[May-2024] NSE7_SDW-7.2 Exam Dumps, NSE7_SDW-7.2 Practice Test Questions [Q32-Q55]

Share

[May-2024] NSE7_SDW-7.2 Exam Dumps, NSE7_SDW-7.2 Practice Test Questions

Attested NSE7_SDW-7.2 Dumps PDF Resource [2024]

NEW QUESTION # 32
Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)

  • A. By default, FortiGate does not check if the selected member has a valid route to the destination.
  • B. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for local-out traffic.
  • C. By default, local-out traffic does not use SD-WAN.
  • D. You must configure each local-out feature individually, to use SD-WAN.

Answer: C,D


NEW QUESTION # 33
Refer to the exhibit.

An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to
the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over
T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)

  • A. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
  • B. T_INET_0_0 does not have a valid route to the destination.
  • C. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
  • D. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.

Answer: B,C


NEW QUESTION # 34
Refer to the exhibit.

Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)

  • A. Gateway IP
  • B. Priority
  • C. Cost
  • D. Interface member

Answer: A,D


NEW QUESTION # 35
Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections
to match all possible IPsec dial-up interfaces? (Choose two.)

  • A. Use different proposals are used between the interfaces.
  • B. Configure the IKE mode to be aggressive mode.
  • C. Use unique Diffie Hellman groups on each VPN interface.
  • D. Specify a unique peer ID for each dial-up VPN interface.

Answer: B,D


NEW QUESTION # 36
Refer to the exhibits.
Exhibit A

Exhibit B -

Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the
routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?

  • A. The traffic will be routed over T_INET_1_0.
  • B. The traffic will be routed over T_MPLS_0.
  • C. The traffic will be routed over T_INET_0_0.
  • D. The traffic will be load balanced across all three overlays.

Answer: A


NEW QUESTION # 37
Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.

What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?

  • A. You must enable auto-discovery-sender.
  • B. You must set ike-version to 1.
  • C. You must enable net-device.
  • D. You must disable idle-timeout.

Answer: C


NEW QUESTION # 38
Refer to the exhibit.

Based on the exhibit, which action does FortiGate take?

  • A. FortiGate brings down port5 after it detects all SD-WAN members as dead.
  • B. FortiGate bounces port5 after it detects all SD-WAN members as dead.
  • C. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
  • D. FortiGate brings up port5 after it detects all SD-WAN members as alive.

Answer: C


NEW QUESTION # 39
Refer to the exhibits.


Exhibit A shows the SD-WAN rule status and the learned BGP routes with community 65000:10.
Exhibit B shows the SD-WAN rule configuration, the BGP neighbor configuration, and the route map configuration.
The administrator wants to steer corporate traffic using routes tags in the SD-WAN rule ID 1.
However, the administrator observes that the corporate traffic does not match the SD-WAN rule ID 1.
Based on the exhibits, which configuration change is required to fix issue?

  • A. In the dcl-lab-rm route map configuration, set set-route-tag to 10.
  • B. In the BGP neighbor configuration, apply the route map dcl-lab-rm in the outbound direction.
  • C. In the dcl-lab-rm route map configuration, unset match-community.
  • D. In SD-WAN rule ID 1, change the destination to use ISDB entries.

Answer: B


NEW QUESTION # 40
Refer to the exhibit.

An administrator used the SD-WAN overlay template to prepare an IPsec configuration for a hub-and-spoke SD-WAN topology. The exhibit shows the installation preview for one FortiGate device. In the exhibit, which statement best describes the configuration applied to the FortiGate device?

  • A. It is a hub device and will automatically discover the spoke devices that are in the SD-WAN topology.
  • B. It is a hub device. It can send ADVPN shortcut offers.
  • C. It is a spoke device that establishes dynamic IPsec tunnels to the hub. The subnet range is
    10.10.128.0/23.
  • D. It is a spoke device that establishes dynamic IPsec tunnels to the hub. It can send ADVPN shortcut requests.

