloaded to hardware.

d)
  • A. The reply direction of the asymmetric traffic flows from port2 to port3.

50.
  1. 50. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling the anti-replay setting on the hubs?

a)
  • C. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.

b)
  • A. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve performance.

c)
  • D. It instructs the hub to skip content inspection on TCP traffic, to improve performance.

d)
  • B. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions originated from spokes to fail over back and forth between the hubs.

51.
  1. 51. Which SD-WAN setting enables FortiGate to delay the recovery of ADVPN shortcuts?

a)
  • C. auto-discovery-shortcuts

b)
  • A. hold-down-time

c)
  • D. idle-timeout

d)
  • B. link-down-failover

52.
  1. 52. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Which statement about the role of the ADVPN device in handling traffic is true?

a)
  • B. Two hubs, 10.0.1.101 and 10.0.2.101, are receiving and forwarding queries between each other.

b)
  • D. Two spokes, 192.2.0.1 and 10.0.2.101, forward their queries to their hubs.

c)
  • C. This is a hub that has received a query from a spoke and has forwarded it to another spoke.

d)
  • A. This is a spoke that has received a query from a remote hub and has forwarded the response to its hub.

53.
  1. 53. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Based on the exhibit, which two actions does FortiGate perform on traffic passing through port2? (Choose two.)

a)
  • D. FortiGate flushes all routing information from the session table, after a route change.

b)
  • B. FortiGate performs routing lookups for new sessions only, after a route change.

c)
  • C. FortiGate always blocks all traffic, after a route change.

d)
  • A. FortiGate does not change the routing information on existing sessions that use a valid gateway, after a route change.

54.
  1. 54. What is a benefit of using application steering in SD-WAN?

a)
  • B. You steer traffic based on the detected application.

b)
  • C. You do not need to enable SSL inspection.

c)
  • A. The traffic always skips the regular policy routes.

d)
  • D. You do not need to configure firewall policies that accept the SD-WAN traffic.

55.
  1. 55. Which two statements about the SD-WAN zone configuration are true? (Choose two.)

a)
  • B. You can delete the default zones.

b)
  • D. An SD-WAN member can belong to two or more zones.

c)
  • C. The default zones are virtual-wan-link and SASE.

d)
  • A. The service-sla-tie-break setting enables you to configure preferred member selection based on the best route to the destination.

56.
  1. 56. What are two common use cases for remote internet access (RIA)? (Choose two.)

a)
  • B. Provide internet access through the hub

b)
  • D. Provide thorough inspection on spokes

c)
  • A. Provide direct internet access on spokes

d)
  • C. Centralize security inspection on the hub

57.
  1. 57. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.

    Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)

a)
  • C. auto-discovery-forwarder must be enabled on all IPsec VPNs.

b)
  • A. On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.

c)
  • D. On the hubs, net-device must be enabled on all IPsec VPNs.

d)
  • B. On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.

58.
  1. 58. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. The exhibit shows the SD-WAN rule status and configuration.

    Based on the exhibit, which change in the measured packet loss will make T_INET_1_0 the new preferred member?

a)
  • B. When T_INET_0_0 has 4% packet loss.

b)
  • D. When T_INET_1_0 has 4% packet loss.

c)
  • C. When T_INET_0_0 has 12% packet loss.

d)
  • A. When all three members have the same packet loss.

59.
  1. 59. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Based on the exhibit, which action does FortiGate take?

a)
  • A. FortiGate bounces port5 after it detects all SD-WAN members as dead.

b)
  • C. FortiGate brings up port5 after it detects all SD-WAN members as alive.

c)
  • D. FortiGate brings down port5 after it detects all SD-WAN members as dead.

d)
  • B. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.

60.
  1. 60. What are two benefits of using forward error correction (FEC) in IPsec VPNs? (Choose two.)

a)
  • B. FEC improves reliability of noisy links.

b)
  • D. FEC can leverage multiple IPsec tunnels for parity packets transmission.

c)
  • A. FEC supports hardware offloading.

d)
  • C. FEC transmits parity packets that can be used to reconstruct packet loss.

61.
  1. 61. Which two tasks are part of using central VPN management? (Choose two.)

a)
  • B. You must enable VPN zones for SD-WAN deployments.

b)
  • D. You configure VPN communities to define common IPsec settings shared by all VPN gateways.

c)
  • C. FortiManager installs VPN settings on both managed and external gateways.

d)
  • A. You can configure full mesh, star, and dial-up VPN topologies.

62.
  1. 62. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Based on the exhibit, which two statements are correct about the health of the selected members? (Choose two.)

a)
  • D. FortiGate passively monitors the member if TCP traffic is passing through the member.

b)
  • B. During passive monitoring, FortiGate can’t detect dead members.

c)
  • A. After FortiGate switches to active mode, FortiGate never fails back to passive monitoring.

d)
  • C. FortiGate can offload the traffic that is subject to passive monitoring to hardware.

63.
  1. 63. Refer to the exhibit.

  2. -

  3. -

  4. -

  5. -

  6. -

  7. Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2. The administrator configured ADVPN on both hub-and- spoke groups.
    If an ADVPN on-demand tunnel is established between Toronto and London, which two configuration settings are required for ADVPN to work? (Choose two.)

a)
  • B. auto-discovery-forwarder is enabled on all IPsec VPNs.

b)
  • A. On the hubs, auto-discovery-sender is enabled on the IPsec VPNs to spokes.

c)
  • D. On the spokes, auto-discovery-receiver is enabled on the IPsec VPN to the hub.

d)
  • C. On the hubs, tunnel-search is set selectors.