NSE7_SDW-7.2 Exam Dumps, NSE7_SDW-7.2 Practice Test Questions
PDF (New 2024) Actual Fortinet NSE7_SDW-7.2 Exam Questions
NEW QUESTION # 34
Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?
- A. Interface-based shaping mode
- B. Reverse-policy shaping mode
- C. Per-IP shaping mode
- D. Shared-policy shaping mode
Answer: A
Explanation:
Interface-based shaping goes further, enabling traffic controls based on percentage of the interface bandwidth.
NEW QUESTION # 35
Refer to the exhibit.
Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)
- A. Cost
- B. Priority
- C. Gateway IP
- D. Interface member
Answer: C,D
NEW QUESTION # 36
Which are two benefits of using CLI templates in FortiManager? (Choose two.)
- A. You can configure interfaces as SD-WAN members without having to remove references first.
- B. You can configure advanced CLI settings.
- C. You can reference meta fields.
- D. You can configure FortiManager to sync local configuration changes made on the managed device, to
the CLI template.
Answer: B,C
NEW QUESTION # 37
Which two statements about the SD-WAN zone configuration are true? (Choose two.)
- A. An SD-WAN member can belong to two or more zones.
- B. You can delete the default zones.
- C. Theservice-sla-tie-breaksetting enables you to configure preferred member selection based on the best
route to the destination. - D. The default zones are virtual-wan-link and SASE.
Answer: C,D
NEW QUESTION # 38
Refer to the exhibit.
Which two statements about the IPsec VPN configuration and the status of theIPsec VPNtunnel are true?
(Choose two.)
- A. FortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.
- B. The phase 1 configuration supports the network-overlay setting. Most Voted
- C. Dead peer detection is disabled.
- D. FortiGate does not install IPsec static routes for remote protected networks in the routing table. Most
Voted
Answer: B,D
NEW QUESTION # 39
Refer to the exhibit.
Which are two expected behaviors of the traffic that matches the traffic shaper? (Choose two.)
- A. The traffic shaper limits the combined bandwidth of all connections to a maximum of 5 MB/sec.
- B. The traffic shaper limits the bandwidth of each source IP address to a maximum of 625 KB/sec.
- C. The number of simultaneous connections allowed for each source IP address cannot exceed five
connections. - D. The number of simultaneous connections among all source IP addresses cannot exceed five connections.
Answer: B,C
NEW QUESTION # 40
Refer to the exhibit.
The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured packet loss will make T_INET_1_0 the new preferred member?
- A. When T_INET_0_0 has 4% packet loss.
- B. When T_INET_0_0 has 12% packet loss.
- C. When all three members have the same packet loss.
- D. When T_INET_1_0 has 4% packet loss.
Answer: C
NEW QUESTION # 41
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows an SD-WAN event log and exhibit B shows the member status and the SD-WAN rule
configuration.
Based on the exhibits, which two statements are correct? (Choose two.)
- A. SD-WAN rule ID 1 is set to lowest cost (SLA) mode.
- B. Port2 has a lower latency than port1.
- C. FortiGate updated the outgoing interface list on the rule so it prefers port2.
- D. Port2 has the highest member priority.
Answer: B,C
NEW QUESTION # 42
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the
default implicit SD-WAN rule? (Choose two )
- A. Traffic has matched none of the FortiGate policy routes.
- B. An absolute SD-WAN rule was defined and matched traffic.
- C. Matched traffic failed RPF and was caught by the rule.
- D. The FIB lookup resolved interface was the SD-WAN interface.
Answer: A,D
NEW QUESTION # 43
What are two benefits of choosing packet duplication over FEC for data loss correction on noisy links?
(Choose two.)
- A. Packet duplication uses smaller parity packets which results in less bandwidth consumption.
- B. Packet duplication can leverage multiple IPsec overlays for sending additional data.
- C. Packet duplication does not require a route to the destination.
- D. Packet duplication supports hardware offloading.