Answer: D

Explanation:
According to the SD-WAN 7.2 Study Guide, the SD-WAN overlay template simplifies the configuration of IPsec tunnels in a hub-and-spoke topology. The template defines the following parameters:
type: dynamic for spokes, static for hubs
interface: the WAN interface to use for the IPsec tunnel
network-overlay: enable for spokes, disable for hubs
network-id: a unique identifier for each spoke
auto-discovery-sender: enable for hubs, disable for spokes
auto-discovery-receiver: enable for spokes, disable for hubs
Based on the exhibit, the FortiGate device has the following configuration:
type: dynamic
interface: port1
network-overlay: enable
network-id: 5
auto-discovery-sender: disable
auto-discovery-receiver: enable
Therefore, the FortiGate device is a spoke that establishes dynamic IPsec tunnels to the hub. It also has the network-overlay and auto-discovery-receiver options enabled, which means it can send ADVPN shortcut requests to other spokes when it receives a shortcut offer from the hub


NEW QUESTION # 41
What three characteristics apply to provisioning templates available on FortiManager? (Choose three.)

  • A. Templates are applied in order, from top to bottom.
  • B. A template group can contain CLI templates of both types.
  • C. You can apply a system template and a CLI template to the same FortiGate device.
  • D. A CLI template can be of type CLI script or Perl script.
  • E. A template group can include a system template and an SD-WAN template.

Answer: A,B,D

Explanation:
According to the FortiManager Administration Guide, provisioning templates are used to configure FortiGate devices in a consistent and efficient way. There are different types of templates, such as system, IPsec, SD-WAN, certificate, and CLI templates. Some characteristics of provisioning templates are:
You can apply a system template and a CLI template to the same FortiGate device, as long as they do not have conflicting settings1.
A CLI template can be of type CLI script or Perl script. A CLI script template contains FortiOS CLI commands, while a Perl script template contains Perl code that can generate FortiOS CLI commands2.
A template group can include a system template and an SD-WAN template, as well as other types of templates. A template group is a collection of templates that can be applied to multiple devices at once3.
A template group can contain CLI templates of both types, as long as they do not have conflicting settings2.
Templates are applied in order, from top to bottom. The order of the templates in a template group determines the order in which they are applied to the devices3.


NEW QUESTION # 42
Which SD-WAN setting enables FortiGate to delay the recovery of ADVPN shortcuts?

  • A. hold-down-time
  • B. idle-timeout
  • C. auto-discovery-shortcuts
  • D. link-down-failover

Answer: A


NEW QUESTION # 43
Refer to the exhibit.

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)

  • A. auto-discovery-forwarder must be enabled on all IPsec VPNs.
  • B. On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.
  • C. On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.
  • D. On the hubs, net-device must be enabled on all IPsec VPNs.

Answer: B,C


NEW QUESTION # 44
Refer to the exhibit.

In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling the anti-replay setting on the hubs?

  • A. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve performance.
  • B. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.
  • C. It instructs the hub to skip content inspection on TCP traffic, to improve performance.
  • D. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions originated from spokes to fail over back and forth between the hubs.

Answer: D


NEW QUESTION # 45
Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?

  • A. Per-IP shaping mode
  • B. Reverse-policy shaping mode
  • C. Interface-based shaping mode
  • D. Shared-policy shaping mode

Answer: C

Explanation:
Interface-based shaping goes further, enabling traffic controls based on percentage of the interface bandwidth.


NEW QUESTION # 46
Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

  • A. When T_N1PLS_0 has a latency of 80 ms.
  • B. When T_INET_0_0 has a latency of 250 ms.
  • C. When T_MPLS_0 has a latency of 100 ms.
  • D. When T_INET_0_0 and T_MPLS_0 have the same latency.

Answer: A


NEW QUESTION # 47
In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)

  • A. It provides the benefits of a full-mesh topology in a hub-and-spoke network.
  • B. It enables spokes to establish shortcuts to third-party gateways.
  • C. It enables spokes to bypass the hub during shortcut negotiation.
  • D. It provides direct connectivity between spokes by creating shortcuts.

