Fortinet NSE7_SDW-7.0 Exam Practice Questions (P. 3)
- Full Access (62 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)
- AThe sdwan_service_id flag in the session information is 0.Most Voted
- BAll SD-WAN rules have the default setting enabled.
- CTraffic does not match any of the entries in the policy route table.Most Voted
- DTraffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
Correct Answer:
AD
AD

The correct understanding here revolves around how SD-WAN alters traffic management settings within FortiOS settings. When SD-WAN is enabled, the previously used v4-ecmp-mode is not applicable; instead, SD-WAN uses the load-balance-mode parameter for managing traffic distribution. This differentiation is crucial as it directly affects how traffic routes are managed in SD-WAN configurations as opposed to traditional ECMP configurations. Therefore, assertion D, referencing v4-ecmp-mode, does not align with the operational parameters of an enabled SD-WAN system.
send
light_mode
delete
Question #12
Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)
- AThe traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.Most Voted
- BT_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
- CT_INET_0_0 does not have a valid route to the destination.Most Voted
- DT_INET_1_0 has a higher member configuration priority than T_INET_0_0.
Correct Answer:
AB
AB
send
light_mode
delete
Question #13
Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change? (Choose two.)

Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change? (Choose two.)
- AFortiGate flushes all sessions.
- BFortiGate terminates the old sessions.
- CFortiGate does not change existing sessions.Most Voted
- DFortiGate evaluates new sessions.Most Voted
Correct Answer:
CD
CD
send
light_mode
delete
Question #14
Which two statements about SD-WAN central management are true? (Choose two.)
- AThe objects are saved in the ADOM common object database.Most Voted
- BIt does not support meta fields.
- CIt uses templates to configure SD-WAN on managed devices.Most Voted
- DIt supports normalized interfaces for SD-WAN member configuration.
Correct Answer:
CD
CD

SD-WAN central management typically involves the use of templates to ensure consistent configurations across managed devices, supporting streamlined operations and standardization. Furthermore, SD-WAN management allows for the use of normalized interfaces, which simplifies the integration and management of different network interfaces under a unified SD-WAN policy. These capabilities are crucial for efficiently controlling extensive networks using SD-WAN technologies.
send
light_mode
delete
Question #15
Refer to the exhibit.

Which conclusion about the packet debug flow output is correct?

Which conclusion about the packet debug flow output is correct?
- AThe total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
- BThe packet size exceeded the outgoing interface MTU.
- CThe number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.Most Voted
- DThe number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
Correct Answer:
C
C
send
light_mode
delete
All Pages