Answer: B,D
NEW QUESTION # 44
Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when
performing IKE negotiation? (Choose two )
- A. A peer ID is included in the first packet from the initiator, along with suggested security policies.
- B. The use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.
- C. XAuth is enabled as an additional level of authentication, which requires a username and password.
- D. A total of six packets are exchanged between an initiator and a responder instead of three packets.
Answer: C,D
NEW QUESTION # 45
Refer to the exhibit.
Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)
- A. Cost
- B. Priority
- C. Gateway IP
- D. Interface member
Answer: C,D
NEW QUESTION # 46
Which statement is correct about SD-WAN and ADVPN?
- A. You must use IKEv2 on IPsec tunnels.
- B. SD-WAN does not monitor the health and performance of ADVPN shortcuts.
- C. SD-WAN can steer traffic to ADVPN shortcuts, established over IPsec overlays, configured as
SD-WAN members. - D. Routes for ADVPN shortcuts must be manually configured.
Answer: C
NEW QUESTION # 47
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2?
(Choose two.)
- A. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
- B. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.
- C. Non-TCP Facebook and YouTube traffic are not used for performance measurement.
- D. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
Answer: C,D
Explanation:
Study Guide 7.2, pages 103 - 104. Another comment said "because without using application Control on the firewall policy, SDWAN can't work" but there is a app control "default" defined on config.
NEW QUESTION # 48
Which two interfaces are considered overlay links? (Choose two.)
- A. LAG
- B. Physical
- C. IPsec
- D. GRE
Answer: A
NEW QUESTION # 49
Which are two benefits of using CLI templates in FortiManager? (Choose two.)
- A. You can configure interfaces as SD-WAN members without having to remove references first.
- B. You can configure advanced CLI settings.
- C. You can reference meta fields.
- D. You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.
Answer: B,C
NEW QUESTION # 50
Refer to the exhibit.
Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be
used to select an outgoing interface in an SD-WAN rule? (Choose two.)
- A. Set priority 10.
- B. Set source 100.64.1.1.
- C. Set cost 15.
- D. Set load-balance-mode source-ip-ip-based.
Answer: A,C
NEW QUESTION # 51
Which two statements about SD-WAN central management are true? (Choose two.)
- A. It does not support meta fields.
- B. It supports normalized interfaces for SD-WAN member configuration.
- C. The objects are saved in the ADOM common object database.
- D. It uses templates to configure SD-WAN on managed devices.
Answer: C,D
Explanation:
Normalized interfaces are not supported for SD-WAN templates. You can create multiple SD-WAN zones and add interface members to the SD-WAN zones. You must bind the interface members by name to physical interfaces or VPN interfaces.https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-
NEW QUESTION # 52
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?
- A. Host 8.8.8.8 is reachable through port1 and port2.
- B. Port2 becomes alive after three successful probes are detected.
- C. FortiGate removes all static routes for port2.
- D. The administrator manually restores the static routes for port2, if port2 becomes alive.
Answer: C
Explanation:
This is due to Update static route is enable which removes the static route entry referencing the interface if the interface is dead
NEW QUESTION # 53
Which two performance SLA protocols enable you to verify that the server response contains a specific value?
(Choose two.)
- A. http
- B. twamp
- C. dns
- D. icmp
Answer: A,C
NEW QUESTION # 54
Refer to the exhibit.
An administrator used the SD-WAN overlay template to prepare an IPsec configuration for a hub-and-spoke SD-WAN topology. The exhibit shows the installation preview for one FortiGate device. In the exhibit, which statement best describes the configuration applied to the FortiGate device?
- A. It is a spoke device that establishes dynamic IPsec tunnels to the hub. The subnet range is
10.10.128.0/23. - B. It is a hub device and will automatically discover the spoke devices that are in the SD-WAN topology.
- C. It is a hub device. It can send ADVPN shortcut offers.
- D. It is a spoke device that establishes dynamic IPsec tunnels to the hub. It can send ADVPN shortcut requests.
