Fortinet NSE7_SDW-7.2 Exam Practice Questions (P. 2)
- Full Access (70 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Which are three key routing principles in SD-WAN? (Choose three.)
- ABy default. SD-WAN members are skipped if they do not have a valid route to the destination.
- BBy default. SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.
- CFortiGate performs route lookups for new sessions only.
- DSD-WAN rules have precedence over ISDB routes.
- ERegular policy routes have precedence over SD-WAN rules.
send
light_mode
delete
Question #7
Refer to the exhibit.

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)
- AOn the hubs, net-device must be enabled on all IPsec VPNs.
- Bauto-discovery-forwarder must be enabled on all IPsec VPNs.
- COn the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.
- DOn the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.
send
light_mode
delete
Question #8
Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?
- Aget router info routing-table all
- Bget ipsec tunnel list
- Cdiagnose vpn tunnel list
- Ddiagnose debug application ike
send
light_mode
delete
Question #9
What are two common use cases for remote internet access (RIA)? (Choose two.)
- AProvide internet access through the hub.
- BCentralize security inspection on the hub.
- CProvide thorough inspection on spokes.
- DProvide direct internet access on spokes.
send
light_mode
delete
Question #10
Refer to the exhibits.
Exhibit A.

Exhibit B.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)
Exhibit A.

Exhibit B.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)
- APort1 and port2 do not have a valid route to the destination.
- BThe session 3-tuple did not match any of the existing entries in the ISDB application cache.
- CFull SSL inspection is not enabled on the matching firewall policy.
- DFortiGate did not refresh the routing information on the session after the application was detected.
send
light_mode
delete
All Pages