Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Fortinet NSE6_SDW_AD-7.6 Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator Exam Practice Test

Demo: 28 questions
Total 95 questions

Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator Questions and Answers

Question 1

The FortiGate devices are managed by ForliManager, and are configured for direct internet access (DIA). You confirm that DIA is working as expected for each branch, and check the SD-WAN zone configuration and firewall policies shown in the exhibits.

Then, you use the SD-WAN overlay template to configure the IPsec overlay tunnels. You create the associated SD-WAN rules to connect existing branches to the company hub device and apply the changes on the branches.

After those changes, users complain that they lost internet access. DIA is no longer working.

Based on the exhibit, which statement best describes the possible root cause of this issue?

Options:

A.

The SD-WAN overlay template defines a zone for each underlay interface and moves the interfaces into those zones.

B.

The SD-WAN overlay template didn’t configure a firewall policy to allow traffic through the overlay.

C.

The SD-WAN overlay template redefines the interface gateway addresses if they are defined with metadata variables.

D.

The SD-WAN overlay template updates the SD-WAN template and the rules.

Question 2

Refer to the exhibit.

The exhibit shows output of the command diagnose sys adwan aervice4 collected on a FortiGate device.

The administrator wants to know through which interface FortiGate will steer traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the social media application Facebook.

Based on the exhibits, which two statements are correct? (Choose two.)

Options:

A.

When FortiGate cannot recognize the application of the flow, it steers the traffic through the preferred member of rule 3, HQ_T1.

B.

There is no service defined for the Facebook application, so FortiGate appliesservice rule 3 and directs the traffic to headquarters.

C.

FortiGate steers traffic for social media applications according to the service rule 2 and steers traffic through port2.

D.

When FortiGate cannot recognize the application of the flow, it load balances the traffic through the tunnels HQ_T1. HQ_T2. HQ_T3.

Question 3

(Refer to the exhibit.

What can you conclude from the output shown? Choose one answer.)

Options:

A.

It is a spoke device. SD-WAN rule 3 is configured with nine members.

B.

It is a spoke device. The members of SD-WAN rule 3 are grouped into two zones.

C.

It is a hub device. It allowed the establishment of three auto-discovery VPN (ADVPN) shortcuts.

D.

It is a spoke device. SD-WAN rule 4 allows three shortcut tunnels.

Question 4

As an MSSP administrator, you are asked to configure ADVPN on an existing SD-WAN topology. FortiManager manages the customer devices in a dedicated ADOM. The previous administrator used the SD-WAN overlay topology.

Which two statements apply to this scenario? (Choose two.)

Options:

A.

You can activate auto-discovery VPN in the SD-WAN overlay template only if it is a single hub topology.

B.

When auto-discovery VPN is enabled, FortiManager updates the IPsec and BGP templates in the hub.

C.

After you enable auto-discovery VPN in the overlay template, you must select between ADVPN 2.0 and ADVPN 1.0.

D.

You can activate auto-discovery VPN in the SD-WAN overlay template for any type of topology, including a primary-primary dual-hub topology.

Question 5

You have configured the performance SLA with the probe mode as Prefer Passive.

What are two observable impacts of this configuration? (Choose two.)

Options:

A.

FortiGate passively monitors the member if TCP traffic is passing through the member.

B.

After FortiGate switches to active mode, the SLA performance rule falls back to passive monitoring after 3 minutes.

C.

FortiGate passively monitors the member if ICMP traffic is passing through the member.

D.

During passive monitoring, the SLA performance rule cannot detect dead members.

E.

FortiGate can offload the traffic that is subject to passive monitoring to hardware.

Question 6

(Refer to the exhibits.

You collected the output shown in the exhibits and want to know which interface HTTP traffic will flow through from the user device 10.0.1.101 to the corporate web server 10.0.0.126. All SD-WAN links are stable.

Which interface will FortiGate use to steer the traffic? Choose one answer.)

Options:

A.

Only HUB1-VPN3

B.

Only HUB1-VPN2

C.

Either HUB1-VPN2 or HUB1-VPN3

D.

Either HUB1-VPN1, HUB1-VPN2, or HUB1-VPN3

Question 7

Refer to the exhibit.

An administrator checks the status of an SD-WAN topology using the FortiManager SD-WAN monitor menus. All members are configured with one or two SLAs.

Which two conclusions can you draw from the output shown? (Choose two.)

Options:

A.

The template view should be used to see the hub devices.

B.

One member of branch2_fgt is missing the SLAs.

C.

branch2_fgt establishes six tunnels to the hubs and they are all up.

D.

This SD-WAN topology contains only two branch devices.

Question 8

You have a FortiGate configuration with three user-defined SD-WAN zones and two members in each of these zones. One SD-WAN member is no longer in use in health-check and SD-WAN rules. You want to delete it.

What happens if you delete the SD-WAN member from the FortiGate GUI?

Options:

A.

FodiGate accepts the deletion and removes routes as required.

B.

FortiGate displays an error message. You must use the CLI to delete an SD-WAN member.

C.

FortiGate displays an error message. SD-WAN zones must contain at least two members

D.

