NSE7_SDW Security Profiles Routing And IPsec Practice Question
An administrator configures an SD-WAN rule to route guest Wi-Fi traffic out of a secondary broadband internet connection. However, guest users are still able to access internal corporate subnets that are routed over the primary IPsec VPN tunnel. What configuration is missing or incorrect?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall policy permitting traffic from the Guest Wi-Fi interface to the internal VPN interface lacks proper security profile enforcement or is missing a deny rule blocking inter-zone access
SD-WAN rules route internet or specific traffic based on criteria, but traffic between zones (like Guest Wi-Fi to Corporate LAN) is governed by firewall policies. If a firewall policy permits traffic from Guest Wi-Fi directly to Corporate LAN, it bypasses SD-WAN rules because SD-WAN rules only evaluate traffic matching egress SD-WAN zones/interfaces specified by the rule or routing table lookup. To prevent guest traffic from reaching internal subnets, the firewall policy must block or restrict that inter-zone traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SD-WAN health check probe is not monitoring the corporate subnet gateway
Why it's wrong here
Health checks monitor WAN link quality, not internal zone access.
- ✗
The IPsec Phase 2 security association selectors include the guest subnet range
Why it's wrong here
Phase 2 selectors determine encrypted VPN traffic, not local guest-to-corporate traffic isolation.
- ✗
The SD-WAN rule priority for the internal VPN interface is set higher than the broadband interface
Why it's wrong here
SD-WAN rules do not control traffic between internal zones unless explicitly routed through the SD-WAN virtual interface.
- ✓
The firewall policy permitting traffic from the Guest Wi-Fi interface to the internal VPN interface lacks proper security profile enforcement or is missing a deny rule blocking inter-zone access
Why this is correct
Correct. Firewall policies control inter-zone traffic access. SD-WAN rules only affect routing for traffic permitted by firewall policies.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
This NSE7_SDW question is part of Courseiva's 92-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Fortinet exam blueprint
This NSE7_SDW practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7_SDW exam.