Practice NSE7_SDW Security Profiles Routing And IPsec questions with full explanations on every answer.
Start practicing
Security Profiles Routing And IPsec — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator has configured BGP over multiple SD-WAN IPsec tunnels to provide redundant paths to a datacenter. However, asymmetric routing is causing stateful inspection drops on a secondary FortiGate firewall downstream. To ensure that BGP selects the preferred primary SD-WAN member consistently, which BGP attribute is best manipulated via a route-map applied to the BGP neighbor in FortiOS?
2An administrator wants to apply a Web Filtering security profile to traffic that is being dynamically steered via an SD-WAN rule. Where must this security profile be enforced in FortiOS?
3A FortiGate device is configured with an SD-WAN rule utilizing a SLA rule for latency and packet loss. Security profiles including Deep Packet Inspection (DPI) SSL inspection and an Antivirus profile are applied to the firewall policy allowing this traffic. Users report intermittent connection drops on real-time UDP-based applications. Upon troubleshooting, the administrator notices that packet drops occur only when the SD-WAN rule dynamically steers traffic to a backup IPsec tunnel that has a smaller MTU. What is the most likely root cause and mitigation for this behavior?
4An IPsec VPN tunnel used as an SD-WAN member is experiencing intermittent flapping due to DPD (Dead Peer Detection) timeout issues over a high-latency satellite link. How should the administrator adjust the Phase 1 IPsec settings on FortiOS to stabilize the tunnel without completely disabling failure detection?
5An enterprise network uses ADVPN 2.0 with BGP running over IPsec tunnels. A spoke needs to initiate a shortcut tunnel to another spoke. Which FortiOS CLI command is used on the hub to verify the active shortcut tunnels and view the shortcut state information?
6When troubleshooting SD-WAN performance SLA packet loss, an administrator wants to view real-time latency, jitter, and packet loss statistics for individual health check members. Which CLI command should be executed?
7An administrator configures an ADVPN 2.0 deployment between a FortiGate hub and multiple spokes using OSPF as the dynamic routing protocol. The spoke units need to establish direct shortcut tunnels dynamically. Which configuration step is mandatory on the hub to ensure that BGP or OSPF next-hop resolution works correctly for ADVPN shortcut creation?
8An enterprise FortiGate is running SD-WAN with multiple internet breakouts. The administrator applies an Application Control security profile to the firewall policy. Some custom business applications are being incorrectly classified or blocked by the Application Control profile. To ensure SD-WAN can reliably steer this traffic using application signatures while preventing false positives, what is the recommended procedure?
9When configuring an SD-WAN health check to monitor internet reachability using HTTP/HTTPS requests, which parameter defines the specific string the FortiGate expects to receive in the server response body to validate that the path is healthy?
10An administrator is troubleshooting an SD-WAN deployment where traffic matching an SD-WAN rule with a destination service object (e.g., HTTPS) is not being steered according to the SLA priority. Instead, it is always taking the default static route member. Upon checking the firewall policies, what is the most common reason why an SD-WAN rule fails to process application or service-based traffic matching?
11An enterprise deploys BGP over SD-WAN with multiple MPLS and broadband connections. A route-map is applied to incoming BGP updates on the FortiGate to set a specific weight for routes learned over the MPLS interface. Why is the 'weight' attribute particularly effective in this FortiOS SD-WAN and BGP integration scenario?
12In an ADVPN 2.0 deployment, a hub unit uses BGP to advertise routes to spokes. When a spoke learns a prefix via BGP from the hub, what mechanism allows the spoke to automatically initiate an ADVPN shortcut tunnel directly to another spoke when traffic flows between them?
13An administrator implements BGP over SD-WAN tunnels to a cloud provider. The cloud provider requires BGP MD5 authentication on all peering sessions. Where is BGP MD5 authentication configured on the FortiGate?
14An administrator needs to inspect encrypted traffic traversing an SD-WAN IPsec tunnel using Deep Packet Inspection (DPI). What must be installed on the client endpoints or configured on the FortiGate to prevent browser trust warnings when using SSL/TLS full inspection?
15A FortiGate device is running ADVPN 2.0 with OSPF. A spoke experiences transient routing loops when a shortcut tunnel tears down due to inactivity timeout. Which configuration adjustment on the FortiGate hub and spokes prevents these temporary routing blackholes or loops during shortcut teardown?
