Exit demo NSE6_SDW_AD-7.6 Fortinet NSE 6 - SD-WAN 7.6 Enterprise Administrator PDF format · free preview

Fortinet NSE6_SDW_AD-7.6 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/nse6-sdw-ad-76.html

Question 1
Multiple choice

As an IT manager, you want to delegate the installation and management of your SD-WAN deployment to a managed security service provider (MSSP).

Each site must maintain direct internet access and be secure.

You expect significant traffic flow between the sites and want to delegate as much of the network administration and management as possible to the MSSP.

Which two MSSP deployment blueprints address your requirements? Choose two answers.

A.

Use a shared hub on the MSSP premises and a dedicated hub on the customer premises, and install the spokes on the customer premises.

B.

Install a dedicated hub on the MSSP premises for the customer, and install the spokes on the customer premises.

C.

Install the hub and spokes on the customer premises, and enable the MSSP to manage the SD-WAN deployment using FortiManager with a dedicated ADOM.

D.

Use a shared hub on the MSSP premises with a dedicated VDOM for the customer, and install the spokes on the customer premises.

Question 2
Single choice

Refer to the exhibit.

The event log on a FortiGate device is shown.

Based on the output shown in the exhibit, what can you conclude about the tunnels on this device? (Choose one answer))

A.

There is one shortcut tunnel built from the master tunnel VPN4.

B.

The voice traffic is steered through the VPN tunnel HUB1-VPN3.

C.

The VPN tunnel HUB1-VPN1_0 is a shortcut tunnel.

D.

The master tunnel HUB2-VPN3 cannot accept Auto-Discovery VPN (ADVPN) shortcuts.

Question 3
Single choice

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

Based on the exhibit, which change in the measured latency will first make HUB1-VPN3 the new preferred member?

A.

When HUB1-VPN3 has a lower latency than HUB1-VPN1 and HUB1-VPN2

B.

When HUB1-VPN3 has a latency of 80 ms

C.

When HUB1-VPN3 has a latency of 90 ms

D.

When HUB1-VPN1 has a latency of 200 ms

Question 4
Multiple choice

You have configured the performance SLA with the probe mode as Prefer Passive.

What are two observable impacts of this configuration? (Choose two.)

A.

FortiGate passively monitors the member if TCP traffic is passing through the member.

B.

After FortiGate switches to active mode, the SLA performance rule falls back to passive monitoring after 3 minutes.

C.

FortiGate passively monitors the member if ICMP traffic is passing through the member.

D.

During passive monitoring, the SLA performance rule cannot detect dead members.

E.

FortiGate can offload the traffic that is subject to passive monitoring to hardware.

Question 5
Single choice

Which statement describes FortiGate behavior when you reference a zone in a static route?

A.

FoftiGate installs ECMP static routes for the first two members of the zone.

B.

FortiGate ignores the static routes defined through members referenced in the zone.

C.

FortiGate routes the traffic through the best performing member of the zone.

D.

FortiGate installs a static route for each member in the zone.

Question 6
Single choice

Refer to the exhibit. The administrator configured two SD-WAN rules to load balance the traffic.

Which interfaces does FortiGate use to steer the traffic from 10.0.1.124 to 10.0.0.254? Choose one answer.

A.

HUB2-VPN2

B.

HUB1-VPN2 or HUB2-VPN2

C.

port1 or port2

D.

Any interface in the HUB1 or HUB2 zones

Question 7
Single choice

You want to configure two static routes: one that references an SD-WAN zone and a second one that references an SD-WAN member that belongs to that zone.

Which statement about this scenario is true? Choose one answer.

A.

You cannot create static routes for individual SD-WAN members.

B.

You cannot create static routes that reference an SD-WAN zone.

C.

The destination subnets must be different.

D.

The source subnets must be different.

Question 8
Single choice

Refer to the exhibits.

You use FortiManager to manage the branch devices and configure the SD-WAN template.

You have configured direct internet access (DIA) for the IT department users. Now. you must configure secure internet access (SIA) for all local LAN users and have set the firewall policies as shown in the second exhibit.

Then, when you use the install wizard to install the configuration and the policy package on the branch devices, FortiManager reports an error as shown in the third exhibit.

Which statement describes why FortiManager could not install the configuration on the branches?

A.

You must direct SIA traffic to a VPN tunnel.

B.

You cannot install firewall policies that reference an SD-WAN zone.

C.

You cannot install firewall policies that reference an SD-WAN member.

D.

You cannot install SIA and DIA rules on the same device.

Question 9
Single choice

Refer to the exhibit.

You want to configure SD-WAN on a network as shown in the exhibit.
The network contains many FortiGate devices.

Some are used as NGFW, and some are installed with extensions such as FortiSwitch. FortiAP. or Forti Ex tender.

What should you consider when planning your deployment?

A.

You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with Forti Extender.

B.

You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.

C.

You must use FortiManager to manage your SD-WAN topology.

D.

You must build multiple SD-WAN topologies. Each topology must contain only one type of extension.

Question 10
Multiple choice

Refer to the exhibits.

The exhibits show the configuration for SD-WAN performance. SD-WAN rule, the application IDs of Facebook and YouTube along with the firewall policy configuration and the underlay zone status.

Which two statements are true about the health and performance of SD-WAN members 3 and 4? (Choose two.)

A.

Only related TCP traffic is used for performance measurement.

B.

The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.

C.

Encrypted traffic is not used for the performance measurement.

D.

FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.

Showing 10 of 111 questions · Unlock the full set