Courseiva

CCNA Advanced Networking and SD-WAN Questions

75 of 125 questions · Page 1/2 · Advanced Networking and SD-WAN · Answers revealed

1
MCQeasy

What is the purpose of BFD (Bidirectional Forwarding Detection) in a FortiGate routing configuration?

A.To encrypt routing protocol traffic
B.To detect forwarding path failures quickly
C.To authenticate routing peers
D.To provide load balancing across multiple paths
AnswerB

BFD sends sub-second control packets over the forwarding path, so FortiGate can tear down a failed route or adjacency far faster than routing protocol hellos allow. This satisfies the stem's requirement for rapid failure detection, enabling quicker reconvergence than standard dead-interval timers.

Why this answer

BFD (Bidirectional Forwarding Detection) provides fast failure detection for forwarding paths between two adjacent routers, independent of any routing protocol. In FortiGate configurations, BFD is used to detect link or neighbor failures in sub-second intervals (e.g., 50-100 ms), enabling rapid convergence for dynamic routing protocols like OSPF or BGP. This is critical for SD-WAN and high-availability scenarios where traditional keepalive timers (e.g., OSPF Hello/Dead intervals of 10-40 seconds) are too slow.

Exam trap

The trap here is that candidates confuse BFD's role in fast failure detection with routing protocol features like authentication or encryption, or mistakenly think BFD itself provides load balancing, when in fact it only monitors path liveliness and triggers convergence.

How to eliminate wrong answers

Option A is wrong because BFD does not encrypt routing protocol traffic; encryption is handled by protocols like IPsec or authentication mechanisms within routing protocols (e.g., OSPF MD5 authentication). Option C is wrong because BFD does not authenticate routing peers; authentication is a separate feature of routing protocols (e.g., BGP MD5 password or OSPF authentication) and BFD itself has no authentication mechanism. Option D is wrong because BFD is a detection mechanism, not a load-balancing tool; load balancing across multiple paths is achieved by ECMP (Equal-Cost Multi-Path) routing or SD-WAN rules, while BFD simply detects failures on those paths.

2
MCQeasy

An administrator wants to use a FortiGate to manage FortiSwitch units via the LAN. Which interface configuration is required on the FortiGate to allow this management?

A.The interface must have 'set role lan' configured
B.The interface must be configured as a 'trunk' mode to connect to the FortiSwitch
C.The interface must be a member of a VDOM
D.The interface must have 'set type switch' enabled
AnswerD

Correct. Setting 'set type switch' enables FortiLink, allowing the FortiGate to manage connected FortiSwitch units.

Why this answer

The interface must have 'set type switch' enabled to manage FortiSwitch units. This configuration sets the interface as a FortiLink port, enabling automatic discovery, provisioning, and management of FortiSwitch devices. Trunk mode is not required; in fact, setting the interface as a trunk (set mode trunk) is for aggregating multiple ports or carrying multiple VLANs but does not enable FortiLink control protocols.

Therefore, option D is correct.

Exam trap

The trap is that candidates often assume that a trunk port is needed to carry multiple VLANs, but for FortiSwitch management, the interface must be configured as a switch type to enable FortiLink.

How to eliminate wrong answers

Option A is wrong because 'set role lan' is a generic interface role used for regular LAN access, not for FortiSwitch management; FortiLink requires a trunk interface to handle multiple VLANs and control protocols. Option C is wrong because while the interface can be a member of a VDOM, VDOM membership is not a requirement for FortiSwitch management—FortiLink works in both VDOM and non-VDOM modes. Option D is wrong because 'set type switch' is not a valid FortiGate interface command; FortiGate interfaces are typically physical, VLAN, or aggregate types, and FortiSwitch management uses a trunk interface, not a switch-type interface.

3
MCQmedium

An administrator wants to use FortiExtender to provide LTE WAN connectivity. After connecting the FortiExtender to the FortiGate, the LTE interface is not showing up. What is the first troubleshooting step?

A.Run 'execute lte test' command
B.Configure an SD-WAN rule for LTE traffic
C.Verify the FortiExtender is connected to the correct port and powered on
D.Check the signal strength of the LTE connection
AnswerC

Before any FortiGate-side discovery or CAPWAP configuration can succeed, the FortiExtender must be physically cabled to the correct FortiGate port and receiving power; without link and power the LTE interface never appears, so this is the first check.

Why this answer

The first troubleshooting step is to verify the physical connection and power status of the FortiExtender. If the FortiExtender is not connected to the correct port (typically a USB or PoE port) or is not powered on, the FortiGate will not detect the LTE interface at all, making any software-level checks premature.

Exam trap

The trap here is that candidates jump to software-level troubleshooting (like running diagnostic commands or checking signal strength) without first confirming the basic physical connectivity and power status of the FortiExtender.

How to eliminate wrong answers

Option A is wrong because 'execute lte test' is a diagnostic command that requires the LTE interface to already be present and operational; running it before verifying physical connectivity will fail or return irrelevant errors. Option B is wrong because configuring an SD-WAN rule for LTE traffic assumes the LTE interface is already recognized and available, which is not the case here. Option D is wrong because checking signal strength presupposes that the LTE interface is up and has established a connection to the cellular network, which cannot happen if the FortiExtender is not physically connected or powered.

4
MCQhard

An administrator is troubleshooting an SD-WAN setup where a specific application's traffic is not being steered according to the configured SD-WAN rule. The rule uses a performance SLA and the 'lowest-cost' strategy. The administrator runs 'diagnose sys sdwan health-check' and sees that both members are alive and meeting the SLA. However, traffic still goes over the higher-cost member. What is the most likely cause?

A.The SD-WAN rule is not matching the traffic because the source or destination criteria are incorrect.
B.The higher-cost member is configured with a lower priority value, causing it to be preferred.
C.The performance SLA is not assigned to the SD-WAN zone.
D.The 'lowest-cost' strategy is not supported for application-based rules.
AnswerA

If the SD-WAN rule does not match the traffic, the default routing or another rule will be used, which may select the higher-cost member. Even though the health-check shows both members alive, the rule must match the traffic to enforce the 'lowest-cost' selection. Incorrect match criteria are a common cause of unexpected routing.

Why this answer

When traffic does not follow the SD-WAN rule despite healthy members, the most likely cause is that the rule is not matching the traffic. This can happen if the source, destination, application, or other match criteria are misconfigured. Without a match, the FortiGate falls back to the routing table or other rules, potentially using the higher-cost member.

Administrators should verify rule match criteria and session details.

Exam trap

The trap here is assuming that healthy members guarantee rule enforcement, overlooking that the rule must first match the traffic.

5
MCQmedium

A network admin configures OSPF on a FortiGate with multiple areas, including one area that is not directly connected to the backbone (Area 0). To ensure that routes from that area are advertised into other areas, which OSPF feature must be properly configured?

A.OSPF route redistribution
B.OSPF passive interface
C.OSPF virtual-link
D.OSPF network type
AnswerC

An area lacking a direct link to Area 0 must reach the backbone through a virtual link, which tunnels OSPF adjacency across a transit area. This makes the disconnected area appear attached to Area 0, allowing its routes to be advertised into other areas.

Why this answer

OSPF virtual-links are used to connect a non-backbone area to the backbone area through a transit area. This ensures that the area has a logical path to the backbone, allowing ABRs to generate Type 3 summary LSAs and advertise routes between areas. Without proper virtual-link configuration, routes from an area not directly connected to the backbone cannot be advertised to other areas.

Exam trap

The trap is that candidates may think OSPF route redistribution is needed for inter-area routes, but OSPF internally uses ABRs to automatically generate Type 3 LSAs. Virtual-links are a specific feature to connect isolated areas to the backbone, which is necessary for inter-area routing in such topologies.

How to eliminate wrong answers

Option B (OSPF passive interface) is wrong because it prevents OSPF hello packets from being sent on an interface, suppressing neighbor discovery and route exchange, but it does not control inter-area route advertisement. Option C (OSPF virtual-link) is wrong because it is used to connect a non-backbone area to the backbone area through a transit area when a direct physical connection is missing, not to advertise routes between areas. Option D (OSPF network type) is wrong because it determines how OSPF operates on a given interface (e.g., broadcast, point-to-point) and affects neighbor formation and LSA flooding, but it does not enable inter-area route propagation.

6
MCQeasy

Which SD-WAN load balancing algorithm is best for ensuring that all traffic from a specific source-destination pair uses the same WAN link?

A.Spillover
B.Source-dest IP
C.Volume
D.Lowest-cost
AnswerB

Source-destination IP hashing maps each unique source-destination pair to a fixed WAN link, so every flow between that pair traverses the same path. This satisfies the stem's requirement for per-pair link stickiness, unlike round-robin or weighted algorithms, which distribute flows independently and would scatter a pair's traffic across multiple links.

Why this answer

Source-dest IP (B) is the correct algorithm because it uses a hash of both the source and destination IP addresses to deterministically select a WAN link. This ensures that all packets belonging to the same flow (same source-destination pair) are consistently forwarded over the same link, preserving packet order and avoiding reordering issues.

Exam trap

The trap here is that candidates often confuse 'Spillover' with a load-balancing algorithm, but Spillover is actually a bandwidth-based failover or overflow mechanism, not a deterministic per-flow hashing method.

How to eliminate wrong answers

Option A (Spillover) is wrong because it is a traffic-steering method that shifts traffic to another link only after a configured bandwidth threshold is exceeded, not a load-balancing algorithm that ensures per-flow stickiness. Option C (Volume) is wrong because it balances traffic based on the volume of data sent over each link, which can cause flows to be split across multiple links and break source-destination pair consistency. Option D (Lowest-cost) is wrong because it selects the link with the lowest cost metric (e.g., based on link quality or administrative weight), which does not guarantee that all traffic from a specific source-destination pair will use the same link; cost-based decisions can change dynamically.

7
MCQeasy

A FortiGate is configured with multiple virtual routers (VRFs). The administrator wants to allow communication between two VRFs using a firewall policy. Which type of interface is required for the policy?

A.VDOM link
B.VLAN subinterface
C.Loopback interface
D.Virtual-wire pair
AnswerA

VDOM links are used to connect VDOMs or VRFs; firewall policies can be applied to allow traffic between VRFs.

Why this answer

A VDOM link is a virtual interface that connects two VDOMs (Virtual Domains) and inherently supports routing between different VRFs (Virtual Routing and Forwarding instances) within a FortiGate. When a firewall policy is applied to a VDOM link, it can control traffic flowing between the two VRFs, as the link itself is a Layer 3 interface that belongs to both VDOMs and can be assigned to different VRFs on each side. This is the only interface type that natively allows inter-VRF communication with firewall policy enforcement.

Exam trap

The trap here is that candidates often confuse VDOM links with VLAN subinterfaces, assuming that VLAN tagging alone can separate VRFs, but VLAN subinterfaces cannot cross VRF boundaries without additional routing constructs like route leaking, which is not handled by a firewall policy directly.

How to eliminate wrong answers

Option B (VLAN subinterface) is wrong because VLAN subinterfaces operate within a single VRF and cannot directly route traffic between different VRFs; they are used for segmenting traffic within the same VRF or VDOM. Option C (Loopback interface) is wrong because loopback interfaces are virtual interfaces used for management, routing protocol stability, or as tunnel endpoints, and they cannot be used to forward traffic between VRFs via a firewall policy. Option D (Virtual-wire pair) is wrong because virtual-wire pairs are transparent Layer 2 interfaces that bridge traffic without routing, and they do not support VRF separation or inter-VRF firewall policies.

8
MCQmedium

A multi-area OSPF network includes a FortiGate as an ABR. The administrator needs to redistribute a static route into OSPF. Which command is required on the FortiGate to achieve this?

A.config router ospf config redistribute edit 'static' set status enable end
B.config router prefix-list edit 'static' set action permit end
C.config router policy set src 0.0.0.0/0 set dst 0.0.0.0/0 end
D.config router static set redistribute ospf enable end
AnswerA

The FortiGate redistributes static routes only when explicitly enabled under 'config router ospf' then 'config redistribute'. Editing the 'static' entry and setting status enable activates redistribution, injecting the static route into OSPF as an ASBR or ABR.

Why this answer

To redistribute a static route into OSPF on a FortiGate, you must enter the OSPF configuration context, navigate to the 'redistribute' subcommand, select the 'static' route type, and set its status to 'enable'. This is the standard method for enabling route redistribution from one routing protocol (or static routes) into OSPF, as defined in the FortiGate CLI reference.

Exam trap

The trap here is that candidates often confuse redistribution configuration with route filtering or policy routing, mistakenly thinking a prefix-list (Option B) or policy-based routing (Option C) is needed, or they incorrectly assume static routes have a 'redistribute' knob (Option D) instead of configuring it under the OSPF process.

How to eliminate wrong answers

Option B is wrong because a prefix-list is used for filtering route advertisements (e.g., in route maps or distribute lists), not for enabling redistribution; it does not inject static routes into OSPF. Option C is wrong because 'config router policy' configures policy-based routing (PBR) to override the routing table for specific traffic, not OSPF redistribution. Option D is wrong because 'config router static' does not have a 'set redistribute ospf enable' command; redistribution is configured under the OSPF process, not under static routes.

9
MCQmedium

An administrator wants to integrate a FortiExtender with a FortiGate to provide cellular WAN connectivity. Which configuration step is required on the FortiGate to use the FortiExtender as an SD-WAN member?

A.Enable BGP on the FortiExtender interface
B.Create a firewall policy allowing traffic from the FortiExtender
C.Add the FortiExtender's interface to the SD-WAN zone
D.Configure a static route pointing to the FortiExtender
AnswerC

SD-WAN selects members from interfaces assigned to the SD-WAN zone. Adding the FortiExtender's interface to that zone makes it eligible for SD-WAN rules and health checks, enabling cellular WAN participation in load balancing and failover.

Why this answer

To use a FortiExtender as an SD-WAN member, the FortiExtender's physical or logical interface must be added to the SD-WAN zone on the FortiGate. This allows the FortiGate to apply SD-WAN rules, load balancing, and SLA-based path selection to traffic traversing the cellular WAN link. Without this step, the interface remains a standard WAN interface and cannot participate in SD-WAN policies.

Exam trap

The trap here is that candidates often confuse the need for a firewall policy or static route with the SD-WAN membership requirement, but the FortiGate treats the FortiExtender interface as a local interface, so only adding it to the SD-WAN zone is necessary for SD-WAN participation.

How to eliminate wrong answers

Option A is wrong because BGP is not required on the FortiExtender interface for SD-WAN membership; SD-WAN operates at the interface level and does not mandate dynamic routing protocols. Option B is wrong because a firewall policy is needed for traffic to pass through the FortiExtender interface, but it is not a prerequisite for adding the interface to the SD-WAN zone; the SD-WAN membership is configured independently of firewall policies. Option D is wrong because a static route pointing to the FortiExtender is not required; the FortiExtender appears as a directly connected interface on the FortiGate, and SD-WAN uses the interface itself, not a next-hop route.

10
MCQeasy

Which load balancing algorithm in SD-WAN distributes new sessions based on the source and destination IP addresses, ensuring that all sessions from a given source-destination pair go to the same member?

