NSE7_SDW-6.4 Pre-Exam Practice Tests | (Updated 37 Questions)
Valid NSE7_SDW-6.4 Exam Q&A PDF - One Year Free Update
NEW QUESTION 12
What are two benefits of using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two )
- A. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices
- B. It improves SD-WAN performance on the managed FortiGate devices.
- C. It acts as a policy compliance entity to review all managed FortiGate devices
- D. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server
- E. It sends probe signals as health checks to the beacon servers on behalf of FortiGate
Answer: A,D
NEW QUESTION 13
Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when performing IKE negotiation? (Choose two )
- A. The use of Diffie Hellman keys is limited by the responderand needs initiator acceptance
- B. A total of six packets are exchanged between an initiator and a responder instead of three packets.
- C. XAuth is enabled as an additional level of authentication which requires a username and password
- D. A peer ID is included in the first packet from the initiator, along with suggested security policies
Answer: C
NEW QUESTION 14
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A shows the traffic shaping policy and exhibit B show: the firewall policy FortiGate is not performing traffic shaping as expected basi on the policies shown in the exhibits.
To correct this traffic shaping issue on FortiGate, what configuration change must be made on which policy?
- A. The URL category must be specified on the traffic shaping policy
- B. The application control profile must be enabled on the firewall policy.
- C. The shaper mode must be applied per-IP shaper on the traffic shaping policy
- D. The web filter profile must be enabled on the firewall policy
Answer: D
NEW QUESTION 15
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A shows the traffic shaping policy and exhibit B show: the firewall policy FortiGate is not performing traffic shaping as expected basi on the policies shown in the exhibits.
To correct this traffic shaping issue on FortiGate, what configuration change must be made on which policy?
- A. The URL category must be specified on the traffic shaping policy
- B. The application control profile must be enabled on the firewall policy.
- C. The shaper mode must be applied per-IP shaper on the traffic shaping policy
- D. The web filter profile must be enabled on the firewall policy
Answer: D
NEW QUESTION 16
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A shows the SD-WAN rules and exhibit B shows the traffic logs. The SD-WAN traffic logs reflect how FortiGate processed traffic.
Which two statements about how the configured SD-WAN rules are processing traffic are true? (Choose two.)
- A. The implicit rule overrides all other rules because parameters widely cover sources and destinations.
- B. The initial session of an application goes through a learning phase in order to apply the correct rule
- C. SD-WAN rules are evaluated in the same way as firewall policies: from top to bottom
- D. The All_Access_Rules rule load balances Vimeo application traffic among SD-WAN member interfaces
Answer: A,B
NEW QUESTION 17
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A shows the source NAT global setting and exhibit B shows the routing table on FortiGate Based on the exhibits, which two statements about increasing the port2 interface priority to 20 are true? (Choose two )
- A. All the existing sessions will continue to use port2 and new sessions will use port1
- B. All the existing sessions will be blocked from using port1 and port2
- C. All the existing sessions with no SNAT will start using port1 as the outgoing interface instead of port2
- D. All the existing sessions using SNAT will start using port1 as the outgoing interface instead of port2.
Answer: C,D
NEW QUESTION 18
Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when performing IKE negotiation? (Choose two )
- A. XAuth is enabled as an additional level of authentication, which requires a username and password.
- B. A peer ID is included in the first packet from the initiator, along with suggested security policies.
- C. The use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.
- D. A total of six packets are exchanged between an initiator and a responder instead of three packets.
Answer: A,D
NEW QUESTION 19
Refer to the exhibit.
Which statement about the trace evaluation by FomGate is true?
- A. Packets exceeding the configured maximum concurrent connection limit are denied by the per-IP shaper.
- B. Packets exceeding the configured concurrent connection limit are dropped based on the priority configuration.
- C. The packet exceeded the configured maximum bandwidth and was dropped by the shared shaper.
- D. The packet exceeded the configured bandwidth and was dropped based on the priority configuration.
Answer: A
NEW QUESTION 20
Refer to the exhibit.
Which two statements about the debug output are correct? (Choose two )
- A. The debug output shows per-IP shaper values and real-time readings.
- B. FortiGate provides statistics and reading based on historical traffic logs.
- C. Traffic being controlled by the traffic shaper is under 1 Kbps.
