NSE7_SDW-7.2 Dumps with Practice Exam Questions Answers [Q20-Q36]

Share

NSE7_SDW-7.2 Dumps with Practice Exam Questions Answers

NSE7_SDW-7.2 by NSE 7 Network Security Architect Actual Free Exam Practice Test

NEW QUESTION # 20
Refer to the exhibit.

Based on the exhibit, which two statements are correct about the health of the selected members? (Choose two.)

  • A. After FortiGate switches to active mode, FortiGate never fails back to passive monitoring.
  • B. FortiGate can offload the traffic that is subject to passive monitoring to hardware.
  • C. During passive monitoring, FortiGate can't detect dead members.
  • D. FortiGate passively monitors the member if TCP traffic is passing through the member.

Answer: C,D


NEW QUESTION # 21
What is true about SD-WAN multiregion topologies?

  • A. Regions must correspond to geographical areas.
  • B. Each region has its own SD-WAN topology
  • C. It is not compatible with ADVPN.
  • D. Routing between the hub and spokes must be BGP.

Answer: B


NEW QUESTION # 22
Which statement about using BGP for ADVPN is true?

  • A. You must configure AS path prepending.
  • B. You must configure BGP communities.
  • C. You must use BGP to route traffic for both overlay and underlay links.
  • D. IBGP is preferred over EBGP, because IBGP preserves next hop information.

Answer: D

Explanation:
ADVPN is a technology that allows dynamic creation of IPsec tunnels between branch sites without requiring pre-configured policies or keys. BGP is a routing protocol that can be used to exchange routes between ADVPN peers. IBGP is a type of BGP that runs between routers in the same autonomous system (AS), while EBGP is a type of BGP that runs between routers in different ASes. IBGP is preferred over EBGP for ADVPN, because IBGP preserves the next hop information of the routes, which is needed to establish the IPsec tunnels. EBGP changes the next hop information to the EBGP peer address, which may not be reachable by the ADVPN peers. Therefore, using IBGP for ADVPN avoids the need to configure additional static routes or redistribute routes between BGP and another routing protocol. Reference = ADVPN with BGP as the routing protocol, ADVPN, SD-WAN self-healing with BGP, Technical Tip: ADVPN with BGP as the routing protocol The statement that IBGP is preferred over EBGP for ADVPN because IBGP preserves next hop information (D) is true. In a typical ADVPN deployment, it's beneficial to maintain next hop information across the network to ensure proper routing and optimal path selection. Reference: This understanding comes from my knowledge of Fortinet's SD-WAN and ADVPN configurations, where BGP's behavior in terms of next hop preservation is a key consideration.


NEW QUESTION # 23
Refer to the exhibits.
Exhibit A

Exhibit B -

Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

  • A. The traffic will be routed over T_INET_0_0.
  • B. The traffic will be load balanced across all three overlays.
  • C. The traffic will be routed over T_MPLS_0.
  • D. The traffic will be routed over T_INET_1_0.

Answer: D


NEW QUESTION # 24
Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change?
(Choose two.)

  • A. FortiGate does not change existing sessions.
  • B. FortiGate flushes all sessions.
  • C. FortiGate evaluates new sessions.
  • D. FortiGate terminates the old sessions.

Answer: A,C

Explanation:
FortiGate not to flag existing impacted session as dirty by setting firewall-session-dirty to check new. The results is that FortiGate evaluates only new session against the new firewall policy.


NEW QUESTION # 25
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferred member in the matching SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?

  • A. Enable auxiliary-session under config system settings.
  • B. Disable allow-subnet-overlap under config system settings.
  • C. Disable tp-session-without-syn under config system settings.
  • D. Enable snat-route-change under config system global.

Answer: A


NEW QUESTION # 26
Which two statements about SD-WAN central management are true? (Choose two.)

  • A. It uses templates to configure SD-WAN on managed devices.
  • B. It supports normalized interfaces for SD-WAN member configuration.
  • C. It does not support meta fields.
  • D. The objects are saved in the ADOM common object database.

Answer: A,D

Explanation:
Normalized interfaces are not supported for SD-WAN templates.
You can create multiple SD-WAN zones and add interface members to the SD-WAN zones.
You must bind the interface members by name to physical interfaces or VPN interfaces.
https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-fmg


NEW QUESTION # 27
Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on traffic passing through port2? (Choose
two.)

  • A. FortiGate performs routing lookups for new sessions only, after a route change.
  • B. FortiGate always blocks all traffic, after a route change.
  • C. FortiGate does not change the routing information on existing sessions that use a valid gateway, after a
    route change.
  • D. FortiGate flushes all routing information from the session table, after a route change.

Answer: A,C


NEW QUESTION # 28
Refer to the Exhibits:

Exhibit A, which shows the SD-WAN performance SLA and exhibit B shows the health of the participating SD-WAN members.
Based on the exhibits, which statement is correct?

