Best Quality Fortinet NSE7_SDW-6.4 Exam Questions TopExamCollection Realistic Practice Exams [2023]
Critical Information To Fortinet NSE 7 - SD-WAN 6.4 Pass the First Time
NEW QUESTION # 21
Why is it effective to use SD WAN rules when configuring application control?
- A. Because SD-WAIM rules are independent from firewall policies to avoid controlling applications
- B. Because you must use certificate full inspection on the firewall policy
- C. Because traffic can be load balanced based on application type
- D. Because the application database is manually maintained by administrators
Answer: C
Explanation:
You can configure rules to steer traffic based on the application detected by Fortigate. This is know as application steering or application-aware routing
NEW QUESTION # 22
Refer to the exhibit.
Based on output shown in the exhibit, which two commands can be used by SD-WAN rules? (Choose two.)
- A. set source 100.64.1.1.
- B. set load-balance-mode source-ip-based.
- C. set cost 15.
- D. set priority 10.
Answer: B,D
NEW QUESTION # 23
Which statement about using BGP routes in SD-WAN is true?
- A. You must use external BGP.
- B. Learned routes can be used as dynamic destinations in SD-WAN rules.
- C. You must use BGP to route traffic for both overlay and underlay links.
- D. You must configure AS path prepending.
Answer: B
NEW QUESTION # 24
Which two benefits from using forward error correction (FEC) in IPsec VPNs are true? (Choose two.)
- A. FEC transmits the original payload in full to recover the error in transmission.
- B. FEC reduces the stress on the remote device buffer to reconstruct packet loss.
- C. FEC improves reliability, which overcomes adverse WAN conditions such as noisy links.
- D. FEC transmits additional packets as redundant data to the remote device.
Answer: C,D
NEW QUESTION # 25
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?
- A. diagnose sys virtual-wan-link intf-sla-log
- B. diagnose sys virtual-wan-link log
- C. diagnose sys virtual-wan-link sla-lcg
- D. diagnose sys virtual-wan-link health-check
Answer: D
NEW QUESTION # 26
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?
- A. diagnose sys virtual-wan-link intf-sla-log
- B. diagnose sys virtual-wan-link sla-log
- C. diagnose sys virtual-wan-link log
- D. diagnose sys virtual-wan-link health-check
Answer: B
Explanation:
Reference:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-SLA-Logging/ta-p/190934
NEW QUESTION # 27
Refer to the exhibit.
Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)
- A. Set source 100.64.1.1.
- B. Set load-balance-mode source-ip-ip-based.
- C. Set priority 10.
- D. Set cost 15.
Answer: A
NEW QUESTION # 28
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A shows the traffic shaping policy and exhibit B show: the firewall policy FortiGate is not performing traffic shaping as expected basi on the policies shown in the exhibits.
To correct this traffic shaping issue on FortiGate, what configuration change must be made on which policy?
- A. The URL category must be specified on the traffic shaping policy
- B. The application control profile must be enabled on the firewall policy.
- C. The shaper mode must be applied per-IP shaper on the traffic shaping policy
- D. The web filter profile must be enabled on the firewall policy
Answer: D
Explanation:
SD-WAN_6.4_Study_Guide page 131
NEW QUESTION # 29
Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?
- A. A single user uses the allocated bandwidth divided by total number of users.
- B. Each IP is guaranteed a minimum 10 Mbps of bandwidth
- C. FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.
- D. The 10 Mbps bandwidth is shared equally among the IP addresses.
Answer: C
NEW QUESTION # 30
Which statement reflects how BGP tags work with SD-WAN rules?
- A. BGP tags match the SD-WAN rule based on the order that these rules were installed.
- B. Route tags are used for a BGP community and the SD-WAN rules are assigned the same tag
- C. VPN topologies are formed using only BGP dynamic routing with SD-WAN
- D. BGP tags require that the adding of static routes be enabled on all ADVPN interfaces
Answer: A
NEW QUESTION # 31
What is the lnkmtd process responsible for?
