Courseiva

NSE7_SDW · domain

Security Profiles Routing And IPsec

Practise NSE 7 - SD-WAN (NSE7_SDW) Security Profiles Routing And IPsec practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

31 questions6 easy13 medium12 hard

Focused practice

Practice Security Profiles Routing And IPsec questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Profiles Routing And IPsec

Routing questions usually test route selection (administrative distance, metric), how static routes are configured and when they are preferred over dynamic routing.

Administrative distance comparing routing sources.

Static route configuration: next-hop vs exit interface.

Default route propagation and the gateway of last resort.

Recursive routing table lookups.

Watch out for

Common Security Profiles Routing And IPsec exam traps

  • Lower administrative distance wins when two routing sources have the same prefix.
  • A static route with an exit interface creates a directly-connected dependency.
  • The gateway of last resort is set by the default route, not automatically.
  • Metric is only compared within the same routing protocol.

Question index

All Security Profiles Routing And IPsec questions (31)

Click any question to see the full explanation, or start a practice session above.

1

An administrator has configured BGP over multiple SD-WAN IPsec tunnels to provide redundant paths to a datacenter. However, asymmetric routing is causing stateful inspection drops on a secondary FortiGate firewall downstream. To ensure that BGP selects the preferred primary SD-WAN member consistently, which BGP attribute is best manipulated via a route-map applied to the BGP neighbor in FortiOS?

Hard
2

An IPsec VPN tunnel used as an SD-WAN member is experiencing intermittent flapping due to DPD (Dead Peer Detection) timeout issues over a high-latency satellite link. How should the administrator adjust the Phase 1 IPsec settings on FortiOS to stabilize the tunnel without completely disabling failure detection?

Hard
3

An enterprise network uses OSPF over SD-WAN IPsec tunnels. The administrator notices that OSPF adjacency is constantly dropping over a specific backup SD-WAN member link due to intermittent packet loss. Which THREE configuration adjustments can improve OSPF stability over unstable SD-WAN IPsec links? (Choose three)

Hard
4

An administrator needs to inspect encrypted traffic traversing an SD-WAN IPsec tunnel using Deep Packet Inspection (DPI). What must be installed on the client endpoints or configured on the FortiGate to prevent browser trust warnings when using SSL/TLS full inspection?

Easy
5

An administrator configures an SD-WAN health check with multiple probes (e.g., ping and HTTP) to monitor a set of IPsec VPN tunnels. Which THREE criteria or settings govern how FortiOS determines whether an SD-WAN member has met or failed the performance SLA? (Choose three)

Hard
6

An administrator configures an SD-WAN rule to route guest Wi-Fi traffic out of a secondary broadband internet connection. However, guest users are still able to access internal corporate subnets that are routed over the primary IPsec VPN tunnel. What configuration is missing or incorrect?

Medium
7

An administrator wants to view the active SD-WAN rule hit counts and verify which traffic is matching a specific SD-WAN rule in FortiOS. Which command should be used?

Easy
8

An enterprise network uses ADVPN 2.0 with BGP running over IPsec tunnels. A spoke needs to initiate a shortcut tunnel to another spoke. Which FortiOS CLI command is used on the hub to verify the active shortcut tunnels and view the shortcut state information?

Medium
9

When troubleshooting SD-WAN performance SLA packet loss, an administrator wants to view real-time latency, jitter, and packet loss statistics for individual health check members. Which CLI command should be executed?

Easy
10

When configuring advanced IPsec VPN tunnels to act as members of an SD-WAN zone, which TWO configuration parameters on the FortiGate are critical for ensuring proper IPsec tunnel operation and traffic steering? (Choose two)

Medium
11

An administrator is troubleshooting BGP route propagation over SD-WAN IPsec tunnels where a branch office is not receiving specific routes from the datacenter hub. Which TWO CLI commands on the FortiGate are most useful for diagnosing BGP peering and advertised route issues? (Choose two)

Medium
12

An enterprise FortiGate is running SD-WAN with multiple internet breakouts. The administrator applies an Application Control security profile to the firewall policy. Some custom business applications are being incorrectly classified or blocked by the Application Control profile. To ensure SD-WAN can reliably steer this traffic using application signatures while preventing false positives, what is the recommended procedure?

Medium
13

An enterprise network implements BGP over ADVPN. Spoke units advertise their local subnets to the hub via BGP. To prevent spokes from learning each other's subnets directly through the hub via regular BGP route propagation before an ADVPN shortcut is established (forcing them to route through the hub unnecessarily), or conversely, to optimize route distribution, what BGP feature is typically configured on the hub?

Hard
14

An administrator configures a static route where the gateway is an SD-WAN zone instead of a specific IP address. How does FortiOS process this SD-WAN static route?