FortiGate accepts the deletion and places the member in the default SD-WAN zone.

Question 9

(Refer to the exhibit.

The administrator configured two SD-WAN rules to load balance traffic.

Which interfaces does FortiGate use to steer the traffic from 10.0.1.124 to 10.0.0.254? Choose one answer.)

Options:

A.

port1 or port2

B.

FortiGate routes the traffic according to the FIB.

C.

HUB1-VPN2

D.

Any interface in the HUB1 or HUB2 zones

Question 10

(Refer to the exhibit. You noticed that one SD-WAN member went down and you immediately collected the session output shown in the exhibit. What can you conclude from this output? Choose one answer.)

Options:

A.

FortiGate didn’t receive any traffic related to this session after the interface went down.

B.

FortiGate flushed the gateway for the session.

C.

FortiGate cannot reevaluate the session.

D.

FortiGate already reevaluated this session.

Question 11

Refer to the exhibits.

The exhibits show the configuration for SD-WAN performance. SD-WAN rule, the application IDs of Facebook and YouTube along with the firewall policy configuration and the underlay zone status.

Which two statements are true about the health and performance of SD-WAN members 3 and 4? (Choose two.)

Options:

A.

Only related TCP traffic is used for performance measurement.

B.

The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.

C.

Encrypted traffic is not used for the performance measurement.

D.

FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.

Question 12

(When you deploy SD-WAN, you can choose from several common designs. Each design best applies to specific contexts.

Which two statements correctly associate a common SD-WAN design with its main indication or constraint? Choose two answers.)

Options:

A.

Use a cloud on-ramp topology to improve the performance of cloud applications.

B.

Use a standalone design for sites with only one WAN link to the cloud.

C.

Use remote breakout to centralize traffic inspection and limit local management requirements.

D.

Use a direct internet access (DIA) design to increase the traffic security and allow local devices with limited capabilities.

Question 13

(Refer to the exhibit.

An SD-WAN zone configuration on the FortiGate GUI is shown.

What can you conclude about the zone and member configuration on this device? Choose one answer.)

Options:

A.

You can delete the virtual-wan-link zone.

B.

The WAN2 zone contains no member.

C.

You can delete the WAN1 zone.

D.

You can add the member B-125 to the WAN3 zone and keep it as a member of the Test zone.

Question 14

Refer to the exhibit.

You configure SD-WAN on a standalone FortiGate device. You want to create an SD-WAN rule that steers Facebook and Linkedin traffic through the less costly internet link. The FortiGate GUI page appears as shown in the exhibit.

What should you do to set Facebook and LinkedIn as destinations?

Options:

A.

Install a license to allow applications as destinations of SD-WAN rules.

B.

In the Internet service field, select Facebook and LinkedIn.

C.

Enable the applications as destinations of the SD-WAN rule feature visibility.

D.

You cannot configure applications as destinations of an SD-WAN rule on a standalone FortiGate device.

Question 15

Refer to the exhibit.

Which statement best describe the role of the ADVPN device in handling traffic?

Options:

A.

This is a spoke that has received a direct shortcut query from a remote spoke.

B.

This is a hub, and two spokes, 192.2.0.1 and 10.0.3.101, establish a shortcut.

C.

This is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.

D.

This is a spoke that has received a shortcut query from a remote hub.

Question 16

(Refer to the exhibit.

Which statement correctly describes the role of the ADVPN device in handling traffic? Choose one answer.)

Options:

A.

This device is a spoke that has received a direct shortcut query from a remote spoke.

B.

This device is a hub, and two spokes, 192.2.0.1 and 10.0.3.101, established a shortcut.

C.

This device is a hub that has received a shortcut query from a spoke and has forwarded it to another spoke.

D.

This device is a spoke that has received a shortcut query from a remote hub.

Question 17

Refer to the exhibit that shows a diagnose output on FortiGate.

Based on the output shown in the exhibit, what can you say about the device role and how it handles health checks?

Options:

A.

The device is a spoke. It receives health-check measures for the tunnels of another spoke.

B.

The device is a hub. It receives embedded health-check measures for each tunnel from the spoke.

C.

The device is a spoke. It provides embedded health-check measures for each tunnel to the hub.

D.

The device is a hub. It receives health-check measures for the tunnels of a spoke.

Question 18

Refer to the exhibit.

What conclusions can you draw about the traffic received by FortiGate originating from the source LAN device 10.0.1.133 and destined for the company’s SMTP mail server at 10.66.0.125?

Options:

A.

FortiGate steers the traffic from the LAN device 10.0.1.133 to the company SMTP mail server 10.66 0.125 through port3.

B.

ForliGate steers the traffic from the LAN device 10.0.1.133 to the company SMTP mail server 10.66.0.125 through port2.

C.

FortiGate steers the traffic from the LAN device 10.0.1.133 to the company SMTP mail server 10.66.0.125 through the SD-WAN member ID 4.

D.

FortiGate steers the traffic from the LAN device 10.0.1.133 to the SMTP mail server 10.66.0.125 through the SD-WAN member ID 1 or 2.

Question 19

Refer to the exhibit.

