Courseiva
Security Profiles Routing And IPsecmediumMultiple ChoiceObjective-mapped

NSE7_SDW Security Profiles Routing And IPsec Practice Question

An enterprise FortiGate is running SD-WAN with multiple internet breakouts. The administrator applies an Application Control security profile to the firewall policy. Some custom business applications are being incorrectly classified or blocked by the Application Control profile. To ensure SD-WAN can reliably steer this traffic using application signatures while preventing false positives, what is the recommended procedure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a custom application signature override in the Application Control profile to correctly identify the traffic by port, IP, or pattern

When custom or specific applications are misidentified, administrators can create a Custom Application override or custom signature, or adjust the Application Control profile overrides to change the action (e.g., allow or assign to a specific app category) without disabling security entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a custom application signature override in the Application Control profile to correctly identify the traffic by port, IP, or pattern

    Why this is correct

    Correct. Custom application overrides allow administrators to map specific traffic patterns to known applications or custom definitions so both Application Control and SD-WAN application steering work accurately.

  • Disable all security profiles on the SD-WAN interface zone

    Why it's wrong here

    Disabling security profiles compromises network security and does not resolve classification issues.

  • Configure static routes for the application servers and bypass SD-WAN rules completely

    Why it's wrong here

    Bypassing SD-WAN defeats the purpose of application-based steering.

  • Switch the inspection mode from flow-based to proxy-based for all firewall policies

    Why it's wrong here

    Changing inspection mode globally does not fix application signature misclassification.

About these practice questions

One of 92 original NSE7_SDW practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Fortinet exam blueprint

This NSE7_SDW practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7_SDW exam.