Practice Free NSE7_SDW-7.0 Exam Online Questions
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?
- A . Port2 becomes alive after three successful probes are detected.
- B . FortiGate removes all static routes for port2.
- C . The administrator manually restores the static routes for port2, if port2 becomes alive.
- D . Host 8.8.8.8 is reachable through port1 and port2.
What are two reasons for using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two)
- A . It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
- B . It improves SD-WAN performance on the managed FortiGate devices.
- C . It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
- D . It acts as a policy compliance entity to review all managed FortiGate devices.
- E . It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
Refer to the exhibit.
Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?
- A . type must be set to static.
- B . mode-cfg must be enabled.
- C . exchange-interface-ip must be enabled.
- D . add-route must be disabled.
Refer to the exhibit.
Based on the exhibit, which statement about FortiGate re-evaluating traffic is true?
- A . The type of traffic defined and allowed on firewall policy ID 1 is UDP.
- B . FortiGate has terminated the session after a change on policy ID 1.
- C . Changes have been made on firewall policy ID 1 on FortiGate.
- D . Firewall policy ID 1 has source NAT disabled.
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)
- A . The sdwan_service_id flag in the session information is 0.
- B . All SD-WAN rules have the default setting enabled.
- C . Traffic does not match any of the entries in the policy route table.
- D . Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
Refer to the exhibit.
Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?
- A . All traffic from a source IP to a destination IP is sent to the same interface.
- B . All traffic from a source IP is sent to the same interface.
- C . All traffic from a source IP is sent to the most used interface.
- D . All traffic from a source IP to a destination IP is sent to the least used interface.
Which are two benefits of using CLI templates in FortiManager? (Choose two.)
- A . You can reference meta fields.
- B . You can configure interfaces as SD-WAN members without having to remove references first.
- C . You can configure FortiManager to sync local configuration changes made on the managed device, to the CLI template.
- D . You can configure advanced CLI settings.
Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.
What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?
- A . You must set ike-version to 1.
- B . You must enable net-device.
- C . You must enable auto-discovery-sender.
- D . You must disable idle-timeout.
Refer to the exhibit.
Exhibit B
Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.
Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?
- A . port1 is assigned a manual IP address.
- B . port1 is referenced in a firewall policy.
- C . port2 is referenced in a static route.
- D . port1 and port2 are not administratively down.
Exhibit.
Which conclusion about the packet debug flow output is correct?
- A . The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
- B . The packet size exceeded the outgoing interface MTU.
- C . The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
- D . The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.