Courseiva

NSE7_SDW · topic practice

Security Profiles Routing And IPsec practice questions

Practise NSE 7 - SD-WAN (NSE7_SDW) Security Profiles Routing And IPsec practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Security Profiles Routing And IPsec

What the exam tests

What to know about Security Profiles Routing And IPsec

Routing questions usually test route selection (administrative distance, metric), how static routes are configured and when they are preferred over dynamic routing.

Administrative distance comparing routing sources.

Static route configuration: next-hop vs exit interface.

Default route propagation and the gateway of last resort.

Recursive routing table lookups.

Watch out for

Common Security Profiles Routing And IPsec exam traps

  • Lower administrative distance wins when two routing sources have the same prefix.
  • A static route with an exit interface creates a directly-connected dependency.
  • The gateway of last resort is set by the default route, not automatically.
  • Metric is only compared within the same routing protocol.

Practice set

Security Profiles Routing And IPsec questions

20 questions · select your answer, then reveal the explanation

Question 1easymultiple choice
Read the full VPN explanation →

An administrator configures an SD-WAN rule with a 'Lowest Cost (SLA)' strategy. What determines the metric used by FortiOS to select the best interface when multiple links meet the SLA criteria?

Question 2mediummultiple choice
Read the full VPN explanation →

An administrator configures an IPsec tunnel template for ADVPN 2.0 on a FortiGate hub. Which specific Phase 1 configuration parameter must be enabled to support dynamic shortcut creation between spokes in ADVPN 2.0?

Question 3hardmultiple choice
Open the full BGP breakdown →

An administrator has configured BGP over multiple SD-WAN IPsec tunnels to provide redundant paths to a datacenter. However, asymmetric routing is causing stateful inspection drops on a secondary FortiGate firewall downstream. To ensure that BGP selects the preferred primary SD-WAN member consistently, which BGP attribute is best manipulated via a route-map applied to the BGP neighbor in FortiOS?

Question 4easymultiple choice
Read the full VPN explanation →

An administrator wants to apply a Web Filtering security profile to traffic that is being dynamically steered via an SD-WAN rule. Where must this security profile be enforced in FortiOS?

Question 5hardmultiple choice
Read the full VPN explanation →

A FortiGate device is configured with an SD-WAN rule utilizing a SLA rule for latency and packet loss. Security profiles including Deep Packet Inspection (DPI) SSL inspection and an Antivirus profile are applied to the firewall policy allowing this traffic. Users report intermittent connection drops on real-time UDP-based applications. Upon troubleshooting, the administrator notices that packet drops occur only when the SD-WAN rule dynamically steers traffic to a backup IPsec tunnel that has a smaller MTU. What is the most likely root cause and mitigation for this behavior?

Question 6hardmultiple choice
Read the full VPN explanation →

An IPsec VPN tunnel used as an SD-WAN member is experiencing intermittent flapping due to DPD (Dead Peer Detection) timeout issues over a high-latency satellite link. How should the administrator adjust the Phase 1 IPsec settings on FortiOS to stabilize the tunnel without completely disabling failure detection?

Question 7mediummultiple choice
Open the full BGP breakdown →

An enterprise network uses ADVPN 2.0 with BGP running over IPsec tunnels. A spoke needs to initiate a shortcut tunnel to another spoke. Which FortiOS CLI command is used on the hub to verify the active shortcut tunnels and view the shortcut state information?

Question 8easymultiple choice
Read the full VPN explanation →

When troubleshooting SD-WAN performance SLA packet loss, an administrator wants to view real-time latency, jitter, and packet loss statistics for individual health check members. Which CLI command should be executed?

Question 9mediummultiple choice
Review the full OSPF breakdown →

An administrator configures an ADVPN 2.0 deployment between a FortiGate hub and multiple spokes using OSPF as the dynamic routing protocol. The spoke units need to establish direct shortcut tunnels dynamically. Which configuration step is mandatory on the hub to ensure that BGP or OSPF next-hop resolution works correctly for ADVPN shortcut creation?

