Courseiva

NSE 7 - SD-WAN (NSE7_SDW) (NSE7_SDW) — Questions 7692

92 questions total · 2pages · All types, answers revealed

Page 1

Page 2 of 2

76
Multi-Selectmedium

Which THREE of the following are benefits of using SD-WAN?

Select 3 answers
A.Built-in physical layer cabling.
B.Simplified WAN management through zones.
C.Automated failover between WAN links.
D.Automatic hardware replacement.
E.Dynamic path selection based on application performance.
AnswersB, C, E

Core benefit.

Why this answer

SD-WAN provides link aggregation, intelligent path selection, and simplified WAN management.

77
Multi-Selectmedium

Which TWO methods can be used to update SD-WAN policies across all managed devices in FortiManager?

Select 2 answers
A.Using a CLI script to push updates
B.Modifying the SD-WAN template and installing the changes
C.Editing the individual FortiGate policy
D.Creating a new ADOM
E.Rebooting the FortiManager
AnswersA, B

Scripts are an alternative method for updates.

Why this answer

Updates are performed by modifying the template and then pushing the updated configuration to the devices.

78
MCQmedium

In SD-WAN central management, what is the 'SD-WAN Zone' used for?

A.To define the physical port speed
B.To limit bandwidth for specific users
C.To group multiple SD-WAN members for logical policy routing
D.To isolate the SD-WAN traffic from the WAN
AnswerC

Zones simplify routing by aggregating interfaces.

Why this answer

SD-WAN zones allow you to group multiple physical interfaces into a logical container for easier policy management.

79
MCQmedium

What is the impact of checking the 'Interface Preference' box in an SD-WAN rule?

A.It overrides the SLA strategy selection.
B.It enables failover to the default gateway.
C.It enables load balancing across interfaces.
D.It increases the probe frequency.
AnswerA

It forces traffic to preferred interfaces.

Why this answer

Interface preference forces the rule to prioritize specific interfaces over others, even if SLA metrics might suggest otherwise.

80
MCQmedium

You are configuring a Performance SLA to monitor reachability to a SaaS application. Which parameter determines the threshold for an interface to be considered 'unhealthy' in the SD-WAN routing table?

A.Probe Mode
B.Sequence Number
C.Packet Loss Threshold
D.Update Interval
AnswerC

If packet loss exceeds this percentage, the member is removed from the SD-WAN route table.

Why this answer

The 'threshold-alert' or the individual latency/jitter/packet loss thresholds within the Performance SLA configuration dictate when a member is marked failed.

81
MCQmedium

When creating an SD-WAN template, what must be defined before you can add an SD-WAN interface to the template?

A.Individual SD-WAN member interfaces
B.The SD-WAN health check probes
C.Global firewall policies
D.The virtual domain (VDOM) settings
AnswerA

Members must be defined to form the SD-WAN construct.

Why this answer

You must define the member interfaces within the template before referencing them in SD-WAN zones or rules.

82
MCQeasy

Which interface can be used as an SD-WAN member in an SD-WAN template?

A.Physical ports, VLANs, and VPN tunnels
B.Only WAN physical ports
C.Only VLANs
D.Only loopback interfaces
AnswerA

SD-WAN supports various interface types.

Why this answer

Any physical or logical (VPN tunnel) interface can be added as an SD-WAN member.

83
MCQhard

You have an SD-WAN rule with 'Priority' strategy. What happens if the highest priority member fails its SLA?

A.Traffic is dropped.
B.The FortiGate enters an error state.
C.Traffic is load balanced across all remaining members.
D.Traffic fails over to the member with the next highest priority value.
AnswerD

The system moves down the list of priorities.

Why this answer

In 'Priority' strategy, if the highest priority member becomes unhealthy (SLA failure), the traffic automatically fails over to the next highest priority member.

84
MCQmedium

What is the effect of changing the 'Hold-down' timer in a Performance SLA?

A.It changes the frequency of the probes.
B.It sets the maximum number of failed probes allowed.
C.It prevents route flapping by delaying the transition back to an 'up' state.
D.It determines the timeout duration for a single probe.
AnswerC

It adds a stability buffer to the interface status.

Why this answer

The 'Hold-down' timer defines how long an interface must remain healthy after a failure before it is considered 'up' again, preventing route flapping.

85
MCQmedium

You are configuring SD-WAN templates in FortiManager. What is the primary purpose of using SD-WAN Central Management instead of configuring SD-WAN directly on individual FortiGates?

A.To perform local traffic analysis on the FortiGate only
B.To allow FortiGates to manage their own SD-WAN interfaces independently
C.To bypass the need for ADOMs
D.To enable SD-WAN template inheritance and synchronized policy updates across multiple managed devices
AnswerD

SD-WAN templates allow for standardized configurations across managed FortiGates.

Why this answer

Central management enables consistent SD-WAN policy deployment, simplified configuration management across large-scale deployments, and centralized monitoring.

86
MCQhard

An enterprise deploys BGP over SD-WAN with multiple MPLS and broadband connections. A route-map is applied to incoming BGP updates on the FortiGate to set a specific weight for routes learned over the MPLS interface. Why is the 'weight' attribute particularly effective in this FortiOS SD-WAN and BGP integration scenario?

