New Year Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Fortinet FCSS_SDW_AR-7.6 Dumps

FCSS - SD-WAN 7.6 Architect Questions and Answers

Question 1

(You are using the FortiManager SD-WAN monitor menus to check the status of an SD-WAN topology. When you place the mouse next to branch1_fgt, you receive the output shown in the exhibit.

as

Which two conclusions can you draw from the output shown in the exhibit? Choose two answers.)

Options:

A.

Three spokes have tunnels that are out of SLA.

B.

The template Corp-SOT defines a dual-hub topology.

C.

branch3_fgt is configured with three SD-WAN overlay tunnels and one is down.

D.

branch1_fgt is configured with six SD-WAN overlay tunnels and three are down.

Question 2

(Refer to the exhibit.

as

You update the spokes configuration of an existing auto-discovery VPN (ADVPN) topology by adding the parameters shown in the exhibit.

Which is a valid objective of those settings? Choose one answer.)

Options:

A.

Enable the tunnels as overlay links.

B.

Convert the configuration from ADVPN to ADVPN 2.0.

C.

Prevent cross-overlay shortcuts.

D.

Prevent multiple shortcuts from being established over the same overlay.

Question 3

Which two statements correctly describe what happens when traffic matches the implicit SD-WAN rule? (Choose two.)

Options:

A.

The session information output displays no SD-WAN service id.

B.

Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.

C.

The traffic is distributed, regardless of weight, through all available static routes.

D.

Traffic does not match any of the entries in the policy route table.

E.

FortiGate flags the session with may_dirty and vwl_def ault.

Question 4

Refer to the exhibit.

as

Which statement best describe the role of the ADVPN device in handling traffic?

Options:

A.

This is a hub that has received a query from a spoke and has forwarded it to another spoke.

B.

This is a hub in a dual-region topology. The remote hub tunnel ID is 10.0.2.101.

C.

This is a spoke that has received a shortcut query from another spoke and has forwarded the response to its hub.

D.

This is a spoke. The kernel received a shortcut request and forwards the query to another spoke.

Question 5

Refer to the exhibits.

as

as

The interface details, static route configuration, and firewall policies on the managed FortiGate device are shown.

You want to configure a new SD-WAN zone, named Underlay, that contains the interfaces port1 and port2.

What must be your first action?

Options:

A.

Define port1 as an SD-WAN member.

B.

Delete the static routes.

C.

Delete the SD-WAN Zone Test.

D.

Delete the firewall policies.

Question 6

as

Refer to the exhibit.

You want to configure SD-WAN on a network as shown in the exhibit.

The network contains many FortiGate devices. Some are used as NGFW, and some are installed with extensions such as FortiSwitch. FortiAP. or Forti Ex tender.

What should you consider when planning your deployment?

Options:

A.

You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with Forti Extender.

B.

You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.

C.

You must use FortiManager to manage your SD-WAN topology.

D.

You must build multiple SD-WAN topologies. Each topology must contain only one type of extension.

Question 7

Refer to the exhibit.

as

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths

Which three settings must the administrator configure inside each BGP neighbor group so spokes can learn the prefixes of other spokes and their additional paths? (Choose three.)

Options:

A.

Set additional-path to send

B.

Set additional-path to forward

C.

Enable route-reflector-server

D.

Enable route-reflector-client.

E.

Set adv-additional-path to the number of additional paths to advertise.

Question 8

An administrator is configuring SD-WAN to load balance their network traffic. Which two things should they consider when setting up SD-WAN? (Choose two.)

Options:

A.

You can select the outbandwidth hash mode with all strategies that allow load balancing.

B.

Only the manual and best-quality strategies allow SD-WAN load balancing.

C.

When applicable. FortiGate load balances the traffic through all members that meet the SLA target.

D.

SD-WAN load balancing is possible only using the best quality and lowest cost (SLA) strategies.

Question 9

As an IT manager for a healthcare company, you want to delegate the installation and management of your SD-WAN deployment to a managed security service provider (MSSP). Each site must maintain direct internet access and ensure that it is secure. You expected significant traffic flow between the sites and want to delegate as much of the network administration and management as possible to the MSSP.

Which two MSSP deployment blueprints best address the customer’s requirements? (Choose two.)

Options:

A.

Use a shared hub at the MSSP premises with a dedicated VDOM for the new customer, and install the spokes at the customer premises.

B.

Use a shared hub at the MSSP premises and a dedicated hub at the customer premises and install the spokes at the customer premises.

C.

Install a dedicated hub at the MSSP premises for the new customer, and install the spokes at the customer premises.

D.

Install the hub and spokes at the customer premises and enable the MSSP to manage the SD-WAN deployment using FortiManager with a dedicated ADOM.