16An administrator configures an SD-WAN rule to route guest Wi-Fi traffic out of a secondary broadband internet connection. However, guest users are still able to access internal corporate subnets that are routed over the primary IPsec VPN tunnel. What configuration is missing or incorrect?
17An enterprise network implements BGP over ADVPN. Spoke units advertise their local subnets to the hub via BGP. To prevent spokes from learning each other's subnets directly through the hub via regular BGP route propagation before an ADVPN shortcut is established (forcing them to route through the hub unnecessarily), or conversely, to optimize route distribution, what BGP feature is typically configured on the hub?
18An administrator wants to view the active SD-WAN rule hit counts and verify which traffic is matching a specific SD-WAN rule in FortiOS. Which command should be used?
19An administrator configures an SD-WAN rule using the 'Volume' strategy across two IPsec tunnels with different bandwidth capacities (Tunnel A: 100 Mbps, Tunnel B: 50 Mbps). How does FortiOS distribute traffic across these members when using the Volume strategy?
20A FortiGate SD-WAN deployment uses a firewall policy with an Intrusion Prevention System (IPS) profile applied. After turning on IPS, administrators notice that throughput over an IPsec SD-WAN tunnel drops significantly. What is the primary reason for this throughput reduction, and how can it be mitigated?
21An administrator configures a static route where the gateway is an SD-WAN zone instead of a specific IP address. How does FortiOS process this SD-WAN static route?
22An administrator is configuring BGP over SD-WAN IPsec tunnels between a headquarters FortiGate and branch FortiGates. Which TWO configuration steps are required to ensure robust and stable dynamic routing over the SD-WAN IPsec tunnels? (Choose two)
23An administrator troubleshoots an ADVPN 2.0 deployment where dynamic shortcut tunnels fail to establish between branch spokes. Which THREE diagnostic steps or log checks should the administrator perform on the FortiGate hub or spoke to isolate the issue? (Choose three)
24An administrator applies security profiles (Antivirus, Web Filtering, and IPS) to traffic steered by an SD-WAN rule. Performance issues arise. Which TWO methods can the administrator use to optimize inspection performance without completely disabling security? (Choose two)
25An enterprise network uses OSPF over SD-WAN IPsec tunnels. The administrator notices that OSPF adjacency is constantly dropping over a specific backup SD-WAN member link due to intermittent packet loss. Which THREE configuration adjustments can improve OSPF stability over unstable SD-WAN IPsec links? (Choose three)
26When configuring advanced IPsec VPN tunnels to act as members of an SD-WAN zone, which TWO configuration parameters on the FortiGate are critical for ensuring proper IPsec tunnel operation and traffic steering? (Choose two)
27An administrator troubleshoots a scenario where traffic matching an application-based SD-WAN rule is bypassing the preferred high-speed MPLS tunnel and taking the backup broadband tunnel instead. Which THREE factors should the administrator check to resolve this routing discrepancy? (Choose three)
28An enterprise deploys ADVPN 2.0 with BGP and security profiles applied to traffic traversing the VPN overlay. Which THREE statements are correct regarding how security profiles and ADVPN 2.0 interact in FortiOS? (Choose three)
29An administrator is configuring SD-WAN rules with performance SLAs. Which TWO strategies are available in FortiOS when configuring an SD-WAN rule based on SLA metrics? (Choose two)
30An administrator is troubleshooting BGP route propagation over SD-WAN IPsec tunnels where a branch office is not receiving specific routes from the datacenter hub. Which TWO CLI commands on the FortiGate are most useful for diagnosing BGP peering and advertised route issues? (Choose two)
31An administrator configures an SD-WAN health check with multiple probes (e.g., ping and HTTP) to monitor a set of IPsec VPN tunnels. Which THREE criteria or settings govern how FortiOS determines whether an SD-WAN member has met or failed the performance SLA? (Choose three)
The Security Profiles Routing And IPsec domain covers the key concepts tested in this area of the NSE7_SDW exam blueprint published by Fortinet. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all NSE7_SDW domains — no account required.
The Courseiva NSE7_SDW question bank contains 31 questions in the Security Profiles Routing And IPsec domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Profiles Routing And IPsec domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included