Fortinet NSE7_SDW-7.0 Exam Practice Questions (P. 4)
- Full Access (62 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
Which are two benefits of using CLI templates in FortiManager? (Choose two.)
- AYou can reference meta fields.Most Voted
- BYou can configure interfaces as SD-WAN members without having to remove references first.
- CYou can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.
- DYou can configure advanced CLI settings.Most Voted
Correct Answer:
AD
AD

Correct! CLI templates in FortiManager are indeed powerful primarily because they allow administrators to push advanced CLI settings to multiple devices, streamlining complex configurations. Additionally, their ability to reference meta fields is invaluable because it enables dynamic insertion of content like interface names and IP addresses when deploying configurations to different devices. This dual advantage enhances consistency and considerably reduces the possibility of human error during manual setup.
send
light_mode
delete
Question #17
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?
Exhibit A -

Exhibit B -

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?
- APort2 becomes alive after three successful probes are detected.
- BFortiGate removes all static routes for port2.Most Voted
- CThe administrator manually restores the static routes for port2, if port2 becomes alive.
- DHost 8.8.8.8 is reachable through port1 and port2.
Correct Answer:
B
B
send
light_mode
delete
Question #18
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device? (Choose two.)

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device? (Choose two.)
- AEach BGP route is three hops away from the destination.
- Bibgp-multipath is disabled.
- Cadditional-path is enabled.Most Voted
- DYou can run the get router info routing-table database command to display the additional paths.Most Voted
Correct Answer:
AB
AB
send
light_mode
delete
Question #19
In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)
- AIt provides the benefits of a full-mesh topology in a hub-and-spoke network.Most Voted
- BIt provides direct connectivity between spokes by creating shortcuts.Most Voted
- CIt enables spokes to bypass the hub during shortcut negotiation.
- DIt enables spokes to establish shortcuts to third-party gateways.
Correct Answer:
AB
AB

The advantages of enabling ADVPN in a hub-and-spoke topology include mimicking the benefits of a full mesh topology and allowing direct spoke-to-spoke connectivity through dynamically created shortcuts. Here, ADVPN effectively leverages these shortcuts only after the initial data packets are routed through the hub, maintaining a secure control. Furthermore, being a Fortinet-specific protocol, ADVPN doesn't support shortcut establishment to third-party gateways, ensuring a secure and proprietary environment within Fortinet deployed networks.
send
light_mode
delete
Question #20
Refer to the exhibit.

Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?

Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?
- AAll traffic from a source IP to a destination IP is sent to the same interface.Most Voted
- BAll traffic from a source IP is sent to the same interface.
- CAll traffic from a source IP is sent to the most used interface.
- DAll traffic from a source IP to a destination IP is sent to the least used interface.
Correct Answer:
B
B
send
light_mode
delete
All Pages