A.Lowest cost
B.Volume
C.Source-dest IP
D.Sessions
AnswerC

Hashing on the source-destination IP pair means every new session between the same two hosts resolves to one member, preserving session stickiness without per-session rebalancing. This satisfies the requirement that all sessions from a given source-destination pair use the same SD-WAN member.

Why this answer

The Source-dest IP algorithm in Fortinet SD-WAN uses a hash of the source and destination IP addresses to determine the outbound member for each new session. This ensures that all sessions between the same source-destination pair are consistently forwarded to the same WAN member, preserving flow affinity without requiring session-based state tracking.

Exam trap

The trap here is that candidates often confuse 'Source-dest IP' with 'Sessions' because both involve distribution, but Sessions uses round-robin and does not guarantee source-destination affinity, while Source-dest IP uses a hash to ensure consistent member selection for the same pair.

How to eliminate wrong answers

Option A is wrong because Lowest cost selects the member with the lowest measured cost (e.g., latency or jitter) for each new session, which does not guarantee that sessions from the same source-destination pair go to the same member. Option B is wrong because Volume distributes sessions based on the current traffic volume on each member, aiming to balance load rather than enforce source-destination affinity. Option D is wrong because Sessions distributes sessions in a round-robin fashion across members, which can send sessions from the same source-destination pair to different members.

11
MCQeasy

What is the purpose of BFD on a FortiGate?

A.To load balance traffic across multiple paths.
B.To provide fast detection of link failures.
C.To authenticate OSPF neighbors.
D.To encrypt traffic between two FortiGates.
AnswerB

BFD (Bidirectional Forwarding Detection) provides sub-second detection of link failures between forwarding engines, enabling faster convergence than routing protocol timers alone. This satisfies the stem's requirement to identify its purpose on a FortiGate, which is rapid link failure detection.

Why this answer

BFD (Bidirectional Forwarding Detection) provides sub-second failure detection for routing protocols like OSPF and BGP, independent of the routing protocol's own hello timers. On a FortiGate, BFD is used to rapidly detect link or neighbor failures, enabling faster convergence in SD-WAN and dynamic routing scenarios.

Exam trap

The trap here is that candidates confuse BFD's fast failure detection with load balancing or authentication functions, but BFD is strictly a liveness detection mechanism with no role in traffic distribution or security.

How to eliminate wrong answers

Option A is wrong because BFD does not perform load balancing; load balancing is handled by ECMP (Equal-Cost Multi-Path) or SD-WAN rules, not BFD. Option C is wrong because OSPF neighbor authentication is performed using MD5 or SHA authentication keys, not BFD; BFD only monitors link liveliness. Option D is wrong because traffic encryption between FortiGates is achieved via IPsec VPN tunnels, not BFD, which is a lightweight hello-based protocol with no encryption capabilities.

12
MCQeasy

An administrator wants to load balance traffic across two WAN links by session count. Which SD-WAN load balancing algorithm should they use?

A.Sessions
B.Spillover
C.Lowest-cost
D.Volume
AnswerA

The Sessions algorithm distributes traffic by tracking active session counts per WAN link, directly satisfying the requirement to load balance by session count. Unlike weighted or spillover methods, which use bandwidth ratios or thresholds, it dynamically assigns new sessions to the link with the fewest active sessions, achieving even per-session distribution.

Why this answer

The Sessions algorithm distributes new sessions across WAN links based on the current session count, ensuring each link handles a roughly equal number of active sessions. This directly matches the administrator's requirement to load balance by session count, as it uses the session counter as the metric for link selection.

Exam trap

The trap here is that candidates often confuse 'session count' with 'volume' or 'spillover,' assuming that any load balancing algorithm that distributes traffic equally must use data volume or bandwidth thresholds, rather than recognizing that Sessions is the explicit algorithm for session-based distribution.

How to eliminate wrong answers

Option B is wrong because Spillover is not a load balancing algorithm; it is a traffic steering method that sends traffic to a primary link until its bandwidth threshold is exceeded, then spills over to backup links, which does not balance by session count. Option C is wrong because Lowest-cost selects the link with the lowest cost metric (e.g., latency, jitter, or loss) for each session, not based on session count. Option D is wrong because Volume balances traffic by the amount of data transferred (bytes) across links, not by the number of sessions.

13
MCQmedium

An administrator wants to ensure that traffic from a specific source IP uses a particular SD-WAN member regardless of performance SLA results. Which SD-WAN configuration element should be used?

A.SD-WAN rule with manual strategy
B.Route map
C.Policy-based routing on the firewall policy
D.Performance SLA
AnswerA

A manual-strategy SD-WAN rule pins matching traffic to a chosen member, bypassing SLA-driven selection entirely. Because the requirement is source-IP-based steering that ignores performance measurements, manual strategy satisfies the "regardless of SLA results" constraint directly, unlike best-quality or lowest-cost strategies that continuously evaluate link metrics.

Why this answer

A is correct because an SD-WAN rule with a manual strategy allows the administrator to explicitly pin traffic from a specific source IP to a particular SD-WAN member interface, overriding any performance SLA-based path selection. This is achieved by configuring the rule's 'strategy' as 'manual' and specifying the preferred member, which forces all matching traffic to use that interface regardless of SLA health.

Exam trap

The trap here is that candidates confuse Performance SLA as a steering mechanism rather than a monitoring tool, or mistakenly think policy-based routing can achieve the same result within an SD-WAN context, but Fortinet's SD-WAN architecture requires the rule's strategy to be set to 'manual' for explicit member pinning.

How to eliminate wrong answers

Option B is wrong because route maps are used for route redistribution, filtering, or modifying routing attributes (e.g., metric, next-hop) in routing protocols like BGP or OSPF; they do not provide per-source-IP traffic steering within an SD-WAN zone. Option C is wrong because policy-based routing (PBR) on a firewall policy can direct traffic based on source IP, but it operates at the routing level and does not integrate with SD-WAN member selection or SLA awareness; it would bypass the SD-WAN logic entirely. Option D is wrong because a Performance SLA is a monitoring mechanism that measures link quality (e.g., latency, jitter, packet loss) and is used by SD-WAN rules with 'best quality' or 'load balancing' strategies, but it cannot force traffic to a specific member; it only provides data for dynamic path decisions.

14
MCQeasy

An administrator is configuring an SD-WAN rule on a FortiGate. They want to load balance traffic across three WAN links based on the volume of traffic sent. Which load balancing algorithm should they use?

A.Source IP
B.Session count
C.Volume
D.Weighted round robin
AnswerC

The volume algorithm distributes traffic based on the amount of data sent through each link. It monitors the volume of traffic and selects the link with the least volume, helping to balance the total data transferred across links. This directly addresses the requirement to load balance based on traffic volume, making it the correct choice.

Why this answer

The volume load balancing algorithm in SD-WAN distributes traffic based on the measured volume of data sent through each link. It dynamically selects the link with the least volume, ensuring that the total traffic is balanced across available links. This is the only algorithm among the options that directly uses traffic volume as the metric, making it the correct choice for the scenario.

Exam trap

The trap here is confusing session count with volume; session count balances the number of connections, while volume balances the actual data transferred.

15
MCQmedium

A FortiGate has multiple VRFs configured. An administrator wants to allow traffic from VRF 1 to reach a server in VRF 2. What configuration is required?

A.Use a single VDOM and enable inter-VDOM links.
B.Place both interfaces in the same VRF.
C.Create a static route from one VRF to another.
D.Configure a VRF leak policy using route maps or policy routes.
AnswerD

VRF leak policies permit controlled route redistribution between otherwise isolated routing tables, so traffic from VRF 1 can resolve a path into VRF 2. Route maps or policy routes define which prefixes or flows are leaked, satisfying the inter-VRF reachability requirement without merging the VRFs.

Why this answer

VRF leaking is the standard method to allow traffic between different VRFs on a FortiGate. This is achieved by configuring route maps or policy routes to selectively import/export routes between VRFs, enabling inter-VRF communication without merging the VRFs or using VDOMs.

Exam trap

The trap here is that candidates confuse VRF leaking with inter-VDOM routing or assume a simple static route can bridge VRFs, but FortiGate enforces strict VRF isolation unless an explicit leak policy is configured.

How to eliminate wrong answers

Option A is wrong because inter-VDOM links are used for communication between different VDOMs, not between VRFs within the same VDOM; VRFs are a routing table segmentation feature within a single VDOM. Option B is wrong because placing both interfaces in the same VRF would defeat the purpose of VRF segmentation, merging the routing tables and removing isolation. Option C is wrong because a static route alone cannot leak traffic between VRFs; FortiGate requires explicit VRF leak configuration (e.g., route maps or policy routes) to allow inter-VRF forwarding, as static routes are VRF-scoped by default.

16
MCQmedium

An administrator runs 'diagnose sys session filter dport 443' and sees: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

A.The session is a multicast session with a duration of 3600 seconds.
B.The session is a TCP session in established state that has been up for 3600 seconds and will expire in 3599 seconds.
C.The session is in SYN_SENT state and has timed out after 3600 seconds.
D.The session is a UDP session that has been active for 3600 seconds.
AnswerB

proto=6 denotes TCP, and proto_state=01 is the established state. The duration field shows the session has existed 3600 seconds, while expire=3599 gives the remaining seconds before timeout, confirming an active established TCP session nearing expiry.

Why this answer

The output shows proto=6, which is TCP, and proto_state=01, which indicates the TCP session is in an established state (TCP_ESTABLISHED). The duration=3600 means the session has been active for 3600 seconds, and expire=3599 means it will expire in 3599 seconds (i.e., the idle timeout is counting down). This is a standard TCP session in the established state, not a multicast or UDP session.

Exam trap

The trap here is that candidates confuse proto_state=01 with a SYN_SENT or timed-out state, or misinterpret proto=6 as UDP, because they do not memorize the TCP state codes or protocol numbers used in FortiOS session diagnostics.

How to eliminate wrong answers

Option A is wrong because proto=6 is TCP, not multicast; multicast sessions use UDP (proto=17) and have different state codes. Option C is wrong because proto_state=01 represents TCP_ESTABLISHED, not SYN_SENT (which would be state 02); also, the session has not timed out—it is still active with an expiry counter. Option D is wrong because proto=6 is TCP, not UDP (UDP uses proto=17), and UDP sessions do not have a TCP state machine.

17
MCQmedium

A FortiGate has multiple equal-cost routes to the same destination via two different interfaces. ECMP load balancing is enabled. What determines how traffic is distributed among the routes?

A.The interface speed
B.A hash of source and destination IP addresses
C.Round-robin per packet
D.The route metric
AnswerB

ECMP distributes traffic per flow using a hash of source and destination IP addresses, so each conversation consistently follows one path while different flows spread across the equal-cost routes. This per-flow hashing preserves packet ordering and satisfies the stem's load-balancing requirement.

Why this answer

When ECMP load balancing is enabled on a FortiGate, traffic distribution among equal-cost routes is determined by a hash algorithm that uses source and destination IP addresses (and optionally ports) to select the egress interface. This ensures that all packets belonging to the same flow are consistently forwarded via the same path, preserving packet order and avoiding reordering issues.

Exam trap

The trap here is that candidates often assume ECMP uses round-robin or interface speed weighting, but FortiGate strictly uses a hash-based algorithm to maintain flow affinity and avoid packet reordering.

How to eliminate wrong answers

Option A is wrong because interface speed does not influence ECMP load balancing; FortiGate uses a hash-based selection, not a weighted distribution based on link speed. Option C is wrong because FortiGate does not use per-packet round-robin for ECMP; such a method would cause severe packet reordering and is not implemented in FortiGate's ECMP logic. Option D is wrong because the route metric is identical for all equal-cost routes by definition; ECMP only applies when metrics are equal, so metric does not determine distribution.

18
MCQmedium

A network administrator configures an SD-WAN zone with two members (port1 and port2) and sets the load balancing algorithm to 'spillover'. The spillover threshold is set to 100 Mbps on port1. If traffic reaches 120 Mbps on port1, what happens to new sessions?

A.All traffic is dropped because the threshold exceeded
B.New sessions are sent to port2 until port1 drops below the threshold
C.Port1 continues to receive all new sessions but packets are queued
D.New sessions are distributed equally between port1 and port2
AnswerB

Spillover forwards new sessions to the second member once the primary member exceeds its threshold, while existing sessions stay on port1. At 120 Mbps, above the 100 Mbps threshold, port2 receives new sessions until port1 falls back below the limit.

Why this answer

When the spillover algorithm is configured with a threshold of 100 Mbps on port1 and traffic reaches 120 Mbps, port1 is considered saturated. The SD-WAN zone then directs all new sessions to port2 until the traffic on port1 drops below the threshold. This is the defined behavior of spillover load balancing in Fortinet SD-WAN, where traffic is shifted away from an overloaded member to maintain performance.

Exam trap

The trap here is that candidates often confuse spillover with load balancing algorithms like 'lowest latency' or 'round-robin', incorrectly assuming that traffic is dropped, queued, or evenly distributed when the threshold is exceeded, rather than understanding that spillover is a failover-like mechanism that shifts new sessions to the next available member.

How to eliminate wrong answers

Option A is wrong because spillover does not drop traffic; it redirects new sessions to another member when the threshold is exceeded. Option C is wrong because spillover does not queue packets on the overloaded port; it actively moves new sessions to an alternate member. Option D is wrong because spillover does not distribute sessions equally; it sends all new sessions to the underutilized member (port2) until the primary member's load drops below the threshold.

19
MCQeasy

An administrator wants to ensure that voice traffic (UDP 16384-32768) always uses the MPLS link, while internet-bound traffic uses broadband. Which SD-WAN feature should be configured to achieve this?

A.Performance SLA
B.SD-WAN member configuration
C.Load balancing algorithm
D.SD-WAN rule
AnswerD

An SD-WAN rule matches traffic by application or UDP port range and directs it to a preferred member, so voice (UDP 16384-32768) can be pinned to the MPLS link while internet-bound traffic egresses broadband, satisfying the required path separation.

Why this answer

SD-WAN rules (option D) allow administrators to define policy-based forwarding by matching specific traffic characteristics—such as UDP ports 16384-32768 for voice—and steering that traffic to a preferred interface or link (e.g., the MPLS link). This is the correct feature because it directly controls traffic steering based on application or service, overriding any default load-balancing or failover behavior.

Exam trap

The trap here is that candidates confuse Performance SLA (which monitors and reacts to link quality) with the policy engine that actually decides which traffic goes where, leading them to select option A instead of the correct SD-WAN rule.

How to eliminate wrong answers

Option A is wrong because Performance SLA measures link quality (latency, jitter, packet loss) and triggers link failover or path selection changes, but it does not define which traffic uses which link; it only reacts to link degradation. Option B is wrong because SD-WAN member configuration defines the physical or logical interfaces participating in the SD-WAN zone and their roles (e.g., gateway, cost), but it does not contain the policy logic to steer specific UDP port ranges to a particular link. Option C is wrong because the load balancing algorithm (e.g., source-destination-IP hash, volume-based) distributes traffic across multiple links based on a mathematical formula, not on application-level criteria like UDP port ranges; it cannot guarantee voice traffic always uses the MPLS link.

