Which THREE of the following are benefits of using SD-WAN?
Core benefit.
Why this answer
SD-WAN provides link aggregation, intelligent path selection, and simplified WAN management.
92 questions total · 2pages · All types, answers revealed
Page 2 of 2
Which THREE of the following are benefits of using SD-WAN?
Core benefit.
Why this answer
SD-WAN provides link aggregation, intelligent path selection, and simplified WAN management.
Which TWO methods can be used to update SD-WAN policies across all managed devices in FortiManager?
Scripts are an alternative method for updates.
Why this answer
Updates are performed by modifying the template and then pushing the updated configuration to the devices.
In SD-WAN central management, what is the 'SD-WAN Zone' used for?
Zones simplify routing by aggregating interfaces.
Why this answer
SD-WAN zones allow you to group multiple physical interfaces into a logical container for easier policy management.
What is the impact of checking the 'Interface Preference' box in an SD-WAN rule?
It forces traffic to preferred interfaces.
Why this answer
Interface preference forces the rule to prioritize specific interfaces over others, even if SLA metrics might suggest otherwise.
You are configuring a Performance SLA to monitor reachability to a SaaS application. Which parameter determines the threshold for an interface to be considered 'unhealthy' in the SD-WAN routing table?
If packet loss exceeds this percentage, the member is removed from the SD-WAN route table.
Why this answer
The 'threshold-alert' or the individual latency/jitter/packet loss thresholds within the Performance SLA configuration dictate when a member is marked failed.
When creating an SD-WAN template, what must be defined before you can add an SD-WAN interface to the template?
Members must be defined to form the SD-WAN construct.
Why this answer
You must define the member interfaces within the template before referencing them in SD-WAN zones or rules.
Which interface can be used as an SD-WAN member in an SD-WAN template?
SD-WAN supports various interface types.
Why this answer
Any physical or logical (VPN tunnel) interface can be added as an SD-WAN member.
You have an SD-WAN rule with 'Priority' strategy. What happens if the highest priority member fails its SLA?
The system moves down the list of priorities.
Why this answer
In 'Priority' strategy, if the highest priority member becomes unhealthy (SLA failure), the traffic automatically fails over to the next highest priority member.
What is the effect of changing the 'Hold-down' timer in a Performance SLA?
It adds a stability buffer to the interface status.
Why this answer
The 'Hold-down' timer defines how long an interface must remain healthy after a failure before it is considered 'up' again, preventing route flapping.
You are configuring SD-WAN templates in FortiManager. What is the primary purpose of using SD-WAN Central Management instead of configuring SD-WAN directly on individual FortiGates?
SD-WAN templates allow for standardized configurations across managed FortiGates.
Why this answer
Central management enables consistent SD-WAN policy deployment, simplified configuration management across large-scale deployments, and centralized monitoring.
An enterprise deploys BGP over SD-WAN with multiple MPLS and broadband connections. A route-map is applied to incoming BGP updates on the FortiGate to set a specific weight for routes learned over the MPLS interface. Why is the 'weight' attribute particularly effective in this FortiOS SD-WAN and BGP integration scenario?
Correct. Weight is local to the FortiGate and takes precedence over all other BGP path selection criteria, making it ideal for local path steering.
Why this answer
Weight is a Cisco/FortiOS-specific BGP attribute that is local to the router on which it is configured. It is evaluated first in the BGP best-path selection algorithm, allowing administrators to deterministically force traffic out of a specific SD-WAN/BGP member without affecting other routers in the AS.
An administrator is configuring SD-WAN rules with performance SLAs. Which TWO strategies are available in FortiOS when configuring an SD-WAN rule based on SLA metrics? (Choose two)
Correct. Lowest Cost (SLA) selects the path with the best metric that meets the SLA threshold.
Why this answer
FortiOS SD-WAN rule strategies include Lowest Cost (SLA), Max Bandwidth, Service-ID, Volume, and Priority. Among these, Priority and Lowest Cost (SLA) are standard strategy options utilizing SLA performance metrics.
A FortiGate device is configured with an SD-WAN rule utilizing a SLA rule for latency and packet loss. Security profiles including Deep Packet Inspection (DPI) SSL inspection and an Antivirus profile are applied to the firewall policy allowing this traffic. Users report intermittent connection drops on real-time UDP-based applications. Upon troubleshooting, the administrator notices that packet drops occur only when the SD-WAN rule dynamically steers traffic to a backup IPsec tunnel that has a smaller MTU. What is the most likely root cause and mitigation for this behavior?
Correct. When SD-WAN steers traffic over a tunnel with a smaller MTU, lack of fragmentation or MSS adjustment leads to drops of packets larger than the egress interface MTU.
Why this answer
IPsec encapsulation adds overhead, and if the Path MTU Discovery (PMTUD) fails due to ICMP fragmentation-needed messages being blocked by security profiles or firewalls along the path, packet drops occur for UDP streams exceeding the actual MTU. Adjusting the TCP MSS or enabling ipsec-phase1-interface fragmentation settings/tcp-mss-enforcement resolves this.
When viewing the SD-WAN Monitor in FortiManager, what information is provided for the 'Health Check' status?
These are the key performance indicators for SD-WAN health.
Why this answer
The monitor shows the latency, jitter, and packet loss for every configured health check probe on the monitored device.
An administrator configures an ADVPN 2.0 deployment between a FortiGate hub and multiple spokes using OSPF as the dynamic routing protocol. The spoke units need to establish direct shortcut tunnels dynamically. Which configuration step is mandatory on the hub to ensure that BGP or OSPF next-hop resolution works correctly for ADVPN shortcut creation?
Correct. By default, protocols like BGP use next-hop-self which forces traffic through the hub, breaking ADVPN shortcut creation unless properly configured to preserve the originating peer's IP or using shortcut-specific routing policies.
Why this answer
In ADVPN environments running dynamic routing protocols like OSPF or BGP, network-object settings or interface settings such as setting the route-map or disabling next-hop-self on the hub allow spokes to properly resolve shortcut routes. Specifically, modifying the BGP next-hop or OSPF next-hop behavior ensures traffic is steered directly to the requesting spoke's IP rather than looping back through the hub.
If an SD-WAN template contains a reference to an interface that does not exist on a target FortiGate, what occurs during the installation process?
Validation errors prevent configuration deployment.
Why this answer
The installation will fail during the pre-check or push validation phase because the dependency is missing.
Which THREE tasks are required to successfully deploy SD-WAN via FortiManager?
Installation executes the push.
Why this answer
Deployment requires defining the template, assigning it to devices, and installing the configuration.
Page 2 of 2
Practice NSE7_SDW by domain
Target a specific domain to shore up weak areas.
See all domains with question counts →