Updated Nov-2023 Pass NSE7_SDW-7.0 Exam - Real Practice Test Questions [Q39-Q61]

Share

Updated Nov-2023 Pass NSE7_SDW-7.0 Exam - Real Practice Test Questions

Download Free Fortinet NSE7_SDW-7.0 Real Exam Questions

NEW QUESTION # 39
Refer to the exhibit.

Which conclusion about the packet debug flow output is correct?

  • A. The original traffic exceeded the maximum packets per second of the outgoing interface, and the packet was dropped.
  • B. The original traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.
  • C. The original traffic exceeded the maximum bandwidth of the outgoing interface, and the packet was dropped.
  • D. The reply traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.

Answer: B


NEW QUESTION # 40
What are two reasons for using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two )

  • A. It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
  • B. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
  • C. It improves SD-WAN performance on the managed FortiGate devices.
  • D. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
  • E. It acts as a policy compliance entity to review all managed FortiGate devices.

Answer: B,D


NEW QUESTION # 41
Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)

  • A. By default, FortiGate does not check if the selected member has a valid route to the destination.
  • B. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for local-out traffic.
  • C. By default, local-out traffic does not use SD-WAN.
  • D. You must configure each local-out feature individually, to use SD-WAN.

Answer: C,D


NEW QUESTION # 42
Which two interfaces are considered overlay links? (Choose two.)

  • A. Physical
  • B. GRE
  • C. IPsec
  • D. LAG

Answer: B,C


NEW QUESTION # 43
Which components make up the secure SD-WAN solution?

  • A. Datacenter, branch offices, and public cloud
  • B. FortiGate, FortiManager, FortiAnalyzer, and FortiDeploy
  • C. Telephone, ISDN, and telecom network.
  • D. Application, antivirus, and URL, and SSL inspection

Answer: B


NEW QUESTION # 44
Refer to the exhibit.

Based on the output, which two conclusions are true? (Choose two.)

  • A. There is more than one SD-WAN rule configured.
  • B. Entry 1(id=1) is a regular policy route.
  • C. The all_rules rule represents the implicit SD-WAN rule.
  • D. The SD-WAN rules take precedence over regular policy routes.

Answer: A,B


NEW QUESTION # 45
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)

  • A. The sdwan_service_id flag in the session information is 0.
  • B. All SD-WAN rules have the default setting enabled.
  • C. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
  • D. Traffic does not match any of the entries in the policy route table.

Answer: A,D

Explanation:
sdwan_service_id is 0 = match SD-WAN implicit rule, study guide 7.0 page 120, 7.2 page 149 SD-WAN rules internally are interpreted as a Policy route, so when the traffic doesn't match with any policy route, it will be flowing by implict policy.


NEW QUESTION # 46
Refer to the exhibit.

The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device? (Choose two.)

  • A. ibgp-multipath is disabled.
  • B. You can run the get router info routing-table database command to display the additional paths.
  • C. Each BGP route is three hops away from the destination.
  • D. additional-path is enabled.

Answer: B,D


NEW QUESTION # 47
Refer to the exhibit.

Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)

  • A. Set load-balance-mode source-ip-ip-based.
  • B. Set cost 15.
  • C. Set priority 10.
  • D. Set source 100.64.1.1.

Answer: B,C


NEW QUESTION # 48
Refer to the exhibit.

Based on the exhibit, which statement about FortiGate re-evaluating traffic is true?

  • A. The type of traffic defined and allowed on firewall policy ID 1 is UDP.
  • B. Changes have been made on firewall policy ID 1 on FortiGate.
  • C. Firewall policy ID 1 has source NAT disabled.
  • D. FortiGate has terminated the session after a change on policy ID 1.

Answer: B


NEW QUESTION # 49
Refer to the exhibit.

Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)

  • A. Set load-balance-mode source-ip-ip-based.
  • B. Set cost 15.
  • C. Set priority 10.
  • D. Set source 100.64.1.1.

Answer: B,C


NEW QUESTION # 50
Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

  • A. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
  • B. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
  • C. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
  • D. T_INET_0_0 does not have a valid route to the destination.

Answer: B,D

Explanation:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Assigning-Priority-to-SD-WAN-Members-for-Default/ta-p/230911


NEW QUESTION # 51
Which two statements about SD-WAN central management are true? (Choose two.)

