Download Free Fortinet NSE7_SDW-7.2 Exam Questions & Answer
Online VALID NSE7_SDW-7.2 Exam Dumps File Instantly
Fortinet NSE7_SDW-7.2 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
NEW QUESTION # 47
Refer to the exhibit.
The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device?
(Choose two.)
- A. You can run the get router info routing-table database command to display the additional paths.
- B. additional-path is enabled.
- C. ibgp-multipath is disabled.
- D. Each BGP route is three hops away from the destination.
Answer: A,B
NEW QUESTION # 48
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferred member in the matching SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?
- A. Enable snat-route-change under config system global.
- B. Enable auxiliary-session under config system settings.
- C. Disable t#p-session-without-syn under config system settings.
- D. Disable allow-subnet-overlap under config system settings.
Answer: B
NEW QUESTION # 49
Exhibit.
The exhibit shows VPN event logs on FortiGate. In the output shown in the exhibit, which statement is true?
- A. There are no IPsec tunnel statistics log messages for ADVPN cuts.
- B. The master tunnel T_INET_0 cannot accept the ADVPN shortcut.
- C. There is one shortcut tunnel built from master tunnel T_MPLS_0.
- D. The VPN tunnel T_MPLS_0 is a shortcut tunnel.
Answer: C
Explanation:
VPN event logs record the status of VPN tunnels, such as the establishment, termination, or failure of a tunnel. The output includes the following information:
* logid: the log ID number
* type: the log type, either traffic or event
* subtype: the log subtype, either vpn or ipsec
* level: the log level, either error, warning, or notice
* vd: the virtual domain name
* logdesc: the log description
* msg: the log message
* action: the log action, such as tunnel-up, tunnel-down, or tunnel-stats
* remip: the remote IP address
* locip: the local IP address
* remport: the remote port number
* locport: the local port number
* outintf: the outgoing interface name
* cookies: the IKE SA cookies
* user: the user name
* group: the user group name
* useralt: the alternative user name
* xauthuser: the XAuth user name
* authgroup: the XAuth user group name
* assignip: the assigned IP address
* vpntunnel: the VPN tunnel name
* tunnellip: the tunnel loopback IP address
* tunnelid: the tunnel ID number
* tunneltype: the tunnel type, either ipsec or ssl
* duration: the tunnel duration in seconds
* sentbyte: the number of bytes sent
* rcvdbyte: the number of bytes received
* nextstat: the next statistics interval in seconds
* advpnsc: the ADVPN shortcut flag, either 0 or 1
Based on the exhibit, the following statement is true:
* There is one shortcut tunnel built from master tunnel T_MPLS_0. This means that the VPN tunnel T_MPLS_0 is a master tunnel that can send ADVPN shortcut offers to other spokes, and the VPN tunnel T_MPLS_0_0 is a shortcut tunnel that is built from the master tunnel T_MPLS_01. In the exhibit, the log action for T_MPLS_0 is tunnel-up, and the log action for T_MPLS_0_0 is shortcut-up.
The advpnsc flag for T_MPLS_0 is 0, indicating that it is not a shortcut tunnel, while the advpnsc flag for T_MPLS_0_0 is 1, indicating that it is a shortcut tunnel.
NEW QUESTION # 50
Refer to the exhibit.
Which are two expected behaviors of the traffic that matches the traffic shaper? (Choose two.)
- A. The number of simultaneous connections among all source IP addresses cannot exceed five connections.
- B. The traffic shaper limits the bandwidth of each source IP address to a maximum of 625 KB/sec.
- C. The number of simultaneous connections allowed for each source IP address cannot exceed five
connections. - D. The traffic shaper limits the combined bandwidth of all connections to a maximum of 5 MB/sec.
Answer: B,C
NEW QUESTION # 51
Refer to the exhibit.
The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths.
However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.
Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)
- A. Enable soft-reconfiguration
- B. Set advertisement-interval to the number of additional paths to advertise
- C. Enable route-reflector-client
- D. Set adv-additional-path to the number of additional paths to advertise
- E. Set additional-path to send
Answer: C,D,E
NEW QUESTION # 52
Refer to the exhibit.
Which conclusion about the packet debug flow output is correct?
- A. The reply traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was
dropped. - B. The original traffic exceeded the maximum bandwidth of the outgoing interface, and the packet was
dropped. - C. The original traffic exceeded the maximum packets per second of the outgoing interface, and the packet
was dropped. - D. The original traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet
was dropped.
Answer: D
NEW QUESTION # 53
Refer to the exhibit.
The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device?
(Choose two.)
- A. You can run the get router info routing-table database command to display the additional paths.
- B. additional-path is enabled.
- C. ibgp-multipath is disabled.
- D. Each BGP route is three hops away from the destination.
Answer: A,B
NEW QUESTION # 54
Refer to the exhibit.
The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured packet loss will make T_INET_1_0 the new preferred
member?
- A. When T_INET_1_0 has 4% packet loss.
