Fortinet NSE7_SDW-6.4 Exam Practice Questions (P. 5)
- Full Access (81 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
Refer to the exhibit.

Which statement about the trace evaluation by FortiGate is true?

Which statement about the trace evaluation by FortiGate is true?
- APackets exceeding the configured maximum concurrent connection limit are denied by the per-IP shaper.
- BThe packet exceeded the configured bandwidth and was dropped based on the priority configuration.
- CThe packet exceeded the configured maximum bandwidth and was dropped by the shared shaper.
- DPackets exceeding the configured concurrent connection limit are dropped based on the priority configuration.Most Voted
Correct Answer:
A
A
send
light_mode
delete
Question #22
Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces?
(Choose two.)

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces?
(Choose two.)
- ASpecify a unique peer ID for each dial-up VPN interface.Most Voted
- BUse different proposals are used between the interfaces.
- CConfigure the IKE mode to be aggressive mode.Most Voted
- DUse unique Diffie Hellman groups on each VPN interface.
Correct Answer:
BD
BD
send
light_mode
delete
Question #23
Refer to exhibits.


Exhibit A shows the firewall policy and exhibit B shows the traffic shaping policy.
The traffic shaping policy is being applied to all outbound traffic; however, inbound traffic is not being evaluated by the shaping policy.
Based on the exhibits, what configuration change must be made in which policy so that traffic shaping can be applied to inbound traffic?


Exhibit A shows the firewall policy and exhibit B shows the traffic shaping policy.
The traffic shaping policy is being applied to all outbound traffic; however, inbound traffic is not being evaluated by the shaping policy.
Based on the exhibits, what configuration change must be made in which policy so that traffic shaping can be applied to inbound traffic?
- AThe guaranteed-10mbps option must be selected as the per-IP shaper option.
- BThe guaranteed-10mbps option must be selected as the reverse shaper option.
- CA new firewall policy must be created and SD-WAN must be selected as the incoming interface.
- DThe reverse shaper option must be enabled and a traffic shaper must be selected.Most Voted
Correct Answer:
B
B
send
light_mode
delete
Question #24
Refer to the exhibit.

What must you configure to enable ADVPN?

What must you configure to enable ADVPN?
- AADVPN should only be enabled on unmanaged FortiGate devices.
- BEach VPN device has a unique pre-shared key configured separately on phase one.
- CThe protected subnets should be set to address object to all (0.0.0.0/0).Most Voted
- DOn the hub VPN, only the device needs additional phase one settings.
Correct Answer:
B
B
send
light_mode
delete
Question #25
Which two statements describe how IPsec phase 1 main mode id different from aggressive mode when performing IKE negotiation? (Choose two.)
- AA peer ID is included in the first packet from the initiator, along with suggested security policies.Most Voted
- BXAuth is enabled as an additional level of authentication, which requires a username and password.
- CA total of six packets are exchanged between an initiator and a responder instead of three packets.Most Voted
- DThe use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.
Correct Answer:
BC
BC
send
light_mode
delete
All Pages