Question 10

Refer to the exhibits.

as

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in the first exhibit. After generating GoToMeeting test traffic, the administrator examined the corresponding traffic log on FortiAnalyzer, which is shown in the second exhibit.

The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.

Which two reasons explain why some log messages show that the traffic matched the implicit SD-WAN rule? (Choose two.)

Options:

A.

Full SSL inspection is not enabled on the matching firewall policy.

B.

The session 3-tuple did not match any of the existing entries in the ISDB application cache.

C.

FortiGate could not refresh the routing information on the session after the application was detected.

D.

No configured SD-WAN rule matches the traffic related to the collaboration application GoToMeeting

Question 11

The SD-WAN overlay template helps to prepare SD-WAN deployments. To complete the tasks performed by the SD-WAN overlay template, the administrator must perform some post-run tasks. What are two mandatory post-run tasks that must be performed? (Choose two.)

Options:

A.

Configure routing through the overlay tunnels created by the SD-WAN overlay template.

B.

Create policy packages and assign them to the branch devices.

C.

Assign a hub id metadata variable to each hub device.

D.

Configure SD-WAN rules

E.

Assign an sdwan_id metadata variable to each device (branch and hub)

Question 12

Refer to the exhibit.

as

How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0 125?

Options:

A.

FortiGate drops the traffic flow.

B.

FortiGate routes the traffic flow according to the forwarding information base (FIB).

C.

FortiGate load balances the traffic flow through port7 and port8.

D.

FortiGate steers the traffic flow through port7.

Question 13

(Refer to the exhibit.

as

The administrator configured two SD-WAN rules to load balance traffic.

Which interfaces does FortiGate use to steer the traffic from 10.0.1.124 to 10.0.0.254? Choose one answer.)

Options:

A.

port1 or port2

B.

FortiGate routes the traffic according to the FIB.

C.

HUB1-VPN2

D.

Any interface in the HUB1 or HUB2 zones

Question 14

Refer to the exhibit that shows a diagnose output on FortiGate.

as

Based on the output shown in the exhibit, what can you say about the device role and how it handles health checks?

Options:

A.

The device is a spoke. It receives health-check measures for the tunnels of another spoke.

B.

The device is a hub. It receives embedded health-check measures for each tunnel from the spoke.

C.

The device is a spoke. It provides embedded health-check measures for each tunnel to the hub.

D.

The device is a hub. It receives health-check measures for the tunnels of a spoke.

Question 15

(In the context of SD-WAN, the terms underlay and overlay are commonly used to categorize links.

Which two statements about underlay and overlay links are correct? Choose two answers.)

Options:

A.

A VLAN is a type of overlay link.

B.

Overlay links provide routing flexibility.

C.

FortiLink interface is considered an underlay link.

D.

Wireless connections can be used to build overlay links.

E.

Only wired connections can be used as underlay links.

Question 16

Which three factors about SLA targets and SD-WAN rules should you consider when configuring SD-WAN rules? (Choose three.)

Options:

A.

Member metrics are measured only if a rule uses the SLA target.

B.

SLA targets are used only by SD-WAN rules that are configured with a Lowest Cost (SLA) strategy.

C.

SD-WAN rules can use SLA targets to check whether the preferred members meet the SLA requirements.

D.

When configuring an SD-WAN rule, you can select multiple SLA targets if they are from the same performance SLA.

E.

When configuring an SD-WAN rule, you can select multiple SLA targets from different performance SLAs.

Question 17

What are three key routing principles of SD-WAN? (Choose three.)

Options:

A.

Directly connected routes have precedence over SD-WAN rules.

B.

Policy routes have precedence over SD-WAN rules.

C.

SD-WAN rules are skipped if the best route to the destination is a static route

D.

SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.

E.

SD-WAN members are skipped if they do not have a valid route to the destination.

Question 18

SD-WAN interacts with many other FortiGate features. Some of them are required to allow SD-WAN to steer the traffic.

Which three configuration elements that you must configure before FortiGate can steer traffic according to SD-WAN rules? (Choose three.)

Options:

A.

Firewall policies

B.

Interfaces

C.

Security profiles

D.

Traffic shaping

E.

Routing

Question 19

(Refer to the exhibits.

as

You collected the output shown in the exhibits and want to know which interface HTTP traffic will flow through from the user device 10.0.1.101 to the corporate web server 10.0.0.126. All SD-WAN links are stable.

Which interface will FortiGate use to steer the traffic? Choose one answer.)

Options:

A.

Only HUB1-VPN3

B.

Only HUB1-VPN2

C.

Either HUB1-VPN2 or HUB1-VPN3

D.

Either HUB1-VPN1, HUB1-VPN2, or HUB1-VPN3

Question 20

(In which order does FortiGate consider the following elements during the route lookup process? Choose one answer.)

Options:

A.

SD-WAN rules, ISDB routes, policy routes, BGP routes

B.

