Fortinet FCSS_SDW_AR-7.4 Exam Practice Questions (P. 2)
- Full Access (68 questions)
- One Year of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Refer to the exhibit.

Which statement best describe the role of the ADVPN device in handling traffic?

Which statement best describe the role of the ADVPN device in handling traffic?
- AThis is a hub that has received a query from a spoke and has forwarded it to another spoke.
- BThis is a hub in a dual-region topology. The remote hub tunnel ID is 10.0.2.101.
- CThis is a spoke that has received a shortcut query from another spoke and has forwarded the response to its hub.
- DThis is a spoke. The kernel received a shortcut request and forwards the query to another spoke.
send
light_mode
delete
Question #7
Refer to the exhibit.

The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram. When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed over T2, even though T1 is the preferred member in the matching SD-WAN rule.
What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?

The administrator analyzed the traffic between a branch FortiGate and the server located in the data center, and noticed the behavior shown in the diagram. When the LAN clients located behind FGT1 establish a session to a server behind DC-1, the administrator observes that, on DC-1, the reply traffic is routed over T2, even though T1 is the preferred member in the matching SD-WAN rule.
What can the administrator do to instruct DC-1 to route the reply traffic through the member with the best performance?
- AEnable auxiliary-session under config system settings.
- BEnable snat-route-change under config system global.
- CEnable reply-session under config system sdwan.
- DFortiGate route lookup for reply traffic only considers routes over the original ingress interface.
send
light_mode
delete
Question #8
You are planning a large SD-WAN deployment with approximately 1000 spokes and want to allow ADVPN between the spokes. Some remote sites use FortiSASE to connect to the company’s SD-WAN hub.
Which overlay routing configuration should you use?
Which overlay routing configuration should you use?
- ABGP on loopback with IPsec phase2 selectors for ADVPN shortcut routing.
- BBGP per overlay with dynamic BGP for ADVPN shortcut routing.
- CBGP per overlay with BGP next-hop convergence for ADVPN shortcut routing.
- DBGP on loopback with dynamic BGP for ADVPN shortcut routing.
send
light_mode
delete
Question #9
Refer to the exhibit that shows event logs on FortiGate.

Based on the output shown in the exhibit, what can you say about the tunnels on this device?

Based on the output shown in the exhibit, what can you say about the tunnels on this device?
- AThe master tunnel HUB2-VPN3 cannot accept ADVPN shortcuts.
- BThere is one shortcut tunnel built from master tunnel VPV4.
- CThe device steers voice traffic through the VPN tunnel HUB1-VPN3.
- DThe VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.
send
light_mode
delete
Question #10
Which three characteristics apply to provisioning templates available on FortiManager? (Choose three.)
- AA template group can include a system template and an SD-WAN template.
- BA CLI template group can contain CLI templates of both types.
- CEach template group can contain up to three IPsec tunnel templates.
- DA CLI template can be of type CLI script or Peri script.
- ECLI templates are applied in order, from top to bottom.
send
light_mode
delete
All Pages