20
MCQeasy

An administrator is configuring a FortiGate for SD-WAN and wants to ensure that outgoing traffic from the internal network is distributed across two WAN links based on the number of active sessions. Which SD-WAN load balancing algorithm should be used?

A.Weighted round robin
B.Source IP based
C.Volume
D.Session count
AnswerD

The 'session count' algorithm selects the WAN member with the fewest active sessions. This directly satisfies the requirement to load balance based on the number of active sessions. It dynamically adjusts as sessions are created and torn down, making it ideal for scenarios where session load is the primary concern. This is the correct choice for the described scenario.

Why this answer

The 'session count' SD-WAN algorithm selects the member with the fewest active sessions, which directly load balances based on session count. Other algorithms like source IP, volume, or weighted round robin use different criteria such as source address, data volume, or static weights, and do not dynamically balance based on the number of active sessions. Therefore, 'session count' is the correct choice.

Exam trap

The trap here is confusing 'volume' with 'session count'; volume balances data usage, while session count balances the number of connections.

21
MCQeasy

A FortiGate administrator wants to use BFD to quickly detect link failures in an SD-WAN deployment. Which statement about BFD configuration on FortiGate is correct?

A.BFD is enabled by default on all FortiGate interfaces
B.BFD can be configured under the interface or routing protocol to detect forwarding path failures
C.BFD sessions are established automatically when OSPF neighbors form
D.BFD uses performance SLA probes to determine link health
AnswerB

BFD operates as a lightweight, protocol-independent hello mechanism that can be bound either directly to an interface or to a routing protocol such as BGP or OSPF. This dual placement lets it detect forwarding-path failures at sub-second intervals, satisfying the SD-WAN requirement for rapid link-failure detection.

Why this answer

BFD (Bidirectional Forwarding Detection) on FortiGate can be configured either directly on an interface or under a dynamic routing protocol (such as OSPF or BGP). When configured under the interface, BFD monitors the forwarding path to that specific neighbor; when configured under the routing protocol, it provides sub-second failure detection for routes learned via that protocol. This flexibility allows the administrator to tailor BFD to the SD-WAN deployment's needs, ensuring rapid link failure detection without relying on routing protocol timers.

Exam trap

The trap here is that candidates often confuse BFD with performance SLA probes or assume BFD is automatically enabled with routing protocols, but FortiGate requires explicit BFD configuration and BFD does not measure link quality metrics like jitter or packet loss.

How to eliminate wrong answers

Option A is wrong because BFD is not enabled by default on any FortiGate interface; it must be explicitly enabled per interface or per routing protocol. Option C is wrong because BFD sessions are not automatically established when OSPF neighbors form; BFD must be explicitly enabled under the OSPF configuration (e.g., 'set bfd enable' under the OSPF interface or process) for the sessions to be created. Option D is wrong because BFD does not use performance SLA probes; BFD uses its own lightweight hello and echo packets to detect failures, while performance SLA probes are used by SD-WAN rules for link quality measurement (jitter, latency, packet loss).

22
MCQeasy

A company has two internet connections: a primary fiber link (port1, 100 Mbps) and a backup DSL link (port2, 20 Mbps). They are using SD-WAN to load balance traffic based on volume, with a rule that sends 70% of traffic to port1 and 30% to port2. Recently, users report that video conferencing applications are experiencing high latency and jitter. The network team finds that the SD-WAN performance SLA for the fiber link shows 80% packet loss and high latency. The SD-WAN rule action is set to 'best quality' with a latency threshold of 150 ms. The current latency on port1 is 200 ms, and on port2 is 40 ms. What should the administrator do to ensure that video conferencing traffic uses the DSL link while the fiber link is degraded?

A.Increase the SLA latency threshold to 250 ms so that the fiber link is considered acceptable.
B.Change the SD-WAN rule action to 'lowest cost' to favor the DSL link.
C.Adjust the volume ratio to send 100% of traffic to port2 until the fiber link recovers.
D.No changes are needed; the SD-WAN rule with 'best quality' will automatically use port2 for new sessions because port1 does not meet the SLA.
AnswerD

The 'best quality' action evaluates SLA per session and steers new sessions to port2, which meets the 150 ms latency threshold while port1 at 200 ms does not. Existing sessions may need re-establishment, but new video sessions use the DSL link automatically.

Why this answer

The SD-WAN rule action is set to 'best quality', which means the FortiGate will automatically steer new sessions away from any interface that fails the performance SLA. Since port1 has 80% packet loss and 200 ms latency (exceeding the 150 ms threshold), it is considered degraded, and new video conferencing traffic will be directed to port2 (40 ms latency) without manual intervention.

Exam trap

The trap here is that candidates often assume manual configuration (like changing thresholds or ratios) is required to fix a degraded link, when in fact the 'best quality' action with performance SLA already provides automatic failover to the best-performing link.

How to eliminate wrong answers

Option A is wrong because increasing the SLA latency threshold to 250 ms would make the degraded fiber link appear acceptable, causing traffic to continue using the high-latency, high-packet-loss link and defeating the purpose of SLA monitoring. Option B is wrong because changing the rule action to 'lowest cost' would select the link based on cost metrics (e.g., bandwidth cost), not performance, and the DSL link might not be the lowest cost; even if it were, this action does not consider SLA compliance for latency and jitter. Option C is wrong because manually adjusting the volume ratio to 100% on port2 is a static workaround that bypasses the dynamic SLA-based steering, which is less efficient and not necessary when the 'best quality' action already handles failover automatically.

23
MCQmedium

A FortiGate has two equal-cost paths to a destination network through two different ISPs. The administrator wants to load balance traffic across both links using ECMP, but notices that all traffic uses only one link. What should the administrator check first?

A.Check that both routes have the same administrative distance and priority
B.Configure 'set v4-ecmp-mode' to 'source-ip-based'
C.Verify that 'set load-balance-eligible' is enabled on both WAN interfaces
D.Disable 'anti-replay' on the security policy
AnswerA

ECMP installs multiple next-hops only when candidate routes match on administrative distance and priority; differing values leave a single best route, so all traffic egresses one ISP. Verifying both attributes equal confirms the routes are genuinely equal-cost before troubleshooting hashing or link health.

Why this answer

ECMP requires that all candidate routes have identical administrative distance and priority values. If either differs, FortiGate will select only the route with the lower distance/priority, breaking load balancing. The administrator should verify these parameters first because they directly control route selection before ECMP is applied.

Exam trap

The trap here is that candidates often jump to configuring ECMP hashing modes or interface settings, overlooking the fundamental requirement that routes must be truly equal in administrative distance and priority before ECMP can function.

How to eliminate wrong answers

Option B is wrong because 'set v4-ecmp-mode' controls the hashing algorithm (e.g., source-ip-based, weighted) for distributing traffic across ECMP paths, but it does not fix the root cause of routes not being considered equal. Option C is wrong because 'load-balance-eligible' is a per-interface setting for SD-WAN rules, not for standard ECMP routing; ECMP eligibility is determined by route attributes, not this interface flag. Option D is wrong because disabling anti-replay on the security policy affects session state tracking and asymmetric traffic handling, not the selection of ECMP paths.

24
MCQeasy

An administrator is configuring an SD-WAN rule to route traffic to a specific destination through a preferred member, but wants to ensure that if that member fails, traffic automatically switches to another member. Which SD-WAN rule configuration setting should they use to define the order of member preference?

A.Member sequence in the SD-WAN rule
B.SLA target
C.Load balancing algorithm
D.Priority
AnswerA

In an SD-WAN rule, members are listed in a specific order. The FortiGate uses this order as a preference sequence when the strategy is set to 'manual' or when failover occurs. The first member in the list is preferred; if it becomes unavailable, the next member is used. This provides a deterministic failover order.

Why this answer

To define a preferred order of members for failover in an SD-WAN rule, the administrator should list the members in the desired sequence within the rule configuration. The FortiGate will use the first available member according to that order when the strategy is 'manual' or when failover is triggered. This ensures deterministic behavior.

Exam trap

The trap here is confusing the load balancing algorithm with member preference order; the algorithm distributes traffic, while the member sequence defines failover priority.

25
MCQhard

A FortiGate is configured with an SD-WAN rule using 'spillover' algorithm. The primary member has a spillover threshold of 100 Mbps. Traffic of 80 Mbps is currently flowing through the primary member. A new session requiring 30 Mbps arrives. What will happen?

A.The new session is sent to the primary member because the current load is below the threshold.
B.The new session is sent to the secondary member because the primary threshold would be exceeded.
C.The new session is dropped because no member can handle it.
D.The primary member's threshold is dynamically increased.
AnswerB

Spillover forwards a new session to a secondary member when adding it would push the primary member past its configured threshold. Current 80 Mbps plus 30 Mbps equals 110 Mbps, exceeding the 100 Mbps limit, so the session uses the secondary.

Why this answer

The SD-WAN 'spillover' algorithm forwards traffic to the primary member until its load reaches the configured threshold (100 Mbps). With 80 Mbps already flowing, adding a new 30 Mbps session would push the total to 110 Mbps, exceeding the threshold. Therefore, the new session is sent to the secondary member to avoid oversubscription, as per the spillover logic.

Exam trap

The trap here is that candidates often assume the algorithm checks if the *new session alone* exceeds the threshold, rather than evaluating the *cumulative load* after adding the new session, leading them to incorrectly select option A.

How to eliminate wrong answers

Option A is wrong because the current load of 80 Mbps plus the new 30 Mbps session would exceed the 100 Mbps spillover threshold, so the session cannot be sent to the primary member. Option C is wrong because the secondary member is available and can handle the traffic; the session is not dropped. Option D is wrong because the spillover threshold is a static configured value and is not dynamically adjusted by the FortiGate based on traffic load.

26
MCQeasy

A FortiGate administrator wants to enable load balancing for equal-cost paths to the same destination. The FortiGate has two equal-cost routes via two different next-hop routers. Which feature should the admin enable to load balance traffic across both paths?

A.BFD (Bidirectional Forwarding Detection)
B.ECMP (Equal Cost Multi-Path)
C.Policy-based routing
D.SD-WAN load balancing
AnswerB

ECMP installs multiple equal-cost next-hops for the same destination in the routing table, letting the FortiGate distribute traffic across both paths. Without it, only one route is selected, so the second path stays unused despite identical cost.

Why this answer

ECMP (Equal Cost Multi-Path) is the correct feature because it enables a FortiGate to distribute traffic across multiple equal-cost routes to the same destination. When the routing table contains two or more routes with identical administrative distance and metric, ECMP automatically load-balances sessions across those paths using a hash-based algorithm (e.g., source-destination IP hash), without requiring additional configuration beyond enabling the feature globally or per-VDOM.

Exam trap

The trap here is that candidates confuse SD-WAN load balancing with ECMP, but SD-WAN is a separate overlay technology that requires SD-WAN zones and performance SLA rules, whereas ECMP is a simple, direct routing-table feature for equal-cost paths without any overlay or application-awareness.

How to eliminate wrong answers

Option A is wrong because BFD (Bidirectional Forwarding Detection) is a fast failure detection protocol that monitors link or neighbor liveness, not a load-balancing mechanism; it can be used with ECMP to quickly remove dead paths but does not distribute traffic. Option C is wrong because policy-based routing (PBR) overrides the routing table with user-defined policies to steer traffic based on attributes like source IP or port, but it does not automatically load-balance across equal-cost paths; it is a manual, rule-based approach that can disrupt ECMP behavior. Option D is wrong because SD-WAN load balancing is a higher-level feature that uses performance SLA rules and application steering to distribute traffic across WAN links, but it is not designed for simple equal-cost path load balancing within a single routing domain; ECMP is the native, lightweight solution for this scenario.

27
MCQmedium

A FortiGate with SD-WAN configured has a Performance SLA monitoring Google DNS (8.8.8.8). The SLA is configured with latency threshold 100 ms and jitter threshold 20 ms. The link is currently meeting both thresholds. The administrator wants to ensure that if the SLA fails, traffic moves to another link. Which SD-WAN rule strategy should be used?

A.Best quality
B.Manual selection
C.Maximize bandwidth (SLA)
D.Failover (SLA)
AnswerD

The Failover (SLA) strategy actively monitors the Performance SLA and withdraws the primary link from the rule once latency or jitter breaches its thresholds, redirecting new sessions to the secondary member. This directly satisfies the requirement to move traffic when the SLA fails.

Why this answer

The Failover (SLA) strategy is correct because it ensures that traffic is moved to another link only when the Performance SLA fails, while the primary link is used as long as it meets the configured latency (100 ms) and jitter (20 ms) thresholds. This strategy provides deterministic failover behavior, matching the administrator's requirement to switch traffic only upon SLA failure.

Exam trap

The trap here is that candidates often confuse 'Failover (SLA)' with 'Best quality', thinking that any SLA degradation should trigger a switch, but Best quality would switch even if thresholds are still met, while Failover (SLA) only switches upon threshold violation.

How to eliminate wrong answers

Option A (Best quality) is wrong because it continuously selects the link with the best SLA metrics (lowest latency/jitter), not just failing over when thresholds are exceeded, which can cause unnecessary link switching even when the primary link is still meeting thresholds. Option B (Manual selection) is wrong because it requires explicit administrator intervention to change the active link and does not automatically failover based on SLA conditions. Option C (Maximize bandwidth (SLA)) is wrong because it load-balances traffic across multiple links based on SLA health, rather than providing a primary/backup failover behavior when the SLA fails.

28
MCQmedium

An administrator configures a performance SLA for SD-WAN health checks. The SLA uses a ping probe to 8.8.8.8 every 2 seconds with a latency threshold of 150 ms and jitter threshold of 20 ms. After some time, the SD-WAN rule still shows the member as 'dead'. Which command should the administrator use to verify the probe results?

A.show system sdwan health-check
B.diagnose sys sdwan health-check
C.diagnose sys session list
D.execute ping-options source 8.8.8.8
AnswerB

This command displays each SD-WAN member's health-check status, including latency and jitter values from the ping probes. Comparing those readings against the 150 ms and 20 ms thresholds reveals why the member is marked dead.

Why this answer

The 'diagnose sys sdwan health-check' command is the correct tool because it provides real-time, detailed probe results for each SD-WAN health-check member, including latency, jitter, packet loss, and SLA status. This allows the administrator to see exactly why the member is marked as 'dead', such as exceeding the 150 ms latency or 20 ms jitter thresholds. The 'show system sdwan health-check' command only displays configured parameters, not live probe data.

Exam trap

The trap here is that candidates confuse the configuration display command ('show system sdwan health-check') with the diagnostic command ('diagnose sys sdwan health-check'), assuming the former shows live results when it only shows static configuration.

How to eliminate wrong answers

Option A is wrong because 'show system sdwan health-check' displays only the configured SLA parameters (e.g., probe target, thresholds) and not the actual live probe results or current member status. Option C is wrong because 'diagnose sys session list' shows active session entries in the session table, which is unrelated to SD-WAN health-check probe results or SLA compliance. Option D is wrong because 'execute ping-options source 8.8.8.8' sets the source IP for ping commands but does not verify SD-WAN health-check probe results; it is a configuration command, not a diagnostic one.

