Use Real NSE7_SDW-7.2 - 100% Cover Real Exam Questions [Apr-2025]
Dumps Brief Outline Of The NSE7_SDW-7.2 Exam - DumpsTorrent
NEW QUESTION # 17
Which two conclusions for traffic that matches the traffic shaper are true? (Choose two.)
- A. The measured bandwidth is less than 100 KBps.
- B. The traffic shaper limits the bandwidth of each source IP to a maximum of 6250 KBps.
- C. The traffic shaper drops packets if the bandwidth exceeds 6250 KBps.
- D. The traffic shaper drops packets if the bandwidth is less than 2500 KBps.
Answer: A,C
NEW QUESTION # 18
In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)
- A. It enables spokes to establish shortcuts to third-party gateways.
- B. It provides the benefits of a full-mesh topology in a hub-and-spoke network.
- C. It provides direct connectivity between spokes by creating shortcuts.
- D. It enables spokes to bypass the hub during shortcut negotiation.
Answer: B,C
NEW QUESTION # 19
Refer to the exhibit.
Which statement explains the output shown in the exhibit?
- A. FortiGate must re-evaluate the session due to routing change.
- B. FortiGate will not re-evaluate the session following a firewall policy change.
- C. FortiGate performed standard FIB routing on the session.
- D. FortiGate used 192.2.0.1 as the gateway for the original direction of the traffic.
Answer: A
Explanation:
The snat-route-change option is enabled by default. This option enables FortiGate to re-evaluate the routing table and select a new egress interface if the next hop IP address changes. This option only applies to sessions in the dirty state. Sessions in the log state are not affected by routing changes.
NEW QUESTION # 20
Which diagnostic command can you use to show the SD-WAN rules, interface information, and state?
- A. diagnose sys sdwan route-tag-list
- B. diagnose sys sdwan member
- C. diagnose sys sdwan neighbor
- D. diagnose sys sdwan service
Answer: B
NEW QUESTION # 21
What three characteristics apply to provisioning templates available on FortiManager? (Choose three.)
- A. Templates are applied in order, from top to bottom.
- B. A template group can contain CLI templates of both types.
- C. You can apply a system template and a CLI template to the same FortiGate device.
- D. A CLI template can be of type CLI script or Perl script.
- E. A template group can include a system template and an SD-WAN template.
Answer: A,B,D
Explanation:
Explanation
According to the FortiManager Administration Guide, provisioning templates are used to configure FortiGate
devices in a consistent and efficient way. There are different types of templates, such as system, IPsec,
SD-WAN, certificate, and CLI templates. Some characteristics of provisioning templates are:
You can apply a system template and a CLI template to the same FortiGate device, as long as they do
not have conflicting settings1.
A CLI template can be of type CLI script or Perl script. A CLI script template contains FortiOS CLI
commands, while a Perl script template contains Perl code that can generate FortiOS CLI commands2.
A template group can include a system template and an SD-WAN template, as well as other types of
templates. A template group is a collection of templates that can be applied to multiple devices at once3.
A template group can contain CLI templates of both types, as long as they do not have conflicting
settings2.
Templates are applied in order, from top to bottom. The order of the templates in a template group
determines the order in which they are applied to the devices3.
NEW QUESTION # 22
Exhibit.
The exhibit shows the output of the command diagnose sys sdwan health-check status collected on a FortiGate device. Which two statements are correct about the health check status on this FortiGate device?
(Choose two.)
- A. The health-check VPN_PING orders the members according to the lowest jitter.
- B. The interface T_INET_1 missed one SLA target.
- C. There is no SLA criteria configured for the health-check Level3_DNS.
- D. The interface T_INET_0 missed three SLA targets.
