Courseiva

CCNA Nse7 SD Wan System Configuration And Setup Questions

32 questions · Nse7 SD Wan System Configuration And Setup · All types, answers revealed

1
MCQhard

What is the purpose of the 'Gateway' override in an SD-WAN member configuration?

A.To force the use of a secondary ISP.
B.To specify a manual gateway for the SD-WAN member.
C.To bypass the firewall policy.
D.To enable load balancing.
AnswerB

Used when a specific gateway is required for the member link.

Why this answer

The gateway override allows the FortiGate to use a specific IP for the probe that is different from the interface's gateway, or to define a manual gateway where DHCP is used.

2
MCQeasy

You are deploying a new SD-WAN interface. What is the mandatory step before you can add an interface to an SD-WAN zone?

A.Configure a performance SLA for that specific interface.
B.Remove all firewall policy, static route, and DHCP references from the interface.
C.Assign a VLAN ID to the interface.
D.Enable SD-WAN on the global system settings.
AnswerB

The interface must be completely clean of any logical references.

Why this answer

Before an interface can be added to an SD-WAN zone, it must not have any existing references, such as being used in a firewall policy, static route, or DHCP server configuration.

3
MCQeasy

Which of the following is required to successfully implement SD-WAN?

A.A FortiManager instance.
B.At least two physical interfaces.
C.A subscription to FortiGuard SD-WAN service.
D.An external load balancer.
AnswerB

SD-WAN is designed to manage path selection between multiple links.

Why this answer

At least two interfaces are typically required to make SD-WAN selection meaningful, though one is technically possible.

4
MCQhard

When configuring an SD-WAN rule for a specific application, how does the FortiGate identify the traffic?

A.By analyzing the packet payload size.
B.By looking at the source MAC address.
C.By using the Application Control database.
D.By forcing traffic through a specific VLAN.
AnswerC

Application signatures allow identification of specific apps like O365.

Why this answer

The FortiGate uses the Application Control engine or specific destination IP/port objects to classify traffic for SD-WAN rules.

5
Multi-Selecthard

Which TWO of the following are necessary to enable SD-WAN on a FortiGate?

Select 2 answers
A.Enabling SD-WAN in the Feature Visibility menu.
B.Creating at least one SD-WAN rule.
C.Adding interfaces to an SD-WAN zone.
D.Updating the FortiGuard database.
E.Configuring a BGP peer.
AnswersB, C

Required to steer traffic.

Why this answer

SD-WAN is enabled by adding members to an SD-WAN zone and configuring rules.

6
Multi-Selecthard

Which TWO of the following occur when a member is removed from an SD-WAN zone?

Select 2 answers
A.The FortiGate restarts automatically.
B.The interface can then be used for other configurations like static routes.
C.The interface automatically reverts to a WAN port.
D.All firewall policies referencing the zone are deleted.
E.The interface must be removed from any SD-WAN rules.
AnswersB, E

Once free, it can be repurposed.

Why this answer

Removing a member from a zone requires updating all associated rules and ensures the interface is free of references.

7
Multi-Selectmedium

Which THREE of the following protocols can be used for Performance SLA probes?

Select 3 answers
A.FTP
B.ICMP
C.TCP Echo
D.HTTP
E.DHCP
AnswersB, C, D

Supported.

Why this answer

FortiGate supports ICMP, TCP Echo, and HTTP/HTTPS for health monitoring.

8
MCQeasy

When using SD-WAN zones, what is the primary benefit of grouping multiple physical interfaces into a single zone?

A.It increases the throughput of individual physical links.
B.It prevents the need for performance SLAs.
C.It automatically enables load balancing between interfaces.
D.It allows you to apply a single firewall policy to the entire group.
AnswerD

This is the main administrative benefit of zones.

Why this answer

Zones allow you to reference a group of interfaces in a single firewall policy, simplifying the configuration.

9
MCQmedium

Which SD-WAN rule strategy should you choose if you want to distribute traffic across multiple interfaces based on their bandwidth weights?

A.Manual
B.Maximize Bandwidth (SLA)
C.Lowest Cost (SLA)
D.SLA Target
AnswerB

Distributes traffic based on weighted bandwidth settings.

Why this answer

The 'Maximize Bandwidth' strategy allows traffic distribution based on the configured bandwidth weight for each interface.

10
MCQmedium

What is the impact of checking the 'Interface Preference' box in an SD-WAN rule?

A.It overrides the SLA strategy selection.
B.It enables failover to the default gateway.
C.It enables load balancing across interfaces.
D.It increases the probe frequency.
AnswerA

It forces traffic to preferred interfaces.

Why this answer

Interface preference forces the rule to prioritize specific interfaces over others, even if SLA metrics might suggest otherwise.