- D. This traffic shaper drops traffic that exceeds the set limits.
Answer: A,D
NEW QUESTION 21
An administrator is troubleshooting VoIP quality issues that occur when calling external phone numbers The SD-WAN interface on the edge FortiGate is configured with the default settings, and is using two upstream links One link has random jitter and latency issues and is based on a wireless connection Which two actions must the administrator apply simultaneously on the edge FortiGate to improve VoIP quality using SD_WAN rules?
- A. Configure an SD-WAN rule to load balance all traffic without VoIP.
- B. Place the troublesome link at the top of the interface preference list.
- C. Select the corresponding SD-WAN balancing strategy in the SD-WAN rule.
- D. Choose the suitable interface based on the interface cost and weight.
- E. Use the performance SLA targets to detect latency and jitter instantly.
Answer: C,E
NEW QUESTION 22
Which components make up the secure SD-WAN solution?
- A. Application, antivirus, and URL, and SSL inspection
- B. FortiGate, FortiManager, FortiAnalyzer, and FortiDeploy
- C. Datacenter, branch offices, and public cloud
- D. Telephone, ISDN, and telecom network.
Answer: A
NEW QUESTION 23
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?
- A. diagnose sys virtual-wan-link health-check
- B. diagnose sys virtual-wan-link intf-sla-log
- C. diagnose sys virtual-wan-link sla-log
- D. diagnose sys virtual-wan-link log
Answer: C
NEW QUESTION 24
What are the two minimum configuration requirements for an outgoing interface to be selected once the SD-WAN logical interface is enabled? (Choose two )
- A. Specify outgoing interface routing cost.
- B. Specify incoming interfaces in SD-WAN rules.
- C. Configure SD-WAN rules interface preference.
- D. Select SD-WAN balancing strategy.
Answer: C
NEW QUESTION 25
Which components make up the secure SD-WAN solution?
- A. Application, antivirus, and URL, and SSL inspection
- B. Datacenter, branch offices, and public cloud
- C. Telephone, ISDN, and telecom network.
- D. FortiGate, FortiManager, FortiAnalyzer, and FortiDeploy
Answer: D
NEW QUESTION 26
What are two benefits of using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two.)
- A. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
- B. It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
- C. It improves SD-WAN performance on the managed FortiGate devices.
- D. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
- E. It acts as a policy compliance entity to review all managed FortiGate devices.
Answer: D,E
NEW QUESTION 27
Which two reasons make forward error correction (FEC) ideal to enable in a phase one VPN interface? (Choose two )
- A. FEC is useful to increase speed at which traffic is routed through IPsec tunnels.
- B. FEC transmits additional packets as redundant data to the remote device.
- C. FEC improves reliability which overcomes adverse WAN conditions such as noisy links.
- D. FEC reduces the stress on the remote device jitter buffer to reconstruct packet loss
- E. FEC transmits the original payload in full to recover the error in transmission.
Answer: B,C
NEW QUESTION 28
What is the lnkmtd process responsible for?
- A. Flushing route tags addresses
- B. Monitoring links for any bandwidth saturation
- C. Logging interface quality information
- D. Processing performance SLA probes
Answer: B
NEW QUESTION 29
Refer to the exhibit.
Which two statements about the status of the VPN tunnel are true? <Choose two )
- A. FortiGate created a single IPsec virtual interface that is shared by all clients
- B. 100.64.3.1 is one of the remote IP address that comes through index interlace 1.
- C. VPN static routes are prevented from populating the FortiGate routing table
- D. There are separate virtual interfaces for each dial-up client
Answer: D
NEW QUESTION 30
Which three parameters are available to configure SD-WAN rules? (Choose three.)
- A. Internet service database (ISDB) address object
- B. Type of physical link connection
- C. URL categories
- D. Application signatures
- E. Source and destination IP address
Answer: A,B,E
NEW QUESTION 31
......
Fortinet NSE 7 - SD-WAN 6.4 Free Update Certification Sample Questions: https://www.dumpstorrent.com/NSE7_SDW-6.4-exam-dumps-torrent.html
Trend for Fortinet NSE7_SDW-6.4 pdf dumps before actual exam: https://drive.google.com/open?id=1q531dMI46QJxBE6eb-fDgjHLckhl2af9