Fortinet NSE7_SDW-6.4 Exam Practice Questions (P. 1)
- Full Access (81 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Refer to the exhibit.

Multiple IPsec VPNs are formed between two hub-and-spokes groups, and site-to-site between Hub 1 and Hub 2. The administrator configured ADVPN on the dual regions topology.
Which two statements are correct if a user in Toronto sends traffic to London? (Choose two.)

Multiple IPsec VPNs are formed between two hub-and-spokes groups, and site-to-site between Hub 1 and Hub 2. The administrator configured ADVPN on the dual regions topology.
Which two statements are correct if a user in Toronto sends traffic to London? (Choose two.)
- AToronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.
- BThe first packets from Toronto to London are routed through Hub 1 then to Hub 2.Most Voted
- CLondon generates an IKE information message that contains the Toronto public IP address.
- DTraffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN.Most Voted
Correct Answer:
AD
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/320160/example-advpn-configuration
AD
Reference:
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/320160/example-advpn-configuration
send
light_mode
delete
Question #2
Refer to exhibits.


Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
FortiGate is not performing traffic shaping as expected, based on the policies shown in the exhibits.
To correct this traffic shaping issue on FortiGate, what configuration change must be made on which policy?


Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
FortiGate is not performing traffic shaping as expected, based on the policies shown in the exhibits.
To correct this traffic shaping issue on FortiGate, what configuration change must be made on which policy?
- AThe URL category must be specified on the traffic shaping policy.
- BThe shaper mode must be applied per-IP shaper on the traffic shaping policy.
- CThe web filter profile must be enabled on the firewall policy.Most Voted
- DThe application control profile must be enabled on the firewall policy.
Correct Answer:
C
C
send
light_mode
delete
Question #3
Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?
- AThe 10 Mbps bandwidth is shared equally among the IP addresses.
- BEach IP is guaranteed a minimum 10 Mbps of bandwidth.
- CFortiGate allocates each IP address a maximum 10 Mbps of bandwidth.Most Voted
- DA single user uses the allocated bandwidth divided by total number of users.
Correct Answer:
C
Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/885253/per-ip-traffic-shaper
C
Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/885253/per-ip-traffic-shaper
send
light_mode
delete
Question #4
Which three parameters are available to configure SD-WAN rules? (Choose three.)
- AApplication signaturesMost Voted
- BURL categories
- CInternet service database (ISDB) address objectMost Voted
- DSource and destination IP addressMost Voted
- EType of physical link connection
Correct Answer:
CDE
CDE
send
light_mode
delete
Question #5
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?
- Adiagnose sys virtual-wan-link health-check
- Bdiagnose sys virtual-wan-link log
- Cdiagnose sys virtual-wan-link sla-log
- Ddiagnose sys virtual-wan-link intf-sla-logMost Voted
Correct Answer:
C
Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/943037/sla-logging
C
Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/943037/sla-logging
send
light_mode
delete
All Pages