11
MCQmedium

What is the purpose of the 'Inbound' interface setting in an SD-WAN rule?

A.To restrict the rule to traffic originating from a specific interface.
B.To enable reverse path forwarding checks.
C.To define the WAN gateway.
D.To specify the egress interface.
AnswerA

This filters the rule based on ingress.

Why this answer

Inbound interface matching allows you to apply SD-WAN logic based on the traffic's ingress interface, providing more specific traffic steering.

12
Multi-Selectmedium

Which THREE of the following are parameters that can be monitored in a Performance SLA?

Select 3 answers
A.Packet Loss
B.CPU load
C.Jitter
D.Disk usage
E.Latency
AnswersA, C, E

Monitored metric.

Why this answer

Performance SLAs monitor latency, jitter, and packet loss.

13
MCQmedium

What is the effect of changing the 'Hold-down' timer in a Performance SLA?

A.It changes the frequency of the probes.
B.It sets the maximum number of failed probes allowed.
C.It prevents route flapping by delaying the transition back to an 'up' state.
D.It determines the timeout duration for a single probe.
AnswerC

It adds a stability buffer to the interface status.

Why this answer

The 'Hold-down' timer defines how long an interface must remain healthy after a failure before it is considered 'up' again, preventing route flapping.

14
Multi-Selectmedium

Which THREE of the following are valid strategies for SD-WAN rules?

Select 3 answers
A.Priority
B.Maximize Bandwidth
C.Load Balance
D.SLA Target
E.Round Robin
AnswersA, B, D

Valid strategy.

Why this answer

The available strategies include Priority, SLA Target, Maximize Bandwidth, Manual, and Lowest Cost.

15
MCQmedium

When setting up a Performance SLA, what is the 'Participant' setting?

A.The monitoring interval.
B.The user group assigned to the probe.
C.The destination IP address.
D.The SD-WAN member that originates the probe.
AnswerD

Defines the source of the health check.

Why this answer

The 'Participant' setting determines which SD-WAN members the probe is sent from.

16
MCQmedium

What is the maximum number of members allowed in a single SD-WAN zone?

A.8
B.2
C.4
D.Depends on the model, but generally limited by system resources.
AnswerD

The number of members is defined by hardware resource limits.

Why this answer

FortiOS supports a large number of members per zone, typically limited only by the hardware model's scale, not a low fixed number.

17
MCQeasy

Where do you configure the 'Gateway' IP address for an SD-WAN member?

A.Under Firewall Policy.
B.Under Network > Static Routes.
C.Under Network > SD-WAN > SD-WAN Members.
D.Under System > Interfaces.
AnswerC

This is the correct path for member gateway configuration.

Why this answer

The gateway for an SD-WAN member is configured within the SD-WAN member settings menu.

18
Multi-Selectmedium

Which THREE of the following criteria are used for SD-WAN rule traffic matching?

Select 3 answers
A.Interface speed
B.Destination address
C.VLAN priority
D.Application/Service
E.Source address
AnswersB, D, E

Matching criteria.

Why this answer

SD-WAN rules match traffic based on Source, Destination, and Application/Service.

19
MCQhard

You are using 'SLA Target' as your strategy. What happens if multiple members meet the SLA?

A.The system selects the first member in the list.
B.The system selects the one with the highest bandwidth capacity.
C.The system selects the member with the best performance (e.g., lowest latency).
D.Traffic is sent through all of them simultaneously.
AnswerC

It dynamically selects the best performer.

Why this answer

When multiple members meet the SLA in 'SLA Target' mode, the FortiGate uses the member with the best performance metric (e.g., lowest latency).

20
MCQhard

You are troubleshooting an issue where traffic is not using an SD-WAN rule despite meeting criteria. What is the most likely cause?

A.A higher-priority SD-WAN rule is matching the traffic first.
B.The SD-WAN rule is disabled.
C.The Performance SLA has timed out.
D.The interface is not in an SD-WAN zone.
AnswerA

Rules are processed sequentially.

Why this answer

SD-WAN rules are evaluated top-down. If a higher-priority rule matches the traffic, the lower-priority rule will never be reached.

21
MCQmedium

You are configuring a Performance SLA to monitor reachability to a SaaS application. Which parameter determines the threshold for an interface to be considered 'unhealthy' in the SD-WAN routing table?

A.Probe Mode
B.Sequence Number
C.Packet Loss Threshold
D.Update Interval
AnswerC

If packet loss exceeds this percentage, the member is removed from the SD-WAN route table.

Why this answer

The 'threshold-alert' or the individual latency/jitter/packet loss thresholds within the Performance SLA configuration dictate when a member is marked failed.

22
MCQmedium

Which command is used to verify the current status of SD-WAN members and their SLA health from the CLI?

