NSE7_SDW Security Profiles Routing And IPsec Practice Question
An enterprise FortiGate is running SD-WAN with multiple internet breakouts. The administrator applies an Application Control security profile to the firewall policy. Some custom business applications are being incorrectly classified or blocked by the Application Control profile. To ensure SD-WAN can reliably steer this traffic using application signatures while preventing false positives, what is the recommended procedure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom application signature override in the Application Control profile to correctly identify the traffic by port, IP, or pattern
When custom or specific applications are misidentified, administrators can create a Custom Application override or custom signature, or adjust the Application Control profile overrides to change the action (e.g., allow or assign to a specific app category) without disabling security entirely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a custom application signature override in the Application Control profile to correctly identify the traffic by port, IP, or pattern
Why this is correct
Correct. Custom application overrides allow administrators to map specific traffic patterns to known applications or custom definitions so both Application Control and SD-WAN application steering work accurately.
- ✗
Disable all security profiles on the SD-WAN interface zone
Why it's wrong here
Disabling security profiles compromises network security and does not resolve classification issues.
- ✗
Configure static routes for the application servers and bypass SD-WAN rules completely
Why it's wrong here
Bypassing SD-WAN defeats the purpose of application-based steering.
- ✗
Switch the inspection mode from flow-based to proxy-based for all firewall policies
Why it's wrong here
Changing inspection mode globally does not fix application signature misclassification.
About these practice questions
One of 92 original NSE7_SDW practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Fortinet exam blueprint
This NSE7_SDW practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7_SDW exam.