Answer: A,C
Explanation:
According to the FortiGate / FortiOS 6.4.2 Administration Guide, the health check status command displays the status of the health check probes for each SD-WAN member interface. The output includes the following information:
* state: the current state of the interface, either alive or dead
* packet-loss: the percentage of packets lost during the health check
* latency: the average round-trip time in milliseconds
* jitter: the variation in latency
* mos: the mean opinion score, a measure of voice quality
* bandwidth: the available bandwidth in kilobits per second for each direction (up, down, bi)
* sla map: a bitmap that indicates which SLA criteria are met or failed Based on the exhibit, the following statements are correct:
* The health-check VPN_PING orders the members according to the lowest jitter. This means that the interface with the lowest jitter value is listed first, followed by the next lowest, and so on1. In the exhibit, the order is T_MPLS, T_INET_1, and T_INET_0.
* There is no SLA criteria configured for the health-check Level3_DNS. This means that the health check does not use any SLA parameters to determine the state of the interface2. In the exhibit, the sla map value is 0x0 for both port1 and port2, indicating that no SLA criteria are applied.
NEW QUESTION # 23
Refer to the exhibit.
The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured packet loss will make T_INET_1_0 the new preferred member?
- A. When T_INET_1_0 has 4% packet loss.
- B. When T_INET_0_0 has 12% packet loss.
- C. When all three members have the same packet loss.
- D. When T_INET_0_0 has 4% packet loss.
Answer: A
NEW QUESTION # 24
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?
- A. Port2 becomes alive after three successful probes are detected.
- B. Host 8.8.8.8 is reachable through port1 and port2.
- C. The administrator manually restores the static routes for port2, if port2 becomes alive.
- D. FortiGate removes all static routes for port2.
Answer: D
Explanation:
This is due to Update static route is enable which removes the static route entry referencing the interface if the interface is dead
NEW QUESTION # 25
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows the SD-WAN performance SLA configuration, the SD-WAN rule configuration, and the application IDs of Facebook and YouTube. Exhibit B shows the firewall policy configuration and the underlay zone status.
Based on the exhibits, which two statements are correct about the health and performance of port1 and port2?
(Choose two.)
- A. The performance is an average of the metrics measured for Facebook and YouTube traffic passing through the member.
- B. FortiGate is unable to measure jitter and packet loss on Facebook and YouTube traffic.
- C. Non-TCP Facebook and YouTube traffic are not used for performance measurement.
- D. FortiGate identifies the member as dead when there is no Facebook and YouTube traffic passing through the member.
Answer: A,C
Explanation:
Study Guide 7.2, pages 103 - 104. Another comment said "because without using application Control on the firewall policy, SDWAN can't work" but there is a app control "default" defined on config.
NEW QUESTION # 26
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?
- A. Port2 becomes alive after three successful probes are detected.
- B. Host 8.8.8.8 is reachable through port1 and port2.
- C. The administrator manually restores the static routes for port2, if port2 becomes alive.
- D. FortiGate removes all static routes for port2.
Answer: D
Explanation:
This is due to Update static route is enable which removes the static route entry referencing the interface if the interface is dead
NEW QUESTION # 27
Refer to the exhibit.
Based on the exhibit, which action does FortiGate take?
- A. FortiGate brings down port5 after it detects all SD-WAN members as dead.
- B. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
- C. FortiGate brings up port5 after it detects all SD-WAN members as alive.
- D. FortiGate bounces port5 after it detects all SD-WAN members as dead.
Answer: B
NEW QUESTION # 28
Refer to the exhibit.
The exhibit shows output of the command diagnose 3vg sdwan service collected on a FortiGate device.
The administrator wants to know through which interface FortiGate will steer the traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the business application Salesforce located on HO servers 10.0.0.1.
Based on the exhibits, which two statements are correct? (Choose two.)
- A. FortiGate steers traffic for business application according to service rule 2 and steers traffic through port2.
- B. When FortiGate cannot recognize the application of the flow it steers the traffic destined to server
10.0.0.1 according to service rule 3. - C. FortiGate steers traffic to HO servers according to service rule 1 and it uses port1 or port2 because both interfaces are selected.
- D. There is no service defined for the Salesforce application, so FortiGate will use the service rule 3 and steer the traffic through interface T_HQ1.
Answer: B,C
NEW QUESTION # 29
Which diagnostic command can you use to show the member utilization statistics measured by performance SLAs for the last 10 minutes?
