Regular Free Updates NSE7_SDW-7.2 Dumps Real Exam Questions Test Engine Apr 13, 2024
Practice Test Questions Verified Answers As Experienced in the Actual Test!
NEW QUESTION # 18
Exhibit.
The exhibit shows the output of the command diagnose sys sdwan health-check status collected on a FortiGate
device. Which two statements are correct about the health check status on this FortiGate device? (Choose
two.)
- A. There is no SLA criteria configured for the health-check Level3_DNS.
- B. The interface T_INET_0 missed three SLA targets.
- C. The interface T_INET_1 missed one SLA target.
- D. The health-check VPN_PING orders the members according to the lowest jitter.
Answer: A,D
Explanation:
Explanation
According to the FortiGate / FortiOS 6.4.2 Administration Guide, the health check status command displays
the status of the health check probes for each SD-WAN member interface. The output includes the following
information:
state: the current state of the interface, either alive or dead
packet-loss: the percentage of packets lost during the health check
latency: the average round-trip time in milliseconds
jitter: the variation in latency
mos: the mean opinion score, a measure of voice quality
bandwidth: the available bandwidth in kilobits per second for each direction (up, down, bi)
sla map: a bitmap that indicates which SLA criteria are met or failed
Based on the exhibit, the following statements are correct:
The health-check VPN_PING orders the members according to the lowest jitter. This means that the
interface with the lowest jitter value is listed first, followed by the next lowest, and so on1. In the
exhibit, the order is T_MPLS, T_INET_1, and T_INET_0.
There is no SLA criteria configured for the health-check Level3_DNS. This means that the health check
does not use any SLA parameters to determine the state of the interface2. In the exhibit, the sla map
value is 0x0 for both port1 and port2, indicating that no SLA criteria are applied.
NEW QUESTION # 19
Refer to the exhibit.
The device exchanges routes using IBGP.
Which two statements are correct about the IBGP configuration and routing information on the device?
(Choose two.)
- A. ibgp-multipath is disabled.
- B. Each BGP route is three hops away from the destination.
- C. You can run the get router info routing-table database command to display the additional paths.
- D. additional-path is enabled.
Answer: C,D
NEW QUESTION # 20
What are two reasons for using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two.)
- A. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
- B. It improves SD-WAN performance on the managed FortiGate devices.
- C. It acts as a policy compliance entity to review all managed FortiGate devices.
- D. It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
- E. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
Answer: A,E
NEW QUESTION # 21
Refer to the exhibit.
The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants
BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths.
However, when looking at the spoke routing table, the administrator does not see the prefixes from other
spokes and the additional paths.
Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so
spokes can learn other spokes prefixes and their additional paths? (Choose three.)
- A. Enablesoft-reconfiguration
- B. Enableroute-reflector-client
- C. Setadvertisement-intervalto the number of additional paths to advertise
- D. Setadv-additional-pathto the number of additional paths to advertise
- E. Setadditional-pathtosend
Answer: B,D,E
NEW QUESTION # 22
Which three matching traffic criteria are available in SD-WAN rules? (Choose three.)
- A. Source and destination IP address
- B. Type of physical link connection
- C. Internet service database (ISDB) address object
- D. URL categories
- E. Application signatures
Answer: B,C,E
NEW QUESTION # 23
Which are three key routing principles in SD-WAN? (Choose three.)
- A. SD-WAN rules have precedence over ISDB routes.
- B. FortiGate performs route lookups for new sessions only.
- C. Regular policy routes have precedence over SD-WAN rules.
- D. By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.
- E. By default, SD-WAN members are skipped if they do not have a valid route to the destination.
Answer: C,D,E
Explanation:
Explanation
Study Guide 7.2, pages 125, 129, 151
NEW QUESTION # 24
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator determines that FortiGate does not apply traffic shaping on YouTube traffic.
Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs traffic shaping on YouTube traffic?
- A. Destination internet service must be enabled on the traffic shaping policy.
- B. Application control must be enabled on the firewall policy.
- C. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.
- D. Web filtering must be enabled on the firewall policy.
