Courseiva

CCNA Advanced Networking and SD-WAN Questions

50 of 125 questions · Page 2/2 · Advanced Networking and SD-WAN · Answers revealed

76
MCQhard

An administrator is troubleshooting an SD-WAN rule that is not matching traffic as expected. The rule is configured with a source address of 'all', destination '10.0.0.0/24', and service 'HTTP'. The rule is placed after a rule that matches all traffic to '10.0.0.0/24' with service 'ALL'. The administrator notices that HTTP traffic to 10.0.0.0/24 is being handled by the first rule. What is the most likely cause?

A.The SD-WAN rule with service 'ALL' has a higher priority value, which overrides the order of rules.
B.SD-WAN rules are evaluated in order, and the first matching rule is applied. The rule with service 'ALL' matches HTTP traffic, so it takes precedence.
C.The HTTP rule is not matching because the service 'HTTP' is not defined in the SD-WAN rule; the administrator must use 'ALL' for web traffic.
D.SD-WAN rules are evaluated based on the most specific match, so the HTTP rule should take precedence regardless of order.
AnswerB

SD-WAN rules are evaluated sequentially from top to bottom. The first rule matches all services, including HTTP, so it captures the traffic before the more specific rule is evaluated. To fix this, the administrator should reorder the rules so that the HTTP-specific rule is above the generic rule.

Why this answer

SD-WAN rules are processed in the order they are listed, and the first rule that matches the traffic is used. In this case, the rule with service 'ALL' matches HTTP traffic before the HTTP-specific rule is evaluated. The solution is to move the HTTP rule above the generic rule.

Exam trap

The trap here is assuming that SD-WAN rules use a most-specific-match logic like firewall policies, when in fact they are order-dependent.

77
MCQmedium

An administrator configures a prefix list to filter routes received from a BGP neighbor. The prefix list permits 192.168.0.0/16 le 24. Which routes are permitted?

A.Only routes with prefix length exactly 16 within 192.168.0.0/16
B.Only routes with prefix length exactly 24 within 192.168.0.0/16
C.Any route with prefix length greater than 24 within 192.168.0.0/16
D.Any route with prefix length between 16 and 24 inclusive, starting with 192.168
AnswerD

The `le 24` operator extends the match beyond the /16 network to any more-specific prefix up to and including /24, so 192.168.0.0/16 through 192.168.1.0/24 all qualify. Routes with prefix lengths of 25 or greater, and any prefix outside the 192.168 range, are denied.

Why this answer

The prefix list `192.168.0.0/16 le 24` permits any route that matches the prefix `192.168.0.0/16` and has a prefix length between 16 and 24 inclusive. The `le` (less-than-or-equal-to) operator sets the maximum prefix length, so routes with lengths 16, 17, 18, 19, 20, 21, 22, 23, and 24 are all allowed, as long as they fall within the 192.168.0.0/16 network.

Exam trap

The trap here is that candidates often misinterpret `le 24` as meaning 'length exactly 24' or 'lengths less than 24', when in fact it means 'lengths from the network prefix length up to and including 24'.

How to eliminate wrong answers

Option A is wrong because it incorrectly restricts the prefix length to exactly 16, ignoring the `le 24` modifier that permits longer prefixes up to 24. Option B is wrong because it incorrectly restricts the prefix length to exactly 24, ignoring the base prefix length of 16 and the range allowed by `le`. Option C is wrong because it states prefix lengths greater than 24 are permitted, but `le 24` explicitly limits the maximum prefix length to 24, so lengths 25 or longer are denied.

78
MCQeasy

A network administrator needs to configure SD-WAN on a FortiGate to distribute traffic across two WAN links based on session count. Which load balancing algorithm should be selected in the SD-WAN rule?

A.Volume
B.Lowest-cost
C.Spillover
D.Sessions
AnswerD

The Sessions algorithm distributes traffic according to the number of active sessions on each member, directly matching the session-count requirement. Source-IP, volume and spillover balance on different metrics, so they would not satisfy the stated constraint.

Why this answer

The 'Sessions' load balancing algorithm distributes new sessions across SD-WAN members based on the current session count, ensuring an even distribution of sessions. This directly matches the requirement to distribute traffic based on session count, as it selects the member with the fewest active sessions for each new session.

Exam trap

The trap here is confusing 'Sessions' with 'Volume' or 'Spillover', as candidates often assume bandwidth-based algorithms (like Volume) are the default for session distribution, but FortiGate's SD-WAN explicitly separates session count from byte volume in its load balancing options.

How to eliminate wrong answers

Option A is wrong because 'Volume' distributes traffic based on the total bytes transferred, not session count. Option B is wrong because 'Lowest-cost' selects the link with the lowest cost (based on cost metric), not session count. Option C is wrong because 'Spillover' forwards traffic to a primary link until a configured bandwidth threshold is exceeded, then spills over to a backup link, which is unrelated to session count.

79
Multi-Selectmedium

A network admin needs to configure a FortiGate to load balance traffic across two ISP links using SD-WAN. The requirement is to use both links simultaneously for different sessions based on source-destination IP hash. Which two settings are required? (Select TWO.)

Select 2 answers
A.Create an SD-WAN zone with both WAN members
B.Configure an SD-WAN rule with load balancing algorithm 'source-dest-ip-hash'
C.Add a performance SLA for each member
D.Set the rule strategy to 'best quality'
E.Enable 'spillover' under the SD-WAN rule
AnswersA, B

An SD-WAN zone groups the two WAN interfaces as members, which is the prerequisite for any SD-WAN rule to reference them. Without the zone, the load-balancing rule cannot bind both ISP links, so this satisfies the requirement to use both links simultaneously.

Why this answer

Option A is correct because SD-WAN load balancing requires the WAN interfaces to be grouped into an SD-WAN zone, which serves as the logical interface containing both ISP members that traffic can be distributed across. Option B is correct because the requirement explicitly states sessions must be distributed based on a source-destination IP hash, and the SD-WAN rule's load-balance algorithm must be set to 'source-dest-ip-hash' to achieve per-session hashing across both links simultaneously. Option C is not required because a performance SLA is only needed for quality-based or SLA-driven steering, not for pure hash-based load balancing.

Option D is incorrect because the 'best quality' strategy selects a single best link based on SLA metrics rather than distributing sessions across both links. Option E is incorrect because spillover is a strategy used to send traffic to a secondary link only when the primary exceeds a threshold, which does not satisfy the requirement of using both links simultaneously for different sessions.

Exam trap

The trap here is that candidates often confuse 'load balancing algorithm' (like source-dest-ip-hash) with 'strategy' (like best quality) or assume that performance SLAs are mandatory for any SD-WAN rule, when in fact SLAs are only needed for dynamic path selection based on link quality.

80
MCQhard

A FortiGate is configured with two VRF instances: VRF10 (for the finance department) and VRF20 (for the engineering department). Each VRF has its own routing table and interfaces. The administrator needs to allow a server in VRF10 (10.10.10.10) to communicate with a server in VRF20 (10.20.20.20). The administrator has already configured the necessary firewall policies to allow the traffic. However, pings from 10.10.10.10 to 10.20.20.20 fail. What is the most likely cause?

A.The FortiGate requires a static route in the global routing table to route traffic between VRFs.
B.The VRFs are isolated by default; inter-VRF routing requires configuring route leaking or a VRF-to-VRF link.
C.The FortiGate does not support inter-VRF routing; a separate physical interface is required to connect the VRFs.
D.The firewall policies must be configured with the 'set vrf' option to specify the source and destination VRFs.
AnswerB

VRF instances on FortiGate are isolated routing domains. By default, there is no communication between them. To allow traffic between VRFs, the administrator must configure route leaking, which involves exporting routes from one VRF and importing them into another, typically using route-maps or BGP. Alternatively, a VRF-to-VRF link can be created using a pair of interfaces, but that is more complex. Since the administrator only configured firewall policies, the missing piece is the routing configuration to leak routes between VRF10 and VRF20.

Why this answer

VRF instances provide isolated routing tables. By default, traffic cannot flow between them. To enable communication, the administrator must configure route leaking, which allows routes from one VRF to be imported into another.

This is typically done using BGP with route targets or static route leaking commands. Firewall policies alone are insufficient because the FortiGate lacks a route to the destination network in the other VRF. Therefore, the missing configuration is route leaking or a VRF-to-VRF link.

Exam trap

The trap here is assuming that firewall policies alone can enable inter-VRF communication, overlooking the need for route leaking between isolated routing tables.

81
MCQmedium

An administrator is configuring an SD-WAN rule to prefer a specific overlay tunnel for VoIP traffic. The rule uses the 'SLA' strategy with a performance SLA that measures jitter and latency. After applying the rule, the administrator notices that VoIP traffic is still being routed over a different member that does not meet the SLA. What is the most likely cause?

A.The performance SLA is not assigned to the SD-WAN rule, so the rule cannot use SLA status for member selection.
B.The SD-WAN rule is placed below a static route in the routing table, so it is not evaluated.
C.The performance SLA is configured with the wrong protocol; it must use HTTP to measure jitter and latency.
D.The SD-WAN rule is configured with the 'load-balance' strategy instead of 'SLA', so it does not consider SLA status.
AnswerA

For an SD-WAN rule using the SLA strategy to select members based on performance, the performance SLA must be referenced in the rule's configuration. Without it, the rule cannot evaluate SLA status and may default to other criteria. This is the most likely cause of the observed behavior.

Why this answer

An SD-WAN rule with the SLA strategy must explicitly reference a performance SLA to use its measurements for member selection. If the SLA is not linked, the rule cannot determine which members meet the SLA and may fall back to other criteria, causing traffic to use a non-compliant member. Ensuring the correct SLA is attached to the rule resolves the issue.

Exam trap

The trap here is assuming that the SD-WAN rule automatically uses any performance SLA configured on the same members without explicit association.