  • A. The objects are saved in the ADOM common object database.
  • B. It uses templates to configure SD-WAN on managed devices.
  • C. It supports normalized interfaces for SD-WAN member configuration.
  • D. It does not support meta fields.

Answer: A,B

Explanation:
Normalized interfaces are not supported for SD-WAN templates. You can create multiple SD-WAN zones and add interface members to the SD-WAN zones. You must bind the interface members by name to physical interfaces or VPN interfaces.https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-fmg


NEW QUESTION # 52
Refer to the exhibit.

Based on the exhibit, which two actions does FortiGate perform on traffic passing through port2? (Choose two.)

  • A. FortiGate flushes all routing information from the session table, after a route change.
  • B. FortiGate performs routing lookups for new sessions only, after a route change.
  • C. FortiGate does not change the routing information on existing sessions that use a valid gateway, after a route change.
  • D. FortiGate always blocks all traffic, after a route change.

Answer: B,C


NEW QUESTION # 53
Which SD-WAN setting enables FortiGate to delay the recovery of ADVPN shortcuts?

  • A. auto-discovery-shortcuts
  • B. link-down-failover
  • C. idle-timeout
  • D. hold-down-time

Answer: D


NEW QUESTION # 54
Which two performance SLA protocols enable you to verify that the server response contains a specific value?
(Choose two.)

  • A. icmp
  • B. twamp
  • C. http
  • D. dns

Answer: C,D


NEW QUESTION # 55
Refer to the exhibits.
Exhibit A

Exhibit B

Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2? (Choose two.)

  • A. Non-TCP Facebook and YouTube traffic are not used for performance measurement.
  • B. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
  • C. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
  • D. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.

Answer: A,C

Explanation:
Study Guide 7.0, pages 88 - 89.
Study Guide 7.2, pages 103 - 104.
Another comment said "because without using application Control on the firewall policy, SDWAN can't work" but there is a app control "default" defined on config.


NEW QUESTION # 56
Refer to the exhibits.

Which conclusion about the packet debug flow output is correct?

  • A. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • B. The packet size exceeded the outgoing interface MTU.
  • C. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
  • D. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.

Answer: A

Explanation:
In a Per-IP shaper configuration, if an IP address exceeds the configured concurrent session limit, the message "Denied by quota check" appears. SD-WAN 7.0 Study Guide page 287


NEW QUESTION # 57
What are two reasons why FortiGate would be unable to complete the zero-touch provisioning process?
(Choose two.)

  • A. The zero-touch provisioning process has completed internally, behind FortiGate.
  • B. The FortiGate cloud key has not been added to the FortiGate cloud portal.
  • C. FortiDeploy has connected with FortiGate and provided the initial configuration to contact FortiManager
  • D. A factory reset performed on FortiGate.
  • E. FortiGate has obtained a configuration from the platform template in FortiGate cloud.

Answer: A,B


NEW QUESTION # 58
Refer to the exhibit.

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

  • A. type must be set to static.
  • B. mode-cfg must be enabled.
  • C. add-route must be disabled.
  • D. exchange-interface-ip must be enabled.

Answer: C

Explanation:
for using "non ike" routes (for example BGP/static and so on) you must do disable the add-route that inject automatically kernel route based on p2 selectors from the remote site from the SD-WAN_7.2_Study_Guide page 236


NEW QUESTION # 59
Which are two benefits of using CLI templates in FortiManager? (Choose two.)

  • A. You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.
  • B. You can configure interfaces as SD-WAN members without having to remove references first.
  • C. You can configure advanced CLI settings.
  • D. You can reference meta fields.

Answer: C,D


NEW QUESTION # 60
Refer to the exhibits.
Exhibit A

Exhibit B -

Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

  • A. The traffic will be routed over T_INET_0_0.
  • B. The traffic will be routed over T_INET_1_0.
  • C. The traffic will be load balanced across all three overlays.
  • D. The traffic will be routed over T_MPLS_0.

Answer: D


NEW QUESTION # 61
......

NSE7_SDW-7.0 Dumps 100 Pass Guarantee With Latest Demo: https://www.easy4engine.com/NSE7_SDW-7.0-test-engine.html

Pass Your Exam With 100% Verified NSE7_SDW-7.0 Exam Questions: https://drive.google.com/open?id=1fzcv7GjXNN4sroDLSq3mGNP7mXqx0ioC