Pass Fortinet NSE7_SDW-7.2 Actual Free Exam Q&As Updated Dump Apr 12, 2024
Latest NSE7_SDW-7.2 Actual Free Exam Updated 83 Questions
NEW QUESTION # 30
Refer to the exhibits.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator
collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on
FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit
SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)
- A. Full SSL inspection is not enabled on the matching firewall policy.
- B. FortiGate did not refresh the routing information on the session after the application was detected.
- C. Port1 and port2 do not have a valid route to the destination.
- D. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
Answer: B,D
Explanation:
Explanation
Study guide 7.2 Page 191
NEW QUESTION # 31
Refer to the exhibit.
Based on the exhibit, which statement about FortiGate re-evaluating traffic is true?
- A. FortiGate has terminated the session after a change on policy ID 1.
- B. The type of traffic defined and allowed on firewall policy ID 1 is UDP.
- C. Firewall policy ID 1 has source NAT disabled.
- D. Changes have been made on firewall policy ID 1 on FortiGate.
Answer: D
NEW QUESTION # 32
Refer to the exhibit.
Which conclusion about the packet debug flow output is correct?
- A. The reply traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.
- B. The original traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.
- C. The original traffic exceeded the maximum packets per second of the outgoing interface, and the packet was dropped.
- D. The original traffic exceeded the maximum bandwidth of the outgoing interface, and the packet was dropped.
Answer: B
NEW QUESTION # 33
Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)
- A. By default, local-out traffic does not use SD-WAN.
- B. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for
local-out traffic. - C. By default, FortiGate does not check if the selected member has a valid route to the destination.
- D. You must configure each local-out feature individually, to use SD-WAN.
Answer: A,D
NEW QUESTION # 34
Exhibit.
Which conclusion about the packet debug flow output is correct?
- A. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions
configured in the traffic shaper, and the packet was dropped. - B. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions
configured in the firewall policy, and the packet was dropped. - C. The packet size exceeded the outgoing interface MTU.
- D. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions
configured in the traffic shaper, and the packet was dropped.
Answer: A
Explanation:
Explanation
In a Per-IP shaper configuration, if an IP address exceeds the configured concurrent session limit, the message
"Denied by quota check" appears.SD-WAN 7.0 Study Guide page 287
NEW QUESTION # 35
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the default implicit SD-WAN rule? (Choose two )
- A. Matched traffic failed RPF and was caught by the rule.
- B. An absolute SD-WAN rule was defined and matched traffic.
- C. Traffic has matched none of the FortiGate policy routes.
- D. The FIB lookup resolved interface was the SD-WAN interface.
Answer: C,D
NEW QUESTION # 36
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the
routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?
- A. Port2 becomes alive after three successful probes are detected.
- B. The administrator manually restores the static routes for port2, if port2 becomes alive.
- C. FortiGate removes all static routes for port2.
- D. Host 8.8.8.8 is reachable through port1 and port2.
Answer: C
Explanation:
Explanation
This is due to Update static route is enable which removes the static route entry referencing the interface if the
interface is dead
NEW QUESTION # 37
Which statement about SD-WAN zones is true?
- A. An SD-WAN zone can contain between 0 and 512 members.
- B. You cannot use an SD-WAN zone in static route definitions.
- C. You can configure up to 32 SD-WAN zones per VDOM.
- D. An SD-WAN zone can contain only one type of interface.
Answer: C
Explanation:
SD-WAN zones are a group of interfaces that share the same SD-WAN settings, such as health check, SLA, and load balancing. Some characteristics of SD-WAN zones are:
An SD-WAN zone can contain different types of interfaces, such as physical, VLAN, aggregate, and tunnel interfaces1.
An SD-WAN zone can contain up to 512 members1.
You can use an SD-WAN zone in static route definitions, as long as the destination interface is also an SD-WAN zone1.
You can configure up to 32 SD-WAN zones per VDOM1.
NEW QUESTION # 38
Refer to the exhibit.
Based on the output, which two conclusions are true? (Choose two.)
- A. There is more than one SD-WAN rule configured.
- B. Theall_rulesrule represents the implicit SD-WAN rule.
- C. Entry1(id=1)is a regular policy route.
- D. The SD-WAN rules take precedence over regular policy routes.
Answer: A,C
NEW QUESTION # 39
Refer to the exhibit.
The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured packet loss will make T_INET_1_0 the new preferred member?
- A. When T_INET_0_0 has 12% packet loss.
- B. When T_INET_1_0 has 4% packet loss.
- C. When T_INET_0_0 has 4% packet loss.
- D. When all three members have the same packet loss.
Answer: D
NEW QUESTION # 40
Refer to the exhibits.