- A. Monitoring links for any bandwidth saturation
- B. Flushing route tags addresses
- C. Logging interface quality information
- D. Processing performance SLA probes
Answer: D
NEW QUESTION # 32
Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?
- A. Each IP is guaranteed a minimum 10 Mbps of bandwidth.
- B. A single user uses the allocated bandwidth divided by total number of users.
- C. FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.
- D. The 10 Mbps bandwidth is shared equally among the IP addresses.
Answer: C
Explanation:
Explanation/Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/885253/per-ip-traffic-shaper
NEW QUESTION # 33
Which two statements describe how IPsec phase 1 aggressive mode is different from main mode when performing IKE negotiation? (Choose two)
- A. XAuth is enabled as an additional level of authentication, which requires a username and password.
- B. A peer ID is included in the first packet from the initiator, along with suggested security policies.
- C. The use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.
- D. A total of six packets are exchanged between an initiator and a responder instead of three packets.
Answer: A,D
NEW QUESTION # 34
In which two ways does FortiGate learn the FortiManager IP address or FQDN for zero-touch provisioning? (Choose two.)
- A. From a DHCP server configured with options 240 or 241
- B. From another FortiGate device in the same local network
- C. From a FortiGuard definitions update
- D. From the central management configuration configured in FortiDeploy
Answer: A,D
Explanation:
https://www.historiantech.com/zeroish-touch-provisioning-with-fortimanager-explained/
NEW QUESTION # 35
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A shows the traffic shaping policy and exhibit B show: the firewall policy FortiGate is not performing traffic shaping as expected basi on the policies shown in the exhibits.
To correct this traffic shaping issue on FortiGate, what configuration change must be made on which policy?
- A. The URL category must be specified on the traffic shaping policy
- B. The application control profile must be enabled on the firewall policy.
- C. The shaper mode must be applied per-IP shaper on the traffic shaping policy
- D. The web filter profile must be enabled on the firewall policy
Answer: D
NEW QUESTION # 36
Which diagnostic command can you use to show the SD-WAN rules interface information and state?
- A. diagnose sys sdwan service.
- B. diagnose sys sdwan member.
- C. diagnose sys sdwan neighbor.
- D. diagnose sys sdwan route-tag-list.
Answer: A
Explanation:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Diagnostic-commands-to-check-the-status-of-the-SD/ta-p/194246
NEW QUESTION # 37
Which feature enables SD-WAN to combine IPsec VPN dynamic shortcut tunnels between spokes and a static tunnel to the hub?
- A. SSLVPN
- B. OCVPN
- C. ADVPN
- D. GRE
Answer: C
NEW QUESTION # 38
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the default implicit SD-WAN rule? (Choose two )
- A. Matched traffic failed RPF and was caught by the rule.
- B. Traffic has matched none of the FortiGate policy routes
- C. The FIB lookup resolved interface was the SD-WAN member interface
- D. An absolute SD-WAN rule was defined and matched traffic
Answer: B,D
NEW QUESTION # 39
Refer to the exhibit.
What must you configure to enable ADVPN?
- A. ADVPN should only be enabled on unmanaged FortiGate devices.
- B. On the hub VPN, only the device needs additional phase one settings.
- C. The protected subnets should be set to address object to all (0.0.0.0/0).
- D. Each VPN device has a unique pre-shared key configured separately on phase one.
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION # 40
Refer to exhibits.

Exhibit A shows the performance SLA exhibit B shows the SD-WAN diagnostics output.
Based on the exhibits, which statement is correct?
- A. Both SD-WAN member interfaces have used separate SLA targets.
- B. The SLA state of port1 is dead after five unanswered requests by the SLA servers.
- C. SD-WAN member interfaces are affected by the SLA state of the inactive interface
- D. Port1 became dead 1ecause no traffic was offload through the egress of port1.
Answer: B
NEW QUESTION # 41
......
NSE7_SDW-6.4 EXAM DUMPS WITH GUARANTEED SUCCESS: https://examcompass.topexamcollection.com/NSE7_SDW-6.4-vce-collection.html