A.Weight replaces the need for SD-WAN SLA rules by performing layer 7 packet inspection
B.Weight automatically adjusts the SD-WAN health check probe frequency based on route stability
C.Weight is evaluated first in the BGP best-path selection algorithm on FortiOS, allowing local preference override without altering global AS path attributes
D.Weight is propagated to all iBGP peers, ensuring cluster-wide path synchronization
AnswerC

Correct. Weight is local to the FortiGate and takes precedence over all other BGP path selection criteria, making it ideal for local path steering.

Why this answer

Weight is a Cisco/FortiOS-specific BGP attribute that is local to the router on which it is configured. It is evaluated first in the BGP best-path selection algorithm, allowing administrators to deterministically force traffic out of a specific SD-WAN/BGP member without affecting other routers in the AS.

87
Multi-Selectmedium

An administrator is configuring SD-WAN rules with performance SLAs. Which TWO strategies are available in FortiOS when configuring an SD-WAN rule based on SLA metrics? (Choose two)

Select 2 answers
A.Lowest Cost (SLA)
B.Priority
C.Round-Robin DNS Load Balancing
D.Dynamic BGP AS-Prepending
E.Static Flow-Hashing
AnswersA, B

Correct. Lowest Cost (SLA) selects the path with the best metric that meets the SLA threshold.

Why this answer

FortiOS SD-WAN rule strategies include Lowest Cost (SLA), Max Bandwidth, Service-ID, Volume, and Priority. Among these, Priority and Lowest Cost (SLA) are standard strategy options utilizing SLA performance metrics.

88
MCQhard

A FortiGate device is configured with an SD-WAN rule utilizing a SLA rule for latency and packet loss. Security profiles including Deep Packet Inspection (DPI) SSL inspection and an Antivirus profile are applied to the firewall policy allowing this traffic. Users report intermittent connection drops on real-time UDP-based applications. Upon troubleshooting, the administrator notices that packet drops occur only when the SD-WAN rule dynamically steers traffic to a backup IPsec tunnel that has a smaller MTU. What is the most likely root cause and mitigation for this behavior?

A.Path MTU Discovery is failing because ICMP unreachable messages are blocked, and TCP MSS clamping is not adjusting the encapsulated IPsec packet size correctly
B.SD-WAN health check probes are overwhelming the IPsec tunnel bandwidth
C.The Antivirus proxy buffer is overflowing due to UDP streaming packets
D.The SSL inspection profile is attempting to decrypt UDP traffic, causing kernel panic and packet drops
AnswerA

Correct. When SD-WAN steers traffic over a tunnel with a smaller MTU, lack of fragmentation or MSS adjustment leads to drops of packets larger than the egress interface MTU.

Why this answer

IPsec encapsulation adds overhead, and if the Path MTU Discovery (PMTUD) fails due to ICMP fragmentation-needed messages being blocked by security profiles or firewalls along the path, packet drops occur for UDP streams exceeding the actual MTU. Adjusting the TCP MSS or enabling ipsec-phase1-interface fragmentation settings/tcp-mss-enforcement resolves this.

89
MCQmedium

When viewing the SD-WAN Monitor in FortiManager, what information is provided for the 'Health Check' status?

A.The firmware version of the device
B.The number of active users
C.Latency, jitter, and packet loss metrics
D.The current IP address of the interface
AnswerC

These are the key performance indicators for SD-WAN health.

Why this answer

The monitor shows the latency, jitter, and packet loss for every configured health check probe on the monitored device.

90
MCQmedium

An administrator configures an ADVPN 2.0 deployment between a FortiGate hub and multiple spokes using OSPF as the dynamic routing protocol. The spoke units need to establish direct shortcut tunnels dynamically. Which configuration step is mandatory on the hub to ensure that BGP or OSPF next-hop resolution works correctly for ADVPN shortcut creation?

A.Enable split-horizon globally within the OSPF routing process
B.Disable next-hop-self on the hub's BGP neighbor configuration or adjust OSPF interface settings so the advertising router is not forced as the next hop
C.Enable exchange-interface in the hub's OSPF interface configuration
D.Configure a static blackhole route for all spoke subnets on the hub
AnswerB

Correct. By default, protocols like BGP use next-hop-self which forces traffic through the hub, breaking ADVPN shortcut creation unless properly configured to preserve the originating peer's IP or using shortcut-specific routing policies.

Why this answer

In ADVPN environments running dynamic routing protocols like OSPF or BGP, network-object settings or interface settings such as setting the route-map or disabling next-hop-self on the hub allow spokes to properly resolve shortcut routes. Specifically, modifying the BGP next-hop or OSPF next-hop behavior ensures traffic is steered directly to the requesting spoke's IP rather than looping back through the hub.

91
MCQhard

If an SD-WAN template contains a reference to an interface that does not exist on a target FortiGate, what occurs during the installation process?

A.The FortiGate automatically creates a dummy interface
B.The installation fails with a configuration error
C.The installation proceeds and ignores the missing interface
D.The FortiGate enters an 'Emergency' state
AnswerB

Validation errors prevent configuration deployment.

Why this answer

The installation will fail during the pre-check or push validation phase because the dependency is missing.

92
Multi-Selecthard

Which THREE tasks are required to successfully deploy SD-WAN via FortiManager?

Select 3 answers
A.Installing the configuration to the devices
B.Creating an SD-WAN template
C.Performing a hard factory reset on the FortiGate
D.Deleting all existing firewall policies
E.Assigning the template to managed FortiGates
AnswersA, B, E

Installation executes the push.

Why this answer

Deployment requires defining the template, assigning it to devices, and installing the configuration.

Page 1

Page 2 of 2

All pages