82
MCQhard

You run 'diagnose sys session filter dport 179' on a FortiGate and see many sessions with proto=6 and proto_state=01. What does this indicate about the BGP sessions?

A.BGP sessions are fully established and exchanging routes.
B.BGP sessions are being actively torn down.
C.BGP sessions are in the process of being established, but not yet fully up.
D.BGP sessions are using TCP port 179 but are idle.
AnswerC

proto_state=01 denotes a TCP session in the SYN-sent or SYN-received phase, meaning the three-way handshake has not completed. For BGP over TCP port 179, this confirms sessions are still being established and are not yet exchanging routing updates.

Why this answer

Proto=6 indicates TCP, and proto_state=01 corresponds to TCP SYN_SENT (state 1 in the Linux TCP state model used by FortiGate). This means the BGP session has sent a SYN but has not yet received a SYN-ACK, so the three-way handshake is incomplete and the session is not established. BGP uses TCP port 179, so seeing many sessions in this state indicates ongoing connection attempts that have not yet completed.

Exam trap

The trap here is that candidates often assume any session on port 179 with proto=6 (TCP) means BGP is working, but they overlook the TCP state field; FortiGate's proto_state values directly map to TCP connection phases, and 01 specifically indicates the session is still in the handshake phase, not established.

How to eliminate wrong answers

Option A is wrong because a fully established BGP session would show proto_state=08 (TCP ESTABLISHED), not 01. Option B is wrong because sessions being torn down would show states like FIN_WAIT (proto_state=09 or 0A) or CLOSE_WAIT (proto_state=0B), not SYN_SENT. Option D is wrong because an idle TCP session on port 179 would still be in ESTABLISHED state (08) if the connection was previously successful, or would not exist if never established; proto_state=01 indicates active connection initiation, not idleness.

83
MCQeasy

Which FortiGate feature is used to detect link failures within milliseconds, allowing rapid convergence for routing protocols like OSPF and BGP?

A.ECMP
B.OSPF Fast Hello
C.BFD
D.Route tagging
AnswerC

BFD (Bidirectional Forwarding Detection) provides sub-second, millisecond-level link failure detection by sending rapid echo and control packets independent of routing protocol hello timers. This satisfies the stem's requirement for millisecond detection, triggering OSPF and BGP to converge rapidly rather than waiting for slower protocol-specific dead intervals.

Why this answer

Bidirectional Forwarding Detection (BFD) is the correct answer because it provides sub-second (millisecond) link failure detection independent of routing protocols. Unlike OSPF or BGP's own keepalive mechanisms, BFD can detect failures in as little as 50-100 ms, enabling rapid convergence for protocols like OSPF and BGP by immediately notifying them of a neighbor loss.

Exam trap

The trap here is that candidates confuse OSPF Fast Hello (which still operates in the hundreds-of-milliseconds range) with BFD's true sub-100 ms detection, or they mistakenly think ECMP or route tagging are involved in failure detection.

How to eliminate wrong answers

Option A is wrong because ECMP (Equal-Cost Multi-Path) is a load-balancing technique that distributes traffic across multiple equal-cost paths, not a failure detection mechanism. Option B is wrong because OSPF Fast Hello reduces the hello interval to achieve faster neighbor loss detection (e.g., 1 second), but it still relies on OSPF's own timers and cannot reach the millisecond detection speeds that BFD offers. Option D is wrong because route tagging is used for policy-based routing or redistribution control (e.g., marking routes with tags to filter or manipulate them), not for detecting link failures.

84
MCQeasy

Which routing protocol is commonly used in SD-WAN deployments to exchange routes between FortiGate and the provider edge router in an MPLS network?

A.RIP
B.BGP
C.IS-IS
D.OSPF
AnswerB

BGP is the exterior gateway protocol used between the FortiGate and the provider edge router to exchange routes across the MPLS network, supporting policy and multi-path control. OSPF and RIP are interior protocols, unsuitable for PE-to-CE peering here.

Why this answer

BGP is the correct answer because it is the standard exterior gateway protocol used in MPLS Layer 3 VPNs to exchange customer routes between a FortiGate (CE router) and the provider edge (PE) router. BGP supports advanced features like route filtering, load balancing, and traffic engineering, which are essential for SD-WAN overlay integration with MPLS underlay networks.

Exam trap

The trap here is that candidates often default to OSPF as a 'common' routing protocol in enterprise networks, failing to recognize that MPLS VPNs specifically require BGP for inter-domain route exchange and SD-WAN overlay integration.

How to eliminate wrong answers

Option A is wrong because RIP is a distance-vector protocol with a maximum hop count of 15, making it unsuitable for the scalable, policy-rich route exchange required between a FortiGate and an MPLS PE router. Option C is wrong because IS-IS is a link-state IGP typically used within service provider networks for internal routing, not for exchanging customer routes with a CE device in an MPLS VPN context. Option D is wrong because OSPF is an IGP designed for intra-domain routing and lacks the path-vector attributes (e.g., AS_PATH, MED) needed for MPLS VPN route distribution and SD-WAN policy-based path selection.

85
MCQeasy

Which feature allows a FortiGate to participate in multiple routing tables simultaneously, enabling network segmentation and overlapping IP address spaces?

A.VDOM
B.Policy-based routing
C.VRF
D.Route redistribution
AnswerC

VRF (virtual routing and forwarding) creates separate routing table instances on one FortiGate, allowing simultaneous participation in multiple routing domains. This satisfies the segmentation and overlapping IP address requirement, since each VRF maintains independent routes.

Why this answer

C is correct because VRF (Virtual Routing and Forwarding) allows a FortiGate to maintain multiple separate routing tables (RIB) on the same physical device. Each VRF instance operates as an independent routing domain, enabling network segmentation and the use of overlapping IP address spaces without conflict, which is essential for MPLS L3VPN and multi-tenant environments.

Exam trap

The trap here is that candidates often confuse VDOMs with VRFs, assuming VDOMs alone provide routing table separation, but VDOMs are a management and security context while VRFs are the actual mechanism for multiple routing tables and overlapping IP spaces.

How to eliminate wrong answers

Option A is wrong because VDOMs (Virtual Domains) provide administrative separation and independent firewall policies, but they do not inherently create multiple routing tables for overlapping IP spaces; VDOMs can use VRFs internally, but the feature directly responsible for multiple routing tables is VRF. Option B is wrong because policy-based routing (PBR) allows traffic to be forwarded based on policies (e.g., source/destination) rather than the routing table, but it does not create multiple independent routing tables; it only overrides the default routing decision for specific traffic. Option D is wrong because route redistribution is a mechanism to exchange routes between different routing protocols or routing tables, but it does not enable the existence of multiple routing tables; it assumes they already exist.

86
MCQmedium

An administrator is troubleshooting SD-WAN and runs the following CLI command: 'execute sdwan-health-check status' The output shows that one SD-WAN member has a status of 'dead'. What does this indicate?

A.The member interface is administratively down
B.The member is not meeting the performance SLA thresholds
C.The SD-WAN member is not included in any SD-WAN rule
D.The member has failed the health check probe to the target server
AnswerD

The health-check probe targets a configured server; a 'dead' status means probes from that member are failing, so it is excluded from SD-WAN path selection. This satisfies the stem's constraint of identifying why one member is unusable.

Why this answer

The 'execute sdwan-health-check status' command displays the results of active health-check probes sent to configured target servers. A status of 'dead' means that the SD-WAN member has failed to receive a successful response from the target server within the configured probe interval and retry count, indicating a loss of connectivity or reachability to that target. This is distinct from interface administrative status or SLA compliance, as the health check specifically tests end-to-end reachability to the probe target.

Exam trap

The trap here is confusing 'dead' (probe failure) with 'SLA violation' (performance threshold breach), as candidates often assume a dead member means it failed SLA metrics, but the health check status is binary—alive or dead—based solely on probe reachability, not on latency or jitter thresholds.

How to eliminate wrong answers

Option A is wrong because 'administratively down' is a separate interface state shown by 'show interface' or 'get system interface', not by the SD-WAN health check status command; a dead health check does not imply the interface is disabled. Option B is wrong because performance SLA thresholds (e.g., latency, jitter, packet loss) are measured separately and a member can be 'dead' even if it meets SLA metrics, as 'dead' indicates probe failure, not SLA violation. Option C is wrong because an SD-WAN member not included in any rule would simply not be used for traffic steering, but its health check status would still be reported as 'alive' or 'dead' based on probe results; exclusion from rules does not cause a 'dead' status.

87
MCQmedium

A network administrator is troubleshooting an SD-WAN setup where a specific application is not using the intended overlay tunnel. The SD-WAN rule is configured with a destination of 'all' and a source of 'all', and the strategy is set to 'manual' with the overlay tunnel as the preferred member. However, traffic is still going out via the underlay. What is the most likely reason?

A.The 'manual' strategy requires a gateway to be specified for the preferred member.
B.The overlay tunnel member is down or not meeting the SLA, so the rule falls back to the underlay.
C.The SD-WAN rule is placed below a static route that directs traffic to the underlay.
D.The SD-WAN rule is missing a matching service or application, so it does not match the traffic.
AnswerB

If the preferred overlay member is down or fails its performance SLA, the SD-WAN rule may fall back to other available members, such as the underlay. This is a common cause of traffic not using the intended tunnel. Checking the member's status and SLA results is essential.

Why this answer

When an SD-WAN rule uses a manual strategy with a preferred member, the FortiGate will use that member if it is available and healthy. If the member is down or fails its SLA, the rule will fall back to other members, such as the underlay. Thus, the most likely reason for traffic using the underlay is that the overlay member is not available or not meeting the SLA.

Exam trap

The trap here is assuming that manual strategy ignores member health and always uses the preferred member, when in fact it falls back if the member is unhealthy.

88
Multi-Selectmedium

An administrator is configuring an SD-WAN rule that uses the 'volume' load balancing algorithm. The rule includes two members: port1 with a volume ratio of 3, and port2 with a volume ratio of 1. Which two statements correctly describe how the FortiGate will distribute sessions? (Choose two.)

