Latest NSE7_SDW-7.0 Exam Dumps Fortinet Exam from Training Expert Prep4King
Pass Fortinet Fortinet NSE 7 - SD-WAN 7.0 PDF Dumps | Recently Updated 70 Questions
Fortinet NSE7_SDW-7.0 exam is suitable for IT professionals with experience in networking, security, and cloud computing. Candidates must have a deep understanding of networking technologies, such as TCP/IP, LAN, and WAN, and be familiar with network security concepts, such as firewalls, VPNs, and intrusion prevention systems. They must also have experience with cloud computing technologies, such as virtualization, containers, and cloud-based services.
NEW QUESTION # 14
Which statement is correct about SD-WAN and ADVPN?
- A. SD-WAN does not monitor the health and performance of ADVPN shortcuts.
- B. You must use IKEv2 on IPsec tunnels.
- C. SD-WAN can steer traffic to ADVPN shortcuts, established over IPsec overlays, configured as SD-WAN members.
- D. Routes for ADVPN shortcuts must be manually configured.
Answer: C
NEW QUESTION # 15
Which statement about using BGP for ADVPN is true?
- A. You must configure BGP communities.
- B. You must configure AS path prepending.
- C. IBGP is preferred over EBGP, because IBGP preserves next hop information.
- D. You must use BGP to route traffic for both overlay and underlay links.
Answer: C
NEW QUESTION # 16
Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)
- A. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for local-out traffic.
- B. By default, local-out traffic does not use SD-WAN.
- C. You must configure each local-out feature individually, to use SD-WAN.
- D. By default, FortiGate does not check if the selected member has a valid route to the destination.
Answer: B,C
NEW QUESTION # 17
Refer to the exhibits.
Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2. The administrator configured ADVPN on both hub-and-spoke groups.
Which two outcomes are expected if a user in Toronto sends traffic to London? (Choose two.)
- A. Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.
- B. Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN.
- C. The first packets from Toronto to London are routed through Hub 1 then to Hub 2.
- D. London generates an IKE information message that contains the Toronto public IP address.
Answer: B,C
NEW QUESTION # 18
Refer to the exhibits.

Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)
- A. FortiGate does not install IPsec static routes for remote protected networks in the routing table.
- B. Dead peer detection is disabled.
- C. FortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.
- D. The phase 1 configuration supports the network-overlay setting.
Answer: A,D
NEW QUESTION # 19
Refer to the exhibit.
Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)
- A. Gateway IP
- B. Priority
- C. Cost
- D. Interface member
Answer: A,D
NEW QUESTION # 20
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?
- A. Port2 becomes alive after three successful probes are detected.
- B. Host 8.8.8.8 is reachable through port1 and port2.
- C. The administrator manually restores the static routes for port2, if port2 becomes alive.
- D. FortiGate removes all static routes for port2.
Answer: D
Explanation:
This is due to Update static route is enable which removes the static route entry referencing the interface if the interface is dead
NEW QUESTION # 21
Refer to the exhibits.
Exhibit A
Exhibit B -
Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?
- A. The traffic will be load balanced across all three overlays.
- B. The traffic will be routed over T_INET_1_0.
- C. The traffic will be routed over T_MPLS_0.
- D. The traffic will be routed over T_INET_0_0.
Answer: C
NEW QUESTION # 22 
Exhibit B -
Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.
Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?
- A. port1 and port2 are not administratively down.
- B. port1 is assigned a manual IP address.
- C. port2 is referenced in a static route.
- D. port1 is referenced in a firewall policy.
Answer: D
NEW QUESTION # 23
Refer to the exhibit.
Based on the exhibit, which action does FortiGate take?
- A. FortiGate brings down port5 after it detects all SD-WAN members as dead.
- B. FortiGate brings up port5 after it detects all SD-WAN members as alive.
- C. FortiGate bounces port5 after it detects all SD-WAN members as dead.
- D. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
Answer: D
NEW QUESTION # 24
Which two statements about SLA targets and SD-WAN rules are true? (Choose two.)
- A. Member metrics are measured only if an SLA target is configured.
- B. SD-WAN rules use SLA targets to check if the preferred members meet the SLA requirements.
- C. SLA targets are used only by SD-WAN rules that are configured with Lowest Cost (SLA) or Maximize Bandwidth (SLA) as strategy.
- D. When configuring an SD-WAN rule, you can select multiple SLA targets of the same performance SLA.
Answer: B,C
NEW QUESTION # 25
Which two interfaces are considered overlay links? (Choose two.)
