NSE7_SDW-7.2 Premium Exam Engine - Download Free PDF Questions
Instant Download NSE7_SDW-7.2 Free Updated Test Dumps
NEW QUESTION # 10
Refer to the exhibit.
An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)
- A. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
- B. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
- C. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
- D. T_INET_0_0 does not have a valid route to the destination.
Answer: A,D
NEW QUESTION # 11
What are two reasons why FortiGate would be unable to complete the zero-touch provisioning process?
(Choose two.)
- A. A factory reset performed on FortiGate.
- B. The zero-touch provisioning process has completed internally, behind FortiGate.
- C. FortiDeploy has connected with FortiGate and provided the initial configuration to contact FortiManager
- D. The FortiGate cloud key has not been added to the FortiGate cloud portal.
- E. FortiGate has obtained a configuration from the platform template in FortiGate cloud.
Answer: B,D
NEW QUESTION # 12
Refer to the exhibit.
The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate
appliance that supports hardware offloading. Based on the information shown in the exhibits, which two
statements about the session are true? (Choose two.)
- A. The reply direction of the asymmetric traffic flows from port2 to port3.
- B. The original direction of the symmetric traffic flows from port3 to port2.
- C. The auxiliary session can be offloaded to hardware.
- D. The main session cannot be offloaded to hardware.
Answer: A,C
NEW QUESTION # 13
Refer to the exhibit.
Which conclusion about the packet debug flow output is correct?
- A. The original traffic exceeded the maximum bandwidth of the outgoing interface, and the packet was
dropped. - B. The original traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet
was dropped. - C. The reply traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was
dropped. - D. The original traffic exceeded the maximum packets per second of the outgoing interface, and the packet
was dropped.
Answer: B
NEW QUESTION # 14
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows an SD-WAN event log and exhibit B shows the member status and the SD-WAN rule
configuration.
Based on the exhibits, which two statements are correct? (Choose two.)
- A. Port2 has a lower latency than port1.
- B. Port2 has the highest member priority.
- C. FortiGate updated the outgoing interface list on the rule so it prefers port2.
- D. SD-WAN rule ID 1 is set to lowest cost (SLA) mode.
Answer: A,C
NEW QUESTION # 15
Refer to the exhibits.
Exhibit A
Exhibit B -
Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the
routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?
- A. The traffic will be routed over T_INET_1_0.
- B. The traffic will be load balanced across all three overlays.
- C. The traffic will be routed over T_MPLS_0.
- D. The traffic will be routed over T_INET_0_0.
Answer: A
NEW QUESTION # 16
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)
- A. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
- B. All SD-WAN rules have the default setting enabled.
- C. The sdwan_service_id flag in the session information is 0.
- D. Traffic does not match any of the entries in the policy route table.
Answer: C,D
Explanation:
Explanation
sdwan_service_id is 0 = match SD-WAN implicit rule, study guide 7.0 page 120, 7.2 page 149 SD-WAN rules
internally are interpreted as a Policy route, so when the traffic doesn't match with any policy route, it will be
flowing by implict policy.
NEW QUESTION # 17
Which two interfaces are considered overlay links? (Choose two.)
- A. LAG
- B. IPsec
- C. Physical
- D. GRE
Answer: B,D
NEW QUESTION # 18
Which statement about SD-WAN zones is true?
- A. You can configure up to 32 SD-WAN zones per VDOM.
- B. An SD-WAN zone can contain between 0 and 512 members.
- C. An SD-WAN zone can contain only one type of interface.
- D. You cannot use an SD-WAN zone in static route definitions.
Answer: A
NEW QUESTION # 19 
Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2. The
administrator configured ADVPN on both hub-and-spoke groups.
Which two outcomes are expected if a user in Toronto sends traffic to London? (Choose two.)
- A. Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.
- B. London generates an IKE information message that contains the Toronto public IP address.
- C. The first packets from Toronto to London are routed through Hub 1 then to Hub 2.
- D. Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN.
Answer: C,D
NEW QUESTION # 20
Refer to the exhibits.
Exhibit A shows two IPsec templates to define Branch_IPsec_1 and Branch_IPsec_2. Each template defines a VPN tunnel.
Exhibit B shows the error message that FortiManager displayed when the administrator tried to assign the second template to the FortiGate device.
Which statement best explain the cause for this issue?
- A. You can assign only one template with a tunnel of fype static to each FortiGate device
- B. You can assign only one IPsec template to each FortiGate device.
- C. You can define only one IPsec tunnel from branch devices to HUB1.
- D. You should review the branch1_fgt configuration for the already configured tunnel with the name HUB1-VPN2.
Answer: D
Explanation:
The error message indicates that there is a conflict between the IPsec templates Branch_IPsec_1 and Branch_IPsec_2 for the device branch1_fgt. This means that the device already has an IPsec tunnel with the name HUB1-VPN2 configured, and the second template is trying to assign the same name to another tunnel.
This is not allowed, as each IPsec tunnel must have a unique name. Therefore, the administrator should review the branch1_fgt configuration and either delete or rename the existing tunnel with the name HUB1-VPN2 before assigning the second template. References = IPsec tunnel templates, IPsec VPN template
6.4.3, Understand and Use Debug Commands to Troubleshoot IPsec, L2L VPN TroubleShooting :"IPSec policy invalidated proposal with error ...
NEW QUESTION # 21
Which are three key routing principles in SD-WAN? (Choose three.)
- A. SD-WAN rules have precedence over ISDB routes.
