NSE7_SDW · domain
Security Profiles Routing And IPsec
Practise NSE 7 - SD-WAN (NSE7_SDW) Security Profiles Routing And IPsec practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Profiles Routing And IPsec questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Profiles Routing And IPsec
Routing questions usually test route selection (administrative distance, metric), how static routes are configured and when they are preferred over dynamic routing.
Administrative distance comparing routing sources.
Static route configuration: next-hop vs exit interface.
Default route propagation and the gateway of last resort.
Recursive routing table lookups.
Watch out for
Common Security Profiles Routing And IPsec exam traps
- ▸Lower administrative distance wins when two routing sources have the same prefix.
- ▸A static route with an exit interface creates a directly-connected dependency.
- ▸The gateway of last resort is set by the default route, not automatically.
- ▸Metric is only compared within the same routing protocol.
Question index
All Security Profiles Routing And IPsec questions (31)
Click any question to see the full explanation, or start a practice session above.
An administrator has configured BGP over multiple SD-WAN IPsec tunnels to provide redundant paths to a datacenter. However, asymmetric routing is causing stateful inspection drops on a secondary FortiGate firewall downstream. To ensure that BGP selects the preferred primary SD-WAN member consistently, which BGP attribute is best manipulated via a route-map applied to the BGP neighbor in FortiOS?
Hard2An IPsec VPN tunnel used as an SD-WAN member is experiencing intermittent flapping due to DPD (Dead Peer Detection) timeout issues over a high-latency satellite link. How should the administrator adjust the Phase 1 IPsec settings on FortiOS to stabilize the tunnel without completely disabling failure detection?
Hard3An enterprise network uses OSPF over SD-WAN IPsec tunnels. The administrator notices that OSPF adjacency is constantly dropping over a specific backup SD-WAN member link due to intermittent packet loss. Which THREE configuration adjustments can improve OSPF stability over unstable SD-WAN IPsec links? (Choose three)
Hard4An administrator needs to inspect encrypted traffic traversing an SD-WAN IPsec tunnel using Deep Packet Inspection (DPI). What must be installed on the client endpoints or configured on the FortiGate to prevent browser trust warnings when using SSL/TLS full inspection?
Easy5An administrator configures an SD-WAN health check with multiple probes (e.g., ping and HTTP) to monitor a set of IPsec VPN tunnels. Which THREE criteria or settings govern how FortiOS determines whether an SD-WAN member has met or failed the performance SLA? (Choose three)
Hard6An administrator configures an SD-WAN rule to route guest Wi-Fi traffic out of a secondary broadband internet connection. However, guest users are still able to access internal corporate subnets that are routed over the primary IPsec VPN tunnel. What configuration is missing or incorrect?
Medium7An administrator wants to view the active SD-WAN rule hit counts and verify which traffic is matching a specific SD-WAN rule in FortiOS. Which command should be used?
Easy8An enterprise network uses ADVPN 2.0 with BGP running over IPsec tunnels. A spoke needs to initiate a shortcut tunnel to another spoke. Which FortiOS CLI command is used on the hub to verify the active shortcut tunnels and view the shortcut state information?
Medium9When troubleshooting SD-WAN performance SLA packet loss, an administrator wants to view real-time latency, jitter, and packet loss statistics for individual health check members. Which CLI command should be executed?
Easy10When configuring advanced IPsec VPN tunnels to act as members of an SD-WAN zone, which TWO configuration parameters on the FortiGate are critical for ensuring proper IPsec tunnel operation and traffic steering? (Choose two)
Medium11An administrator is troubleshooting BGP route propagation over SD-WAN IPsec tunnels where a branch office is not receiving specific routes from the datacenter hub. Which TWO CLI commands on the FortiGate are most useful for diagnosing BGP peering and advertised route issues? (Choose two)
Medium12An enterprise FortiGate is running SD-WAN with multiple internet breakouts. The administrator applies an Application Control security profile to the firewall policy. Some custom business applications are being incorrectly classified or blocked by the Application Control profile. To ensure SD-WAN can reliably steer this traffic using application signatures while preventing false positives, what is the recommended procedure?
Medium13An enterprise network implements BGP over ADVPN. Spoke units advertise their local subnets to the hub via BGP. To prevent spokes from learning each other's subnets directly through the hub via regular BGP route propagation before an ADVPN shortcut is established (forcing them to route through the hub unnecessarily), or conversely, to optimize route distribution, what BGP feature is typically configured on the hub?
Hard14An administrator configures a static route where the gateway is an SD-WAN zone instead of a specific IP address. How does FortiOS process this SD-WAN static route?