- B. When T_INET_0_0 has 12% packet loss.
- C. When T_INET_0_0 has 4% packet loss.
- D. When all three members have the same packet loss.
Answer: D
NEW QUESTION # 55
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2? (Choose two.)
- A. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
- B. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
- C. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.
- D. Non-TCP Facebook and YouTube traffic are not used for performance measurement.
Answer: B,D
Explanation:
Study Guide 7.2, pages 103 - 104. Another comment said "because without using application Control on the firewall policy, SDWAN can't work" but there is a app control "default" defined on config.
NEW QUESTION # 56
Refer to the exhibit.
Based on the exhibit, which action does FortiGate take?
- A. FortiGate brings up port5 after it detects all SD-WAN members as alive.
- B. FortiGate bounces port5 after it detects all SD-WAN members as dead.
- C. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
- D. FortiGate brings down port5 after it detects all SD-WAN members as dead.
Answer: C
NEW QUESTION # 57
Refer to the exhibit.
Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?
- A. mode-cfg must be enabled.
- B. exchange-interface-ip must be enabled.
- C. type must be set to static.
- D. add-route must be disabled.
Answer: D
NEW QUESTION # 58
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the
application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay
zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2?
(Choose two.)
- A. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing
through the member. - B. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.
- C. The performance is an average of the metrics measured for Facebook and YouTube traffic passing
through the member. - D. Non-TCP Facebook and YouTube traffic are not used for performance measurement.
Answer: C,D
Explanation:
Explanation
Study Guide 7.2, pages 103 - 104. Another comment said "because without using application Control on the
firewall policy, SDWAN can't work" but there is a app control "default" defined on config.
NEW QUESTION # 59
Refer to the exhibit.
The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate appliance that supports hardware offloading. Based on the information shown in the exhibits, which two statements about the session are true? (Choose two.)
- A. The original direction of the symmetric traffic flows from port3 to port2.
- B. The auxiliary session can be offloaded to hardware.
- C. The reply direction of the asymmetric traffic flows from port2 to port3.
- D. The main session cannot be offloaded to hardware.
Answer: B,C
NEW QUESTION # 60
Which two conclusions for traffic that matches the traffic shaper are true? (Choose two.)
- A. The measured bandwidth is less than 100 KBps.
- B. The traffic shaper drops packets if the bandwidth exceeds 6250 KBps.
- C. The traffic shaper drops packets if the bandwidth is less than 2500 KBps.
- D. The traffic shaper limits the bandwidth of each source IP to a maximum of 6250 KBps.
Answer: A,B
NEW QUESTION # 61
Refer to the Exhibits:
Exhibit A, which shows the SD-WAN performance SLA and exhibit B shows the health of the participating SD-WAN members.
Based on the exhibits, which statement is correct?
- A. Port2 needs to wait 500 milliseconds to change the status from alive to dead.
- B. Static routes using port2 are active in the routing table.
- C. FortiGate has not received three consecutive requests from the SLA server configured for port2.
- D. The dead member interface stays unavailable until an administrator manually brings the interface back.
Answer: B
NEW QUESTION # 62
Exhibit.
Which conclusion about the packet debug flow output is correct?
- A. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions
configured in the firewall policy, and the packet was dropped. - B. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions
configured in the traffic shaper, and the packet was dropped. - C. The packet size exceeded the outgoing interface MTU.
- D. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions
configured in the traffic shaper, and the packet was dropped.
Answer: D
Explanation:
Explanation
In a Per-IP shaper configuration, if an IP address exceeds the configured concurrent session limit, the message
"Denied by quota check" appears.SD-WAN 7.0 Study Guide page 287
NEW QUESTION # 63
What are two benefits of using forward error correction (FEC) in IPsec VPNs? (Choose two.)
- A. FEC supports hardware offloading.
- B. FEC improves reliability of noisy links.
- C. FEC can leverage multiple IPsec tunnels for parity packets transmission.
- D. FEC transmits parity packets that can be used to reconstruct packet loss.
Answer: B,D
NEW QUESTION # 64
Which statement about using BGP for ADVPN is true?
- A. You must use BGP to route traffic for both overlay and underlay links.
- B. You must configure AS path prepending.
- C. IBGP is preferred over EBGP, because IBGP preserves next hop information.
- D. You must configure BGP communities.
Answer: C
Explanation:
ADVPN is a technology that allows dynamic creation of IPsec tunnels between branch sites without requiring pre-configured policies or keys. BGP is a routing protocol that can be used to exchange routes between ADVPN peers. IBGP is a type of BGP that runs between routers in the same autonomous system (AS), while EBGP is a type of BGP that runs between routers in different ASes. IBGP is preferred over EBGP for ADVPN, because IBGP preserves the next hop information of the routes, which is needed to establish the IPsec tunnels. EBGP changes the next hop information to the EBGP peer address, which may not be reachable by the ADVPN peers. Therefore, using IBGP for ADVPN avoids the need to configure additional static routes or redistribute routes between BGP and another routing protocol. References = ADVPN with BGP as the routing protocol, ADVPN, SD-WAN self-healing with BGP, Technical Tip: ADVPN with BGP as the routing protocol The statement that IBGP is preferred over EBGP for ADVPN because IBGP preserves next hop information (D) is true. In a typical ADVPN deployment, it's beneficial to maintain next hop information across the network to ensure proper routing and optimal path selection. References: This understanding comes from my knowledge of Fortinet's SD-WAN and ADVPN configurations, where BGP's behavior in terms of next hop preservation is a key consideration.