- B. FortiGate performs route lookups for new sessions only.
- C. By default, SD-WAN members are skipped if they do not have a valid route to the destination.
- D. By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.
- E. Regular policy routes have precedence over SD-WAN rules.
Answer: C,D,E
Explanation:
Study Guide 7.2, pages 125, 129, 151
NEW QUESTION # 22
Which two protocols in the IPsec suite are most used for authentication and encryption? (Choosetwo.)
- A. Internet Key Exchange (IKE)
- B. Secure Shell (SSH)
- C. Security Association (SA)
- D. Encapsulating Security Payload (ESP)
Answer: A,D
NEW QUESTION # 23
What are two advantages of using an IPsec recommended template to configure an IPsec tunnel in a
hub-and-spoke topology? (Choose two.)
- A. IPsec recommended template ensures consistent settings between phase1 and phase2
- B. FortiManager automatically installs IPsec tunnels to every spoke when they are added to the
FortiManager ADOM. - C. VPN monitor tool provides additional statistics for tunnels defined with an IPsec recommended
template. - D. IPsec recommended template guides the administrator to use Fortinet recommended settings.
Answer: B,D
Explanation:
Explanation
According to the SD-WAN 7.2 Study Guide, IPsec recommended templates are designed to simplify the
configuration of IPsec tunnels in a hub-and-spoke topology. They have the following advantages:
FortiManager automatically installs IPsec tunnels to every spoke when they are added to the
FortiManager ADOM. This reduces the manual effort and ensures that all spokes have the same
configuration.
IPsec recommended template guides the administrator to use Fortinet recommended settings, such as
encryption algorithms, key lifetimes, and dead peer detection. This ensures optimal performance and
security of the IPsec tunnels.
NEW QUESTION # 24
Refer to the exhibits.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator
collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on
FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit
SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)
- A. FortiGate did not refresh the routing information on the session after the application was detected.
- B. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
- C. Port1 and port2 do not have a valid route to the destination.
- D. Full SSL inspection is not enabled on the matching firewall policy.
Answer: A,B
Explanation:
Explanation
Study guide 7.2 Page 191
NEW QUESTION # 25
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the default implicit SD-WAN rule? (Choose two )
- A. The FIB lookup resolved interface was the SD-WAN interface.
- B. Matched traffic failed RPF and was caught by the rule.
- C. An absolute SD-WAN rule was defined and matched traffic.
- D. Traffic has matched none of the FortiGate policy routes.
Answer: A,D
NEW QUESTION # 26
Refer to the exhibit.
Based on the exhibit, which action does FortiGate take?
- A. FortiGate brings down port5 after it detects all SD-WAN members as dead.
- B. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
- C. FortiGate brings up port5 after it detects all SD-WAN members as alive.
- D. FortiGate bounces port5 after it detects all SD-WAN members as dead.
Answer: B
NEW QUESTION # 27
What is a benefit of using application steering in SD-WAN?
- A. You steer traffic based on the detected application.
- B. You do not need to enable SSL inspection.
- C. The traffic always skips the regular policy routes.
- D. You do not need to configure firewall policies that accept the SD-WAN traffic.
Answer: A
NEW QUESTION # 28
Which two statements about SD-WAN central management are true? (Choose two.)
- A. It supports normalized interfaces for SD-WAN member configuration.
- B. It does not support meta fields.
- C. The objects are saved in the ADOM common object database.
- D. It uses templates to configure SD-WAN on managed devices.
Answer: C,D
Explanation:
Explanation
Normalized interfaces are not supported for SD-WAN templates. You can create multiple SD-WAN zones and
add interface members to the SD-WAN zones. You must bind the interface members by name to physical
interfaces or VPN
interfaces.https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-
NEW QUESTION # 29
Exhibit.
The exhibit shows the output of the command diagnose sys sdwan health-check status collected on a FortiGate device. Which two statements are correct about the health check status on this FortiGate device? (Choose two.)
- A. The interface T_INET_1 missed one SLA target.
- B. There is no SLA criteria configured for the health-check Level3_DNS.
- C. The health-check VPN_PING orders the members according to the lowest jitter.
- D. The interface T_INET_0 missed three SLA targets.
Answer: B,C
Explanation:
According to the FortiGate / FortiOS 6.4.2 Administration Guide, the health check status command displays the status of the health check probes for each SD-WAN member interface. The output includes the following information:
state: the current state of the interface, either alive or dead
packet-loss: the percentage of packets lost during the health check
latency: the average round-trip time in milliseconds
jitter: the variation in latency
mos: the mean opinion score, a measure of voice quality
bandwidth: the available bandwidth in kilobits per second for each direction (up, down, bi) sla map: a bitmap that indicates which SLA criteria are met or failed Based on the exhibit, the following statements are correct:
The health-check VPN_PING orders the members according to the lowest jitter. This means that the interface with the lowest jitter value is listed first, followed by the next lowest, and so on1. In the exhibit, the order is T_MPLS, T_INET_1, and T_INET_0.
There is no SLA criteria configured for the health-check Level3_DNS. This means that the health check does not use any SLA parameters to determine the state of the interface2. In the exhibit, the sla map value is 0x0 for both port1 and port2, indicating that no SLA criteria are applied.
NEW QUESTION # 30
......
Free NSE7_SDW-7.2 Exam Braindumps Fortinet Pratice Exam: https://pass4sure.actual4dump.com/Fortinet/NSE7_SDW-7.2-actualtests-dumps.html