Question 10mediummultiple choice
Read the full VPN explanation →

An enterprise FortiGate is running SD-WAN with multiple internet breakouts. The administrator applies an Application Control security profile to the firewall policy. Some custom business applications are being incorrectly classified or blocked by the Application Control profile. To ensure SD-WAN can reliably steer this traffic using application signatures while preventing false positives, what is the recommended procedure?

Question 11easymultiple choice
Read the full VPN explanation →

When configuring an SD-WAN health check to monitor internet reachability using HTTP/HTTPS requests, which parameter defines the specific string the FortiGate expects to receive in the server response body to validate that the path is healthy?

Question 12hardmultiple choice
Read the full VPN explanation →

An administrator is troubleshooting an SD-WAN deployment where traffic matching an SD-WAN rule with a destination service object (e.g., HTTPS) is not being steered according to the SLA priority. Instead, it is always taking the default static route member. Upon checking the firewall policies, what is the most common reason why an SD-WAN rule fails to process application or service-based traffic matching?

Question 13hardmultiple choice
Open the full BGP breakdown →

An enterprise deploys BGP over SD-WAN with multiple MPLS and broadband connections. A route-map is applied to incoming BGP updates on the FortiGate to set a specific weight for routes learned over the MPLS interface. Why is the 'weight' attribute particularly effective in this FortiOS SD-WAN and BGP integration scenario?

Question 14mediummultiple choice
Open the full BGP breakdown →

In an ADVPN 2.0 deployment, a hub unit uses BGP to advertise routes to spokes. When a spoke learns a prefix via BGP from the hub, what mechanism allows the spoke to automatically initiate an ADVPN shortcut tunnel directly to another spoke when traffic flows between them?

Question 15mediummultiple choice
Open the full BGP breakdown →

An administrator implements BGP over SD-WAN tunnels to a cloud provider. The cloud provider requires BGP MD5 authentication on all peering sessions. Where is BGP MD5 authentication configured on the FortiGate?

Question 16easymultiple choice
Read the full VPN explanation →

An administrator needs to inspect encrypted traffic traversing an SD-WAN IPsec tunnel using Deep Packet Inspection (DPI). What must be installed on the client endpoints or configured on the FortiGate to prevent browser trust warnings when using SSL/TLS full inspection?

Question 17hardmultiple choice
Review the full OSPF breakdown →

A FortiGate device is running ADVPN 2.0 with OSPF. A spoke experiences transient routing loops when a shortcut tunnel tears down due to inactivity timeout. Which configuration adjustment on the FortiGate hub and spokes prevents these temporary routing blackholes or loops during shortcut teardown?

Question 18mediummultiple choice
Read the full wireless explanation →

An administrator configures an SD-WAN rule to route guest Wi-Fi traffic out of a secondary broadband internet connection. However, guest users are still able to access internal corporate subnets that are routed over the primary IPsec VPN tunnel. What configuration is missing or incorrect?

Question 19hardmultiple choice
Open the full BGP breakdown →

An enterprise network implements BGP over ADVPN. Spoke units advertise their local subnets to the hub via BGP. To prevent spokes from learning each other's subnets directly through the hub via regular BGP route propagation before an ADVPN shortcut is established (forcing them to route through the hub unnecessarily), or conversely, to optimize route distribution, what BGP feature is typically configured on the hub?

Question 20easymultiple choice
Read the full VPN explanation →

An administrator wants to view the active SD-WAN rule hit counts and verify which traffic is matching a specific SD-WAN rule in FortiOS. Which command should be used?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Profiles Routing And IPsec sessions

Start a Security Profiles Routing And IPsec only practice session

Every question in these sessions is drawn from the Security Profiles Routing And IPsec domain — nothing else.

Related practice questions

Related NSE7_SDW topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the NSE7_SDW exam test about Security Profiles Routing And IPsec?
Routing questions usually test route selection (administrative distance, metric), how static routes are configured and when they are preferred over dynamic routing.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Profiles Routing And IPsec questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Profiles Routing And IPsec domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other NSE7_SDW topics?
Use the topic links above to move to related areas, or go back to the NSE7_SDW question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the NSE7_SDW exam covers. They are not copied from any real exam or dump site.