Easy
15

An administrator troubleshoots an ADVPN 2.0 deployment where dynamic shortcut tunnels fail to establish between branch spokes. Which THREE diagnostic steps or log checks should the administrator perform on the FortiGate hub or spoke to isolate the issue? (Choose three)

Hard
16

An administrator implements BGP over SD-WAN tunnels to a cloud provider. The cloud provider requires BGP MD5 authentication on all peering sessions. Where is BGP MD5 authentication configured on the FortiGate?

Medium
17

A FortiGate SD-WAN deployment uses a firewall policy with an Intrusion Prevention System (IPS) profile applied. After turning on IPS, administrators notice that throughput over an IPsec SD-WAN tunnel drops significantly. What is the primary reason for this throughput reduction, and how can it be mitigated?

Medium
18

An administrator configures an SD-WAN rule using the 'Volume' strategy across two IPsec tunnels with different bandwidth capacities (Tunnel A: 100 Mbps, Tunnel B: 50 Mbps). How does FortiOS distribute traffic across these members when using the Volume strategy?

Medium
19

An administrator is configuring BGP over SD-WAN IPsec tunnels between a headquarters FortiGate and branch FortiGates. Which TWO configuration steps are required to ensure robust and stable dynamic routing over the SD-WAN IPsec tunnels? (Choose two)

Medium
20

An enterprise deploys ADVPN 2.0 with BGP and security profiles applied to traffic traversing the VPN overlay. Which THREE statements are correct regarding how security profiles and ADVPN 2.0 interact in FortiOS? (Choose three)

Hard
21

An administrator is troubleshooting an SD-WAN deployment where traffic matching an SD-WAN rule with a destination service object (e.g., HTTPS) is not being steered according to the SLA priority. Instead, it is always taking the default static route member. Upon checking the firewall policies, what is the most common reason why an SD-WAN rule fails to process application or service-based traffic matching?

Hard
22

A FortiGate device is running ADVPN 2.0 with OSPF. A spoke experiences transient routing loops when a shortcut tunnel tears down due to inactivity timeout. Which configuration adjustment on the FortiGate hub and spokes prevents these temporary routing blackholes or loops during shortcut teardown?

Hard
23

When configuring an SD-WAN health check to monitor internet reachability using HTTP/HTTPS requests, which parameter defines the specific string the FortiGate expects to receive in the server response body to validate that the path is healthy?

Easy
24

In an ADVPN 2.0 deployment, a hub unit uses BGP to advertise routes to spokes. When a spoke learns a prefix via BGP from the hub, what mechanism allows the spoke to automatically initiate an ADVPN shortcut tunnel directly to another spoke when traffic flows between them?

Medium
25

An administrator applies security profiles (Antivirus, Web Filtering, and IPS) to traffic steered by an SD-WAN rule. Performance issues arise. Which TWO methods can the administrator use to optimize inspection performance without completely disabling security? (Choose two)

Medium
26

An administrator wants to apply a Web Filtering security profile to traffic that is being dynamically steered via an SD-WAN rule. Where must this security profile be enforced in FortiOS?

Easy
27

An administrator troubleshoots a scenario where traffic matching an application-based SD-WAN rule is bypassing the preferred high-speed MPLS tunnel and taking the backup broadband tunnel instead. Which THREE factors should the administrator check to resolve this routing discrepancy? (Choose three)

Hard
28

An enterprise deploys BGP over SD-WAN with multiple MPLS and broadband connections. A route-map is applied to incoming BGP updates on the FortiGate to set a specific weight for routes learned over the MPLS interface. Why is the 'weight' attribute particularly effective in this FortiOS SD-WAN and BGP integration scenario?

Hard
29

An administrator is configuring SD-WAN rules with performance SLAs. Which TWO strategies are available in FortiOS when configuring an SD-WAN rule based on SLA metrics? (Choose two)

Medium
30

A FortiGate device is configured with an SD-WAN rule utilizing a SLA rule for latency and packet loss. Security profiles including Deep Packet Inspection (DPI) SSL inspection and an Antivirus profile are applied to the firewall policy allowing this traffic. Users report intermittent connection drops on real-time UDP-based applications. Upon troubleshooting, the administrator notices that packet drops occur only when the SD-WAN rule dynamically steers traffic to a backup IPsec tunnel that has a smaller MTU. What is the most likely root cause and mitigation for this behavior?

Hard
31

An administrator configures an ADVPN 2.0 deployment between a FortiGate hub and multiple spokes using OSPF as the dynamic routing protocol. The spoke units need to establish direct shortcut tunnels dynamically. Which configuration step is mandatory on the hub to ensure that BGP or OSPF next-hop resolution works correctly for ADVPN shortcut creation?

Medium

Frequently asked questions

What does the Security Profiles Routing And IPsec domain cover on the NSE7_SDW exam?
Routing questions usually test route selection (administrative distance, metric), how static routes are configured and when they are preferred over dynamic routing.
How many questions are in this domain?
This page lists all 31 Security Profiles Routing And IPsec questions in the NSE7_SDW question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Profiles Routing And IPsec questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
fortinet-nse7-sdwan FORTINET-NSE7-SDWAN security profiles routing and ipsec Practice Questions