Easy15An administrator troubleshoots an ADVPN 2.0 deployment where dynamic shortcut tunnels fail to establish between branch spokes. Which THREE diagnostic steps or log checks should the administrator perform on the FortiGate hub or spoke to isolate the issue? (Choose three)
Hard16An administrator implements BGP over SD-WAN tunnels to a cloud provider. The cloud provider requires BGP MD5 authentication on all peering sessions. Where is BGP MD5 authentication configured on the FortiGate?
Medium17A FortiGate SD-WAN deployment uses a firewall policy with an Intrusion Prevention System (IPS) profile applied. After turning on IPS, administrators notice that throughput over an IPsec SD-WAN tunnel drops significantly. What is the primary reason for this throughput reduction, and how can it be mitigated?
Medium18An administrator configures an SD-WAN rule using the 'Volume' strategy across two IPsec tunnels with different bandwidth capacities (Tunnel A: 100 Mbps, Tunnel B: 50 Mbps). How does FortiOS distribute traffic across these members when using the Volume strategy?
Medium19An administrator is configuring BGP over SD-WAN IPsec tunnels between a headquarters FortiGate and branch FortiGates. Which TWO configuration steps are required to ensure robust and stable dynamic routing over the SD-WAN IPsec tunnels? (Choose two)
Medium20An enterprise deploys ADVPN 2.0 with BGP and security profiles applied to traffic traversing the VPN overlay. Which THREE statements are correct regarding how security profiles and ADVPN 2.0 interact in FortiOS? (Choose three)
Hard21An administrator is troubleshooting an SD-WAN deployment where traffic matching an SD-WAN rule with a destination service object (e.g., HTTPS) is not being steered according to the SLA priority. Instead, it is always taking the default static route member. Upon checking the firewall policies, what is the most common reason why an SD-WAN rule fails to process application or service-based traffic matching?
Hard22A FortiGate device is running ADVPN 2.0 with OSPF. A spoke experiences transient routing loops when a shortcut tunnel tears down due to inactivity timeout. Which configuration adjustment on the FortiGate hub and spokes prevents these temporary routing blackholes or loops during shortcut teardown?
Hard23When configuring an SD-WAN health check to monitor internet reachability using HTTP/HTTPS requests, which parameter defines the specific string the FortiGate expects to receive in the server response body to validate that the path is healthy?
Easy24In an ADVPN 2.0 deployment, a hub unit uses BGP to advertise routes to spokes. When a spoke learns a prefix via BGP from the hub, what mechanism allows the spoke to automatically initiate an ADVPN shortcut tunnel directly to another spoke when traffic flows between them?
Medium25An administrator applies security profiles (Antivirus, Web Filtering, and IPS) to traffic steered by an SD-WAN rule. Performance issues arise. Which TWO methods can the administrator use to optimize inspection performance without completely disabling security? (Choose two)
Medium26An administrator wants to apply a Web Filtering security profile to traffic that is being dynamically steered via an SD-WAN rule. Where must this security profile be enforced in FortiOS?
Easy27An administrator troubleshoots a scenario where traffic matching an application-based SD-WAN rule is bypassing the preferred high-speed MPLS tunnel and taking the backup broadband tunnel instead. Which THREE factors should the administrator check to resolve this routing discrepancy? (Choose three)
Hard28An enterprise deploys BGP over SD-WAN with multiple MPLS and broadband connections. A route-map is applied to incoming BGP updates on the FortiGate to set a specific weight for routes learned over the MPLS interface. Why is the 'weight' attribute particularly effective in this FortiOS SD-WAN and BGP integration scenario?
Hard29An administrator is configuring SD-WAN rules with performance SLAs. Which TWO strategies are available in FortiOS when configuring an SD-WAN rule based on SLA metrics? (Choose two)
Medium30A FortiGate device is configured with an SD-WAN rule utilizing a SLA rule for latency and packet loss. Security profiles including Deep Packet Inspection (DPI) SSL inspection and an Antivirus profile are applied to the firewall policy allowing this traffic. Users report intermittent connection drops on real-time UDP-based applications. Upon troubleshooting, the administrator notices that packet drops occur only when the SD-WAN rule dynamically steers traffic to a backup IPsec tunnel that has a smaller MTU. What is the most likely root cause and mitigation for this behavior?
Hard31An administrator configures an ADVPN 2.0 deployment between a FortiGate hub and multiple spokes using OSPF as the dynamic routing protocol. The spoke units need to establish direct shortcut tunnels dynamically. Which configuration step is mandatory on the hub to ensure that BGP or OSPF next-hop resolution works correctly for ADVPN shortcut creation?
MediumOther domains
All NSE7_SDW exam domains
Frequently asked questions
- What does the Security Profiles Routing And IPsec domain cover on the NSE7_SDW exam?
- Routing questions usually test route selection (administrative distance, metric), how static routes are configured and when they are preferred over dynamic routing.
- How many questions are in this domain?
- This page lists all 31 Security Profiles Routing And IPsec questions in the NSE7_SDW question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Profiles Routing And IPsec questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.