Policy routes, SD-WAN rules, Internet Service Database (ISDB) routes, BGP routes

C.

SD-WAN rules, policy routes, static routes, ISDB routes

D.

Policy routes, ISDB routes, SD-WAN rules, static routes

Question 21

The administrator uses the FortiManager SD-WAN overlay template to prepare an SD-WAN deployment. Using information provided through the SD-WAN overlay template wizard, FortiManager creates templates ready to install on the spoke and hub devices.

What are the three templates created by the SD-WAN overlay template for a spoke device? (Choose three.)

Options:

A.

Static route template

B.

Rules template

C.

CLI template

D.

BGP template

E.

IPsec tunnel template

Question 22

You configured an SD-WAN rule with the best quality strategy and selected the predefined health check, Default_FortiGuard, to check the link performances against FortiGuard servers.

For the quality criteria, you selected Custom-profile-1.

Which factors does FortiGate use, and in which order. to determine the link that it should use to steer the traffic?

Options:

A.

Latency – Member configuration order – Link cost threshold

B.

Link quality index – Member configuration order – Link cost threshold

C.

Links that meet the SLA targets – Member configuration order – Member local cost

D.

Latency – Jitter - Packet loss – Bibandwidth – Member configuration order

Question 23

Refer to the exhibit.

as

The exhibit shows the health-check configuration on a FortiGate device used as a spoke. You notice that the hub FortiGate doesn’t prioritize the traffic as expected.

Which two configuration elements should you check on the hub? (Choose two.)

Options:

A.

The performance SLA has the parameter priority-out-sla configured.

B.

This performance SLA uses the same members.

C.

The performance SLA uses the same criteria.

D.

The performance SLA is configured with set embedded-measure accept.

Question 24

Which statement describes FortiGate behavior when you reference a zone in a static route?

Options:

A.

FoftiGate installs ECMP static routes for the first two members of the zone.

B.

FortiGate ignores the static routes defined through members referenced in the zone.

C.

FortiGate routes the traffic through the best performing member of the zone.

D.

FortiGate installs a static route for each member in the zone.

Question 25

An SD-WAN member is no longer used to steer SD-WAN traffic. The administrator updated the SD-WAN configuration and deleted the unused member. After the configuration update, users report that some destinations are unreachable. You confirm that the affected flow does not match an SD-WAN rule.

What could be a possible cause of the traffic interruption?

Options:

A.

FortiGate, with SD-WAN enabled, cannot route traffic through interfaces that are not SD-WAN members.

B.

FortiGate can remove some static routes associated with an interface when the member is removed from SD-WAN.

C.

FortiGate removes the layer 3 settings for interfaces that are removed from the SD-WAN configuration.

D.

FortiGate administratively brings down interfaces when they are removed from the SD-WAN configuration.

Question 26

You have a FortiGate configuration with three user-defined SD-WAN zones and two members in each of these zones. One SD-WAN member is no longer in use in health-check and SD-WAN rules. You want to delete it.

What happens if you delete the SD-WAN member from the FortiGate GUI?

Options:

A.

FodiGate accepts the deletion and removes routes as required.

B.

FortiGate displays an error message. You must use the CLI to delete an SD-WAN member.

C.

FortiGate displays an error message. SD-WAN zones must contain at least two members

D.

FortiGate accepts the deletion and places the member in the default SD-WAN zone.

Question 27

Refer to the exhibit, which shows the SD-WAN rule status and configuration.

as

Based on the exhibit, which change in the measured latency will first make HUB1-VPN3 the new preferred member?

Options:

A.

When HUB1-VPN3 has a lower latency than HUB1-VPN1 and HUB1-VPN2

B.

When HUB1-VPN3 has a latency of 80 ms

C.

When HUB1-VPN3 has a latency of 90 ms

D.

When HUB1-VPN1 has a latency of 200 ms

Question 28

The FortiGate devices are managed by ForliManager, and are configured for direct internet access (DIA). You confirm that DIA is working as expected for each branch, and check the SD-WAN zone configuration and firewall policies shown in the exhibits.

as

as

as

Then, you use the SD-WAN overlay template to configure the IPsec overlay tunnels. You create the associated SD-WAN rules to connect existing branches to the company hub device and apply the changes on the branches.

After those changes, users complain that they lost internet access. DIA is no longer working.

Based on the exhibit, which statement best describes the possible root cause of this issue?

Options:

A.

The SD-WAN overlay template defines a zone for each underlay interface and moves the interfaces into those zones.

B.

The SD-WAN overlay template didn’t configure a firewall policy to allow traffic through the overlay.

C.

The SD-WAN overlay template redefines the interface gateway addresses if they are defined with metadata variables.

D.

The SD-WAN overlay template updates the SD-WAN template and the rules.

Page: 1 / 9
Total 94 questions