  • A. Static routes using port2 are active in the routing table.
  • B. The dead member interface stays unavailable until an administrator manually brings the interface back.
  • C. Port2 needs to wait 500 milliseconds to change the status from alive to dead.
  • D. FortiGate has not received three consecutive requests from the SLA server configured for port2.

Answer: A


NEW QUESTION # 29

Which two conclusions for traffic that matches the traffic shaper are true? (Choose two.)

  • A. The measured bandwidth is less than 100 KBps.
  • B. The traffic shaper limits the bandwidth of each source IP to a maximum of 6250 KBps.
  • C. The traffic shaper drops packets if the bandwidth is less than 2500 KBps.
  • D. The traffic shaper drops packets if the bandwidth exceeds 6250 KBps.

Answer: A,D


NEW QUESTION # 30
Exhibit.

Which conclusion about the packet debug flow output is correct?

  • A. The packet size exceeded the outgoing interface MTU.
  • B. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
  • C. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • D. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.

Answer: D

Explanation:
In a Per-IP shaper configuration, if an IP address exceeds the configured concurrent session limit, the message "Denied by quota check" appears. SD-WAN 7.0 Study Guide page 287


NEW QUESTION # 31
What is the route-tag setting in an SD-WAN rule used for?

  • A. To indicate the routes for health check probes.
  • B. To indicate the members that can be used to route SD-WAN traffic.
  • C. To indicate the routes that can be used for routing SD-WAN traffic.
  • D. To indicate the destination of a rule based on learned BGP prefixes.

Answer: D


NEW QUESTION # 32
Which two performance SLA protocols enable you to verify that the server response contains a specific value?
(Choose two.)

  • A. http
  • B. twamp
  • C. dns
  • D. icmp

Answer: A,C


NEW QUESTION # 33
Refer to the exhibit.

Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)

  • A. Set load-balance-mode source-ip-ip-based.
  • B. Set priority 10.
  • C. Set source 100.64.1.1.
  • D. Set cost 15.

Answer: B,D


NEW QUESTION # 34
Refer to the exhibits.
Exhibit A

Exhibit B

Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2?
(Choose two.)

  • A. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.
  • B. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
  • C. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
  • D. Non-TCP Facebook and YouTube traffic are not used for performance measurement.

Answer: C,D

Explanation:
Study Guide 7.2, pages 103 - 104. Another comment said "because without using application Control on the firewall policy, SDWAN can't work" but there is a app control "default" defined on config.


NEW QUESTION # 35
Refer to the exhibits.
Exhibit A

Exhibit B

Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2?
(Choose two.)

  • A. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.
  • B. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
  • C. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
  • D. Non-TCP Facebook and YouTube traffic are not used for performance measurement.

Answer: C,D

Explanation:
Study Guide 7.2, pages 103 - 104. Another comment said "because without using application Control on the firewall policy, SDWAN can't work" but there is a app control "default" defined on config.


NEW QUESTION # 36
......


Fortinet NSE7_SDW-7.2 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Centralized Management: This area focuses on deploying and managing SD-WAN through FortiManager, including using IPsec templates and SD-WAN Overlay Templates. Mastery here demonstrates the abilities of Fortinet network and security professionals to streamline SD-WAN configuration, enhance security, and maintain consistent policies across multiple sites.
Topic 2
  • SD-WAN Overlay Design and Best Practices: It focuses on the deployment of hub-and-spoke IPsec topologies and configuring ADVPN. Proficiency in this topic ensures that Fortinet network and security professionals can implement effective and reliable SD-WAN overlays tailored to organizational needs.
Topic 3
  • SD-WAN Configuration: This topic assesses skills of Fortinet network and security professionals in setting up basic SD-WAN environments, including configuring Direct Internet Access (DIA), SD-WAN Members, and Performance Service Level Agreements (SLAs). Proficiency here ensures the ability to design efficient and resilient SD-WAN configurations.
Topic 4
  • SD-WAN Troubleshooting: Troubleshooting SD-WAN issues, including rules, routing, and ADVPN, is vital for maintaining network reliability. This section of the Fortinet NSE 7 - SD-WAN 7.2 exam tests the ability to diagnose and resolve SD-WAN problems using diagnostic commands and monitoring tools, ensuring robust and uninterrupted network operations.
Topic 5
  • Rules and Routing: Understanding SD-WAN Rules and Routing is crucial for directing traffic effectively. This topic of the NSE7_SDW-7.2 exam evaluates the capabilities of Fortinet network and security professionals to configure SD-WAN rules and routing.

 

Free NSE 7 Network Security Architect NSE7_SDW-7.2 Exam Question: https://www.prepawayete.com/Fortinet/NSE7_SDW-7.2-practice-exam-dumps.html

NSE7_SDW-7.2 dumps & NSE 7 Network Security Architect sure practice dumps: https://drive.google.com/open?id=1TtH39_gW4_OCHgR1qMZjCRW1SWk0D64D

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now