29
MCQeasy

What is the purpose of a route map when used with route redistribution on a FortiGate?

A.To create a prefix list for BGP
B.To define the administrative distance of redistributed routes
C.To enable the redistribution process
D.To filter or modify route attributes during redistribution
AnswerD

A route map applies match conditions and set actions during redistribution, permitting or denying specific routes and altering attributes such as metric, tag, or community. This controls exactly which routes enter the target routing protocol and with what values.

Why this answer

Route maps are used with route redistribution to filter which routes are redistributed and to modify route attributes (such as metric, tag, or next-hop) as they are injected from one routing protocol into another. Option D is correct because route maps provide granular control over the redistribution process, allowing administrators to match specific routes using prefix lists or ACLs and then set attributes like metric or tag before the routes are redistributed.

Exam trap

The trap here is that candidates often confuse the route map's role as a filter or modifier with the enabling of redistribution itself, thinking the route map is required to start redistribution, when in fact redistribution is enabled by the 'redistribute' command and the route map is an optional parameter.

How to eliminate wrong answers

Option A is wrong because a prefix list is a separate tool used to match IP prefixes, not a route map; route maps can reference prefix lists, but the route map itself is not a prefix list. Option B is wrong because administrative distance is a property of the routing protocol or static route, not something set by a route map during redistribution; route maps can set metric, tag, or next-hop, but not administrative distance. Option C is wrong because the redistribution process is enabled by the 'redistribute' command under the routing protocol configuration, not by a route map; the route map is an optional filter applied to that redistribution.

30
MCQmedium

A network administrator is configuring SD-WAN on a FortiGate. They have multiple WAN links and want to ensure that traffic for a critical application uses the link with the lowest latency. Which SD-WAN configuration component should be used to achieve this?

A.Performance SLA with latency threshold and SD-WAN rule using best-quality strategy
B.SD-WAN rule with spillover load balancing
C.SD-WAN members with static priority
D.Load balancing algorithm set to lowest-cost (SLA)
AnswerA

A Performance SLA actively probes each WAN link, measuring latency against the configured threshold, while the SD-WAN rule's best-quality strategy selects the member with the lowest measured latency for the critical application. This directly satisfies the requirement to route traffic over the lowest-latency link.

Why this answer

The Performance SLA monitors latency (and other metrics) against a configured threshold, and the SD-WAN rule with the 'best-quality' strategy dynamically selects the WAN link that currently has the lowest latency. This ensures the critical application traffic is steered to the optimal link based on real-time performance measurements.

Exam trap

The trap here is that candidates confuse 'static priority' (which is a fixed preference) with dynamic SLA-based selection, or they incorrectly assume 'spillover' or 'lowest-cost' algorithms can react to latency changes in real time.

How to eliminate wrong answers

Option B is wrong because spillover load balancing uses bandwidth utilization thresholds to shift traffic, not latency, so it cannot ensure the lowest-latency link is selected. Option C is wrong because static priority assigns fixed preference to links regardless of current performance; if the highest-priority link has high latency, traffic will still use it. Option D is wrong because 'lowest-cost (SLA)' is not a valid load balancing algorithm in FortiOS; the correct term for SLA-based selection is 'best-quality' or 'SLA' strategy, and 'lowest-cost' typically refers to routing protocol metrics, not SD-WAN link quality.

31
MCQeasy

A FortiGate is configured with ECMP load balancing. What is the default behavior when multiple routes have equal cost?

A.The route with the lowest metric is always preferred
B.The administrator must enable per-packet load balancing
C.Traffic is load balanced across the routes using a hash algorithm
D.All traffic is sent over the first route until it fails
AnswerC

With equal-cost multipath, FortiGate installs all matching routes and distributes sessions across them using a hash of source and destination addresses and ports. This preserves per-flow ordering while sharing traffic, rather than selecting one route or preferring the oldest entry.

Why this answer

When ECMP load balancing is configured on a FortiGate, the default behavior is to distribute traffic across multiple equal-cost routes using a hash algorithm. This hash algorithm considers fields such as source/destination IP, protocol, and ports to ensure session consistency, meaning all packets belonging to the same session follow the same path. This is the standard ECMP behavior in FortiOS, as documented in the FortiGate Administration Guide.

Exam trap

The trap here is that candidates often confuse ECMP with per-packet load balancing or assume that FortiGate defaults to a failover model, but the NSE7 exam expects you to know that ECMP uses a hash algorithm for per-session load balancing by default, not per-packet or primary-backup.

How to eliminate wrong answers

Option A is wrong because in ECMP, all routes have equal cost (metric), so no single route is preferred based on metric; the FortiGate uses a hash algorithm instead. Option B is wrong because per-packet load balancing is not the default and must be explicitly enabled via CLI (e.g., 'set load-balance-mode per-packet'), and even then it is rarely used due to packet reordering issues; the default is per-session load balancing using a hash. Option D is wrong because that describes a failover or primary/backup routing behavior, not ECMP; FortiGate does not send all traffic over the first route until failure unless 'set priority' or 'set weight' is used to create unequal costs.

32
MCQmedium

An administrator configures an SD-WAN rule to steer traffic from a specific subnet to an SD-WAN member with the lowest cost. Which load balancing algorithm should be selected in the SD-WAN rule to achieve this behavior?

A.Lowest-cost
B.Volume
C.Sessions
D.Source-dest-IP
AnswerA

Lowest-cost selects the member with the cheapest path metric, matching the stem's requirement to steer the subnet's traffic to the lowest-cost SD-WAN member. Other algorithms (such as weighted round-robin or source-IP based) ignore cost, so they cannot guarantee this outcome.

Why this answer

The 'Lowest-cost' algorithm is correct because it directs traffic to the SD-WAN member with the lowest configured cost metric, which directly matches the administrator's requirement to steer traffic from a specific subnet to the member with the lowest cost. In Fortinet SD-WAN, the cost is a static metric assigned per SD-WAN member interface, and the Lowest-cost algorithm selects the member with the smallest cost value for each new session, ensuring traffic follows the least-cost path.

Exam trap

The trap here is that candidates often confuse 'Lowest-cost' with dynamic path selection algorithms like 'Best Quality' or 'SLA-based' routing, assuming cost implies real-time performance metrics, whereas in Fortinet SD-WAN, cost is a static administrative value unrelated to link quality.

How to eliminate wrong answers

Option B (Volume) is wrong because the Volume algorithm balances traffic based on the volume of data transferred (bytes) across members, not on cost; it distributes sessions to equalize throughput, not to select the lowest-cost path. Option C (Sessions) is wrong because the Sessions algorithm distributes new sessions based on the current number of active sessions per member, aiming to balance session count, not to steer traffic by cost. Option D (Source-dest-IP) is wrong because Source-dest-IP uses a hash of source and destination IP addresses to consistently map flows to a specific member, providing stickiness without considering cost metrics.

33
MCQeasy

Which routing technique allows a FortiGate to forward packets based on source IP address, destination IP address, or other criteria, in addition to the destination IP alone?

A.Policy-Based Routing (PBR)
B.RIP
C.OSPF route redistribution
D.ECMP
AnswerA

Policy-Based Routing evaluates configured criteria such as source address, destination address, protocol, or port before consulting the routing table, letting the FortiGate forward on more than destination IP alone. Standard destination-based routing cannot match source or service attributes.

Why this answer

Policy-Based Routing (PBR) allows a FortiGate to forward packets based on criteria beyond the destination IP address, such as source IP, destination port, protocol, or application. This is achieved by configuring policy routes that override the default routing table lookup, enabling granular traffic steering for advanced networking scenarios like SD-WAN.

Exam trap

The trap here is that candidates often confuse Policy-Based Routing with ECMP, assuming ECMP can also use source IP for path selection, but ECMP only balances traffic based on destination IP and does not support criteria like source IP or application without additional configuration like PBR or SD-WAN rules.

How to eliminate wrong answers

Option B (RIP) is wrong because RIP is a dynamic routing protocol that exchanges routes based solely on destination network prefixes, not on source IP or other packet attributes. Option C (OSPF route redistribution) is wrong because redistribution is a mechanism to import routes from one routing protocol into another, not a technique for forwarding packets based on multiple criteria. Option D (ECMP) is wrong because ECMP (Equal-Cost Multi-Path) distributes traffic across multiple paths with the same destination prefix cost, but it does not consider source IP or other packet-level criteria for forwarding decisions.

34
Multi-Selectmedium

A FortiGate is configured with OSPF and BGP. The administrator wants to redistribute OSPF routes into BGP. Which TWO steps are required?

Select 2 answers
A.Configure a route map to filter the routes being redistributed
B.Set the BGP table version to 2
C.Use the 'redistribute ospf' command under the BGP configuration
D.Ensure the OSPF routes are present in the routing table
E.Disable OSPF on the interface
AnswersC, D

This enables redistribution of OSPF routes into BGP.

Why this answer

The 'redistribute ospf' command under BGP configuration is the explicit method to inject OSPF-learned routes into the BGP table. This command triggers the redistribution process, allowing OSPF routes to be advertised to BGP peers.

Exam trap

The trap here is that candidates often assume a route map is mandatory for redistribution, but the exam tests the knowledge that only the redistribution command and the presence of routes in the routing table are strictly required.

35
MCQhard

A FortiGate is configured with two SD-WAN members (wan1, wan2) and a performance SLA for each. The SD-WAN rule uses 'Maximize Bandwidth' strategy with volume-based load balancing. The administrator notices that traffic is only using wan1, even though both links have capacity. The SLA status for wan2 shows 'alive'. What could be the problem?

A.The link cost for wan2 is too high.
B.The SD-WAN rule has a 'set member' statement that lists only wan1.
C.The performance SLA for wan2 is not associated with the SD-WAN rule.
D.The bandwidth weight for wan2 is set to 0.
AnswerB

A static `set member` statement restricts the rule to wan1 alone, so the Maximize Bandwidth strategy and volume-based load balancing never evaluate wan2, regardless of its alive SLA status. Removing the member restriction lets both links participate in the bandwidth calculation and share traffic.

Why this answer

The 'Maximize Bandwidth' strategy with volume-based load balancing distributes traffic based on bandwidth weights, but the SD-WAN rule's 'set member' statement explicitly defines which interfaces are eligible for load balancing. If the rule lists only wan1, traffic will never be sent to wan2, regardless of SLA status or bandwidth weights. This is the most direct cause of the observed behavior.

Exam trap

The trap here is that candidates often assume a healthy SLA and correct bandwidth weights are sufficient for load balancing, overlooking that the SD-WAN rule's member list explicitly controls which interfaces are used, and a missing member will exclude that interface entirely.

How to eliminate wrong answers

Option A is wrong because link cost is used in 'Lowest Cost' (SLA) strategies, not in 'Maximize Bandwidth' with volume-based load balancing; a high cost does not prevent traffic from using wan2 in this strategy. Option C is wrong because the performance SLA for wan2 being associated with the rule is not required for the rule to use wan2; the SLA only affects the interface's health status, and since wan2 is 'alive', it is eligible. Option D is wrong because a bandwidth weight of 0 would still allow traffic to be sent to wan2 if the rule includes it, though it would receive no traffic under volume-based load balancing; however, the question states traffic is only using wan1, implying wan2 is not even considered, which is caused by the rule's member list, not the weight.

36
MCQeasy

An administrator is configuring an SD-WAN rule to route VoIP traffic over the most reliable link. The performance SLA monitors latency, jitter, and packet loss. The administrator wants the rule to select the member with the lowest jitter that also meets the SLA thresholds. Which SD-WAN strategy should be used?

A.maximize-bandwidth (SLA)
B.lowest-jitter (SLA)
C.lowest-latency (SLA)
D.lowest-cost (SLA)
AnswerB

The lowest-jitter (SLA) strategy selects the member with the lowest jitter that also meets the SLA thresholds. This directly matches the requirement to route VoIP traffic over the link with the least jitter, ensuring high call quality. It is specifically designed for real-time traffic where jitter is critical.

Why this answer

For VoIP, jitter is a critical metric. The lowest-jitter (SLA) strategy chooses the member with the lowest jitter among those passing the SLA. Other strategies focus on cost, bandwidth, or latency, which do not directly address the need for minimal jitter.

Exam trap

The trap here is assuming that lowest-latency (SLA) is sufficient for VoIP, when jitter is the specific metric that most affects voice quality.

37
MCQeasy

What is the purpose of a prefix list in FortiGate routing?

A.To match routes based on their network prefix and subnet mask.
B.To configure NAT rules.
C.To define SD-WAN members.
D.To assign IP addresses to interfaces.
AnswerA

Prefix lists match routes by network prefix and subnet mask, letting the FortiGate filter or redistribute specific routes in routing updates. This satisfies the requirement to identify routes by their prefix and mask rather than by other attributes such as metric or administrative distance.

Why this answer

A prefix list in FortiGate is used to match routes based on their network prefix and subnet mask (prefix length). It is commonly applied in route maps or BGP configurations to filter or manipulate routing information, such as in redistribution or neighbor policy statements. Unlike access lists, prefix lists match the exact prefix and length, providing more granular control over route advertisement and acceptance.

Exam trap

The trap here is that candidates often confuse prefix lists with access lists or route maps, assuming they can be used for general packet filtering or interface configuration, but prefix lists are strictly for route prefix matching in routing policy contexts.

How to eliminate wrong answers

Option B is wrong because NAT rules are configured using firewall policies or central NAT tables, not prefix lists. Option C is wrong because SD-WAN members are defined in the SD-WAN configuration under the 'config system sdwan' context, where interfaces and their roles are specified, not via prefix lists. Option D is wrong because IP addresses are assigned to interfaces using the 'config system interface' command with the 'set ip' directive, not through prefix lists.

38
MCQmedium

An administrator is configuring an SD-WAN rule to route VoIP traffic over the most reliable link. They have two WAN members: port1 (MPLS) and port2 (Internet). They create a performance SLA that monitors latency and jitter, and set the SLA target to 150 ms latency and 30 ms jitter. They apply the SLA to both members. The SD-WAN rule is set to 'Best Quality' strategy. After applying the configuration, they notice that VoIP traffic is sometimes routed over port2 even though port1 has lower latency and jitter. What is the most likely reason?

A.Port1 is intermittently failing the SLA due to jitter spikes, causing the FortiGate to temporarily select port2 until port1 meets the SLA again.
B.The performance SLA is not enabled on the SD-WAN rule, so the FortiGate falls back to a default load balancing method.
C.The 'Best Quality' strategy selects the member with the lowest cost, not the best quality, so port2 is chosen because it has a lower cost.
D.The SD-WAN rule is configured with a source IP-based load balancing method, which overrides the 'Best Quality' strategy.
AnswerA

The 'Best Quality' strategy continuously monitors SLA metrics. If port1 experiences jitter spikes that exceed the configured 30 ms threshold, it fails the SLA, and the FortiGate selects port2, which may meet the SLA. Once port1 recovers, it will be preferred again. This intermittent behavior is expected when SLA thresholds are tight and link quality fluctuates.

Why this answer

With the 'Best Quality' strategy, the FortiGate continuously evaluates member health against the SLA. If port1 experiences jitter spikes that exceed the configured threshold, it is considered to have failed the SLA, and the rule will select the next best member, which is port2. This can cause VoIP traffic to temporarily switch to port2.