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths

Which three settings must the administrator configure inside each BGP neighbor group so spokes can learn the prefixes of other spokes and their additional paths? (Choose three.)

Options:

A.

Set additional-path to send

B.

Set additional-path to forward

C.

Enable route-reflector-server

D.

Enable route-reflector-client.

E.

Set adv-additional-path to the number of additional paths to advertise.

Question 20

Refer to the exhibit.

An administrator configures SD-WAN rules for a DIA setup using the FortiGate GUI. The page to configure the source and destination part of the rule looks as shown in the exhibit. The GUI page shows no option to configure an application as the destination of the SD-WAN rule Why?

Options:

A.

You cannot use applications as the destination when FortiGate is used for a DIA setup.

B.

FortiGate allows the configuration of applications as the destination of SD-WAN rules only on the CLI.

C.

You must enable the feature on the CLI.

D.

You must enable the feature first using the GUI menu System > Feature Visibility.

Question 21

(As an IT manager, you want to delegate the installation and management of your SD-WAN deployment to a managed security service provider (MSSP). Each site must maintain direct internet access and be secure. You expect significant traffic flow between the sites and want to delegate as much of the network administration and management as possible to the MSSP.

Which two MSSP deployment blueprints address your requirements? Choose two answers.)

Options:

A.

Use a shared hub on the MSSP premises and a dedicated hub on the customer premises, and install the spokes on the customer premises.

B.

Install a dedicated hub on the MSSP premises for the customer, and install the spokes on the customer premises.

C.

Install the hub and spokes on the customer premises, and enable the MSSP to manage the SD-WAN deployment using FortiManager with a dedicated ADOM.

D.

Use a shared hub on the MSSP premises with a dedicated VDOM for the customer, and install the spokes on the customer premises.

Question 22

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured latency will first make HUB1-VPN3 the new preferred member?

Options:

A.

When HUB1-VPN3 has a lower latency than HUB1-VPN1 and HUB1-VPN2

B.

When HUB1-VPN3 has a latency of 80 ms

C.

When HUB1-VPN3 has a latency of 90 ms

D.

When HUB1-VPN1 has a latency of 200 ms

Question 23

(Refer to the exhibits.

Two SD-WAN event logs, the member status, the SD-WAN rule configuration, and the health-check configuration for a FortiGate device are shown.

Immediately after the log messages are displayed, how will the FortiGate steer the traffic based on the information shown in the exhibits? Choose one answer.)

Options:

A.

FortiGate skips SD-WAN rule ID 1.

B.

FortiGate uses port2 to steer the traffic for SD-WAN rule ID 1.

C.

FortiGate uses port1 to steer the traffic for SD-WAN rule ID 1.

D.

FortiGate uses port1 or port2 to steer the traffic for SD-WAN rule ID 1.

Question 24

Exhibit.

Two hub-and-spoke groups are connected through redundant site-to-site IPsec VPNs between Hub 1 and Hub 2

Which two configuration settings are required for the spoke A1 to establish an ADVPN shortcut with the spoke B2? (Choose two.)

Options:

A.

On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to hubs.

B.

On hubs, auto-discovery-receiver must be enabled on the IPsec VPNs to spokes.

C.

On hubs, auto-discovery-forwarder must be enabled on the IPsec VPNs to spokes.

D.

On hubs, auto-diacovery-sender must be enabled on the IPsec VPNs to spokes

Question 25

Refer to the exhibit.

The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate device that supports hardware offloading.

Based on the information shown in the exhibits, which two conclusions can you draw? (Choose two.)

Options:

A.

By default, FortiGate offloads symmetric and asymmetric flows.

B.

The original direction of the symmetric traffic flows from port3 to port2.

C.

The reply direction of the asymmetric traffic flows from port2 to port3.

D.

The auxiliary session can be offloaded to hardware.

Question 26

Refer to the exhibit.

The exhibit shows the health-check configuration on a FortiGate device used as a spoke. You notice that the hub FortiGate doesn’t prioritize the traffic as expected.

Which two configuration elements should you check on the hub? (Choose two.)

Options:

A.

The performance SLA has the parameter priority-out-sla configured.

B.

This performance SLA uses the same members.

C.

The performance SLA uses the same criteria.

D.

The performance SLA is configured with set embedded-measure accept.

Question 27

You manage an SD-WAN topology. You will soon deploy 50 new branches.

Which three tasks can you do in advance to simplify this deployment? (Choose three.)

Options:

A.

Update the DHCP server configuration.

B.

Create model devices.

C.

Create a ZTP template.

D.

Define metadata variables value for each device.

E.

Create policy blueprint.

Question 28

Refer to the exhibit.

Which statement best describe the role of the ADVPN device in handling traffic?

Options:

A.

This is a hub that has received a query from a spoke and has forwarded it to another spoke.

B.

This is a hub in a dual-region topology. The remote hub tunnel ID is 10.0.2.101.

C.

This is a spoke that has received a shortcut query from another spoke and has forwarded the response to its hub.

D.

This is a spoke. The kernel received a shortcut request and forwards the query to another spoke.

Demo: 28 questions
Total 95 questions