Select 2 answers
A.The FortiGate will send sessions to port1 until its volume limit is reached, then switch to port2.
B.The volume ratio must be configured as a percentage that totals 100%.
C.The FortiGate will send approximately 75% of sessions to port1 and 25% to port2.
D.The volume algorithm will only use port2 if port1 is down or fails its SLA.
E.The volume ratio is used to calculate the proportion of total traffic volume that each member should carry.
AnswersC, E

With volume ratios of 3 and 1, the total ratio is 4. Port1 gets 3/4 (75%) and port2 gets 1/4 (25%) of the traffic volume. The volume algorithm distributes sessions based on these ratios, so approximately 75% of sessions will be sent to port1 and 25% to port2, assuming both members are alive and have available bandwidth.

Why this answer

The volume load balancing algorithm distributes sessions based on configured volume ratios. With ratios of 3 and 1, port1 receives three times the traffic volume of port2, resulting in approximately 75% and 25% distribution. The algorithm continuously uses both members according to these ratios as long as they are alive.

It does not fill one member before using the other, nor does it require percentages that sum to 100.

Exam trap

The trap here is thinking that volume ratios are percentages or that the algorithm fills one link completely before using the next.

89
Multi-Selectmedium

An administrator wants to integrate a FortiExtender into an existing SD-WAN deployment. Which TWO steps are required for proper integration?

Select 2 answers
A.Disable all other WAN interfaces
B.Authorize the FortiExtender on the FortiGate
C.Enable NAT on the FortiExtender interface
D.Configure a separate VDOM for the FortiExtender
E.Configure the FortiExtender as an SD-WAN member
AnswersB, E

Authorising the FortiExtender on the FortiGate establishes the management trust relationship, letting the FortiGate discover, provision and monitor the extender as an SD-WAN member interface. Without this authorisation step, the FortiExtender cannot join the SD-WAN fabric or participate in path selection.

Why this answer

The FortiExtender must first be authorized on the FortiGate to establish a secure management and data plane connection. Once authorized, it must be added as an SD-WAN member interface so that SD-WAN rules and load-balancing algorithms can be applied to traffic traversing the FortiExtender's cellular or LTE link.

Exam trap

The trap here is that candidates assume the FortiExtender requires a separate VDOM or NAT configuration, when in fact it simply needs authorization and SD-WAN membership to function as a standard WAN interface within the existing SD-WAN topology.

90
MCQmedium

An administrator has an SD-WAN deployment with two members, port1 (primary, low latency) and port2 (secondary, high latency). A performance SLA is configured using a ping probe to 8.8.8.8 with a 100 ms latency threshold. The SLA status for port1 is 'alive' and for port2 is 'dead'. The administrator creates an SD-WAN rule with the 'SLA' strategy that includes both members. They expect traffic to use port1 and, if it fails, port2. However, after applying the rule, all traffic is still going out port1 and never uses port2. What is the cause of this behavior?

A.The performance SLA probe target 8.8.8.8 is unreachable from port2, causing the SLA to be 'dead' and thus port2 is excluded from the rule.
B.The SD-WAN rule is missing the 'load-balance' setting; by default, it uses only the first member in the list.
C.The SD-WAN rule must include a manual order of members; the 'SLA' strategy does not automatically fall back to a member with 'dead' SLA status.
D.The SD-WAN rule's 'SLA' strategy only uses members that meet the SLA; since port2 is 'dead', it is excluded, and port1 is used exclusively as long as it meets SLA.
AnswerD

The 'SLA' strategy selects members that meet the configured SLA targets. If a member's SLA status is 'dead', it is not used unless all members are dead, in which case the rule may fall back to the best available member based on other criteria. In this scenario, port1 is alive, so it is used exclusively. Port2 is not used because it does not meet the SLA. This matches the observed behavior. The administrator's expectation of fallback to port2 while port1 is alive is incorrect; fallback occurs only when no member meets SLA.

Why this answer

The 'SLA' strategy in an SD-WAN rule prioritizes members that meet the performance SLA. When at least one member meets the SLA, only those members are used. A member with a 'dead' SLA status is excluded from selection unless all members are dead, in which case the rule falls back to the best available member.

In this scenario, port1 meets the SLA, so it is used exclusively, and port2 is not used. The administrator's expectation of immediate fallback is a misunderstanding of the strategy's behavior.

Exam trap

The trap here is assuming that the 'SLA' strategy will use a member with a 'dead' SLA status as a backup even when another member is alive.

91
MCQeasy

What is the function of a route map in FortiGate routing?

A.To configure load balancing between multiple WAN links.
B.To filter and modify routing information during redistribution.
C.To enable BFD on a specific interface.
D.To create a static route for a specific destination.
AnswerB

Route maps apply match and set clauses to routes as they are redistributed between protocols or routing instances, permitting filtering of unwanted prefixes and modification of attributes such as metric, tag or community during that exchange.

Why this answer

A route map in FortiGate routing is primarily used to filter and modify routing information during route redistribution between different routing protocols (e.g., OSPF, BGP, RIP). It allows granular control over which routes are accepted, advertised, or tagged with attributes like metric or community values, ensuring policy-based routing decisions.

Exam trap

The trap here is that candidates often confuse route maps with policy-based routing (PBR) or SD-WAN rules, but route maps are specifically for redistribution filtering and attribute manipulation, not for direct traffic steering or load balancing.

How to eliminate wrong answers

Option A is wrong because load balancing between multiple WAN links is typically achieved using ECMP (Equal-Cost Multi-Path) routing or SD-WAN rules, not a route map. Option C is wrong because BFD (Bidirectional Forwarding Detection) is enabled on an interface or neighbor using specific BFD configuration commands, not a route map. Option D is wrong because creating a static route for a specific destination is done via the 'config router static' CLI or GUI, and a route map is not used for static route creation.

92
MCQmedium

An administrator has deployed a FortiGate in an SD-WAN hub-and-spoke topology. Spoke sites use IPsec tunnels to the hub, and the hub advertises a default route to the spokes. The administrator wants traffic from any spoke to another spoke to flow through the hub without requiring additional tunnels between spokes. Which SD-WAN feature should be configured on the hub to achieve this?

A.Enable 'set preserve-session-route' on the hub's SD-WAN zone.
B.Enable 'set exchange-interface-ip' on the hub's IPsec tunnels and configure BGP with route reflection.
C.Configure ADVPN on the hub and spokes, and enable 'set auto-discovery' on the IPsec phase1-interface.
D.Create a static route on each spoke pointing to the hub for all remote spoke subnets.
AnswerC

ADVPN (Auto-Discovery VPN) allows spokes to dynamically establish direct shortcuts through the hub when traffic between them is detected. By enabling auto-discovery on the hub and spokes, the hub can facilitate spoke-to-spoke tunnels without manual configuration, meeting the requirement for traffic to flow through the hub initially and then directly.

Why this answer

ADVPN enables dynamic spoke-to-spoke tunnels through a hub, allowing traffic to initially flow via the hub and then directly between spokes. Enabling auto-discovery on the IPsec phase1-interface is the key step to activate this behavior. Other options either preserve sessions, add static routes without dynamic tunneling, or configure routing protocols that do not create the necessary overlay shortcuts.

Exam trap

The trap here is assuming that any routing protocol or static route configuration automatically enables spoke-to-spoke communication, when ADVPN's dynamic tunnel negotiation is specifically required.

93
MCQeasy

An administrator wants to verify which SD-WAN member is currently being used for a specific traffic flow. Which command should they use on the FortiGate?

A.diagnose sys sdwan health-check
B.diagnose sys sdwan session
C.diagnose sys session list
D.diagnose sys sdwan member
AnswerB

This command displays active sessions that are being handled by SD-WAN, including the selected member for each session. It provides a clear view of which SD-WAN member is used for specific traffic flows, helping troubleshoot steering decisions.

Why this answer

The command 'diagnose sys sdwan session' shows active sessions that are being processed by SD-WAN rules, including the chosen member. It is the most direct way to verify which SD-WAN member is used for a specific flow.

Exam trap

The trap here is confusing health-check or member status commands with session-specific member selection; only the session command shows the actual member used for a flow.

94
MCQhard

A FortiGate with two WAN interfaces configured in an SD-WAN setup uses the 'lowest-cost' load balancing algorithm. The performance SLA monitors latency and jitter. If wan1 has a cost of 10 and wan2 has a cost of 20, but wan1 is experiencing 50% packet loss, what will happen to traffic?

A.Traffic is distributed equally between both links
B.Traffic is dropped until wan1 recovers
C.Traffic continues using wan1 because cost is lower
D.Traffic is sent to wan2 because wan1 is considered dead
AnswerD

The performance SLA marks wan1 dead once packet loss breaches its threshold, so SD-WAN withdraws it from the lowest-cost selection and forwards traffic to wan2. Cost values only rank healthy members; a failed SLA overrides the cheaper cost.

Why this answer

When an SD-WAN member interface fails the performance SLA (e.g., 50% packet loss), FortiGate marks it as 'dead' and removes it from the active member set. The 'lowest-cost' algorithm then selects the next lowest-cost member that is alive, which is wan2 (cost 20). Traffic is not load-balanced equally because wan1 is dead, and it is not dropped because wan2 is available.

Exam trap

The trap here is that candidates assume the 'lowest-cost' algorithm always uses the link with the lowest cost regardless of link health, but FortiGate SD-WAN first checks the SLA status and only considers active (alive) members for the cost comparison.

How to eliminate wrong answers

Option A is wrong because the 'lowest-cost' algorithm does not distribute traffic equally; it selects the link with the lowest cost among active members, and since wan1 is dead, all traffic goes to wan2. Option B is wrong because FortiGate does not drop traffic when a link fails; it fails over to the next available link in the SD-WAN zone. Option C is wrong because even though wan1 has a lower cost, it is marked dead due to SLA failure, so it is no longer considered for traffic forwarding.