Once port1's jitter returns below the threshold, it will be preferred again. This behavior ensures that traffic only uses links that meet the required quality.

Exam trap

The trap here is thinking that 'Best Quality' always selects the member with the lowest latency and jitter, ignoring SLA thresholds; in reality, a member must meet the SLA to be considered, and intermittent violations cause temporary failover.

39
MCQhard

You run 'diagnose sys session filter dport 443' and see the following output: proto=6 proto_state=01 duration=3600 expire=3599 What does this indicate about the session?

A.The session is a UDP session with a short timeout.
B.The session is a UDP session that has been active for 1 hour.
C.The session is a TCP session in established state that has been active for 1 hour and will expire in about 1 hour.
D.The session is a TCP session that has timed out and is being removed.
AnswerC

Proto 6 denotes TCP, and proto_state 01 confirms the established state. Duration 3600 shows the session has been active for one hour, while expire 3599 indicates roughly one hour remains before timeout. This matches the stem's requirement to interpret each field of the diagnose output accurately.

Why this answer

The output shows 'proto=6', which is the protocol number for TCP, and 'proto_state=01', which indicates the TCP session is in an established state (TCP_ESTABLISHED). The 'duration=3600' means the session has been active for 3600 seconds (1 hour), and 'expire=3599' means the session will expire in 3599 seconds (approximately 1 hour), consistent with the default TCP session timeout of 3600 seconds in FortiGate.

Exam trap

The trap here is that candidates confuse 'proto=6' with UDP or misinterpret 'proto_state=01' as a timeout indicator, when in fact it specifically denotes an established TCP session with a standard 1-hour idle timeout.

How to eliminate wrong answers

Option A is wrong because 'proto=6' indicates TCP, not UDP (UDP uses protocol 17), and the session has a long timeout (3600 seconds), not a short one. Option B is wrong because 'proto=6' is TCP, not UDP, and while the duration is 1 hour, the protocol is misidentified. Option D is wrong because the session has not timed out; 'expire=3599' shows it is still active with nearly a full hour remaining, and 'proto_state=01' indicates an established state, not a timed-out or being-removed state.

40
MCQhard

A FortiGate is configured with two VRF instances: VRF10 (for a customer) and VRF20 (for another customer). Each VRF has its own interfaces and routing table. The administrator wants to allow a specific server in VRF10 (10.10.10.5) to be reachable from a host in VRF20 (20.20.20.5) without leaking all routes between VRFs. Which FortiGate feature should be used to achieve this?

A.A firewall policy with source VRF10 and destination VRF20, using NAT to translate the server IP.
B.An inter-VRF link using a pair of interfaces, one in each VRF, with a firewall policy allowing the specific traffic.
C.A static route in VRF20 pointing to 10.10.10.5/32 with the next-hop being the VRF10 interface gateway.
D.Inter-VRF routing using a route leaking policy with a route-map.
AnswerB

FortiOS supports inter-VRF routing by creating a link between two VRF instances using a pair of interfaces (or subinterfaces) assigned to each VRF. A firewall policy then permits traffic from the source VRF to the destination VRF. This allows granular control: only the desired server can be reached if the policy restricts destination to 10.10.10.5. This method does not leak routes between VRFs, maintaining isolation.

Why this answer

Inter-VRF routing on FortiGate is achieved by creating a link between VRFs using a pair of interfaces, each assigned to a different VRF. A firewall policy then controls what traffic can traverse that link. This allows selective reachability, such as permitting only one server, without leaking all routes between the VRFs.

The other options either do not provide the necessary routing or lack the granular control required.

Exam trap

The trap here is thinking that a firewall policy or a static route can directly bridge VRFs, when in fact you need a dedicated inter-VRF link with interfaces in each VRF.

41
MCQmedium

An administrator configures BFD on a FortiGate to improve convergence time for OSPF. What is the primary purpose of BFD in this context?

A.To reduce the number of OSPF neighbors
B.To encrypt OSPF packets
C.To detect link failures faster than OSPF hello timers
D.To load balance OSPF traffic across multiple links
AnswerC

BFD sends rapid sub-second hello packets between neighbours, detecting path failures far sooner than OSPF's slower hello and dead intervals. This satisfies the convergence-time goal by triggering immediate OSPF neighbour teardown, allowing faster route recalculation and failover.

Why this answer

BFD (Bidirectional Forwarding Detection) provides sub-second link failure detection, typically in the range of 50-300 milliseconds, which is significantly faster than OSPF's default hello/dead intervals (e.g., 10/40 seconds for broadcast networks). By integrating BFD with OSPF, the FortiGate can trigger OSPF neighbor state changes and route convergence almost immediately upon a link failure, without waiting for OSPF's own hello timer expiration.

Exam trap

The trap here is that candidates may confuse BFD's fast detection with OSPF's own hello mechanism, thinking BFD replaces or modifies OSPF timers, when in fact BFD works in parallel and triggers OSPF state changes only after a failure is detected.

How to eliminate wrong answers

Option A is wrong because BFD does not reduce the number of OSPF neighbors; it operates independently on each established OSPF adjacency to monitor link continuity. Option B is wrong because BFD provides no encryption or security functions; it is a lightweight, unauthenticated (or optionally authenticated) hello-based protocol for fast failure detection. Option D is wrong because BFD does not perform load balancing; it is solely a detection mechanism and does not influence traffic distribution across multiple links.

42
MCQhard

A FortiGate is configured with two SD-WAN members: port1 and port2. The administrator wants to ensure that voice traffic uses port1, but if port1's latency exceeds 150 ms, voice traffic should fail over to port2. Which configuration is required to achieve this?

A.Create an SD-WAN rule with the 'Application' criteria for voice, set the outgoing interface to port1, and enable 'SLA target' with a latency threshold of 150 ms on port1.
B.Create an SD-WAN rule with the 'Application' criteria for voice, set the outgoing interface to port1 and port2, and configure a performance SLA with latency threshold 150 ms on both members.
C.Create two SD-WAN rules: one for port1 with a latency threshold of 150 ms, and one for port2 with a higher priority. Voice traffic will automatically use port1 and fail over to port2.
D.Create an SD-WAN rule with the 'Application' criteria for voice, set the outgoing interface to port1, and configure a performance SLA with latency threshold 150 ms on port1 only.
AnswerB

This configuration allows the SD-WAN rule to consider both members. If port1 exceeds the latency threshold, it will be marked as out of SLA, and the rule will fail over to port2 if it meets the SLA. This achieves the desired behavior.

Why this answer

To achieve automatic failover based on latency, the SD-WAN rule must include both members as possible outgoing interfaces, and a performance SLA must be configured to monitor latency on both. If the preferred member exceeds the threshold, it is marked out of SLA, and the rule selects the next best member.

Exam trap

The trap here is thinking that a single-member rule can fail over; failover requires the rule to have multiple members and an SLA that monitors them.

43
MCQeasy

An administrator is configuring an SD-WAN rule to distribute traffic across two WAN links based on the number of active sessions. They want to ensure that new sessions are assigned to the link with the fewest current sessions. Which load balancing algorithm should they use?

A.Source IP
B.Round robin
C.Volume
D.Session count
AnswerD

The 'session count' algorithm distributes new sessions to the member with the fewest active sessions. This directly balances the load based on session count, ensuring that no single link is overwhelmed. It is the correct choice when the administrator wants to distribute traffic based on the number of active sessions.

Why this answer

The 'session count' load balancing algorithm selects the WAN member with the fewest active sessions for each new session. This directly achieves the administrator's goal of distributing traffic based on the number of active sessions, ensuring balanced utilization of the links. Other algorithms like source IP, volume, or round robin do not specifically target session count.

Exam trap

The trap here is mixing up 'session count' with 'volume' or 'round robin'; only 'session count' explicitly uses the number of active sessions to choose a link.

44
MCQmedium

An administrator has configured an SD-WAN zone named 'virtual-wan-link' with two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'SLA1' is created and assigned to the zone. The administrator wants to ensure that SD-WAN rules use the SLA results to select the best member. Which statement correctly describes how the FortiGate uses the performance SLA results in SD-WAN rule selection?

A.The performance SLA results are used only for monitoring and logging; SD-WAN rules do not consider them.
B.The FortiGate uses the SLA status to mark members as 'alive' or 'dead' and only selects members that are 'alive' when the rule's strategy is 'SLA' or when the rule is configured to use SLA information.
C.The FortiGate uses the SLA results to automatically adjust the link cost of each member, which then influences routing decisions.
D.The performance SLA results are used only for load balancing algorithms like 'source-ip-based' and 'session-based'.
AnswerB

SD-WAN rules can be configured with a strategy that considers SLA status. When a member fails the SLA, it is marked as dead and not used for traffic that requires the SLA. This ensures traffic is steered to a member that meets the configured latency, jitter, and packet loss thresholds.

Why this answer

When a performance SLA is assigned to an SD-WAN zone, the FortiGate actively probes the members. If a member fails to meet the SLA thresholds, it is marked as dead. SD-WAN rules that are configured to use SLA information will then avoid that member, ensuring traffic is sent over a link that meets the required performance criteria.

This is a core feature of Fortinet SD-WAN.

Exam trap

The trap here is assuming that SLA results are only for monitoring and do not influence traffic steering, when in fact they directly affect member selection in SD-WAN rules.

45
MCQmedium

A FortiGate is configured with two SD-WAN members (port1 and port2). The administrator sets an SD-WAN rule with 'set load-balance-mode source-dst-ip' for all internal traffic. The source IP is 10.0.0.1 and destination IP is 172.16.0.1. Which factor determines the outgoing interface for this traffic?

A.The destination IP only
B.The combination of source IP and destination IP hashed to select an interface
C.The source IP only
D.The interface with the lowest current utilization
AnswerB

Source-dst-ip load balancing hashes the source and destination address pair, so 10.0.0.1 to 172.16.0.1 always maps to the same SD-WAN member, satisfying the stem's requirement to identify the determining factor. Unlike source-ip-only, both addresses feed the hash, pinning this flow to one interface.

Why this answer

With 'set load-balance-mode source-dst-ip', the FortiGate performs a hash of both the source IP and destination IP to deterministically select an outgoing SD-WAN member. This ensures that all packets belonging to the same source-destination pair are consistently forwarded over the same interface, preserving flow symmetry without relying on per-packet metrics.

Exam trap

The trap here is that candidates confuse 'source-dst-ip' with 'source-ip' or 'destination-ip' modes, or incorrectly assume that SD-WAN load balancing always considers real-time link utilization, which is only true for 'spillover' or 'lowest-cost' strategies, not hash-based modes.

How to eliminate wrong answers

Option A is wrong because the destination IP alone is used only in 'load-balance-mode destination-ip', not in 'source-dst-ip' mode. Option C is wrong because the source IP alone is used only in 'load-balance-mode source-ip', not in 'source-dst-ip' mode. Option D is wrong because 'load-balance-mode source-dst-ip' uses a static hash of the IP pair, not dynamic interface utilization; the FortiGate does not consider current utilization in this mode.

46
MCQhard

An administrator runs 'get router info bgp summary' and sees that the BGP session to a neighbor is in the 'Idle' state. The neighbor IP is reachable via ping. The BGP configuration uses loopback interfaces with 'update-source loopback1'. What is the MOST likely reason for the Idle state?

A.There is no route on the neighbor back to the FortiGate's loopback IP
B.The loopback interface is down or has no IP address assigned
C.The BGP neighbor's remote-as is misconfigured
D.The BGP timer values (keepalive/hold) are mismatched
AnswerA

With update-source loopback1, the FortiGate sources BGP packets from its loopback address, so the neighbour must have a return route to that loopback. Ping to the neighbour succeeds, but without the reverse route the TCP session cannot establish, leaving BGP Idle.

Why this answer

The 'Idle' state in BGP indicates that the session cannot start, often due to a missing route to the neighbor's update-source IP. Since the neighbor IP is reachable via ping but the session uses loopback interfaces with 'update-source loopback1', the FortiGate's BGP packets will source from its loopback1 IP. If the neighbor does not have a route back to that loopback IP, it cannot respond to the TCP handshake, leaving the session stuck in Idle.

This is a classic BGP loopback peering issue where reachability of the source IP is required, not just the physical interface IP.

Exam trap

The trap here is that candidates assume ping reachability to the neighbor IP guarantees BGP session establishment, but they overlook that BGP packets are sourced from the loopback interface, requiring the neighbor to have a return route to that specific source IP.

How to eliminate wrong answers

Option B is wrong because if the loopback interface were down or had no IP, the 'update-source loopback1' command would fail to source packets, but the question states the neighbor IP is reachable via ping, implying the loopback is operational. Option C is wrong because a misconfigured remote-as would typically cause the session to transition to 'Active' or 'Connect' states, not remain in 'Idle', as BGP first attempts a TCP connection before checking AS numbers. Option D is wrong because mismatched keepalive/hold timers do not prevent the session from leaving Idle; they are negotiated during the Open message exchange after the TCP connection is established, so the session would reach 'Active' or 'Connect' first.

47
MCQeasy

What is the function of a VRF (Virtual Routing and Forwarding) on a FortiGate?

A.To provide redundancy for routing protocols
B.To aggregate multiple physical interfaces into one logical interface
C.To create multiple independent routing tables
D.To encrypt traffic between different virtual domains
AnswerC

A VRF maintains a separate routing table and forwarding instance, allowing overlapping IP subnets to coexist on one FortiGate. Traffic within each VRF is isolated from others, enabling multi-tenant or segmented routing without additional hardware.

Why this answer

VRF (Virtual Routing and Forwarding) on a FortiGate allows the creation of multiple independent routing tables within a single physical device. This enables network segmentation and traffic isolation at Layer 3, where each VRF maintains its own routing table, forwarding decisions, and interface associations, preventing routes from leaking between VRFs unless explicitly configured with route leaking.

Exam trap

The trap here is that candidates confuse VRF with VDOM (Virtual Domain), but VRF is a Layer 3 routing isolation mechanism within a single VDOM, whereas VDOM provides full administrative and security separation at the device level.

How to eliminate wrong answers

Option A is wrong because VRF does not provide redundancy for routing protocols; redundancy is achieved through protocols like VRRP, FGCP (FortiGate Cluster Protocol), or routing protocol features like BGP multipath. Option B is wrong because aggregating multiple physical interfaces into one logical interface is the function of link aggregation (LAG) or interface bonding, not VRF. Option D is wrong because encrypting traffic between different virtual domains is the role of IPsec VPNs or VDOM inter-VDOM links with encryption, not VRF; VRF focuses on routing table separation, not encryption.

48
MCQeasy

An administrator is configuring an SD-WAN rule to load balance traffic across two WAN links based on the source IP address of the traffic. Which load balancing algorithm should be used to achieve this?

A.Volume-based
B.Session-based
C.Source IP-based
D.Spoiled-weighted round robin
AnswerC

The source IP-based algorithm distributes traffic across members based on the source IP address, ensuring that sessions from the same source IP consistently use the same member. This meets the requirement to load balance based on source IP. It is a common method for session persistence.