Answer: D
Explanation:
According to the SD-WAN 7.2 Study Guide, the SD-WAN overlay template simplifies the configuration of IPsec tunnels in a hub-and-spoke topology. The template defines the following parameters:
type: dynamic for spokes, static for hubs
interface: the WAN interface to use for the IPsec tunnel
network-overlay: enable for spokes, disable for hubs
network-id: a unique identifier for each spoke
auto-discovery-sender: enable for hubs, disable for spokes
auto-discovery-receiver: enable for spokes, disable for hubs
Based on the exhibit, the FortiGate device has the following configuration:
type: dynamic
interface: port1
network-overlay: enable
network-id: 5
auto-discovery-sender: disable
auto-discovery-receiver: enable
Therefore, the FortiGate device is a spoke that establishes dynamic IPsec tunnels to the hub. It also has the network-overlay and auto-discovery-receiver options enabled, which means it can send ADVPN shortcut requests to other spokes when it receives a shortcut offer from the hub
NEW QUESTION # 55
Refer to the exhibit.
The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate
appliance that supports hardware offloading. Based on the information shown in the exhibits, which two
statements about the session are true? (Choose two.)
- A. The original direction of the symmetric traffic flows from port3 to port2.
- B. The auxiliary session can be offloaded to hardware.
- C. The main session cannot be offloaded to hardware.
- D. The reply direction of the asymmetric traffic flows from port2 to port3.
Answer: B,D
NEW QUESTION # 56
Refer to the exhibit.
An administrator used the SD-WAN overlay template to prepare an IPsec configuration for a hub-and-spoke
SD-WAN topology. The exhibit shows the installation preview for one FortiGate device. In the exhibit, which
statement best describes the configuration applied to the FortiGate device?
- A. It is a spoke device that establishes dynamic IPsec tunnels to the hub. The subnet range is
10.10.128.0/23. - B. It is a hub device and will automatically discover the spoke devices that are in the SD-WAN topology.
- C. It is a spoke device that establishes dynamic IPsec tunnels to the hub. It can send ADVPN shortcut
requests. - D. It is a hub device. It can send ADVPN shortcut offers.
Answer: C
Explanation:
Explanation
According to the SD-WAN 7.2 Study Guide, the SD-WAN overlay template simplifies the configuration of
IPsec tunnels in a hub-and-spoke topology. The template defines the following parameters:
type: dynamic for spokes, static for hubs
interface: the WAN interface to use for the IPsec tunnel
network-overlay: enable for spokes, disable for hubs
network-id: a unique identifier for each spoke
auto-discovery-sender: enable for hubs, disable for spokes
auto-discovery-receiver: enable for spokes, disable for hubs
Based on the exhibit, the FortiGate device has the following configuration:
type: dynamic
interface: port1
network-overlay: enable
network-id: 5
auto-discovery-sender: disable
auto-discovery-receiver: enable
Therefore, the FortiGate device is a spoke that establishes dynamic IPsec tunnels to the hub. It also has the
network-overlay and auto-discovery-receiver options enabled, which means it can send ADVPN shortcut
requests to other spokes when it receives a shortcut offer from the hub
NEW QUESTION # 57
Which two protocols in the IPsec suite are most used for authentication and encryption? (Choosetwo.)
- A. Encapsulating Security Payload (ESP)
- B. Secure Shell (SSH)
- C. Internet Key Exchange (IKE)
- D. Security Association (SA)
Answer: A,C
NEW QUESTION # 58
Refer to the exhibit.
Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)
- A. On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.
- B. On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.
- C. On the hubs, net-device must be enabled on all IPsec VPNs.
- D. auto-discovery-forwarder must be enabled on all IPsec VPNs.
Answer: A,B
NEW QUESTION # 59
......
Updated Apr-2024 Pass NSE7_SDW-7.2 Exam - Real Practice Test Questions: https://www.exam4docs.com/NSE7_SDW-7.2-study-questions.html
Dumps Moneyack Guarantee - NSE7_SDW-7.2 Dumps UpTo 90% Off: https://drive.google.com/open?id=1H6A-nK3w5OiElXBoIqX449cra9Sw1hMO