95
MCQhard

A FortiGate has two WAN interfaces (port1, port2) as SD-WAN members. The performance SLA monitor is configured for both with a latency threshold of 50 ms. The measured latency on port1 is 45 ms and on port2 is 55 ms. An SD-WAN rule uses 'lowest-cost' algorithm. Which interface will be selected for new sessions?

A.port1 because its latency is within threshold and lower than port2
B.port2 because port1's latency is close to threshold
C.The session is dropped
D.Both interfaces are used equally
AnswerA

The lowest-cost algorithm selects the member with the best measured performance among those meeting the SLA. port1's 45 ms latency is within the 50 ms threshold and lower than port2's 55 ms, which breaches it, so port1 satisfies both the threshold and lowest-latency constraints.

Why this answer

The SD-WAN rule uses the 'lowest-cost' algorithm, which selects the interface with the lowest cost among those that meet the performance SLA threshold. Here, port1 has a measured latency of 45 ms, which is below the 50 ms threshold, while port2's latency of 55 ms exceeds the threshold, making port2 ineligible. Therefore, port1 is the only qualifying interface and is selected for new sessions.

Exam trap

The trap here is that candidates assume the 'lowest-cost' algorithm compares raw latency values directly, but it actually first filters out interfaces that fail the SLA threshold, so port2 is excluded despite having a lower cost or being otherwise functional.

How to eliminate wrong answers

Option B is wrong because port2's latency of 55 ms exceeds the 50 ms threshold, so it is considered out of SLA and is not eligible for selection by the lowest-cost algorithm, regardless of port1's proximity to the threshold. Option C is wrong because the session is not dropped; the SD-WAN rule will still select an interface that meets the SLA (port1), and if no interface meets the SLA, the session may use the best-effort path or fall back to a configured action, but not drop outright. Option D is wrong because the lowest-cost algorithm does not load-balance equally; it selects a single interface based on cost, and since only port1 meets the SLA, it is chosen exclusively.

96
MCQhard

A FortiGate is running OSPF with multiple areas. The admin wants to redistribute a static route (192.168.100.0/24) into OSPF area 0. The route is configured as a static route on the FortiGate. Which configuration step is essential to ensure the static route is redistributed into OSPF?

A.Create a prefix list to allow the static route and apply it to the OSPF area
B.Set the administrative distance of the static route to 110
C.Configure a route map to match the static route and set OSPF type
D.Enable 'redistribute static' under the OSPF router configuration
AnswerD

Static routes are not advertised by OSPF unless explicitly redistributed. Enabling 'redistribute static' under the OSPF router configuration injects the 192.168.100.0/24 prefix into area 0 as an external LSA, which is the essential step the scenario demands.

Why this answer

The 'redistribute static' command under OSPF router configuration is the essential step to inject static routes into the OSPF domain. Without this explicit redistribution command, OSPF will not advertise any static routes, regardless of other filtering or metric settings. This is a fundamental requirement for route redistribution in OSPF.

Exam trap

The trap here is that candidates often think a route map or prefix list is mandatory for redistribution, but the essential step is simply enabling 'redistribute static' under OSPF; filters are optional refinements.

How to eliminate wrong answers

Option A is wrong because a prefix list controls which routes are allowed or denied during redistribution, but it is not essential; the redistribution itself must first be enabled. Option B is wrong because setting the administrative distance of the static route to 110 (the default OSPF distance) does not trigger redistribution; it only affects route preference within the routing table. Option C is wrong because a route map is optional for filtering or modifying route attributes during redistribution, but the core requirement is enabling 'redistribute static'.

97
MCQhard

An administrator is configuring an SD-WAN rule to route VoIP traffic (identified by application 'VoIP') over the best available link. The SD-WAN zone 'virtual-wan-link' contains three members: port1 (cost 10), port2 (cost 20), and port3 (cost 30). A performance SLA named 'VoIP-SLA' is applied to the rule, monitoring latency, jitter, and packet loss. The administrator wants the rule to select the member with the lowest latency that meets the SLA. Which SD-WAN algorithm should be used?

A.Maximize Bandwidth (SLA)
B.Source IP
C.Lowest Latency (SLA)
D.Lowest Cost (SLA)
AnswerC

Lowest Latency (SLA) selects the member with the lowest measured latency among those that meet the SLA. This directly matches the administrator's requirement to route VoIP traffic over the link with the lowest latency. The SLA ensures that only links meeting the latency, jitter, and packet loss thresholds are considered, and then the one with the lowest latency is chosen.

Why this answer

The Lowest Latency (SLA) algorithm is designed to select the member with the lowest measured latency among those that meet the SLA. This is ideal for latency-sensitive applications like VoIP. Other algorithms focus on cost, bandwidth, or static assignment, none of which prioritize latency as the selection metric.

Exam trap

The trap here is confusing lowest cost with lowest latency; cost is a static value, while latency is dynamically measured by the SLA.

98
Multi-Selectmedium

A network administrator is configuring SD-WAN rules with load balancing. They want to distribute HTTP traffic evenly across two WAN links based on the number of sessions. Which TWO settings should they use? (Choose two.)

Select 2 answers
A.Ensure the SD-WAN rule matches HTTP traffic (e.g., using protocol or port criteria).
B.Set the load balancing algorithm to 'volume'.
C.Create a performance SLA to monitor the links.
D.Enable 'set update-static-route' on the SD-WAN rule.
E.Set the load balancing algorithm to 'session'.
AnswersA, E

The rule must first identify HTTP flows, so matching protocol or port criteria isolates that traffic. Without this match, session-based balancing would apply to all traffic rather than the HTTP sessions the administrator intends to spread across both links.

Why this answer

Option A is correct because the SD-WAN rule must first identify the traffic to be balanced, so it needs to match HTTP traffic using protocol or port criteria (e.g., TCP port 80/443) before any load-balancing algorithm can be applied to it. Option E is correct because the scenario explicitly requires distributing traffic based on the number of sessions, and the 'session' load-balancing algorithm in FortiGate SD-WAN distributes sessions across the member links to achieve a per-session balance. Option B is incorrect because the 'volume' algorithm balances based on traffic volume (bytes) rather than session count, which does not meet the stated requirement.

Option C is incorrect because a performance SLA monitors link health and quality (latency, jitter, packet loss) and is not the mechanism that distributes HTTP sessions evenly. Option D is incorrect because 'set update-static-route' controls whether the SD-WAN rule updates the static route for the selected interface and does not affect load-balancing behavior.

Exam trap

The trap here is confusing 'session' with 'volume' or assuming that performance SLA monitoring is required for any SD-WAN rule, when in fact load balancing algorithms are independent of SLA-based path selection.

99
MCQhard

A FortiGate has an SD-WAN rule with two members: port1 and port2. The rule uses the 'lowest-cost' algorithm. The administrator configures a performance SLA that monitors latency to a remote server. The SLA is applied to both members. After some time, port1's latency exceeds the SLA threshold and its status becomes 'dead'. What happens to new sessions that match the SD-WAN rule?

A.New sessions will be dropped until port1's SLA status becomes alive again.
B.New sessions will be load balanced across both members, but existing sessions on port1 will be re-evaluated.
C.New sessions will be sent to port2, because port1 is excluded due to SLA failure.
D.New sessions will still be sent to port1 because lowest-cost ignores SLA status.
AnswerC

When a member fails its performance SLA, it is marked as dead and is no longer eligible for selection by the SD-WAN rule. The FortiGate will automatically use the remaining alive member, port2, for new sessions. This ensures that traffic is not sent over a link that does not meet the required performance criteria.

Why this answer

When a performance SLA fails, the member is marked as dead and excluded from SD-WAN rule selection. The FortiGate will use the remaining alive member, port2, for new sessions. This behavior ensures that traffic is only sent over links that meet the configured performance criteria.

The lowest-cost algorithm only considers alive members, so port1 is not used while it is dead.

Exam trap

The trap here is assuming that lowest-cost will still choose a dead member if it has the lowest cost, but SLA status takes precedence.

100
MCQmedium

An administrator wants to ensure that all traffic from a specific LAN subnet (192.168.10.0/24) to the internet uses a particular WAN interface (wan1) in an SD-WAN setup, while other traffic uses wan2. What is the correct configuration to achieve this?

A.Create a policy-based routing rule with source 192.168.10.0/24 and set outgoing interface to wan1
B.Configure an SD-WAN rule with source address matching 192.168.10.0/24 and set the preferred member to wan1
C.Set the default route for wan1 with a higher distance
D.Use a route map with prefix list to match the subnet and set next-hop to wan1
AnswerB

SD-WAN rules allow source-based matching and preferred member selection.

Why this answer

In Fortinet SD-WAN, traffic steering is achieved through SD-WAN rules, not policy routes. An SD-WAN rule with a source address matching 192.168.10.0/24 and a preferred member set to wan1 ensures that all traffic from that subnet is directed to wan1, while other traffic falls through to the default SD-WAN rule or other rules using wan2. This is the correct method because SD-WAN rules are evaluated before the routing table and provide granular control over member selection based on application, source, or destination.

Exam trap

The trap here is that candidates confuse policy-based routing (PBR) with SD-WAN rules, assuming PBR can achieve the same outcome, but Fortinet's SD-WAN requires explicit SD-WAN rules to control member selection within the SD-WAN zone.

How to eliminate wrong answers

Option A is wrong because policy-based routing (PBR) in FortiOS is used for specific traffic steering but does not integrate with SD-WAN member selection or load-balancing algorithms; it bypasses SD-WAN logic entirely. Option C is wrong because setting a higher distance on the default route for wan1 would make it less preferred in the routing table, causing traffic to use wan2 instead of wan1, which is the opposite of the requirement. Option D is wrong because route maps with prefix lists are used in BGP or OSPF route redistribution, not for SD-WAN traffic steering; they influence routing table entries, not SD-WAN member selection.