Why this answer

The source IP-based algorithm is designed to distribute traffic across SD-WAN members based on the source IP address. This ensures that all sessions from a particular source IP are consistently routed through the same member, which can be important for applications that require session persistence. It is one of the available load balancing algorithms in FortiOS SD-WAN.

Exam trap

The trap here is confusing session-based with source IP-based load balancing, as both involve sessions but use different criteria for distribution.

49
MCQmedium

A company with a hub-and-spoke SD-WAN topology uses FortiGates at each site. The hub has two WAN links: MPLS (10 Mbps) and broadband (100 Mbps). The spokes connect only via MPLS. The company deploys a new real-time application that requires low latency and low jitter. The network administrator creates an SD-WAN rule for this application with 'best quality' strategy and both MPLS and broadband as members. The SLA for MPLS is configured with latency < 10 ms and jitter < 5 ms. The SLA for broadband is configured with latency < 50 ms and jitter < 20 ms. The actual measured latency on MPLS is 12 ms, and jitter is 4 ms. The broadband latency is 25 ms, jitter 10 ms. Which path will the application traffic take?

A.The traffic will use the broadband link because MPLS SLA fails and broadband SLA is met.
B.The traffic will be load-balanced between MPLS and broadband.
C.The traffic will use the MPLS link because it is the preferred member.
D.The traffic will be dropped because no link meets the SLA.
AnswerA

Broadband satisfies its configured SLA thresholds (25 ms latency, 10 ms jitter, both within 50 ms and 20 ms), while MPLS breaches its latency SLA at 12 ms against the 10 ms limit. FortiGate's best quality strategy selects the member meeting its SLA, so traffic fails over to broadband despite MPLS's lower measured latency.

Why this answer

The SD-WAN rule uses the 'best quality' strategy, which selects the member with the best SLA performance. The MPLS link fails its SLA because its measured latency of 12 ms exceeds the configured threshold of 10 ms, even though jitter is within limits. The broadband link meets both its latency (25 ms < 50 ms) and jitter (10 ms < 20 ms) thresholds, so it becomes the active path for the application traffic.

Exam trap

The trap here is that candidates assume MPLS is always preferred due to its lower latency profile, but the 'best quality' strategy strictly enforces SLA thresholds, and a link that fails its SLA is excluded from selection regardless of its absolute performance.

How to eliminate wrong answers

Option B is wrong because 'best quality' strategy does not perform load-balancing; it selects a single best path based on SLA compliance and performance metrics. Option C is wrong because MPLS is not inherently preferred; the rule treats both members equally, and MPLS is disqualified due to SLA failure. Option D is wrong because the broadband link meets its SLA thresholds, so traffic is not dropped.

50
MCQmedium

You want to use policy-based routing (PBR) to send traffic from a specific subnet to a different next-hop than the default route. Which configuration is required?

A.Configure a route map under 'config router policy'
B.Create a firewall policy with 'set policy-based-route enable'
C.Enable 'set pbr-enforce-symmetric' on the interface
D.Configure a prefix list and apply to the static route
AnswerA

PBR uses route maps with set-next-hop in the policy route configuration.

Why this answer

Policy-based routing (PBR) on FortiGate is configured under 'config router policy' using route maps. This allows you to match traffic based on criteria such as source subnet and set a specific next-hop, overriding the default route. Option A correctly identifies the required configuration path for PBR.

Exam trap

The trap here is that candidates confuse PBR configuration with firewall policy settings or static route modifications, but FortiGate requires the explicit 'config router policy' and route map syntax to define policy-based routing rules.

How to eliminate wrong answers

Option B is wrong because 'set policy-based-route enable' is not a valid command; firewall policies use 'set action accept' and policy-based routing is applied via route maps, not a firewall policy toggle. Option C is wrong because 'set pbr-enforce-symmetric' is used to enforce symmetric routing for PBR traffic on an interface, but it is not the configuration required to define the PBR rule itself. Option D is wrong because a prefix list applied to a static route can influence route selection but does not implement PBR, which requires a route map under 'config router policy' to match and set next-hop.

51
MCQmedium

An administrator configures a route map on a FortiGate to redistribute connected routes into OSPF. The route map sets a metric of 100. After applying, the redistributed routes appear with metric 20. What is the most likely reason?

A.The route map is applied to the wrong direction
B.OSPF does not allow metric setting via route maps
C.The route map is not applied to the redistribution configuration
D.The metric type is set to type 1
AnswerC

Without the route map attached to the OSPF redistribute command, FortiGate ignores its set metric and applies the default OSPF external metric of 20. The stem's constraint — a configured metric of 100 appearing as 20 — is satisfied only because the map never filters or modifies the redistribution.

Why this answer

The most likely reason the redistributed routes appear with metric 20 instead of the configured 100 is that the route map was not applied to the redistribution configuration. In FortiGate OSPF redistribution, a route map must be explicitly referenced under the 'redistribute connected' command; otherwise, the route map is ignored, and OSPF uses its default metric of 20 for redistributed connected routes.

Exam trap

The trap here is that candidates assume creating a route map automatically applies it to redistribution, but FortiGate requires explicit application under the redistribution command, and the default metric of 20 is used if no route map is referenced.

How to eliminate wrong answers

Option A is wrong because route maps in OSPF redistribution do not have a 'direction' like in route filtering; they are applied as a filter or modifier during the redistribution process itself, so direction is not a factor. Option B is wrong because OSPF does allow metric setting via route maps using the 'set metric' action, which is a standard feature in FortiGate OSPF configuration. Option D is wrong because setting the metric type to type 1 does not affect the metric value; it changes how the metric is calculated (adding internal cost), but the base metric would still be set by the route map if applied correctly.

52
MCQmedium

A FortiGate is configured with VRF. Which statement about VRF is true?

A.Interfaces can belong to multiple VRFs simultaneously.
B.VRF allows multiple routing tables to coexist on the same FortiGate.
C.Routes from different VRFs can be automatically redistributed without configuration.
D.VRF can only be used when OSPF is enabled.
AnswerB

VRF (virtual routing and forwarding) instantiates separate routing tables on one FortiGate, so overlapping IP subnets can be isolated per tenant or interface without leaking routes between them. This directly satisfies the stem's requirement that multiple routing tables coexist on the same device, which is the defining property of VRF.

Why this answer

VRF (Virtual Routing and Forwarding) allows a single FortiGate to maintain multiple independent routing tables, each with its own set of interfaces, routes, and forwarding decisions. This enables network segmentation and traffic isolation without requiring separate physical devices, making option B correct.

Exam trap

The trap here is that candidates often assume interfaces can belong to multiple VRFs (like VLAN sub-interfaces can belong to multiple VLANs), but in VRF, each interface is exclusively bound to a single VRF instance.

How to eliminate wrong answers

Option A is wrong because a physical or logical interface can belong to only one VRF at a time; an interface is assigned to a specific VRF instance and cannot be shared across multiple VRFs simultaneously. Option C is wrong because routes between VRFs are not automatically redistributed; explicit route leaking or inter-VRF routing policies (e.g., using route maps or VRF leak commands) must be configured to share routes between VRFs. Option D is wrong because VRF is independent of any specific routing protocol; it works with static routes, BGP, OSPF, RIP, or any combination, and does not require OSPF to be enabled.

53
Multi-Selecthard

An administrator is troubleshooting an SD-WAN deployment where traffic is not being forwarded according to the configured SD-WAN rules. The FortiGate has two WAN interfaces, port1 and port2, both members of an SD-WAN zone. A performance SLA is configured and both members are within SLA. The administrator suspects that the SD-WAN rules are not being evaluated correctly. Which two statements about SD-WAN rule evaluation are correct? (Choose two.)

Select 2 answers
A.SD-WAN rules are evaluated in the order they appear in the configuration, and the first matching rule is applied.
B.If no SD-WAN rule matches, traffic is dropped by default.
C.SD-WAN rules can match traffic based on the application identified by the application control profile.
D.SD-WAN rules are evaluated only after a firewall policy has allowed the traffic.
E.SD-WAN rules are applied only to outbound traffic initiated from the internal network.
AnswersA, C

SD-WAN rules are processed sequentially from top to bottom. The first rule that matches the traffic's criteria (source, destination, application, etc.) is used for path selection. Subsequent rules are not evaluated. Therefore, rule order is critical; a broad rule placed before a specific one can prevent the specific rule from ever being matched.

Why this answer

SD-WAN rules are evaluated in a top-down order, and the first matching rule determines the path selection. They can match on various criteria, including applications identified by application control. If no rule matches, the FortiGate uses the regular routing table.

SD-WAN rules are part of the routing decision and are evaluated before firewall policies. They are not limited to outbound traffic; they can apply to any traffic that matches the criteria.

Exam trap

The trap here is assuming that SD-WAN rules are evaluated after firewall policies or that unmatched traffic is dropped, when in fact routing decisions precede policy enforcement and fallback to the routing table occurs.

54
MCQhard

You are troubleshooting BFD on a FortiGate SD-WAN deployment. BFD is configured on two WAN interfaces (wan1, wan2) with a minimum transmit interval of 100 ms and a multiplier of 3. The network experiences occasional jitter causing packet loss. After a brief outage, the BFD session does not recover. Which setting should be adjusted to improve BFD resilience without significantly increasing failover time?

A.Disable BFD and rely on route timers.
B.Enable BFD on the management interface.
C.Increase the BFD minimum transmit interval on both interfaces.
D.Increase the BFD multiplier to 4 or higher.
AnswerD

Raising the multiplier from 3 to 4+ tolerates more consecutive missed BFD packets before declaring the peer down, absorbing jitter-induced loss so sessions recover. Transmit interval changes would alter detection timing more drastically, so the multiplier is the precise resilience lever.

Why this answer

Increasing the BFD multiplier (from 3 to 4 or higher) allows the session to tolerate more lost BFD control packets before declaring a failure. This directly addresses the jitter-induced packet loss without changing the detection timing for sustained outages, as the multiplier only affects the number of missed packets required to trigger a failure. The minimum transmit interval remains at 100 ms, so the base detection time (multiplier × interval) increases only slightly, preserving fast failover for true link failures.

Exam trap

The trap here is that candidates mistakenly increase the transmit interval (Option C) thinking it reduces jitter sensitivity, but that actually increases failover time for all failures, whereas adjusting the multiplier provides resilience against intermittent loss without proportionally increasing detection time for sustained outages.

How to eliminate wrong answers

Option A is wrong because disabling BFD removes sub-second failure detection entirely, reverting to slower routing protocol timers (e.g., OSPF dead interval of 40 seconds), which would significantly increase failover time. Option B is wrong because enabling BFD on the management interface is irrelevant to SD-WAN WAN link resilience; BFD on the management interface monitors management-plane connectivity, not data-plane SD-WAN paths. Option C is wrong because increasing the minimum transmit interval (e.g., to 200 ms) would directly increase the base detection time for all failures, including sustained outages, thereby increasing failover time, which contradicts the requirement to not significantly increase failover time.

55
MCQmedium

An administrator has deployed a FortiGate at a branch with two WAN links: port1 (primary) and port2 (backup). They create an SD-WAN zone and a performance SLA named 'ISP-Health' that monitors 8.8.8.8 using ping. The SLA is configured with link-cost-factor latency and a threshold of 50 ms. After a week, they notice that the primary link is still being used for all traffic even though its latency frequently exceeds 150 ms. The backup link has 20 ms latency. What is the most likely reason the SD-WAN rule is not failing over?

A.The SD-WAN rule is using the 'lowest-cost' algorithm, which ignores SLA status and only uses link cost.
B.The performance SLA is not referenced in the SD-WAN rule, so the rule cannot use the SLA status to make decisions.
C.The SLA monitor uses ping, which is not supported for latency measurement; only HTTP and TCP echo are valid.
D.The link-cost-factor is set to latency, but the backup link must also have an SLA configured to be eligible for failover.
AnswerB

For an SD-WAN rule to react to SLA status, the rule must explicitly reference the performance SLA in its configuration. Without that reference, the FortiGate only uses static criteria like interface priority, ignoring the SLA results. This matches the symptom of the primary link remaining in use despite high latency. The administrator must edit the SD-WAN rule and select 'ISP-Health' as the SLA target.

Why this answer

The SD-WAN rule must explicitly reference the performance SLA for the FortiGate to use SLA results in path selection. Without that association, the rule falls back to static criteria such as interface priority or link cost, so the primary link continues to be used even when its latency exceeds the threshold. The administrator needs to edit the rule and select the SLA as a target.

Exam trap

The trap here is assuming that creating a performance SLA automatically makes all SD-WAN rules SLA-aware, when each rule must explicitly reference the SLA.

56
MCQeasy

Which FortiGate feature allows the creation of multiple virtual routing tables within a single VDOM?

A.VRF
B.Policy-based routing
C.VDOM
D.ECMP
AnswerA

VRF (virtual routing and forwarding) instantiates independent routing tables inside one VDOM, each with its own interfaces, routes and forwarding decisions. This separation satisfies the requirement for multiple virtual routing tables within a single VDOM without deploying additional VDOMs.

Why this answer

VRF (Virtual Routing and Forwarding) allows a single FortiGate VDOM to maintain multiple independent routing tables, each with its own forwarding decisions. This is achieved by creating separate VRF instances (identified by VRF IDs 1-255) within the same VDOM, enabling traffic isolation and overlapping IP address spaces without requiring separate VDOMs.

Exam trap

The trap here is confusing VDOM with VRF: candidates often think VDOMs are the only way to create multiple routing tables, but VRF achieves this within a single VDOM, which is a more granular and resource-efficient approach for network segmentation.

How to eliminate wrong answers

Option B (Policy-based routing) is wrong because it overrides the routing table for specific traffic based on policies, but does not create multiple independent routing tables; it only redirects traffic within a single routing table. Option C (VDOM) is wrong because VDOMs create separate virtual firewalls with their own routing tables, but the question asks for multiple routing tables within a single VDOM, not separate VDOMs. Option D (ECMP) is wrong because ECMP (Equal-Cost Multi-Path) is a load-balancing technique that distributes traffic across multiple paths within a single routing table, not a mechanism to create multiple routing tables.

57
MCQmedium

A FortiGate is configured with ECMP load balancing for equal-cost routes. The administrator wants to ensure that all traffic from a specific source IP uses the same next hop. Which ECMP load balancing method should be selected?

A.Destination-IP-based
B.Source-IP-based
C.Weighted random
D.Round-robin
AnswerB

Source-IP-based load balancing hashes the source address to select the next hop, so every flow from one source consistently maps to the same ECMP member. Other methods, such as source-destination IP or weighted round-robin, can distribute that host's traffic across paths.

Why this answer

Source-IP-based ECMP load balancing ensures that all packets from a specific source IP address are forwarded to the same next hop by hashing only the source IP field. This maintains session consistency for traffic originating from a single host, which is critical for stateful inspection and applications that require symmetric routing.

Exam trap

The trap here is that candidates often confuse 'per-flow' load balancing (which uses source and destination IP) with 'source-IP-based' persistence, assuming that any hash including the source IP will keep all traffic from that source on the same path, but only a hash using exclusively the source IP achieves that guarantee.

