Fortinet

NSE7_SDW-7.2 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 70-question bank.

Provider
Fortinet
Question bank
70
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE7_SDW-7.2, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Refer to the exhibit. The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths. Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)

    Choose all answers that apply.

    Question illustration 1
    • Enable soft-reconfiguration
    • Enable route-reflector-client
    • Set additional-path to send
    • Set adv-additional-path to the number of additional paths to advertise
    • Set advertisement-interval to the number of additional paths to advertise
  2. Question 2 · 1

    Refer to the exhibits. Exhibit A. Exhibit B. An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A. After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1. Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    Question illustration 2
    • Port1 and port2 do not have a valid route to the destination.
    • The session 3-tuple did not match any of the existing entries in the ISDB application cache.
    • Full SSL inspection is not enabled on the matching firewall policy.
    • FortiGate did not refresh the routing information on the session after the application was detected.
  3. Question 3 · 1

    Which diagnostic command can you use to show the configured SD-WAN zones and their assigned members?

    Choose one answer.

    • diagnose sys sdwan member
    • diagnose sys sdwan interface
    • diagnose sys sdwan zone
    • diagnose sys sdwan service
  4. Question 4 · 1

    Which statement is correct about SD-WAN and ADVPN?

    Choose one answer.

    • SD-WAN can steer traffic to ADVPN shortcuts only for rules defined with strategy manual or best quality.
    • SD-WAN does not monitor the health and performance of ADVPN shortcuts.
    • SD-WAN cannot steer traffic to ADVPN shortcuts established over IPSec overlays if the zone contains physical interfaces.
    • SD-WAN can steer traffic to ADVPN shortcuts established over IPsec overlays configured as SD-WAN members.
  5. Question 5 · 1

    Refer to the exhibit. The exhibit shows the SD-WAN rule status and configuration. Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

    Choose one answer.

    Question illustration 1
    • When T_INET_0_0 has a latency of 250 ms.
    • When T_MPLS_0 has a latency of 80 ms.
    • When T_INET_0_0 and T_MPLS_0 have the same latency.
    • When T_MPLS_0 has a latency of 100 ms.
  6. Question 6 · 1

    What is a benefit of using application steering in SD-WAN?

    Choose one answer.

    • The traffic always skips the regular policy routes.
    • You do not need to configure firewall policies that accept the SD-WAN traffic.
    • You steer traffic based on the detected application.
    • You do not need to enable SSL inspection.
  7. Question 7 · 1

    Refer to the exhibit. Based on the exhibit, which two statements are correct about the health of the selected members? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • After FortiGate switches to active mode, the SLA performance rule never fallsback to passive monitoring.
    • FortiGate passively monitors the member if TCP traffic is passing through the member.
    • FortiGate can offload the traffic that is subject to passive monitoring to hardware.
    • During passive monitoring, the SLA performance rule cannot detect dead members.
  8. Question 8 · 1

    Which two statements about the SD-WAN members are true? (Choose two.)

    Choose all answers that apply.

    • Interfaces of type virtual wire pair can be used as SD-WAN members.
    • You can manually define the SD-WAN members sequence number.
    • An SD-WAN member can belong to two or more SD-WAN zones.
    • Interfaces of type VLAN can be used as SD-WAN members.
  9. Question 9 · 1

    Refer to the exhibit. An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0. However, the traffic is routed over T_INET_1. Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • T_INET_1 has a lower route priority value (higher priority) than T_INET_0.
    • The traffic matches a regular policy route configured with T_INET_1 as the outgoing device.
    • T_INET_1 has a higher member configuration priority than T_INET_0.
    • T_INET_0 does not have a valid route to the destination.
  10. Question 10 · 1

    Within IPsec tunnel templates available on FortiManager, which template will you use to configure static tunnels for a hub and spoke topology?

    Choose one answer.

    • Hub_IPsec_Recommended
    • Static_IPsec_Recommended
    • IPsec Fortinet Recommended
    • Branch IPsec Recommended
  11. Question 11 · 1

    The administrator uses the FortiManager SD-WAN overlay template to prepare an SD-WAN deployment. With information provided through the SD-WAN overlay template wizard, FortiManager creates templates ready to install on spoke and hub devices. Select three templates created by the SD-WAN overlay template for a spoke device. (Choose three.)

    Choose all answers that apply.

    • IPsec tunnel template
    • BGP template
    • Overlay template
    • System template
    • CLI template
  12. Question 12 · 1

    What are two advantages of using an IPsec recommended template to configure an IPsec tunnel in an hub-and-spoke topology? (Choose two.)

    Choose all answers that apply.

    • It ensures consistent settings between phase1 and phase2.
    • It guides the administrator to use Fortinet recommended settings.
    • The VPN monitor tool provides additional statistics for tunnels defined with an IPsec recommended template.
    • It automatically install IPsec tunnels to every spoke when they are added to the FortiManager ADOM.
  13. Question 13 · 1

    Refer to the exhibit. Based on the output, which two conclusions are true? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Entry 1 (id=1) is a regular policy route.
    • There is more than one SD-WAN rule configured.
    • The SD-WAN rules take precedence over regular policy routes.
    • The all_rules rule represents the implicit SD-WAN rule.
  14. Question 14 · 1

    What are two benefits of using forward error correction (FEC) in IPsec VPNs? (Choose two.)

    Choose all answers that apply.

    • FEC can leverage multiple IPsec tunnels for parity packets transmission.
    • FEC transmits parity packets that can be used to reconstruct packet loss.
    • FEC improves reliability of noisy links.
    • FEC supports hardware offloading.
  15. Question 15 · 1

    Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. Based on the exhibit, which statement is true?

    Choose one answer.

    Question illustration 1
    • You can move port1 from the underlay zone to the overlay zone.
    • You can delete the virtual-wan-link zone because it contains no member.
    • The corporate zone contains no member.
    • The overlay zone contains four members.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free