101
MCQhard

An administrator has configured a FortiGate with two VRF instances: VRF10 and VRF20. They need to allow a server in VRF10 (10.10.10.0/24) to communicate with a server in VRF20 (10.20.20.0/24). The administrator creates a firewall policy with source interface VRF10 and destination interface VRF20, but traffic is not passing. What is the most likely cause?

A.The firewall policy must have 'match-vip' enabled to allow traffic between different VRFs.
B.VRF instances are isolated by default; inter-VRF traffic requires a static route or policy route to leak routes between VRFs.
C.Inter-VRF traffic is only supported when using VXLAN tunnels between the VRFs.
D.VRF instances require the use of 'set vrf' in the firewall policy to specify the source and destination VRFs.
AnswerB

FortiGate VRF instances maintain separate routing tables. By default, there is no route leaking between VRFs. Even with a firewall policy allowing traffic, the FortiGate cannot forward packets from VRF10 to VRF20 without a route in each VRF pointing to the other. A static route or policy route must be configured to leak the destination prefix between the VRFs, enabling inter-VRF communication.

Why this answer

FortiGate VRF instances have separate routing tables. To allow traffic between them, the administrator must configure route leaking, typically by adding a static route in each VRF that points to the other VRF's interface or using policy routes. Without these routes, the FortiGate will drop packets even if a firewall policy permits them, because it cannot determine the next hop for the destination network.

Exam trap

The trap here is assuming that a firewall policy alone can enable inter-VRF traffic, overlooking the need for route leaking between separate routing tables.

102
MCQeasy

Which FortiGate feature allows multiple independent routing tables on a single device, enabling traffic separation for different departments or customers?

A.ECMP
B.VRF
C.VDOM
D.Policy-based routing
AnswerB

VRF (Virtual Routing and Forwarding) creates separate, independent routing tables on one FortiGate, so each department or customer has isolated routing and overlapping IP addresses can coexist. This directly satisfies the stem's requirement for multiple independent routing tables enabling traffic separation on a single device.

Why this answer

VRF (Virtual Routing and Forwarding) allows a single FortiGate to maintain multiple independent routing tables, each with its own set of interfaces, routes, and forwarding decisions. This enables traffic separation for different departments or customers without requiring separate physical devices, as each VRF instance operates as a logically isolated router within the same hardware.

Exam trap

The trap here is that candidates often confuse VRF with VDOM, assuming both provide the same level of isolation, but VRF only virtualizes the routing table while VDOM virtualizes the entire device, making VRF the correct answer when the question specifically asks about 'multiple independent routing tables' rather than full device virtualization.

How to eliminate wrong answers

Option A (ECMP) is wrong because ECMP (Equal-Cost Multi-Path) is a load-balancing technique that distributes traffic across multiple equal-cost paths within a single routing table, not a mechanism for creating independent routing tables. Option C (VDOM) is wrong because while VDOMs (Virtual Domains) also provide traffic separation, they virtualize the entire FortiGate (including firewall policies, administrators, and routing tables) as separate logical devices, whereas VRF is specifically a routing-table-level virtualization that can be used within a single VDOM or global context. Option D (Policy-based routing) is wrong because PBR allows traffic to be forwarded based on policies (e.g., source/destination IP) rather than the destination-based routing table, but it does not create multiple independent routing tables; it overrides the routing table for specific traffic flows.

103
Multi-Selectmedium

A network administrator is configuring SD-WAN on a FortiGate and wants to ensure that VoIP traffic uses the link with the lowest latency while bulk download traffic uses the link with the highest bandwidth. Which TWO configuration steps are required?

Select 2 answers
A.Assign a static route for the VoIP subnet
B.Create an SD-WAN rule for VoIP traffic with 'best quality' strategy
C.Enable BFD on all WAN interfaces
D.Configure a route map for VoIP traffic
E.Create a performance SLA for latency
AnswersB, E

The 'best quality' strategy selects the member with the lowest measured latency, directly satisfying the VoIP requirement. It relies on an associated performance SLA to supply those latency values, so pairing it with a latency SLA makes VoIP follow the fastest link.

Why this answer

Option B is correct because an SD-WAN rule with the 'best quality' strategy selects the member link that best satisfies the configured performance SLA (lowest latency, jitter, and packet loss), which is exactly what VoIP traffic requires. Option E is correct because the 'best quality' strategy depends on a performance SLA that defines the latency threshold and probes (e.g., ping, HTTP, or twamp) used to measure each member's link quality; without a latency SLA, the SD-WAN rule cannot evaluate link quality. Option A is incorrect because a static route for the VoIP subnet does not perform dynamic link selection based on latency and would bypass SD-WAN path selection.

Option C is incorrect because BFD is a failure-detection mechanism for fast link-down detection, not a latency-based path selection method. Option D is incorrect because route maps are used for route filtering and attribute manipulation in routing protocols, not for SD-WAN quality-based steering.

Exam trap

NSE7 often tests the misconception that BFD or static routes alone can steer traffic by quality; candidates must remember that SD-WAN rules require a performance SLA to make quality-based decisions.

104
MCQmedium

A FortiGate has two WAN interfaces configured as SD-WAN members. The administrator wants traffic to specific destination IP addresses to use a particular member. Which SD-WAN configuration object should be used to achieve this?

A.SD-WAN rule
B.Route map
C.Prefix list
D.Performance SLA
AnswerA

An SD-WAN rule defines matching criteria such as destination IP addresses and specifies which member to use, so traffic to particular destinations can be steered to a chosen WAN member. This is the object that achieves the required path selection.

Why this answer

SD-WAN rules are the correct configuration object because they allow you to define policy-based forwarding (PBF) criteria, such as source/destination IP addresses, to steer traffic to a specific SD-WAN member interface. Unlike static routes, SD-WAN rules evaluate traffic against match conditions and then apply an explicit action to use a designated member or strategy, making them the precise tool for this requirement.

Exam trap

The trap here is that candidates confuse Performance SLA with the actual traffic-steering mechanism, thinking that a Performance SLA object alone can direct traffic to a specific member, when in fact it only provides link quality data that must be referenced by an SD-WAN rule to influence path selection.

How to eliminate wrong answers

Option B is wrong because a route map is used for route redistribution and policy-based routing in traditional routing contexts, not for SD-WAN member selection; it cannot directly force traffic to a specific SD-WAN member interface. Option C is wrong because a prefix list is a filter used in route maps or BGP to match IP prefixes, not an object that defines traffic steering to an SD-WAN member. Option D is wrong because a Performance SLA is used to measure link quality (latency, jitter, packet loss) and can be referenced by SD-WAN rules, but it does not itself direct traffic to a specific member; it only provides metrics for dynamic path selection.

105
Drag & Dropmedium

Drag and drop the steps to configure a FortiGate to use an external authentication server (e.g., RADIUS) for admin login into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence ensures that the RADIUS server is defined with full details before it is referenced by a user group, which is then assigned to an admin profile. Testing validates the entire chain, confirming that authentication works as expected.

106
Multi-Selectmedium

Which THREE statements are true about FortiGate SD-WAN health-check configuration?

Select 3 answers
A.Health-check probes can be sent from any interface, including loopback.
B.Health-check can only be configured on physical interfaces, not VLANs or subinterfaces.
C.Health-check can be configured with multiple thresholds for jitter, latency, and packet loss.
D.Health-check can update the routing table by setting 'update-static-route' to enable fallback.
E.Health-check can be configured to use HTTP or DNS protocols to verify link health.
AnswersC, D, E

SD-WAN health checks support separate SLA thresholds for latency, jitter and packet loss, and each member can be assigned multiple threshold values to define acceptable performance bands. This lets FortiGate mark a link degraded or dead when any measured metric breaches its configured limit.

Why this answer

Option C is correct because FortiGate SD-WAN health checks support SLA targets with separate thresholds for latency, jitter, and packet loss, allowing each performance metric to be evaluated independently. Option D is correct because the 'update-static-route' setting (enabled by default) lets the health check dynamically remove or restore a static route when the link's SLA is violated or recovered, providing automatic fallback. Option E is correct because SD-WAN health checks can use several probe protocols, including ping, TCP echo, HTTP, and DNS, to verify end-to-end link health beyond simple ICMP.

Option A is incorrect because health-check probes must be sourced from the interface being monitored, not from arbitrary interfaces such as a loopback. Option B is incorrect because health checks can be applied to VLANs and subinterfaces, not only physical interfaces.

Exam trap

The trap here is that candidates often assume health-check can use any interface as a source (like loopback) or that it only works on physical interfaces, but FortiGate restricts probe source to the member interface and supports VLANs and aggregates.

107
MCQhard

An administrator configures OSPF on a FortiGate with multiple areas. After configuration, the FortiGate does not become an ABR. What is the most likely reason?

A.The router-id is not configured
B.The OSPF process is not enabled
C.The network type is set to point-to-point
D.There is no interface assigned to area 0
AnswerD

An OSPF router becomes an ABR only when it has interfaces in multiple areas, one of which must be the backbone area 0. Without any interface assigned to area 0, the FortiGate cannot form the required backbone adjacency.

Why this answer

For a FortiGate to function as an OSPF Area Border Router (ABR), it must have at least one interface assigned to the backbone area (area 0) and at least one interface assigned to a non-backbone area. Without an interface in area 0, the FortiGate cannot generate Type 3 summary LSAs or perform inter-area routing, so it remains an internal router. Option D is correct because the absence of an interface in area 0 is the most direct and common reason for a FortiGate not becoming an ABR.

Exam trap

The trap here is that candidates often assume ABR status is tied to router-id configuration or OSPF process enablement, but the critical requirement is the presence of an interface in area 0, which is a fundamental OSPF design rule that is frequently overlooked.