- A. LAG
- B. Physical
- C. GRE
- D. IPsec
Answer: C,D
NEW QUESTION # 26
Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.
What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?
- A. You must set ike-version to 1.
- B. You must enable auto-discovery-sender.
- C. You must enable net-device.
- D. You must disable idle-timeout.
Answer: C
NEW QUESTION # 27
Which two protocols in the IPsec suite are most used for authentication and encryption? (Choose two.)
- A. Encapsulating Security Payload (ESP)
- B. Secure Shell (SSH)
- C. Security Association (SA)
- D. Internet Key Exchange (IKE)
Answer: A,D
NEW QUESTION # 28
Refer to the exhibit.
In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling the anti-replay setting on the hubs?
- A. It instructs the hub to skip content inspection on TCP traffic, to improve performance.
- B. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.
- C. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve performance.
- D. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions originated from spokes to fail over back and forth between the hubs.
Answer: D
NEW QUESTION # 29
Refer to the exhibit.
Which statement about the role of the ADVPN device in handling traffic is true?
- A. Two spokes, 192.2.0.1 and 10.0.2.101, forward their queries to their hubs.
- B. This is a spoke that has received a query from a remote hub and has forwarded the response to its hub.
- C. Two hubs, 10.0.1.101 and 10.0.2.101, are receiving and forwarding queries between each other.
- D. This is a hub that has received a query from a spoke and has forwarded it to another spoke.
Answer: D
NEW QUESTION # 30
Refer to the exhibit.
Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change?
(Choose two.)
- A. FortiGate flushes all sessions.
- B. FortiGate terminates the old sessions.
- C. FortiGate does not change existing sessions.
- D. FortiGate evaluates new sessions.
Answer: C,D
Explanation:
Explanation
FortiGate not to flag existing impacted session as dirty by setting firewall-session-dirty to check new. The results is that FortiGate evaluates only new session against the new firewall policy.
NEW QUESTION # 31
Refer to the exhibit.
An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)
- A. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
- B. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
- C. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
- D. T_INET_0_0 does not have a valid route to the destination.
Answer: C,D
Explanation:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Assigning-Priority-to-SD-WAN-Members-for-Default/ta-p/230911
NEW QUESTION # 32
Which are three key routing principles in SD-WAN? (Choose three.)
- A. FortiGate performs route lookups for new sessions only.
- B. By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.
- C. Regular policy routes have precedence over SD-WAN rules.
- D. SD-WAN rules have precedence over ISDB routes.
- E. By default, SD-WAN members are skipped if they do not have a valid route to the destination.
Answer: B,C,E
NEW QUESTION # 33
Refer to the exhibit.
Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?
- A. All traffic from a source IP to a destination IP is sent to the same interface.
- B. All traffic from a source IP is sent to the same interface.
- C. All traffic from a source IP is sent to the most used interface.
- D. All traffic from a source IP to a destination IP is sent to the least used interface.
Answer: A
NEW QUESTION # 34
Refer to the exhibit.
Which are two expected behaviors of the traffic that matches the traffic shaper? (Choose two.)
- A. The number of simultaneous connections allowed for each source IP address cannot exceed five connections.
- B. The traffic shaper limits the combined bandwidth of all connections to a maximum of 5 MB/sec.
- C. The traffic shaper limits the bandwidth of each source IP address to a maximum of 625 KB/sec.
- D. The number of simultaneous connections among all source IP addresses cannot exceed five connections.
Answer: A,C
NEW QUESTION # 35
Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?
- A. Reverse-policy shaping mode
- B. Shared-policy shaping mode
- C. Per-IP shaping mode
- D. Interface-based shaping mode
Answer: D
Explanation:
Interface-based shaping goes further, enabling traffic controls based on percentage of the interface bandwidth.
NEW QUESTION # 36
Which two statements about the SD-WAN zone configuration are true? (Choose two.)
- A. An SD-WAN member can belong to two or more zones.
- B. The default zones are virtual-wan-link and SASE.
- C. The service-sla-tie-break setting enables you to configure preferred member selection based on the best route to the destination.
- D. You can delete the default zones.
Answer: B,C
NEW QUESTION # 37
......
Updated Test Engine to Practice NSE7_SDW-7.0 Dumps & Practice Exam: https://www.prep4king.com/NSE7_SDW-7.0-exam-prep-material.html
Dumps Collection NSE7_SDW-7.0 Test Engine Dumps Training With 70 Questions: https://drive.google.com/open?id=1oOdxxDX3xUjGCmeffDrQXwNr675diS8R