A.diagnose sys sdwan health-check
B.show router info bgp
C.get system interface
D.get system sdwan member
AnswerA

Provides real-time health data for SLA probes.

Why this answer

The command 'diagnose sys sdwan health-check' shows the status of configured health checks and member reachability.

23
MCQeasy

Which protocol is NOT a valid option for Performance SLA probes?

A.TCP Echo
B.UDP Broadcast
C.HTTP
D.ICMP
AnswerB

UDP Broadcast is not a supported protocol for standard SD-WAN health checks.

Why this answer

FortiGate supports ping (ICMP), TCP echo, HTTP, and Two-Way Active Measurement Protocol (TWAMP).

24
Multi-Selecthard

Which TWO of the following can be used as a 'Source' in an SD-WAN rule?

Select 2 answers
A.Source IP address object.
B.SLA target name.
C.Interface MAC address.
D.Firewall policy ID.
E.User group.
AnswersA, E

Standard match criteria.

Why this answer

SD-WAN rules can match traffic based on source IP addresses or specific user groups.

25
MCQeasy

Where are SD-WAN zones managed in the FortiGate GUI?

A.Interface > Physical Interfaces.
B.System > Network > Zones.
C.Firewall > Policy > Objects.
D.Network > SD-WAN > SD-WAN Zones.
AnswerD

Correct menu path.

Why this answer

SD-WAN zones are created and managed under the Network > SD-WAN menu.

26
MCQhard

An SD-WAN rule is configured with 'Lowest Cost (SLA)' strategy. If all members in the SLA meet the requirements, how does the FortiGate select the outgoing interface?

A.The member with the lowest interface cost value defined in the SD-WAN member configuration.
B.Round Robin
C.The interface with the highest bandwidth.
D.The interface that was most recently added to the zone.
AnswerA

Lowest cost strategy specifically uses the manual cost value.

Why this answer

In 'Lowest Cost (SLA)' mode, the FortiGate selects the member with the lowest configured cost that meets the SLA requirements.

27
MCQmedium

When configuring an SD-WAN rule, what is the purpose of the 'Source' address field?

A.To define the gateway IP for the route.
B.To force traffic to a specific SD-WAN zone.
C.To determine which ISP the traffic exits through regardless of SLA.
D.To match traffic based on the source IP or user.
AnswerD

This provides granular traffic steering.

Why this answer

The 'Source' field allows you to selectively apply SD-WAN rules based on specific traffic origins, such as a subnet or user group.

28
MCQhard

You have an SD-WAN rule with 'Priority' strategy. What happens if the highest priority member fails its SLA?

A.Traffic is dropped.
B.The FortiGate enters an error state.
C.Traffic is load balanced across all remaining members.
D.Traffic fails over to the member with the next highest priority value.
AnswerD

The system moves down the list of priorities.

Why this answer

In 'Priority' strategy, if the highest priority member becomes unhealthy (SLA failure), the traffic automatically fails over to the next highest priority member.

29
Multi-Selectmedium

Which THREE of the following are benefits of using SD-WAN?

Select 3 answers
A.Built-in physical layer cabling.
B.Simplified WAN management through zones.
C.Automated failover between WAN links.
D.Automatic hardware replacement.
E.Dynamic path selection based on application performance.
AnswersB, C, E

Core benefit.

Why this answer

SD-WAN provides link aggregation, intelligent path selection, and simplified WAN management.

30
Multi-Selecthard

Which TWO of the following steps are required to correctly configure a Performance SLA?

Select 2 answers
A.Configure a firewall address object for the probe.
B.Enable BGP on the interface.
C.Select the probe protocol.
D.Define the destination IP address.
E.Assign the probe to a VPN tunnel.
AnswersC, D

Required for the health check method.

Why this answer

To configure an SLA, you must define the destination IP (or server) and the probe protocol.

31
MCQhard

You need to ensure that VoIP traffic stays on the interface with the lowest jitter. Which strategy should you use?

A.Load Balance
B.Lowest Cost (SLA)
C.SLA Target
D.Manual
AnswerC

Allows selecting interfaces based on jitter performance.

Why this answer

'SLA Target' strategy allows you to set specific criteria like jitter, latency, and packet loss, and select the best interface for those metrics.

32
Multi-Selecthard

Which TWO of the following can cause an SD-WAN member to be marked as 'down' in an SLA?

Select 2 answers
A.The probe times out.
B.The system clock is updated.
C.The packet loss exceeds the threshold.
D.The firewall policy is disabled.
E.The interface IP address is changed.
AnswersA, C

Failure condition.

Why this answer

An interface is marked down if the probe fails to receive a response or if the response exceeds configured thresholds.

Ready to test yourself?

Try a timed practice session using only Nse7 SD Wan System Configuration And Setup questions.