How to eliminate wrong answers

Option A is wrong because the router-id is used for OSPF router identification and DR/BDR election, but it does not determine ABR status; a router can become an ABR without a manually configured router-id (it will use the highest loopback or physical interface IP). Option B is wrong because if the OSPF process were not enabled, the FortiGate would not participate in OSPF at all, not simply fail to become an ABR; the question implies OSPF is configured but ABR status is missing. Option C is wrong because setting the network type to point-to-point affects neighbor adjacency behavior and LSA flooding, but it does not prevent a router from becoming an ABR as long as it has interfaces in both area 0 and another area.

108
MCQeasy

Which load balancing algorithm in SD-WAN sends new sessions to the member interface with the least number of active sessions?

A.Sessions
B.Volume
C.Spillover
D.Source-dest IP
AnswerA

The sessions algorithm selects the SD-WAN member currently holding the fewest active sessions, distributing new sessions to the least-loaded interface. This directly matches the stated requirement of sending new sessions to the member with the lowest active session count.

Why this answer

The Sessions algorithm in Fortinet SD-WAN selects the member interface with the fewest active sessions when a new session is initiated. This is the default load-balancing method and ensures even distribution of session counts across WAN links, preventing any single interface from becoming overloaded with connections.

Exam trap

The trap here is that candidates often confuse 'Sessions' with 'Volume' because both involve load distribution, but Sessions focuses on connection count while Volume focuses on data throughput, and Fortinet explicitly tests this distinction in the SD-WAN configuration context.

How to eliminate wrong answers

Option B (Volume) is wrong because it distributes traffic based on the total bytes transferred through each interface, not the number of active sessions. Option C (Spillover) is wrong because it is not a load-balancing algorithm; it is a failover mechanism that sends traffic to a backup interface only when the primary interface exceeds a configured bandwidth threshold. Option D (Source-dest IP) is wrong because it uses a hash of source and destination IP addresses to consistently map sessions to the same interface, which does not consider the current number of active sessions.

109
MCQeasy

Which SD-WAN load balancing algorithm distributes traffic based on the number of active sessions per interface?

A.Sessions
B.Volume
C.Source-destination IP
D.Spillover
AnswerA

The Sessions algorithm selects the interface carrying the fewest active sessions, spreading load by session count rather than bandwidth, latency or packet volume. This directly matches the stem's constraint of distributing traffic based on the number of active sessions per interface, unlike throughput- or quality-based methods.

Why this answer

The Sessions algorithm in Fortinet SD-WAN distributes new sessions by selecting the interface with the fewest currently active sessions. This ensures balanced session distribution across WAN links, preventing any single interface from becoming overloaded with connections while others remain underutilized.

Exam trap

The trap here is that candidates often confuse 'Sessions' with 'Volume' because both involve traffic distribution, but Volume measures bytes while Sessions measures connection counts, and the exam expects you to distinguish between these two distinct load-balancing metrics.

How to eliminate wrong answers

Option B is wrong because Volume distributes traffic based on the total bytes transferred per interface, not the number of active sessions. Option C is wrong because Source-destination IP uses a hash of source and destination IP addresses to consistently route traffic from the same flow to the same interface, ignoring session counts. Option D is wrong because Spillover forwards traffic to a preferred interface until its bandwidth or session threshold is exceeded, then spills over to a backup interface, rather than balancing based on active session counts.

110
MCQeasy

Which SD-WAN load balancing algorithm distributes new sessions based on the number of active sessions on each link?

A.Source-dest IP
B.Spillover
C.Volume
D.Sessions
AnswerD

The sessions algorithm counts currently active sessions per member and assigns each new session to the link with the fewest, directly satisfying the stem's requirement to balance on active session counts rather than bandwidth, volume or fixed hashing.

Why this answer

The Sessions algorithm distributes new sessions based on the current number of active sessions on each SD-WAN link. When a new session is initiated, the SD-WAN controller selects the link with the fewest active sessions, ensuring a balanced load across all available transport interfaces. This is distinct from algorithms that consider source/destination IP pairs, traffic volume, or bandwidth thresholds.

Exam trap

The trap here is that candidates often confuse 'Sessions' with 'Volume' because both involve load balancing, but Sessions counts active connections while Volume measures data throughput, leading to incorrect selection of Volume when the question explicitly mentions 'number of active sessions'.

How to eliminate wrong answers

Option A is wrong because Source-dest IP uses a hash of the source and destination IP addresses to consistently map sessions to a specific link, not the number of active sessions. Option B is wrong because Spillover is a bandwidth-based algorithm that shifts traffic to another link only when a predefined bandwidth threshold is exceeded, not based on session count. Option C is wrong because Volume distributes traffic based on the total volume of data (bytes) transmitted over each link, not the number of active sessions.

111
MCQhard

A FortiGate with FortiExtender is using LTE as a backup WAN link. When the primary link fails, the LTE link does not take over. What could be the cause?

A.The primary link's performance SLA is still passing.
B.The FortiExtender is not configured in pass-through mode.
C.The FortiExtender firmware is out of date.
D.The LTE interface is not added as an SD-WAN member.
AnswerD

SD-WAN only steers traffic across members of the virtual WAN link. If the LTE interface is not added as an SD-WAN member, the failover rule cannot select it, so the backup link never activates when the primary fails.

Why this answer

For an LTE interface to be used as a backup WAN link in an SD-WAN setup, it must be explicitly added as an SD-WAN member. Without this, the FortiGate will not consider the LTE interface for traffic steering or failover, even if the primary link fails. The SD-WAN rules and performance SLA are only evaluated against interfaces that are members of the SD-WAN zone.

Exam trap

The trap here is that candidates often assume any working backup interface will automatically take over when the primary fails, but FortiGate SD-WAN requires explicit membership in the SD-WAN zone for failover to occur.

How to eliminate wrong answers

Option A is wrong because if the primary link's performance SLA is still passing, the SD-WAN logic would not trigger a failover to the backup link; the LTE link would not take over because the primary is considered healthy. Option B is wrong because pass-through mode is relevant for extending the FortiGate's interfaces via the FortiExtender, but it is not a prerequisite for LTE failover; the LTE interface can be used in normal mode as long as it is properly configured and added to SD-WAN. Option C is wrong while outdated firmware can cause various issues, the most direct and common reason for LTE not taking over is that the interface is not a member of the SD-WAN zone, not a firmware version problem.

112
MCQmedium

An administrator configures SD-WAN with two members (wan1, wan2) and a performance SLA for ICMP to 1.1.1.1. The SD-WAN rule is set to 'Best Quality' with 'latency' metric. The admin notices that traffic sometimes switches to the other link even when the current link has acceptable latency. Which action can reduce unnecessary flapping?

A.Configure a hysteresis value for the SLA
B.Increase the SLA probe interval
C.Use 'manual' strategy instead
D.Increase the 'update-cascade-interface' setting
AnswerA

Hysteresis adds a buffer so the SLA must degrade beyond a threshold before traffic moves, and must improve beyond another before it returns. This dampens metric jitter around the latency boundary, preventing unnecessary link flapping.

Why this answer

Configuring a hysteresis value for the SLA introduces a buffer or deadband around the latency threshold. This prevents the SD-WAN from switching links when latency fluctuates slightly above and below the threshold, which is the root cause of flapping. Without hysteresis, even a minor transient spike in latency can trigger a switch, even if the link's overall performance is acceptable.

Exam trap

The trap here is that candidates often confuse 'hysteresis' with 'increasing the probe interval' (Option B), thinking that less frequent measurements will reduce flapping, but hysteresis is the correct mechanism because it introduces a deadband to prevent switching on minor fluctuations, whereas a longer interval only delays detection and does not prevent the oscillation.

How to eliminate wrong answers

Option B is wrong because increasing the SLA probe interval reduces the frequency of measurements, which can delay the detection of actual link degradation but does not prevent flapping caused by minor latency fluctuations around the threshold. Option C is wrong because using a 'manual' strategy would disable automatic link selection based on SLA metrics entirely, which is an overreaction and does not address the flapping issue while sacrificing the benefits of dynamic path selection. Option D is wrong because 'update-cascade-interface' is a FortiGate setting related to updating routing tables when an interface's status changes, not a mechanism to dampen SLA-triggered path switching.

113
MCQeasy

A FortiGate is configured with OSPF multi-area. The administrator wants to ensure that routes from area 0 are redistributed into area 1. Which OSPF configuration is required?

A.Enable 'redistribute connected' on the ABR
B.Set the 'area type' to 'nssa' on area 1
C.Configure a route redistribution policy under OSPF
D.No additional configuration is needed; ABRs automatically advertise inter-area routes
AnswerD

Area Border Routers automatically generate and advertise inter-area routes, including those from the backbone, into attached non-backbone areas. Because area 0 routes are injected into area 1 by default, no redistribution or extra OSPF configuration is required to satisfy the stem.

Why this answer

OSPF ABRs (Area Border Routers) automatically advertise inter-area routes between areas by default. In a multi-area OSPF setup, the ABR learns Type 3 LSAs from area 0 and floods them into other areas (like area 1) without any additional redistribution configuration. No explicit redistribution policy is needed for inter-area route advertisement.

Exam trap

The trap here is that candidates confuse route redistribution (importing external routes) with the automatic inter-area route advertisement performed by ABRs, leading them to select options involving redistribution policies or area type modifications.

How to eliminate wrong answers

Option A is wrong because 'redistribute connected' is used to inject directly connected routes into OSPF, not to advertise routes between areas; inter-area routes are handled natively by ABRs via Type 3 LSAs. Option B is wrong because setting area 1 as NSSA would actually restrict Type 5 LSAs and require special handling for external routes, but it does not affect the automatic advertisement of inter-area routes from area 0; in fact, NSSA still allows Type 3 LSAs by default. Option C is wrong because a route redistribution policy under OSPF is used for importing routes from other protocols (e.g., BGP, static) or from different OSPF processes, not for inter-area route propagation within the same OSPF domain.