Answer: A,D


NEW QUESTION # 48
What is a benefit of using application steering in SD-WAN?

  • A. The traffic always skips the regular policy routes.
  • B. You steer traffic based on the detected application.
  • C. You do not need to enable SSL inspection.
  • D. You do not need to configure firewall policies that accept the SD-WAN traffic.

Answer: B


NEW QUESTION # 49
Which two statements about the SD-WAN zone configuration are true? (Choose two.)

  • A. You can delete the default zones.
  • B. Theservice-sla-tie-breaksetting enables you to configure preferred member selection based on the best
    route to the destination.
  • C. An SD-WAN member can belong to two or more zones.
  • D. The default zones are virtual-wan-link and SASE.

Answer: B,D


NEW QUESTION # 50
Which diagnostic command can you use to show the member utilization statistics measured by performance SLAs for the last 10 minutes?

  • A. diagnose sys sdwan intf-sla-log
  • B. diagnose ays sdwan health-check
  • C. diagnose sys sdwan sla-log
  • D. diagnose sys sdwan log

Answer: C


NEW QUESTION # 51
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B
shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the
reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferred member in the matching
SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so
dc1_fgt routes the reply traffic over T_INET_1_0?

  • A. Disable allow-subnet-overlap under config system settings.
  • B. Enable auxiliary-session under config system settings.
  • C. Disable tp-session-without-syn under config system settings.
  • D. Enable snat-route-change under config system global.

Answer: C


NEW QUESTION # 52
Refer to the exhibit.

In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling theanti-replaysetting on
the hubs?

  • A. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve
    performance.
  • B. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.
  • C. It instructs the hub to skip content inspection on TCP traffic, to improve performance.
  • D. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions
    originated from spokes to fail over back and forth between the hubs.

Answer: D


NEW QUESTION # 53
Refer to the exhibits.


Exhibit A shows the SD-WAN rule status and the learned BGP routes with community 65000:10.
Exhibit B shows the SD-WAN rule configuration, the BGP neighbor configuration, and the route map
configuration.
The administrator wants to steer corporate traffic using routes tags in the SD-WAN rule ID 1.
However, the administrator observes that the corporate traffic does not match the SD-WAN rule ID 1.
Based on the exhibits, which configuration change is required to fix issue?

  • A. In the dcl-lab-rm route map configuration, set set-route-tag to 10.
  • B. In the BGP neighbor configuration, apply the route map dcl-lab-rm in the outbound direction.
  • C. In the dcl-lab-rm route map configuration, unset match-community.
  • D. In SD-WAN rule ID 1, change the destination to use ISDB entries.

Answer: B


NEW QUESTION # 54
Refer to the exhibits.

Exhibit A shows the packet duplication rule configuration, the SD-WAN zone status output, and the sniffer
output on FortiGate acting as the sender. Exhibit B shows the sniffer output on a FortiGate acting as the
receiver.
The administrator configured packet duplication on both FortiGate devices. The sniffer output on the sender
FortiGate shows that FortiGate forwards an ICMP echo request packet over three overlays, but it only receives
one reply packet through T_INET_1_0.
Based on the output shown in the exhibits, which two reasons can cause the observed behavior? (Choose two.)

  • A. On the sender FortiGate,duplication-max-numis set to3.
  • B. The ICMP echo request packets sent over T_INET_0_0 and T_MPLS_0 were dropped along the way.
  • C. The ICMP echo request packets received over T_INET_0_0 and T_MPLS_0 were offloaded to NPU.
  • D. On the receiver FortiGate,packet-de-duplicationis enabled.

Answer: A,D


NEW QUESTION # 55
......

Latest NSE7_SDW-7.2 Actual Free Exam Questions Updated 83 Questions: https://exampasspdf.testkingit.com/Fortinet/latest-NSE7_SDW-7.2-exam-dumps.html