How to eliminate wrong answers

Option A is wrong because Destination-IP-based hashing uses only the destination IP, which would not guarantee that traffic from the same source IP uses the same next hop; different destinations could be load-balanced to different paths. Option C is wrong because Weighted random distributes traffic probabilistically based on weights, not deterministically by source IP, so packets from the same source could take different paths. Option D is wrong because Round-robin cycles through next hops in order without any per-source affinity, breaking source-IP stickiness.

58
Multi-Selecthard

A FortiGate is configured with BGP and OSPF. The administrator wants to ensure that routes learned via BGP are redistributed into OSPF, but only specific prefixes. Which three components are needed? (Select THREE.)

Select 3 answers
A.A route map that references the prefix list and sets OSPF parameters
B.Redistribution of BGP into OSPF under router ospf with the route map applied
C.A VRF to separate the routing tables
D.A prefix list to match the desired BGP routes
E.A distribute list in OSPF to filter incoming routes
AnswersA, B, D

The route map is the filtering and attribute-setting mechanism: it references the prefix list that matches only the specific prefixes, then sets the OSPF parameters applied during redistribution. This satisfies the requirement to redistribute only chosen BGP prefixes into OSPF.

Why this answer

Option D is correct because a prefix list is the mechanism used to match the specific BGP-learned prefixes that should be redistributed into OSPF, allowing granular control over which networks are permitted. Option A is correct because a route map is required to reference that prefix list and apply the desired OSPF parameters (such as metric, metric-type, or tag) to the redistributed routes. Option B is correct because redistribution must be configured under the OSPF routing process with the route map applied, for example using 'config redistribute bgp' and 'set route-map <name>' under 'config router ospf', so that only the matched BGP routes are injected into OSPF.

Option C is not needed because a VRF is only required to separate routing tables in multi-tenant or overlapping-address scenarios, not for basic route redistribution between BGP and OSPF. Option E is not needed because a distribute list filters OSPF routes being received or advertised within OSPF, not BGP routes being redistributed into OSPF.

Exam trap

The trap here is that candidates often confuse distribute lists (which filter OSPF routes received from neighbors) with route maps used for redistribution filtering, leading them to select option E instead of understanding that redistribution filtering requires a route map referencing a prefix list.

59
MCQeasy

An administrator is configuring an SD-WAN rule to load balance traffic across two WAN links. The administrator wants to distribute traffic based on the source IP address to ensure that each source uses a consistent path. Which load balancing algorithm should be used?

A.Weighted round robin
B.Lowest cost (SLA)
C.Volume
D.Source IP
AnswerD

The 'source-ip' algorithm distributes traffic based on the source IP address, ensuring that all sessions from a given source use the same WAN link. This provides session persistence and is ideal for scenarios where consistent path selection is required. It directly matches the administrator's goal.

Why this answer

The 'source-ip' load balancing algorithm uses a hash of the source IP address to select an SD-WAN member. This ensures that all traffic from a specific source IP consistently uses the same WAN link, providing session persistence. This meets the administrator's requirement to distribute traffic based on source IP and maintain consistent paths.

Exam trap

The trap here is confusing source-based load balancing with other algorithms that distribute traffic evenly but do not provide source-based persistence, such as weighted round robin or volume.

60
MCQeasy

What is the purpose of configuring BFD (Bidirectional Forwarding Detection) on a FortiGate?

A.To provide rapid failure detection between two forwarding engines.
B.To load balance traffic across multiple links.
C.To encrypt BGP updates between peers.
D.To authenticate OSPF neighbors.
AnswerA

BFD runs a lightweight, sub-second hello exchange directly between forwarding engines, independent of routing protocol timers. This satisfies the stem's requirement for rapid failure detection, letting OSPF or BGP tear down a dead neighbour far sooner than default dead intervals would allow.

Why this answer

BFD (Bidirectional Forwarding Detection) provides sub-second failure detection between two forwarding engines, such as FortiGate peers running OSPF or BGP. It operates independently of the routing protocol, using a lightweight hello mechanism to detect link or neighbor failures faster than protocol-native timers (e.g., OSPF dead interval of 40 seconds). This enables rapid convergence in SD-WAN and advanced networking scenarios.

Exam trap

The trap here is that candidates confuse BFD with routing protocol features like authentication or load balancing, but BFD is exclusively a fast failure detection mechanism that works alongside, not instead of, routing protocols.

How to eliminate wrong answers

Option B is wrong because load balancing across multiple links is achieved through ECMP (Equal-Cost Multi-Path) routing or SD-WAN load-balancing rules, not BFD, which only detects failures. Option C is wrong because encrypting BGP updates between peers is done using IPsec or MD5/TCP-AO authentication, not BFD, which has no encryption capability. Option D is wrong because authenticating OSPF neighbors is performed using OSPF authentication (plaintext, MD5, or SHA) in the OSPF packet header, not BFD, which focuses solely on bidirectional liveness detection.

61
MCQhard

A FortiGate is configured with ECMP load balancing for multiple equal-cost routes. The administrator wants to ensure that all packets belonging to the same session go out the same interface. Which ECMP load balancing method should be used?

A.Weighted
B.Source-dest-IP-based
C.Source-IP-based
D.Spillover
AnswerB

Source-dest-IP-based hashing derives the egress interface from a hash of the source and destination IP pair, so every packet in a given session maps to the same next hop. This satisfies the stem's requirement that all packets belonging to the same session leave through one interface, preserving session integrity across ECMP paths.

Why this answer

Source-dest-IP-based ECMP (often called per-flow load balancing) uses a hash of both source and destination IP addresses to consistently map all packets of a session to the same next-hop interface. This ensures session integrity because the hash remains constant for the entire flow, preventing out-of-order delivery or packet drops that would occur if packets from the same session took different paths.

Exam trap

The trap here is that candidates often confuse 'source-dest-IP-based' with 'source-IP-based' or assume that any ECMP method inherently preserves session affinity, but only the source-dest-IP-based (or per-flow) method guarantees that all packets of a session use the same interface.

How to eliminate wrong answers

Option A is wrong because Weighted ECMP distributes traffic based on configured weight ratios, but it still uses per-packet or per-flow hashing depending on the underlying method; it does not inherently guarantee session persistence unless combined with a per-flow hash. Option C is wrong because Source-IP-based hashing only considers the source IP, which can cause packets from the same session (same source and destination) to be split if the source IP alone does not uniquely identify the flow, leading to asymmetric routing. Option D is wrong because Spillover is a load balancing method that sends traffic to a secondary link only when the primary link's bandwidth threshold is exceeded; it does not use hashing and can break session continuity when traffic spills over mid-session.

62
MCQmedium

A FortiGate with SD-WAN has two members: MPLS (port1) and Broadband (port2). The performance SLA is configured to monitor latency and packet loss. The administrator notices that after a brief outage on the MPLS link, traffic fails over to Broadband but does not fail back when MPLS recovers. What is the likely cause?

A.The SD-WAN rule for the traffic has 'set failback disable'.
B.The SLA threshold is set too aggressively, causing the link to be considered down long after recovery.
C.The Broadband link has a higher cost, so the FortiGate prefers to keep traffic there.
D.The SLA probe interval is longer than the outage duration, so the SLA never detected the outage.
AnswerA

The SD-WAN rule's failback setting governs whether traffic returns to a preferred member once it recovers. With failback disabled, the rule keeps sessions on Broadband after the MPLS outage, satisfying the stem's symptom of no automatic return. Re-enabling failback restores MPLS preference when its SLA checks pass again.

Why this answer

The 'set failback disable' command in the SD-WAN rule prevents traffic from automatically returning to the preferred MPLS link after it recovers. By default, failback is enabled, meaning traffic will revert to the higher-priority member once the performance SLA is satisfied again. When disabled, the FortiGate keeps traffic on the backup link indefinitely, which matches the described behavior.

Exam trap

The trap here is that candidates often confuse failback with failover triggers or SLA thresholds, assuming the issue is with detection or cost rather than the explicit failback disable setting in the SD-WAN rule.

How to eliminate wrong answers

Option B is wrong because an overly aggressive SLA threshold would cause the link to be considered down more easily, not prevent failback after recovery; the issue is about failback, not detection. Option C is wrong because cost influences initial path selection and load balancing, not failback behavior; a higher-cost link would not be preferred for failback, and the FortiGate does not use cost to decide whether to revert traffic. Option D is wrong because if the SLA probe interval were longer than the outage, the SLA would never detect the outage, so traffic would not fail over at all; the scenario states failover occurred, so the probe interval is not the cause.

63
MCQhard

An administrator has configured BGP on a FortiGate with two upstream ISPs. They notice that traffic to a specific prefix is not load-balanced as expected; all traffic goes through ISP1 even though both paths are available. 'get router info bgp network' shows the prefix with two next hops. What is the MOST likely cause?

A.The prefix is being learned via an IGP with a lower administrative distance
B.The BGP multi-path is disabled
C.The administrative distance of BGP is higher than OSPF
D.The eBGP multihop is not configured
AnswerB

BGP load balancing requires multi-path to be enabled. Even with multiple paths, if multi-path is off, only the best path is installed.

Why this answer

BGP multi-path must be explicitly enabled to allow load balancing across multiple equal-cost paths. Even if both next hops are present in the BGP table, without the 'set multipath' or 'set multipath number' configuration under the BGP process, the FortiGate will select only the best path (lowest weight, local preference, AS-path length, etc.) and install that single route in the routing table. This is why all traffic uses ISP1 despite both paths being available.

Exam trap

The trap here is that candidates assume BGP automatically load-balances across multiple equal-cost paths, but BGP requires explicit multi-path configuration to enable ECMP, unlike IGPs such as OSPF or EIGRP which do so by default.

How to eliminate wrong answers

Option A is wrong because the prefix is learned via BGP (as shown by 'get router info bgp network'), not an IGP; administrative distance only affects route selection between different protocols, not BGP multi-path behavior. Option C is wrong because administrative distance is irrelevant when comparing two BGP-learned routes from the same protocol; BGP uses its own path selection algorithm (weight, local preference, AS-path, etc.) to choose the best path. Option D is wrong because eBGP multihop is only needed when the BGP peers are not directly connected (TTL=1 default); it has no effect on load balancing across multiple paths to the same prefix.

64
MCQmedium

An administrator has configured a FortiGate with an SD-WAN zone named 'virtual-wan-link' containing two members: port1 (WAN1) and port2 (WAN2). A performance SLA named 'CriticalSLA' monitors a server at 8.8.8.8 using ICMP probes every 5 seconds, with failure thresholds: latency 200 ms, jitter 50 ms, packet loss 5%. The SLA status for port1 is 'alive' and for port2 is 'dead'. An SD-WAN rule is configured to use the 'lowest-cost' algorithm with the SLA target 'CriticalSLA'. The administrator notices that all traffic is being routed through port1, even though port2 has a lower cost metric. What is the most likely reason for this behavior?

A.The SD-WAN rule is configured with the 'lowest-cost' algorithm, which only selects members that meet the SLA target; port2 is excluded because it is dead.
B.The performance SLA is using ICMP probes, which are not supported for SLA monitoring; the FortiGate falls back to using only port1.
C.The SD-WAN rule is missing a priority configuration; without priority, the FortiGate defaults to using the first member in the zone.
D.The 'lowest-cost' algorithm only considers the configured cost of each member, and port2 has a higher cost than port1.
AnswerA

The lowest-cost algorithm selects the member with the lowest cost among those that meet the SLA target. Since port2 is dead, it does not meet the SLA and is excluded. Port1, being alive, is the only eligible member, so all traffic uses port1. This is the expected behavior: SLA status takes precedence over cost.

Why this answer

The lowest-cost algorithm selects the member with the lowest cost among those that meet the SLA target. Since port2 is dead, it is excluded from selection, leaving port1 as the only eligible member. This ensures traffic only uses links that meet the performance requirements.

The cost metric is only considered after filtering by SLA status.

Exam trap

The trap here is assuming that the lowest-cost algorithm ignores SLA status and simply picks the member with the lowest configured cost.

65
MCQeasy

What is the purpose of using a prefix list in route redistribution?

A.To match routes based on IP prefix and prefix length
B.To define a list of allowed source IPs for management access
C.To specify the next-hop for a set of routes
D.To set BGP community values on matched prefixes
AnswerA

A prefix list filters routes by network address and subnet mask length, giving granular control over exactly which prefixes enter or leave the routing domain during redistribution. This satisfies the stem's requirement by matching on both IP prefix and prefix length, unlike access lists that match only the network portion.

Why this answer

A prefix list is used in route redistribution to match routes based on their IP prefix and prefix length (e.g., 192.168.0.0/16). This allows granular control over which routes are redistributed from one routing protocol to another, such as from OSPF to BGP, by filtering based on the network address and subnet mask.

Exam trap

The trap here is that candidates often confuse prefix lists with route maps or ACLs, thinking prefix lists can modify route attributes or specify next-hops, when in reality prefix lists only perform matching based on prefix and length, while route maps handle attribute manipulation.

How to eliminate wrong answers

Option B is wrong because defining a list of allowed source IPs for management access is the purpose of an access control list (ACL) or a local-in policy, not a prefix list. Option C is wrong because specifying the next-hop for a set of routes is done using a route map with the set next-hop command or a static route, not a prefix list. Option D is wrong because setting BGP community values on matched prefixes is performed using a route map with the set community command, while a prefix list only matches routes and does not modify attributes.

66
MCQeasy

An administrator needs to configure an SD-WAN rule that routes traffic from the guest VLAN to the Internet using the most cost-effective link. The SD-WAN zone contains three members: port1 (MPLS, cost 10), port2 (Broadband, cost 5), and port3 (LTE, cost 20). All members meet the performance SLA. Which load balancing algorithm should be used to ensure traffic uses the lowest-cost link?

A.Best Quality
B.Source IP
C.Volume
D.Lowest Cost
AnswerD

The 'Lowest Cost' strategy selects the member with the lowest configured cost that also meets the SLA. In this scenario, port2 has the lowest cost (5), so it will be chosen, provided it meets the SLA. This directly satisfies the requirement to use the most cost-effective link while ensuring performance.

Why this answer

The 'Lowest Cost' strategy is designed to select the member with the lowest cost that meets the SLA. In this scenario, port2 has the lowest cost, so it will be chosen as long as it meets the SLA. This ensures that guest traffic uses the most cost-effective link while still maintaining acceptable performance.

The other strategies do not prioritize cost and would not meet the requirement.

Exam trap

The trap here is confusing 'Lowest Cost' with 'Best Quality' or 'Volume', and assuming that cost is considered in those algorithms when it is not.

67
MCQeasy

A network administrator is configuring SD-WAN on a FortiGate. The organization has two internet links: MPLS (primary) and broadband (backup). The administrator wants all traffic to use the MPLS link unless it fails, in which case traffic should fail over to the broadband link. Which SD-WAN configuration best achieves this requirement?

A.Set the MPLS link priority to 10 and the broadband link priority to 5, then configure an SD-WAN rule with the 'best quality' strategy.
B.Enable 'set role' on the MPLS link as 'primary' and on the broadband link as 'standby' with the 'redundant' strategy.
C.Configure both links in the SD-WAN zone with equal priority and use the 'lowest cost' strategy.
D.Create two static routes: one with higher distance for MPLS and one with lower distance for broadband.
AnswerA

Higher priority for MPLS ensures it is preferred. The 'best quality' strategy selects the member with the highest priority when available, providing failover.