114
MCQhard

A FortiGate is configured with two SD-WAN members: port1 and port2, both with the same cost. An SD-WAN rule is set to use the 'lowest-cost (SLA)' strategy. The administrator observes that all traffic is going out port1, even though port2 is also within SLA. What is the most likely reason?

A.Port2 is configured with a higher link priority value, causing it to be preferred over port1.
B.The 'lowest-cost (SLA)' strategy always selects the first member in the list when costs are equal.
C.Port2 is administratively down or has no active route, so it is excluded from the SD-WAN rule.
D.The SD-WAN rule is configured with 'set gateway enable', which forces traffic through the first member.
AnswerC

If port2 is administratively down or lacks a valid route, it cannot be used for traffic, even if it is within SLA. The FortiGate would then use only port1. This is a common reason for traffic to be sent exclusively over one member despite equal costs and SLA status.

Why this answer

In lowest-cost (SLA), traffic is distributed among members with the lowest cost that meet SLA. If port2 is down or has no route, it is removed from consideration, leaving port1 as the only viable member. Equal costs alone do not guarantee load sharing; operational status and routing must be valid.

Exam trap

The trap here is assuming that equal cost and SLA compliance automatically result in load balancing, ignoring the operational state of the interface or its routing.

115
MCQmedium

An administrator has configured an SD-WAN rule with the 'lowest-cost' strategy. The rule includes two members: port1 and port2. The administrator notices that all traffic is being sent over port1, even though port2 has a lower latency. Which factor is most likely causing this behavior?

A.The SD-WAN rule is configured with 'maximize-bandwidth' instead of 'lowest-cost'.
B.The cost of port1 is configured lower than the cost of port2.
C.Port2 is administratively down.
D.The performance SLA is not configured for port2.
AnswerB

In the 'lowest-cost' strategy, the FortiGate selects the member with the lowest cost. If port1 has a lower cost than port2, it will be chosen regardless of latency. The cost is a manual setting that can override performance metrics. This is the most likely reason for all traffic going over port1.

Why this answer

The 'lowest-cost' strategy selects the member with the lowest configured cost. Even if another member has better performance metrics like latency, the cost takes precedence. Therefore, if port1 has a lower cost than port2, it will be selected for all traffic.

Administrators must ensure costs are set appropriately to reflect the desired priority.

Exam trap

The trap here is assuming that the lowest-cost strategy considers latency, when it actually uses a manually configured cost value.

116
MCQmedium

A FortiGate is configured with two WAN interfaces in an SD-WAN zone. The administrator wants to ensure that Voice over IP (VoIP) traffic uses the link with the lowest latency, while all other traffic uses the link with the highest available bandwidth. The performance SLA 'VoIP_SLA' monitors latency to a VoIP provider. Which SD-WAN configuration should the administrator implement to meet these requirements?

A.Create an SD-WAN rule with the 'lowest-latency' algorithm, referencing the VoIP_SLA, and apply it to VoIP traffic; create a second rule with the 'lowest-cost' algorithm for all other traffic.
B.Create an SD-WAN rule with the 'lowest-cost' algorithm, referencing the VoIP_SLA, and apply it to VoIP traffic; create a second rule with the 'maximize-bandwidth' algorithm for all other traffic.
C.Create an SD-WAN rule with the 'lowest-latency' algorithm, referencing the VoIP_SLA, and apply it to VoIP traffic; create a second rule with the 'maximize-bandwidth' algorithm for all other traffic.
D.Create an SD-WAN rule with the 'lowest-jitter' algorithm, referencing the VoIP_SLA, and apply it to VoIP traffic; create a second rule with the 'maximize-bandwidth' algorithm for all other traffic.
AnswerC

The 'lowest-latency' algorithm selects the member with the lowest latency based on the performance SLA measurements. This directly meets the VoIP requirement. The second rule with 'maximize-bandwidth' selects the link with the highest bandwidth for other traffic, which also matches the requirement.

Why this answer

The correct configuration uses an SD-WAN rule with the 'lowest-latency' algorithm for VoIP traffic, which selects the WAN member with the lowest latency as measured by the performance SLA. For all other traffic, a rule with the 'maximize-bandwidth' algorithm selects the member with the highest available bandwidth. This combination satisfies both requirements.

Exam trap

The trap here is confusing latency with jitter or cost, and assuming that 'lowest-cost' is equivalent to 'lowest-latency'.

117
MCQhard

A FortiGate has two equal-cost paths to a destination network. ECMP is enabled. The administrator notices that all traffic uses the first path. What is the most likely cause?

A.ECMP is configured with 'spillover' mode
B.The second path is administratively down
C.ECMP is configured to use 'source-dest-ip' hash and all sessions are from same source to same destination
D.The route metric is not equal
AnswerC

With the source-dest-ip hash, FortiGate selects a path from the source and destination IP pair. Identical pairs always hash to the same interface, so every session between the same endpoints traverses one path, leaving the second equal-cost link idle.

Why this answer

When ECMP is configured with the 'source-dest-ip' hash algorithm, traffic is load-balanced based on a hash of both source and destination IP addresses. If all sessions originate from the same source IP and go to the same destination IP, the hash value is identical for every session, causing all traffic to be forwarded over the same path. This is the most likely cause because the administrator sees all traffic using the first path despite ECMP being enabled.

Exam trap

The trap here is that candidates assume ECMP always distributes traffic evenly across all paths, but they overlook that the hash algorithm's behavior depends on the diversity of source-destination pairs; when all sessions share the same IP pair, the hash produces the same result, causing all traffic to follow one path.

How to eliminate wrong answers

Option A is wrong because 'spillover' mode is an SD-WAN feature that shifts traffic to another path only when a bandwidth threshold is exceeded, but it does not cause all traffic to use a single path by default; it would still distribute traffic until the threshold is reached. Option B is wrong because if the second path were administratively down, the route would not be present in the routing table as an equal-cost path, and ECMP would not consider it; the question states two equal-cost paths exist. Option D is wrong because the question explicitly states the paths have equal cost, so the route metric is equal; unequal metrics would prevent ECMP from load-balancing, but that contradicts the given condition.

118
MCQmedium

A FortiGate with SD-WAN enabled uses two members: MPLS (10 ms latency) and Internet (40 ms latency). The SD-WAN rule uses 'Best Quality' strategy with latency as the metric. Traffic to a critical application (10.1.1.0/24) is currently using the MPLS link. The MPLS link's latency increases to 60 ms due to a routing issue. How will FortiGate handle new sessions to 10.1.1.0/24?

A.New sessions will use the Internet link; existing sessions continue on MPLS.
B.FortiGate will wait for the MPLS link to recover before sending new traffic.
C.All sessions immediately switch to the Internet link.
D.Existing sessions continue on MPLS; new sessions will use MPLS until the next SLA probe.
AnswerA

Best Quality evaluates link metrics per new session, so once MPLS latency exceeds the Internet member's 40 ms, new sessions to 10.1.1.0/24 select the Internet link. FortiGate does not rebalance established sessions, so existing MPLS flows persist until they end.

Why this answer

The 'Best Quality' strategy with latency metric selects the link with the lowest latency for new sessions. When MPLS latency rises to 60 ms, it exceeds the Internet link's 40 ms, so new sessions will be steered to the Internet. However, SD-WAN does not preemptively rehash existing sessions; they remain on the original link (MPLS) until they expire or are torn down.

Exam trap

The trap here is that candidates assume SD-WAN automatically re-routes all traffic (including existing sessions) when link quality degrades, but in reality, only new sessions are affected unless a session-based failover mechanism like session TTL or manual intervention is configured.

How to eliminate wrong answers

Option B is wrong because FortiGate does not wait for link recovery; it actively selects the best link based on current SLA metrics. Option C is wrong because SD-WAN does not force an immediate failover of all sessions; only new sessions are affected by the updated latency measurement. Option D is wrong because new sessions are evaluated immediately based on the latest SLA probe results, not deferred until the next probe cycle.

119
MCQmedium

An administrator has configured an SD-WAN zone named 'virtual-wan' containing two members: port1 and port2. They want to apply different SD-WAN rules based on the destination IP address. Which FortiGate configuration object should they use to define the destination IP address for matching traffic in an SD-WAN rule?

A.Policy route with destination address and outgoing interface
B.Address object referenced in the SD-WAN rule's destination field
C.Internet Service Database (ISDB) entry selected in the SD-WAN rule
D.Application control signature referenced in the SD-WAN rule
AnswerB

In FortiOS SD-WAN rules, the destination is specified by referencing a firewall address object. This allows granular matching based on IP subnet, FQDN, or geography. The address object is created under Firewall Objects > Addresses and then selected in the SD-WAN rule configuration. This is the correct method to match traffic by destination IP.

Why this answer

SD-WAN rules on FortiGate use firewall address objects to define destination criteria. These objects can represent IP subnets, FQDNs, or geographic locations. When configuring an SD-WAN rule, the destination field expects an address object, which is then used to match traffic.

This allows flexible and granular control over which traffic is routed through which SD-WAN member.

Exam trap

The trap here is confusing SD-WAN rule destination matching with policy routes or ISDB entries, which serve different purposes.

120
MCQmedium

An administrator is troubleshooting BGP with SD-WAN. They have configured BGP on the FortiGate and the SD-WAN rule uses 'best quality' strategy. However, failover does not happen when a WAN link goes down. The BGP session is still up. What is the most likely reason?

A.The performance SLA is not configured to track the BGP next hop.
B.The SD-WAN rule is configured with 'set update-static-route disable'.
C.The BGP session is using eBGP multihop.
D.The load balancing algorithm is set to 'volume'.
AnswerA

For SD-WAN to detect link failure, the performance SLA must monitor the actual path to the BGP next hop or internet. BGP session may remain up via an alternate path, but the link may be degraded.

