[Aug 23, 2021] Latest NSE7_SDW-6.4 Exam with Accurate Fortinet NSE 7 - SD-WAN 6.4 PDF Questions
Practice To NSE7_SDW-6.4 - TorrentExam Remarkable Practice On your Fortinet NSE 7 - SD-WAN 6.4 Exam
NEW QUESTION 14
Which two reasons make forward error correction (FEC) ideal to enable in a phase one VPN interface? (Choose two )
- A. FEC is useful to increase speed at which traffic is routed through IPsec tunnels.
- B. FEC transmits additional packets as redundant data to the remote device.
- C. FEC improves reliability which overcomes adverse WAN conditions such as noisy links.
- D. FEC reduces the stress on the remote device jitter buffer to reconstruct packet loss
- E. FEC transmits the original payload in full to recover the error in transmission.
Answer: B,C
NEW QUESTION 15
Refer to the exhibit.
Multiple IPsec VPNs are formed between two hub-and-spokes groups, and site-to-site between Hub 1 and Hub 2 The administrator configured ADVPN on the dual regions topology
Which two statements are correct if a user in Toronto sends traffic to London? (Choose two )
- A. Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.
- B. The first packets from Toronto to London are routed through Hub 1 then to Hub 2.
- C. London generates an IKE information message that contains the Toronto public IP address
- D. Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN
Answer: A,D
NEW QUESTION 16
What are the two minimum configuration requirements for an outgoing interface to be selected once the SD-WAN logical interface is enabled? (Choose two )
- A. Specify incoming interfaces in SD-WAN rules.
- B. Configure SD-WAN rules interface preference.
- C. Select SD-WAN balancing strategy.
- D. Specify outgoing interface routing cost.
Answer: B,D
NEW QUESTION 17
Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?
- A. The 10 Mbps bandwidth is shared equally among the IP addresses.
- B. A single user uses the allocated bandwidth divided by total number of users.
- C. Each IP is guaranteed a minimum 10 Mbps of bandwidth
- D. FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.
Answer: D
NEW QUESTION 18
Refer to the exhibit.
Based on output shown in the exhibit, which two commands can be used by SD-WAN rules? (Choose two.)
- A. set priority 10.
- B. set cost 15.
- C. set source 100.64.1.1.
- D. set load-balance-mode source-ip-based.
Answer: A,D
NEW QUESTION 19
Refer to the exhibit.
Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)
- A. Set cost 15.
- B. Set source 100.64.1.1.
- C. Set load-balance-mode source-ip-ip-based.
- D. Set priority 10.
Answer: B
NEW QUESTION 20
What would best describe the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?
- A. Interface-based shaping mode
- B. Per-IP shaping mode
- C. Reverse policy shaping mode
- D. Shared policy shaping mode
Answer: A
NEW QUESTION 21
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?
- A. diagnose sys virtual-wan-link health-check
- B. diagnose sys virtual-wan-link sla-lcg
- C. diagnose sys virtual-wan-link intf-sla-log
- D. diagnose sys virtual-wan-link log
Answer: A
NEW QUESTION 22
Which statement defines how a per-IP traffic shaper of 10 Mbps is applied to the entire network?
- A. The 10 Mbps bandwidth is shared equally among the IP addresses.
- B. A single user uses the allocated bandwidth divided by total number of users.
- C. Each IP is guaranteed a minimum 10 Mbps of bandwidth.
- D. FortiGate allocates each IP address a maximum 10 Mbps of bandwidth.
Answer: D
Explanation:
Explanation/Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/885253/per-ip-traffic-shaper
NEW QUESTION 23
Refer to exhibits.

Exhibit A shows the SD-WAN rules and exhibit B shows the traffic logs. The SD-WAN traffic logs reflect how FortiGate processed traffic.
Which two statements about how the configured SD-WAN rules are processing traffic are true? (Choose two.)
- A. The implicit rule overrides all other rules because parameters widely cover sources and destinations.
- B. SD-WAN rules are evaluated in the same way as firewall policies: from top to bottom.
- C. The initial session of an application goes through a learning phase in order to apply the correct rule.
- D. The All_Access_Rules rule load balances Vimeo application traffic among SD-WAN member interfaces.
Answer: A,B
NEW QUESTION 24
Refer to the exhibit.
Which two statements about the debug output are correct? (Choose two )
- A. The debug output shows per-IP shaper values and real-time readings.
- B. FortiGate provides statistics and reading based on historical traffic logs.
- C. Traffic being controlled by the traffic shaper is under 1 Kbps.
- D. This traffic shaper drops traffic that exceeds the set limits.
Answer: A,D
NEW QUESTION 25
Which diagnostic command can you use to show the SD-WAN rules interface information and state?
- A. diagnose sys virtual-wan-link neighbor.
- B. diagnose sys virtual-wan-link service
- C. diagnose sys virtual-wan-link member.
- D. diagnose sys virtual-wan-link route-tag-list
Answer: A
NEW QUESTION 26
Refer to the exhibit.
What must you configure to enable ADVPN?
- A. The protected subnets should be set to address object to all (0.0 .0. o/o).
- B. ADVPN should only be enabled on unmanaged FortiGate devices.
- C. On the hub VPN, only the device needs additional phase one sett
- D. Each VPN device has a unique pre-shared key configured separately on phase one
Answer: D
NEW QUESTION 27
Refer to the exhibit.
What must you configure to enable ADVPN?
- A. The protected subnets should be set to address object to all (0.0 .0. o/o).
- B. ADVPN should only be enabled on unmanaged FortiGate devices.
- C. On the hub VPN, only the device needs additional phase one sett
- D. Each VPN device has a unique pre-shared key configured separately on phase one
Answer: D
NEW QUESTION 28
Which statement about using BGP routes in SD-WAN is true?
- A. Learned routes can be used as dynamic destinations in SD-WAN rules.
- B. Dynamic routing protocols can be used only with non-encrypted traffic.
- C. Adding static routes must be enabled on all ADVPN interfaces.
- D. VPN topologies must be form using only BGP dynamic routing with SD-WAN.
Answer: A
Explanation:
Explanation/Reference:
https://www.fortinetguru.com/2019/09/using-bgp-tags-with-sd-wan-rules-fortios-6-2/#:~:text=SD%2DWAN%
20rules%20can%20use,to%20the%20customer's%20data%20center.
NEW QUESTION 29
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A, which shows the SD-WAN performance SLA and exhibit B shows the health of the participating SD-WAN members.
Based on the exhibits, which statement is correct?
- A. The SLA state of port2 has exceeded three consecutive unanswered requests from the SLA server.
- B. Port2 needs to wait 500 milliseconds to change the status from alive to dead.
- C. Check interval is the time to wait before a packet sent by a member interface considered as lost.
- D. The dead member interface stays unavailable until an administrator manually brings the interface back.
Answer: A
NEW QUESTION 30
Refer to the exhibit.
FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)
- A. Configure the IKE mode to be aggressive mode.
- B. Use different proposals are used between the interfaces.
- C. Specify a unique peer ID for each dial-up VPN interface.
- D. Use unique Diffie Hellman groups on each VPN interface.
Answer: B,D
NEW QUESTION 31
......
Exam Questions and Answers for NSE7_SDW-6.4 Study Guide Questions and Answers!: https://www.torrentexam.com/NSE7_SDW-6.4-exam-latest-torrent.html