- A. diagnose ays sdwan health-check
- B. diagnose sys sdwan log
- C. diagnose sys sdwan intf-sla-log
- D. diagnose sys sdwan sla-log
Answer: D
NEW QUESTION # 30
What are two reasons for using FortiManager to organize and manage the network for a group of FortiGate
devices? (Choose two.)
- A. It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
- B. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
- C. It improves SD-WAN performance on the managed FortiGate devices.
- D. It acts as a policy compliance entity to review all managed FortiGate devices.
- E. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
Answer: B,E
NEW QUESTION # 31
Exhibit.
The exhibit shows the output of the command diagnose sys sdwan health-check status collected on a FortiGate device. Which two statements are correct about the health check status on this FortiGate device? (Choose two.)
- A. The health-check VPN_PING orders the members according to the lowest jitter.
- B. The interface T_INET_1 missed one SLA target.
- C. There is no SLA criteria configured for the health-check Level3_DNS.
- D. The interface T_INET_0 missed three SLA targets.
Answer: A,C
Explanation:
According to the FortiGate / FortiOS 6.4.2 Administration Guide, the health check status command displays the status of the health check probes for each SD-WAN member interface. The output includes the following information:
state: the current state of the interface, either alive or dead
packet-loss: the percentage of packets lost during the health check
latency: the average round-trip time in milliseconds
jitter: the variation in latency
mos: the mean opinion score, a measure of voice quality
bandwidth: the available bandwidth in kilobits per second for each direction (up, down, bi) sla map: a bitmap that indicates which SLA criteria are met or failed Based on the exhibit, the following statements are correct:
The health-check VPN_PING orders the members according to the lowest jitter. This means that the interface with the lowest jitter value is listed first, followed by the next lowest, and so on1. In the exhibit, the order is T_MPLS, T_INET_1, and T_INET_0.
There is no SLA criteria configured for the health-check Level3_DNS. This means that the health check does not use any SLA parameters to determine the state of the interface2. In the exhibit, the sla map value is 0x0 for both port1 and port2, indicating that no SLA criteria are applied.
NEW QUESTION # 32
Which two protocols in the IPsec suite are most used for authentication and encryption? (Choosetwo.)
- A. Security Association (SA)
- B. Encapsulating Security Payload (ESP)
- C. Secure Shell (SSH)
- D. Internet Key Exchange (IKE)
Answer: B,D
NEW QUESTION # 33
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferred member in the matching SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?
- A. Enable snat-route-change under config system global.
- B. Enable auxiliary-session under config system settings.
- C. Disable allow-subnet-overlap under config system settings.
- D. Disable tp-session-without-syn under config system settings.
Answer: B
NEW QUESTION # 34
Exhibit A -
Exhibit B -
Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.
Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?
- A. port1 is assigned a manual IP address.
- B. port1 and port2 are not administratively down.
- C. port1 is referenced in a firewall policy.
- D. port2 is referenced in a static route.
Answer: C
NEW QUESTION # 35
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator
determines that FortiGate does not apply traffic shaping on YouTube traffic.
Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs
traffic shaping on YouTube traffic?
- A. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.
- B. Destination internet service must be enabled on the traffic shaping policy.
- C. Application control must be enabled on the firewall policy.
- D. Web filtering must be enabled on the firewall policy.
Answer: C
NEW QUESTION # 36
Refer to the exhibit.
FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)
- A. Configure the IKE mode to be aggressive mode.
- B. Use unique Diffie Hellman groups on each VPN interface.
- C. Specify a unique peer ID for each dial-up VPN interface.
- D. Use different proposals are used between the interfaces.
Answer: A,C
NEW QUESTION # 37
......
Certification Training for NSE7_SDW-7.2 Exam Dumps Test Engine: https://www.dumpstorrent.com/NSE7_SDW-7.2-exam-dumps-torrent.html
NSE7_SDW-7.2 Training & Certification Get Latest NSE 7 Network Security Architect : https://drive.google.com/open?id=1ppOrf5PyPTx9oIYiPXDJN_2n6qT_TKZI