Why this answer

The 'best quality' SD-WAN strategy selects the best path based on performance SLA metrics. Without a performance SLA monitoring the BGP next hop, the FortiGate cannot detect that the link has failed from a BGP perspective, so it will not trigger a failover even if the physical interface goes down. The BGP session remains up because it is still receiving keepalives, but the SD-WAN rule does not consider the link unusable without SLA tracking.

Exam trap

The trap here is that candidates assume BGP session state alone determines link usability, but FortiGate SD-WAN requires explicit performance SLA monitoring of the BGP next hop to trigger failover in a 'best quality' strategy.

How to eliminate wrong answers

Option B is wrong because 'set update-static-route disable' only prevents the FortiGate from installing BGP routes into the static route table; it does not affect SD-WAN failover behavior. Option C is wrong because eBGP multihop allows BGP sessions across multiple hops but does not prevent failover when a link goes down; the issue is SLA tracking, not BGP hop count. Option D is wrong because the load balancing algorithm set to 'volume' affects how traffic is distributed among multiple paths, not whether failover occurs when a link fails.

121
MCQeasy

A FortiGate is configured with SD-WAN using load balancing algorithm 'source-dest-ip'. What is the primary characteristic of this algorithm?

A.Traffic is sent to the member with the highest bandwidth.
B.Traffic is sent to the member with the lowest cost metric.
C.Traffic is distributed evenly across all SD-WAN members regardless of source or destination.
D.All traffic from the same source IP to the same destination IP uses the same SD-WAN member.
AnswerD

Source-dest-ip hashes the source and destination IP pair, so every session sharing that pair maps to one SD-WAN member. This delivers consistent path selection and session stickiness, unlike per-packet or round-robin algorithms that would spread those sessions across members.

Why this answer

The 'source-dest-ip' load balancing algorithm in SD-WAN uses a hash of both the source IP and destination IP to deterministically select an SD-WAN member. This ensures that all packets belonging to the same flow (same source-destination pair) are consistently forwarded over the same member, preserving per-flow stickiness and avoiding out-of-order delivery.

Exam trap

The trap here is that candidates often confuse 'source-dest-ip' with 'round-robin' or 'bandwidth-based' algorithms, assuming it distributes traffic evenly, when in fact it prioritizes per-flow stickiness over load distribution.

How to eliminate wrong answers

Option A is wrong because the 'source-dest-ip' algorithm does not consider bandwidth; bandwidth-based load balancing is a separate feature (e.g., 'spillover' or 'max-bandwidth' settings). Option B is wrong because cost metric is used in route selection (e.g., via SD-WAN rules or static routes), not in the load balancing algorithm itself; 'source-dest-ip' hashes IPs, not cost. Option C is wrong because it describes round-robin or session-based load balancing, not 'source-dest-ip'; the latter is not evenly distributed across members but rather per-flow consistent.

122
MCQmedium

An administrator needs to apply different routing policies for traffic based on source IP address, overriding the normal routing table. Which feature should be configured?

A.Prefix list
B.SD-WAN rule
C.Route map
D.Policy-based routing
AnswerD

Policy-based routing matches packets against administrator-defined criteria such as source IP address and forwards them via a specified next hop, bypassing the standard destination-based routing table. This directly satisfies the requirement to override normal routing decisions based on source address.

Why this answer

Policy-based routing (PBR) is the correct feature because it allows an administrator to override the normal routing table lookup based on criteria such as source IP address. Unlike static or dynamic routing, PBR uses route maps to match traffic (e.g., source IP) and apply a specific next-hop or interface, enabling granular traffic steering independent of the destination-based routing table.

Exam trap

The trap here is that candidates often confuse route maps (a policy tool) with policy-based routing (the feature that uses route maps to override forwarding), leading them to select 'Route map' instead of 'Policy-based routing' as the feature name.

How to eliminate wrong answers

Option A is wrong because a prefix list is used to match IP prefixes in routing protocols (e.g., BGP) or route redistribution, not to override routing decisions based on source IP. Option B is wrong because SD-WAN rules are designed for application-aware traffic steering and link load balancing in an SD-WAN fabric, not for overriding the routing table based solely on source IP in a traditional routing context. Option C is wrong because a route map is a tool used to manipulate routing information (e.g., set attributes, filter routes) during redistribution or policy application, but it does not itself override the routing table; it must be applied with PBR to achieve source-based forwarding.

123
MCQmedium

A FortiGate is configured with two SD-WAN members: port1 (WAN1) and port2 (WAN2). An SD-WAN rule routes traffic from the internal subnet 10.0.1.0/24 to the internet using the 'volume' load-balancing algorithm. The rule is configured with a volume ratio of 70:30 for port1:port2. After some time, the administrator notices that port1 is handling approximately 90% of the traffic volume, while port2 handles only 10%. What is the most likely cause of this imbalance?

A.The volume algorithm uses the configured volume ratio only when both members are alive and meet the SLA; if port2 is dead, all traffic goes to port1.
B.The volume algorithm distributes traffic based on the configured ratio, but the ratio is applied to the number of sessions, not the volume of data.
C.The volume algorithm uses the configured ratio only as a target, but it also considers the current bandwidth usage; if port1 has higher bandwidth, it may receive more traffic.
D.The volume algorithm may not achieve the exact ratio if there are long-lived sessions that are not re-evaluated; existing sessions remain on their original member, causing an imbalance over time.
AnswerD

The volume algorithm distributes new sessions based on the current volume ratio, but existing sessions are not rebalanced. If many long-lived sessions (e.g., large downloads) are established on port1, they continue to use port1, skewing the overall volume. New sessions may be assigned to port2 to compensate, but if the long-lived sessions dominate, the ratio can deviate significantly from the configured target.

Why this answer

The volume algorithm aims to distribute traffic volume according to the configured ratio, but it does not rebalance existing sessions. Long-lived sessions can cause a persistent imbalance because they remain on their original member. The algorithm only affects new session assignments, so if a few large flows are pinned to one member, the overall volume can deviate from the target ratio.

Exam trap

The trap here is assuming that the volume algorithm dynamically moves existing sessions to maintain the ratio, when it only affects new sessions.

124
MCQhard

A FortiGate is configured with two WAN members in an SD-WAN zone. The performance SLA monitors latency to a probe server. The rule uses 'best quality' strategy. After some time, one member fails the SLA. Which action does the FortiGate take for existing sessions that were using that member?

A.All sessions are dropped and the member is removed from the zone
B.Existing sessions are re-evaluated and may be moved based on policy
C.Existing sessions are immediately moved to another member
D.Existing sessions continue on the failed member until they timeout
AnswerD

SD-WAN's best quality strategy affects only member selection for new sessions. Sessions already pinned to a member that later fails its SLA remain there until they close or time out, since FortiGate does not forcibly rebalance established flows.

Why this answer

When a WAN member fails the performance SLA in an SD-WAN 'best quality' strategy, FortiGate does not disrupt existing sessions that were already using that member. Instead, those sessions continue on the failed member until they naturally timeout or are torn down, because the SD-WAN rule only influences the path selection for new sessions. This behavior is by design to avoid breaking active connections due to transient SLA fluctuations.

Exam trap

The trap here is that candidates often assume SD-WAN 'best quality' strategy dynamically re-routes all traffic, including existing sessions, when an SLA fails, but FortiGate only applies path selection changes to new sessions to maintain session stability.

How to eliminate wrong answers

Option A is wrong because FortiGate does not drop all sessions or remove the member from the zone solely due to SLA failure; the member remains available for new sessions if it is the only path or if other rules permit. Option B is wrong because existing sessions are not re-evaluated or moved based on policy; only new session path selection is affected by SLA status. Option C is wrong because immediate session movement would cause disruption and is not supported; FortiGate relies on session timeout or application-specific mechanisms (like DNS or TCP retransmission) to naturally migrate traffic.

125
MCQmedium

A FortiGate administrator is integrating a FortiSwitch managed by the FortiGate. They want to configure a VLAN interface on the FortiSwitch for user traffic. Which configuration is required on the FortiGate?

A.Enable DHCP relay on the FortiSwitch VLAN
B.Configure a VLAN on the FortiSwitch under the switch controller and assign it to a port
C.Use the config system interface to create a VLAN on the FortiGate and tag it on the trunk
D.Create a VLAN subinterface on the FortiGate's port that connects to the FortiSwitch
AnswerB

FortiLink-managed switches are configured through the FortiGate's switch controller. Creating the VLAN there and assigning it to a physical FortiSwitch port pushes the VLAN definition and membership down to the switch, which is the required step for user traffic separation.

Why this answer

When integrating a FortiSwitch managed by a FortiGate, VLANs for user traffic must be created under the switch controller on the FortiGate. This allows the FortiGate to push the VLAN configuration to the FortiSwitch, including assigning the VLAN to a specific port or port group. Option B correctly describes this process, as the switch controller manages the FortiSwitch as an extension of the FortiGate, not as a standalone device.

Exam trap

The trap here is that candidates confuse creating a VLAN on the FortiGate's own interfaces (using 'config system interface') with configuring a VLAN on a managed FortiSwitch, which requires the switch controller context.

How to eliminate wrong answers

Option A is wrong because DHCP relay is a separate feature that can be enabled on a VLAN interface, but it is not a required configuration for creating a VLAN on a FortiSwitch; the question asks for the required configuration to set up the VLAN itself. Option C is wrong because 'config system interface' is used to create VLAN interfaces on the FortiGate itself, not on a managed FortiSwitch; FortiSwitch VLANs are managed through the switch controller, not system interfaces. Option D is wrong because creating a VLAN subinterface on the FortiGate's physical port is used for router-on-a-stick or inter-VLAN routing on the FortiGate, but it does not configure the VLAN on the FortiSwitch; the FortiSwitch must be explicitly configured via the switch controller to carry that VLAN.

← PreviousPage 2 of 2 · 125 questions total

Ready to test yourself?

Try a timed practice session using only Advanced Networking and SD-WAN questions.