New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Fortinet NSE7_SDW-6.4 Dumps Questions Answers

Fortinet NSE 7 - SD-WAN 6.4.5 Questions and Answers

Question 1

Which two reasons make forward error correction (FEC) ideal to enable in a phase one VPN interface? (Choose two )

Options:

A.

FEC transmits the original payload in full to recover the error in transmission.

B.

FEC improves reliability which overcomes adverse WAN conditions such as noisy links.

C.

FEC is useful to increase speed at which traffic is routed through IPsec tunnels.

D.

FEC transmits additional packets as redundant data to the remote device.

E.

FEC reduces the stress on the remote device jitter buffer to reconstruct packet loss

Buy Now
Question 2

Refer to Exhibit:

Based on the exhibit, which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules, among the member interfaces?

Options:

A.

All traffic from a source IP to a destination IP Is sent to the same interface.

B.

All traffic from a source IP Is sent to the most used Interface.

C.

All traffic from a source IP to a destination IP is sent to the least used interface.

D.

All traffic from a source IP is sent to the same interfaces.

Question 3

FortiGate is connected to the internet and is obtaining the IP address on its egress interlace from the DHCP server

Which statement is due when FortiGate restarts and receives preconfigured settings to install as part of a zero-touch provisioning process?

Options:

A.

FortiDeploy connects with FortiGate and provides the initial configuration to contact FortiManager

B.

The zero-touch provisioning process completes internally, behind FortiGate

C.

FortiManager registers FortiGate after the restart and retrieves the existing configuration

D.

The FortiGate cloud key added to the FortiGate cloud portal and FortiGate performs a factory reset before the restart

Question 4

Refer to the exhibit.

Multiple IPsec VPNs are formed between two hub-and-spokes groups, and site-to-site between Hub 1 and Hub 2 The administrator configured ADVPN on the dual regions topology

Which two statements are correct if a dynamic site-to-site tunne1 between Toronto and London has been established? (Choose two)

Options:

A.

auto-discovery-receiver is enabled on the egress VPN interfaces on the spokes

B.

auto-discovery-sender is enabled on the ingress VPN interfaces on hubs

C.

tunnel-search IS set to phase 2 quick mode selectors

D.

add-route is enabled to install static routes on hub devices

E.

auto-discovery-forwarder IS enabled on all VPN interfaces

Question 5

Refer to exhibits

Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate

Based on the FortiGate configuration shown in the exhibits, what are two issues you might encounter when creating an SD-WAN interface on port1 and port2? {Choose two )

Options:

A.

Member interfaces that are administratively down

B.

Member interface that have IP address of 0.0.0.0/0.0.0.0

C.

Member interfaces that are physical interfaces as well as VLAN aggregate, and iPsec interfaces

D.

Member interfaces that are referenced by any other configuration element

Question 6

When attempting to establish an IPsec tunnel to FortiGate, all remote users match the FIRST_VPN IPsec VPN. This includes remote users that want to connect to the SECOND_VPN IPsec VPN.

Which two configuration changes must you make on both IPsec VPNs so that remote users can connect to their intended IPsec VPN? (Choose two.)

Options:

A.

Configure different proposals.

B.

Configure a unique peer ID.

C.

Change the IKE mode to aggressive.

D.

Configure different Diffie Hellman groups.

Question 7

Refer to the exhibit.

Which statement about the command route-tag in the SD-WAN rule is true?

Options:

A.

It enables the SD-WAN rule to load balance and assign traffic with a route tag

B.

It tags each route and references the tag in the routing table.

C.

It uses route tags for a BGP community and assigns the SD-WAN rules with same tag.

D.

It ensures route tags match the SD-WAN rule based on the rule order

Question 8

Which diagnostic command can you use to show the SD-WAN rules interface information and state?

Options:

A.

diagnose sys virtual-wan-link neighbor.

B.

diagnose sys virtual—wan—link route-tag-list

C.

diagnose sys virtual—wan—link member.

D.

diagnose sys virtual-wan-link service

Question 9

Refer to the exhibit.

FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.

Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)

Options:

A.

Specify a unique peer ID for each dial-up VPN interface.

B.

Use different proposals are used between the interfaces.

C.

Configure the IKE mode to be aggressive mode.

D.

Use unique Diffie Hellman groups on each VPN interface.

Question 10

Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?

Options:

A.

FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.

B.

Each IP is guaranteed a minimum 10 Mbps of bandwidth

C.

A single user uses the allocated bandwidth divided by total number of users.

D.

The 10 Mbps bandwidth is shared equally among the IP addresses.

Question 11

Refer to the exhibit.

Which two statements about the debug output are true? (Choose two)

Options:

A.

The debug output shows per-IP shaper values and real-time readings.

B.

FortiGate provides statistics and reading based on historical traffic logs.

C.

Traffic being controlled by the traffic shaper is under 100 KB/s.

D.

This traffic shaper drops traffic that exceeds the set limits.

Question 12

Which two benefits from using forward error correction (FEC) in IPsec VPNs are true? (Choose two.)

Options:

A.

FEC transmits the original payload in full to recover the error in transmission.

B.

FEC reduces the stress on the remote device buffer to reconstruct packet loss.

C.

FEC transmits additional packets as redundant data to the remote device.

D.

FEC improves reliability, which overcomes adverse WAN conditions such as noisy links.