Why this answer

Setting the MPLS link priority to 10 (higher) and broadband to 5 (lower) ensures the SD-WAN rule with 'best quality' strategy selects the MPLS link as the preferred path. The 'best quality' strategy evaluates link quality metrics and, when priorities differ, prefers the higher-priority link. If the MPLS link fails, the strategy automatically fails over to the broadband link, meeting the requirement.

Exam trap

The trap here is that candidates often confuse SD-WAN failover with traditional static route failover using administrative distance, or incorrectly assume that role-based 'primary/standby' settings exist in FortiGate SD-WAN, leading them to choose options B or D instead of understanding that SD-WAN uses priority and strategy-based path selection.

How to eliminate wrong answers

Option B is wrong because 'set role' with 'primary' and 'standby' is not a valid SD-WAN configuration; FortiGate SD-WAN uses priority values and strategies, not role-based primary/standby assignments, and the 'redundant' strategy is for load balancing, not failover. Option C is wrong because equal priority with 'lowest cost' strategy would load-balance traffic across both links based on cost, not enforce MPLS as primary and broadband as backup. Option D is wrong because static routes with different distances control routing table selection, not SD-WAN link failover; SD-WAN rules override static route behavior and require SD-WAN-specific configuration to achieve policy-based failover.

68
MCQeasy

Which of the following is the primary purpose of BFD (Bidirectional Forwarding Detection) on a FortiGate?

A.To synchronize routing tables between peers
B.To load balance traffic across multiple paths
C.To provide fast detection of link failures
D.To encrypt routing updates between peers
AnswerC

BFD sends rapid heartbeat packets between neighbouring devices, detecting link or path failures in milliseconds rather than waiting for routing protocol timers. This fast failure detection lets the FortiGate reconverge traffic quickly, which is BFD's primary purpose.

Why this answer

BFD (Bidirectional Forwarding Detection) is a lightweight protocol designed to provide sub-second failure detection between two forwarding engines, such as FortiGate peers. Unlike routing protocol hellos (e.g., OSPF Hello at 10-second intervals), BFD can detect link or neighbor failures in as little as 50–100 ms, enabling faster convergence. This makes it the primary mechanism for rapid link failure detection in high-availability and SD-WAN deployments.

Exam trap

The trap here is that candidates confuse BFD with routing protocol keepalives or assume it performs routing table synchronization, when in fact BFD is purely a fast failure detection mechanism that operates independently of the routing protocol.

How to eliminate wrong answers

Option A is wrong because BFD does not exchange or synchronize routing tables; it only monitors the bidirectional forwarding path between peers. Option B is wrong because BFD does not perform load balancing; it is a detection mechanism that can be used alongside ECMP or SD-WAN to trigger path changes upon failure. Option D is wrong because BFD does not encrypt routing updates; it sends simple, unencrypted control packets (RFC 5880) and relies on the underlying transport for security if needed.

69
MCQhard

An administrator configures BFD on a BGP session between two FortiGates. After enabling BFD, the BGP session flaps intermittently. What is the most likely cause?

A.The BFD failure detection intervals are too low, causing false positives
B.BFD is incompatible with BGP and should not be used together
C.BGP hold timer is shorter than BFD detection time
D.The BFD minimum transmit and receive intervals are set too high
AnswerA

Overly aggressive BFD intervals cause the session to declare failure on minor jitter or transient delay, tearing down BGP and triggering flapping. Raising the failure detection intervals to tolerate normal latency satisfies the stem's requirement for a stable BGP session.

Why this answer

When BFD is enabled on a BGP session, the BFD failure detection intervals (typically the minimum transmit and receive intervals) determine how quickly a link failure is detected. If these intervals are set too low, BFD may generate false positives due to transient network jitter or minor packet loss, causing the BGP session to flap as BFD triggers a session reset even though the underlying link is stable. This is the most likely cause because the symptom appeared immediately after enabling BFD, and the default or misconfigured intervals can be too aggressive for the network conditions.

Exam trap

The trap here is that candidates often assume BFD is always beneficial and that lower intervals are better, but the question tests the understanding that overly aggressive BFD timers can cause instability due to false positives, not that BFD is incompatible or that higher intervals cause flapping.

How to eliminate wrong answers

Option B is wrong because BFD is fully compatible with BGP and is commonly used to accelerate link failure detection in BGP sessions; RFC 5880 and RFC 5881 define BFD for IP links, and FortiGate supports BFD for BGP. Option C is wrong because if the BGP hold timer were shorter than the BFD detection time, BGP would time out before BFD detects a failure, but the problem is intermittent flapping, not BGP hold timer expiration; in fact, BFD detection times are typically much shorter than BGP hold timers (e.g., 150ms vs 3 seconds). Option D is wrong because setting BFD minimum transmit and receive intervals too high would make BFD less sensitive, reducing false positives and flapping, not causing it; the issue is intervals being too low, not too high.

70
MCQmedium

An administrator sees the following output from 'get router info routing-table': S 0.0.0.0/0 [10/0] via 192.168.1.1, port1 S 0.0.0.0/0 [10/0] via 192.168.2.1, port2 They have configured ECMP load balancing. However, traffic to a specific destination IP is always using port1. What is the likely reason?

A.The firewall policy only allows traffic on port1
B.ECMP uses per-packet load balancing by default and the traffic is a single flow
C.One of the static routes has a lower administrative distance
D.The destination IP hash results in the same link for all sessions due to the load balancing algorithm
AnswerD

ECMP selects a path per flow using a hash of source and destination attributes. Because the same destination consistently hashes to the same member, all sessions to that IP traverse port1 rather than being spread across both links.

Why this answer

D is correct because FortiGate ECMP load balancing uses a hash-based algorithm (source-destination IP, port, or protocol) by default, not per-packet. When the hash of the destination IP consistently maps to the same link (port1), all sessions to that specific IP will use that interface, even though multiple routes exist with equal administrative distance and cost.

Exam trap

The trap here is that candidates confuse per-packet load balancing (which would alternate packets within a single flow) with FortiGate's default per-session hash-based ECMP, leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because firewall policies are stateful and apply to traffic after routing decisions are made; they do not influence which route is selected for a given destination. Option B is wrong because FortiGate ECMP does not use per-packet load balancing by default; it uses per-session load balancing based on a hash of the 5-tuple (or source/destination IP), so a single flow will always use the same link. Option C is wrong because both static routes show the same administrative distance [10] and cost [0], so they are equal-cost paths; a lower administrative distance would cause one route to be preferred over the other, but that is not the case here.

71
MCQeasy

Which SD-WAN load balancing algorithm distributes traffic based on the number of active sessions per SD-WAN member?

A.Sessions
B.Source-dest-IP
C.Spillover
D.Volume
AnswerA

The sessions algorithm selects the SD-WAN member with the fewest active sessions, balancing load by session count rather than bandwidth, latency or packet volume. This matches the requirement to distribute traffic based on active sessions per member.

Why this answer

The Sessions algorithm in Fortinet SD-WAN distributes traffic by counting the number of active sessions currently traversing each SD-WAN member interface. The member with the fewest active sessions receives the next new session, ensuring a balanced session load across the SD-WAN links. This is distinct from volume-based or hash-based algorithms, as it directly uses session count as the metric.

Exam trap

The trap here is that candidates often confuse 'Sessions' with 'Volume' or 'Spillover', assuming traffic distribution is always based on bandwidth usage rather than session count, which is a distinct metric in Fortinet SD-WAN load balancing.

How to eliminate wrong answers

Option B (Source-dest-IP) is wrong because it uses a hash of source and destination IP addresses to deterministically map traffic to a member, not the number of active sessions. Option C (Spillover) is wrong because it directs traffic to a primary member until a configured bandwidth threshold is exceeded, then spills over to a backup member; it does not consider session counts. Option D (Volume) is wrong because it distributes traffic based on the total bytes transferred per member, not the number of active sessions.

72
MCQhard

An administrator is integrating a FortiExtender with a FortiGate. The FortiExtender is connected to port5 and configured with a cellular WAN connection. What must be configured on the FortiGate to allow the FortiExtender to provide WAN connectivity as an SD-WAN member?

A.Create a static route to the FortiExtender's management IP to use it as a gateway.
B.Configure port5 as a physical member and assign the FortiExtender's SIM card details.
C.Enable the 'fortiextender' option on port5 and configure the FortiExtender as an SD-WAN member using the virtual wan interface.
D.Use the FortiExtender as a standalone router and configure policy-based routing on the FortiGate.
AnswerC

Enabling the fortiextender option on port5 lets the FortiGate discover and manage the device, while the virtual wan interface represents the cellular link so it can join the SD-WAN. Both are required for WAN connectivity.

Why this answer

To integrate a FortiExtender as an SD-WAN member, the FortiGate must enable the 'fortiextender' option on the physical port (port5) to which the FortiExtender is connected. This creates a virtual wan interface that represents the FortiExtender's cellular WAN connection, allowing it to be added as an SD-WAN member for load balancing and failover policies. No static route or SIM card configuration is needed on the FortiGate, as the FortiExtender handles cellular authentication and routing internally.

Exam trap

The trap here is that candidates assume the FortiExtender must be configured as a separate router or that SIM details must be entered on the FortiGate, when in fact the FortiGate only needs to enable the 'fortiextender' option to treat the FortiExtender as a logical SD-WAN member.

How to eliminate wrong answers

Option A is wrong because a static route to the FortiExtender's management IP is not required; the FortiExtender acts as a WAN extension, not a gateway that needs a separate route. Option B is wrong because SIM card details are configured on the FortiExtender itself, not on the FortiGate; port5 must be configured with the 'fortiextender' option, not as a physical SD-WAN member. Option D is wrong because using the FortiExtender as a standalone router with policy-based routing defeats the purpose of SD-WAN integration; the FortiExtender must be managed as a virtual interface on the FortiGate to participate in SD-WAN rules.

73
MCQhard

A FortiGate is running OSPF with multiple areas. The admin wants to redistribute a static route for 192.168.100.0/24 into OSPF. After configuring 'config router ospf' with 'redistribute static' enabled, the route appears in the OSPF database but is not being advertised to other areas. What is the most likely cause?

A.The 'redistribute static' command needs a route map to filter the route correctly.
B.The static route's administrative distance is too high for OSPF.
C.The router is an ABR and the static route is being redistributed as a type 5 LSA, which is not flooded into stub areas.
D.OSPF must be configured with 'default-information originate' to allow redistribution.
AnswerC

Type 5 LSAs are not flooded into stub areas, so a static route redistributed by an ABR never reaches routers inside those areas even though it appears in the OSPF database. This matches the stem's symptom of no advertisement beyond the originating area.

Why this answer

An ABR does not flood Type 5 LSAs (which are generated by redistribution) into stub areas or NSSAs. Since the route appears in the OSPF database on the ABR but is not advertised to other areas, the most likely cause is that the receiving area is a stub area, which by design blocks Type 5 LSAs. The redistribution of a static route into OSPF creates a Type 5 LSA, which is only flooded throughout the AS except into stub areas and NSSAs.

Exam trap

The trap here is that candidates often overlook the impact of stub area restrictions on Type 5 LSAs and mistakenly focus on redistribution syntax or administrative distance, rather than understanding that ABR behavior in stub areas blocks external routes by default.

How to eliminate wrong answers

Option A is wrong because a route map is not required for basic redistribution of a static route; it is optional for filtering or modifying attributes. Option B is wrong because administrative distance is a Cisco concept used for route selection within a router's routing table, not a factor in OSPF LSA flooding or redistribution behavior. Option D is wrong because 'default-information originate' is used to inject a default route into OSPF, not to enable redistribution of static routes; redistribution is already configured with 'redistribute static'.

74
Multi-Selectmedium

An administrator needs to configure VRF to separate traffic for two departments. Which TWO components must be configured for each VRF?

Select 2 answers
A.A VRF instance
B.Interface binding to the VRF
C.A dedicated VDOM
D.Route leaking configuration
E.A separate firewall policy for each VRF
AnswersA, B

A VRF instance is mandatory because it creates the separate routing table that isolates each department's traffic. Without a distinct VRF instance per department, FortiGate cannot maintain independent forwarding decisions, so routes from one department would leak into the other. This satisfies the stem's core requirement for traffic separation.

Why this answer

A VRF instance (option A) is the foundational component that must be created for each VRF, as it establishes the separate routing table that isolates the department's traffic. Interface binding to the VRF (option B) is also required because interfaces must be assigned to the VRF so that traffic entering and leaving those interfaces uses the correct VRF routing table. A dedicated VDOM (option C) is incorrect because VDOMs are a Fortinet-specific virtualization concept separate from VRF, and VRF can be configured without VDOMs.

Route leaking configuration (option D) is not mandatory for each VRF; it is only needed when you want to selectively share routes between VRFs, which is optional. A separate firewall policy for each VRF (option E) is not a required VRF component, as firewall policies are managed independently of VRF configuration and depend on the platform's security policy model.

Exam trap

The trap here is that candidates confuse VRF with VDOM, thinking each VRF requires a separate virtual domain, when in fact VRF is a routing-level isolation mechanism that can exist within a single VDOM or router instance.

75
MCQhard

A FortiGate is deployed with two ISPs and SD-WAN. The organization uses OSPF to exchange routes with a remote branch. The administrator notices that the FortiGate is not installing OSPF-learned routes into the routing table. The OSPF configuration is verified to be correct, and neighbors are established. Which configuration could be causing the issue?

A.The SD-WAN health-check is configured with 'update-static-route' and is overriding OSPF routes.
B.The administrative distance of OSPF is set to 200, which is higher than the default 110.
C.A distribute-list configured under OSPF is filtering the routes from being installed.
D.The OSPF interface is configured as 'passive', which prevents route exchange.
AnswerC

A distribute-list applied under OSPF filters routes during installation into the routing table, so neighbours stay established and the config looks valid while prefixes are silently dropped. This directly explains why OSPF-learned routes never appear despite correct adjacency.

Why this answer

A distribute-list applied under OSPF can filter routes from being installed into the routing table even when OSPF neighbors are fully established and the OSPF database contains the routes. This is a common cause of routes being learned but not installed, as the filter operates after the SPF calculation and before route insertion.

Exam trap

The trap here is that candidates assume OSPF neighbors being up and routes appearing in the OSPF database guarantee route installation, but a distribute-list can silently block installation without affecting neighbor adjacency or the LSDB.

How to eliminate wrong answers

Option A is wrong because the SD-WAN health-check with 'update-static-route' only affects static routes, not OSPF-learned routes; it cannot override OSPF routes in the routing table. Option B is wrong because the default administrative distance for OSPF is 110, and setting it to 200 would make OSPF routes less preferred but would not prevent them from being installed if no better route exists; the question states routes are not installed at all, not that they are overridden. Option D is wrong because a passive OSPF interface prevents sending or receiving OSPF hellos and thus prevents neighbor formation, but the question states neighbors are established, so passive configuration cannot be the issue.

Page 1 of 2 · 125 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Advanced Networking and SD-WAN questions.