Answer: B
NEW QUESTION # 25
What is the route-tag setting in an SD-WAN rule used for?
- A. To indicate the members that can be used to route SD-WAN traffic.
- B. To indicate the routes that can be used for routing SD-WAN traffic.
- C. To indicate the destination of a rule based on learned BGP prefixes.
- D. To indicate the routes for health check probes.
Answer: C
NEW QUESTION # 26
Which diagnostic command can you use to show the member utilization statistics measured by performance SLAs for the last 10 minutes?
- A. diagnose ays sdwan health-check
- B. diagnose sys sdwan sla-log
- C. diagnose sys sdwan intf-sla-log
- D. diagnose sys sdwan log
Answer: B
NEW QUESTION # 27
Refer to the exhibit.
Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN
shortcut? (Choose two.)
- A. On the spokes,auto-discovery-receivermust be enabled on the IPsec VPN to the hub.
- B. On the hubs,net-devicemust be enabled on all IPsec VPNs.
- C. auto-discovery-forwardermust be enabled on all IPsec VPNs.
- D. On the hubs,auto-discovery-sendermust be enabled on the IPsec VPNs to spokes.
Answer: A,D
NEW QUESTION # 28 
Which two conclusions for traffic that matches the traffic shaper are true? (Choose two.)
- A. The traffic shaper drops packets if the bandwidth is less than 2500 KBps.
- B. The measured bandwidth is less than 100 KBps.
- C. The traffic shaper drops packets if the bandwidth exceeds 6250 KBps.
- D. The traffic shaper limits the bandwidth of each source IP to a maximum of 6250 KBps.
Answer: B,C
NEW QUESTION # 29
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit A shows an SD-WAN event log and exhibit B shows the member status and the SD-WAN rule configuration.
Based on the exhibits, which two statements are correct? (Choose two.)
- A. FortiGate updated the outgoing interface list on the rule so it prefers port2.
- B. Port2 has the highest member priority.
- C. SD-WAN rule ID 1 is set to lowest cost (SLA) mode.
- D. Port2 has a lower latency than port1.
Answer: A,D
NEW QUESTION # 30
Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?
- A. diagnose vpn tunnel list
- B. diagnose debug application ike
- C. get router info routing-table all
- D. get ipsec tunnel list
Answer: B
Explanation:
IKE real-time debug - useful when debugging ADVPN shortcut messages and spoke-to-spoke negotiations.
* diagnose debug console timestamp enable
* diagnose vpn ike log filter clear
* diagnose vpn ike log filter mdst-addr4 <ip.of.hub> <ip.of.spoke>
* diagnose debug application ike -1
* diagnose debug enable
NEW QUESTION # 31
Which two statements are true about using SD-WAN to steer local-out traffic? (Choose two.)
- A. FortiGate does not consider the source address of the packet when matching an SD-WAN rule for local-out traffic.
- B. By default, local-out traffic does not use SD-WAN.
- C. You must configure each local-out feature individually, to use SD-WAN.
- D. By default, FortiGate does not check if the selected member has a valid route to the destination.
Answer: B,C
NEW QUESTION # 32
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows the traffic shaping policy and exhibit B shows the firewall policy.
The administrator wants FortiGate to limit the bandwidth used by YouTube. When testing, the administrator
determines that FortiGate does not apply traffic shaping on YouTube traffic.
Based on the policies shown in the exhibits, what configuration change must be made so FortiGate performs
traffic shaping on YouTube traffic?
- A. Destination internet service must be enabled on the traffic shaping policy.
- B. Application control must be enabled on the firewall policy.
- C. Individual SD-WAN members must be selected as the outgoing interface on the traffic shaping policy.
- D. Web filtering must be enabled on the firewall policy.
Answer: B
NEW QUESTION # 33
......
Pass Fortinet NSE7_SDW-7.2 Exam in First Attempt Easily: https://www.suretorrent.com/NSE7_SDW-7.2-exam-guide-torrent.html
The Most Efficient NSE7_SDW-7.2 Pdf Dumps For Assured Success : https://drive.google.com/open?id=1HCq98bYoeIpHJxuntIxplpVLH8bNSU1v