Exhibit A shows the packet duplication rule configuration, the SD-WAN zone status output, and the sniffer output on FortiGate acting as the sender. Exhibit B shows the sniffer output on a FortiGate acting as the receiver.
The administrator configured packet duplication on both FortiGate devices. The sniffer output on the sender FortiGate shows that FortiGate forwards an ICMP echo request packet over three overlays, but it only receives one reply packet through T_INET_1_0.
Based on the output shown in the exhibits, which two reasons can cause the observed behavior? (Choose two.)
- A. The ICMP echo request packets sent over T_INET_0_0 and T_MPLS_0 were dropped along the way.
- B. On the sender FortiGate, duplication-max-num is set to 3.
- C. On the receiver FortiGate, packet-de-duplication is enabled.
- D. The ICMP echo request packets received over T_INET_0_0 and T_MPLS_0 were offloaded to NPU.
Answer: B,C
NEW QUESTION # 41
Exhibit.
Which conclusion about the packet debug flow output is correct?
- A. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
- B. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
- C. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
- D. The packet size exceeded the outgoing interface MTU.
Answer: C
Explanation:
In a Per-IP shaper configuration, if an IP address exceeds the configured concurrent session limit, the message
"Denied by quota check" appears. SD-WAN 7.0 Study Guide page 287
NEW QUESTION # 42
Refer to the exhibits.

An administrator is testing application steering in SD-WAN. Before generating test traffic, the administrator collected the information shown in exhibit A.
After generating GoToMeeting test traffic, the administrator examined the respective traffic log on FortiAnalyzer, which is shown in exhibit B. The administrator noticed that the traffic matched the implicit SD-WAN rule, but they expected the traffic to match rule ID 1.
Which two reasons explain why the traffic matched the implicit SD-WAN rule? (Choose two.)
- A. Full SSL inspection is not enabled on the matching firewall policy.
- B. FortiGate did not refresh the routing information on the session after the application was detected.
- C. Port1 and port2 do not have a valid route to the destination.
- D. The session 3-tuple did not match any of the existing entries in the ISDB application cache.
Answer: B,D
Explanation:
Study guide 7.2 Page 191
NEW QUESTION # 43
Which two statements about the SD-WAN zone configuration are true? (Choose two.)
- A. An SD-WAN member can belong to two or more zones.
- B. The default zones are virtual-wan-link and SASE.
- C. Theservice-sla-tie-breaksetting enables you to configure preferred member selection based on the best
route to the destination. - D. You can delete the default zones.
Answer: B,C
NEW QUESTION # 44
Refer to the exhibit.
Based on the exhibit, which two actions does FortiGate perform on sessions after a firewall policy change?
(Choose two.)
- A. FortiGate does not change existing sessions.
- B. FortiGate flushes all sessions.
- C. FortiGate evaluates new sessions.
- D. FortiGate terminates the old sessions.
Answer: A,C
Explanation:
Explanation
FortiGate not to flag existing impacted session as dirty by setting firewall-session-dirty to check new. The
results is that FortiGate evaluates only new session against the new firewall policy.
NEW QUESTION # 45
Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.
What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?
- A. You must set ike-version to 1.
- B. You must disable idle-timeout.
- C. You must enable auto-discovery-sender.
- D. You must enable net-device.
Answer: D
NEW QUESTION # 46
Which two protocols in the IPsec suite are most used for authentication and encryption? (Choosetwo.)
- A. Internet Key Exchange (IKE)
- B. Encapsulating Security Payload (ESP)
- C. Secure Shell (SSH)
- D. Security Association (SA)
Answer: A,B
NEW QUESTION # 47
What does enabling theexchange-interface-ipsetting enable FortiGate devices to exchange?
- A. The IP address of their IPsec interfaces
- B. The gateway address of their IPsec interfaces
- C. The tunnel ID of their IPsec interfaces
- D. The name of their IPsec interfaces
Answer: A
NEW QUESTION # 48
Which two statements about SD-WAN central management are true? (Choose two.)
- A. It uses templates to configure SD-WAN on managed devices.
- B. The objects are saved in the ADOM common object database.
- C. It does not support meta fields.
- D. It supports normalized interfaces for SD-WAN member configuration.
Answer: A,B
Explanation:
Normalized interfaces are not supported for SD-WAN templates. You can create multiple SD-WAN zones and add interface members to the SD-WAN zones. You must bind the interface members by name to physical interfaces or VPN interfaces.https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-new-features/794804/new-sd-wan-template-
NEW QUESTION # 49
......
Online Questions - Valid Practice NSE7_SDW-7.2 Exam Dumps Test Questions: https://braindumps.free4torrent.com/NSE7_SDW-7.2-valid-dumps-torrent.html