NEW QUESTION # 65
Refer to the exhibit.
Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)
- A. Set load-balance-mode source-ip-ip-based.
- B. Set priority 10.
- C. Set source 100.64.1.1.
- D. Set cost 15.
Answer: B,D
NEW QUESTION # 66
Which two statements about SD-WAN central management are true? (Choose two.)
- A. The objects are saved in the ADOM common object database.
- B. It does not support meta fields.
- C. It supports normalized interfaces for SD-WAN member configuration.
- D. It uses templates to configure SD-WAN on managed devices.
Answer: A,D
Explanation:
Normalized interfaces are not supported for SD-WAN templates. You can create multiple SD-WAN zones and add interface members to the SD-WAN zones. You must bind the interface members by name to physical interfaces or VPN interfaces.https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-fmg
NEW QUESTION # 67
Refer to the exhibit.
Based on the exhibit, which two actions does FortiGate perform on traffic passing through port2? (Choose two.)
- A. FortiGate does not change the routing information on existing sessions that use a valid gateway, after a route change.
- B. FortiGate flushes all routing information from the session table, after a route change.
- C. FortiGate performs routing lookups for new sessions only, after a route change.
- D. FortiGate always blocks all traffic, after a route change.
Answer: A,C
NEW QUESTION # 68
Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available
bandwidth?
- A. Reverse-policy shaping mode
- B. Per-IP shaping mode
- C. Interface-based shaping mode
- D. Shared-policy shaping mode
Answer: C
Explanation:
Explanation
Interface-based shaping goes further, enabling traffic controls based on percentage of the interface bandwidth.
NEW QUESTION # 69
Exhibit.
The exhibit shows the output of the command diagnose sys sdwan health-check status collected on a FortiGate device. Which two statements are correct about the health check status on this FortiGate device? (Choose two.)
- A. The health-check VPN_PING orders the members according to the lowest jitter.
- B. The interface T_INET_1 missed one SLA target.
- C. There is no SLA criteria configured for the health-check Level3_DNS.
- D. The interface T_INET_0 missed three SLA targets.
Answer: A,C
Explanation:
According to the FortiGate / FortiOS 6.4.2 Administration Guide, the health check status command displays the status of the health check probes for each SD-WAN member interface. The output includes the following information:
state: the current state of the interface, either alive or dead
packet-loss: the percentage of packets lost during the health check
latency: the average round-trip time in milliseconds
jitter: the variation in latency
mos: the mean opinion score, a measure of voice quality
bandwidth: the available bandwidth in kilobits per second for each direction (up, down, bi) sla map: a bitmap that indicates which SLA criteria are met or failed Based on the exhibit, the following statements are correct:
The health-check VPN_PING orders the members according to the lowest jitter. This means that the interface with the lowest jitter value is listed first, followed by the next lowest, and so on1. In the exhibit, the order is T_MPLS, T_INET_1, and T_INET_0.
There is no SLA criteria configured for the health-check Level3_DNS. This means that the health check does not use any SLA parameters to determine the state of the interface2. In the exhibit, the sla map value is 0x0 for both port1 and port2, indicating that no SLA criteria are applied.
NEW QUESTION # 70
Refer to the exhibit.
Based on the exhibit, which two statements are correct about the health of the selected members? (Choose
two.)
- A. FortiGate can offload the traffic that is subject to passive monitoring to hardware.
- B. After FortiGate switches to active mode, FortiGate never fails back to passive monitoring.
- C. During passive monitoring, FortiGate can't detect dead members.
- D. FortiGate passively monitors the member if TCP traffic is passing through the member.
Answer: C,D
NEW QUESTION # 71
Which diagnostic command can you use to show the SD-WAN rules, interface information, and state?
- A. diagnose sys sdwan service
- B. diagnose sys sdwan route-tag-list
- C. diagnose sys sdwan neighbor
- D. diagnose sys sdwan member
Answer: D
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/818746/sd-wan-related-diagnose-commands
NEW QUESTION # 72
......
NSE7_SDW-7.2 Exam Dumps For Certification Exam Preparation: https://www.prep4surereview.com/NSE7_SDW-7.2-latest-braindumps.html
100% Pass Guaranteed Download NSE 7 Network Security Architect Exam PDF Q&A: https://drive.google.com/open?id=14rEUhzCInk9Q0q1Q5fNjxbNUrIWe1BsL
