Fortinet

NSE7_SDW-7.0 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 62-question bank.

Provider
Fortinet
Question bank
62
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE7_SDW-7.0, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which diagnostic command can you use to show the member utilization statistics measured by performance SLAs for the last 10 minutes?

    Choose one answer.

    • diagnose sys sdwan intf-sla-log
    • diagnose sys sdwan health-check
    • diagnose sys sdwan log
    • diagnose sys sdwan sla-log
  2. Question 2 · 1

    Refer to the exhibits. Exhibit A - Exhibit B - Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate. Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • port1 is assigned a manual IP address.
    • port1 is referenced in a firewall policy.
    • port2 is referenced in a static route.
    • port1 and port2 are not administratively down.
  3. Question 3 · 1

    Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)

    Choose all answers that apply.

    • The sdwan_service_id flag in the session information is 0.
    • All SD-WAN rules have the default setting enabled.
    • Traffic does not match any of the entries in the policy route table.
    • Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
  4. Question 4 · 1

    Refer to the exhibit. An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0. Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
    • T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
    • T_INET_0_0 does not have a valid route to the destination.
    • T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
  5. Question 5 · 1

    Refer to the exhibit. Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • FortiGate flushes all sessions.
    • FortiGate terminates the old sessions.
    • FortiGate does not change existing sessions.
    • FortiGate evaluates new sessions.
  6. Question 6 · 1

    Which two statements about SD-WAN central management are true? (Choose two.)

    Choose all answers that apply.

    • The objects are saved in the ADOM common object database.
    • It does not support meta fields.
    • It uses templates to configure SD-WAN on managed devices.
    • It supports normalized interfaces for SD-WAN member configuration.
  7. Question 7 · 1

    Refer to the exhibit. Which conclusion about the packet debug flow output is correct?

    Choose one answer.

    Question illustration 1
    • The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
    • The packet size exceeded the outgoing interface MTU.
    • The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
    • The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
  8. Question 8 · 1

    Which are two benefits of using CLI templates in FortiManager? (Choose two.)

    Choose all answers that apply.

    • You can reference meta fields.
    • You can configure interfaces as SD-WAN members without having to remove references first.
    • You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.
    • You can configure advanced CLI settings.
  9. Question 9 · 1

    Refer to the exhibits. Exhibit A - Exhibit B - Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status. If port2 is detected dead by FortiGate, what is the expected behavior?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • Port2 becomes alive after three successful probes are detected.
    • FortiGate removes all static routes for port2.
    • The administrator manually restores the static routes for port2, if port2 becomes alive.
    • Host 8.8.8.8 is reachable through port1 and port2.
  10. Question 10 · 1

    Refer to the exhibit. The device exchanges routes using IBGP. Which two statements are correct about the IBGP configuration and routing information on the device? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Each BGP route is three hops away from the destination.
    • ibgp-multipath is disabled.
    • additional-path is enabled.
    • You can run the get router info routing-table database command to display the additional paths.
  11. Question 11 · 1

    In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)

    Choose all answers that apply.

    • It provides the benefits of a full-mesh topology in a hub-and-spoke network.
    • It provides direct connectivity between spokes by creating shortcuts.
    • It enables spokes to bypass the hub during shortcut negotiation.
    • It enables spokes to establish shortcuts to third-party gateways.
  12. Question 12 · 1

    Which two protocols in the IPsec suite are most used for authentication and encryption? (Choose two.)

    Choose all answers that apply.

    • Encapsulating Security Payload (ESP)
    • Secure Shell (SSH)
    • Internet Key Exchange (IKE)
    • Security Association (SA)
  13. Question 13 · 1

    Refer to the exhibit. Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?

    Choose one answer.

    Question illustration 1
    • All traffic from a source IP to a destination IP is sent to the same interface.
    • All traffic from a source IP is sent to the same interface.
    • All traffic from a source IP is sent to the most used interface.
    • All traffic from a source IP to a destination IP is sent to the least used interface.
  14. Question 14 · 1

    Refer to the exhibits. Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    Question illustration 2
    • FortiGate does not install IPsec static routes for remote protected networks in the routing table.
    • The phase 1 configuration supports the network-overlay setting.
    • FortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.
    • Dead peer detection is disabled.
  15. Question 15 · 1

    Refer to the exhibits. Exhibit A - Exhibit B - Exhibit A shows the source NAT (SNAT) global setting and exhibit B shows the routing table on FortiGate. Based on the exhibits, which two actions does FortiGate perform on existing sessions established over port2, if the administrator increases the static route priority on port2 to 20? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    Question illustration 2
    • FortiGate flags the sessions as dirty.
    • FortiGate continues routing the sessions with no SNAT, over port2.
    • FortiGate performs a route lookup for the original traffic only.
    • FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free