Fortinet NSE7_SDW-7.0 Exam Practice Questions (P. 5)
- Full Access (62 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
Refer to the exhibits.


Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)


Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)
- AFortiGate does not install IPsec static routes for remote protected networks in the routing table.Most Voted
- BThe phase 1 configuration supports the network-overlay setting.Most Voted
- CFortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.
- DDead peer detection is disabled.
Correct Answer:
AC
AC
send
light_mode
delete
Question #22
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the source NAT (SNAT) global setting and exhibit B shows the routing table on FortiGate.
Based on the exhibits, which two actions does FortiGate perform on existing sessions established over port2, if the administrator increases the static route priority on port2 to 20? (Choose two.)
Exhibit A -

Exhibit B -

Exhibit A shows the source NAT (SNAT) global setting and exhibit B shows the routing table on FortiGate.
Based on the exhibits, which two actions does FortiGate perform on existing sessions established over port2, if the administrator increases the static route priority on port2 to 20? (Choose two.)
- AFortiGate flags the sessions as dirty.Most Voted
- BFortiGate continues routing the sessions with no SNAT, over port2.
- CFortiGate performs a route lookup for the original traffic only.
- DFortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.Most Voted
Correct Answer:
AD
AD
send
light_mode
delete
Question #23
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2? (Choose two.)
Exhibit A -

Exhibit B -

Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2? (Choose two.)
- AThe performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.Most Voted
- BFortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.
- CFortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
- DNon-TCP Facebook and YouTube traffic are not used for performance measurement.Most Voted
Correct Answer:
AD
AD
send
light_mode
delete
Question #24
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows an SD-WAN event log and exhibit B shows the member status and the SD-WAN rule configuration.
Based on the exhibits, which two statements are correct? (Choose two.)
Exhibit A -

Exhibit B -

Exhibit A shows an SD-WAN event log and exhibit B shows the member status and the SD-WAN rule configuration.
Based on the exhibits, which two statements are correct? (Choose two.)
- AFortiGate updated the outgoing interface list on the rule so it prefers port2.Most Voted
- BPort2 has the highest member priority.
- CPort2 has a lower latency than port1.Most Voted
- DSD-WAN rule ID 1 is set to lowest cost (SLA) mode.
Correct Answer:
AC
AC
send
light_mode
delete
Question #25
Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?
- AInterface-based shaping modeMost Voted
- BReverse-policy shaping mode
- CShared-policy shaping mode
- DPer-IP shaping mode
Correct Answer:
A
A

The perfect way to think about Interface-based shaping mode is that it adjusts traffic limits as a chunk of the total available bandwidth on an interface. This makes it super effective for managing bandwidth dynamically, reflecting real-time changes in network capacity and ensuring optimal performance across different conditions. So yeah, just imagine intuitively distributing bandwidth where it's most needed, based on how busy each line gets. Cool, right?
send
light_mode
delete
All Pages