Latest Fortinet NSE7_SDW-6.4 Exam questions and answers
Test4Engine NSE7_SDW-6.4 Exam Practice Test Questions (Updated 37 Questions)
NEW QUESTION 19
An administrator is troubleshooting VoIP quality issues that occur when calling external phone numbers The SD-WAN interface on the edge FortiGate is configured with the default settings, and is using two upstream links One link has random jitter and latency issues and is based on a wireless connection Which two actions must the administrator apply simultaneously on the edge FortiGate to improve VoIP quality using SD_WAN rules?
- A. Select the corresponding SD-WAN balancing strategy in the SD-WAN rule
- B. Use the performance SLA targets to detect latency and jitter instantly.
- C. Place the troublesome link at the top of the interface preference list.
- D. Configure an SD-WAN rule to load balance all traffic without VoIP
- E. Choose the suitable interface based on the interface cost and weight
Answer: B,E
NEW QUESTION 20
Which statement is correct about the SD-WAN and ADVPN?
- A. Spoke support dynamic VPN as a static interface.
- B. ADVPN interface can be a member of SD-WAN interface.
- C. Dynamic VPN is not supported as an SD-Wan interface.
- D. Hub FortiGate is limited to use ADVPN as SD-WAN member interface.
Answer: C
NEW QUESTION 21
What are two roles that SD-WAN orchestrator plays when it works with FortiManager? (Choose two )
- A. It configures and monitors SD-WAN networks on FortiGate devices that are managed by FortiManager.
- B. It acts as an application that is released and signed by Fortinet to run as a part of management extensions on FortiManager.
- C. It acts as a standalone device to assist FortiManager to manage SD-WAN interfaces on the managed FortiGate devices.
- D. It acts as a hub FortiGate with an SD-WAN interface enabled and managed along with other FortiGate devices by FortiManager.
Answer: B,C
NEW QUESTION 22
Refer to the exhibit.
What must you configure to enable ADVPN?
- A. ADVPN should only be enabled on unmanaged FortiGate devices.
- B. The protected subnets should be set to address object to all (0.0 .0. o/o).
- C. Each VPN device has a unique pre-shared key configured separately on phase one
- D. On the hub VPN, only the device needs additional phase one sett
Answer: C
NEW QUESTION 23
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SO-WAN interface and the static routes configuration.
Port1 and port2 are member interfaces of the SD-WAN, and port2 becomes a dead member after reaching the failure thresholds Which statement about the dead member is correct?
- A. Dead members require manual administrator access to bring them back alive
- B. SD-WAN interface becomes disabled and port1 becomes the WAN interface
- C. Port2 might become alive when a single response is received from an SLA server
- D. Subnets 100 .64-1.0/23 and 172 . 20 . 0. 0/16 are reachable only through port1
Answer: B
NEW QUESTION 24
Which statement about using BGP routes in SD-WAN is true?
- A. Adding static routes must be enabled on all ADVPN interfaces.
- B. Learned routes can be used as dynamic destinations in SD-WAN rules.
- C. VPN topologies must be form using only BGP dynamic routing with SD-WAN.
- D. Dynamic routing protocols can be used only with non-encrypted traffic.
Answer: B
Explanation:
Explanation/Reference:
https://www.fortinetguru.com/2019/09/using-bgp-tags-with-sd-wan-rules-fortios-6-2/#:~:text=SD%2DWAN%
20rules%20can%20use,to%20the%20customer's%20data%20center.
NEW QUESTION 25
Which statement about using BGP routes in SD-WAN is true?
- A. Dynamic routing protocols can be used only with non-encrypted traffic
- B. Adding static routes must be enabled on all ADVPN interfaces.
- C. Learned routes can be used as dynamic destinations in SD-WAN rules
- D. VPN topologies must be form using only BGP dynamic routing with SD-WAN
Answer: C
NEW QUESTION 26
What is the lnkmtd process responsible for?
- A. Monitoring links for any bandwidth saturation
- B. Flushing route tags addresses
- C. Logging interface quality information
- D. Processing performance SLA probes
Answer: C
NEW QUESTION 27
Which two reasons make forward error correction (FEC) ideal to enable in a phase one VPN interface? (Choose two )
- A. FEC is useful to increase speed at which traffic is routed through IPsec tunnels.
- B. FEC improves reliability which overcomes adverse WAN conditions such as noisy links.
- C. FEC transmits additional packets as redundant data to the remote device.
- D. FEC transmits the original payload in full to recover the error in transmission.
- E. FEC reduces the stress on the remote device jitter buffer to reconstruct packet loss
Answer: B,C
NEW QUESTION 28
Which components make up the secure SD-WAN solution?
- A. Telephone, ISDN, and telecom network.
- B. Application, antivirus, and URL, and SSL inspection
- C. Datacenter, branch offices, and public cloud
- D. FortiGate, FortiManager, FortiAnalyzer, and FortiDeploy
Answer: D
NEW QUESTION 29
Which diagnostic command can you use to show the SD-WAN rules interface information and state?
- A. diagnose sys virtual-wan-link route-tag-list
- B. diagnose sys virtual-wan-link neighbor.
- C. diagnose sys virtual-wan-link member.
- D. diagnose sys virtual-wan-link service
Answer: C
NEW QUESTION 30
Refer to exhibits.

Exhibit A shows the SD-WAN rules and exhibit B shows the traffic logs. The SD-WAN traffic logs reflect how FortiGate processed traffic.
Which two statements about how the configured SD-WAN rules are processing traffic are true? (Choose two.)
- A. The initial session of an application goes through a learning phase in order to apply the correct rule.
- B. The implicit rule overrides all other rules because parameters widely cover sources and destinations.
- C. SD-WAN rules are evaluated in the same way as firewall policies: from top to bottom.
- D. The All_Access_Rules rule load balances Vimeo application traffic among SD-WAN member interfaces.
Answer: B,C
NEW QUESTION 31
Refer to the exhibit.
Which statement about the command route-tag in the SD-WAN rule is true?
- A. It uses route tags for a BGP community and assigns the SD-WAN rules with same tag.
- B. It enables the SD-WAN rule to load balance and assign traffic with a route tag
- C. It ensures route tags match the SD-WAN rule based on the rule order
- D. It tags each route and references the tag in the routing table.
Answer: C
NEW QUESTION 32
Refer to the exhibit.
Multiple IPsec VPNs are formed between two hub-and-spokes groups, and site-to-site between Hub 1 and Hub 2 The administrator configured ADVPN on the dual regions topology
Which two statements are correct if a user in Toronto sends traffic to London? (Choose two )
- A. The first packets from Toronto to London are routed through Hub 1 then to Hub 2.
- B. Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN
- C. London generates an IKE information message that contains the Toronto public IP address
- D. Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.
Answer: B,D
NEW QUESTION 33
Refer to exhibits.
Exhibit A.

Exhibit A shows the performance SLA exhibit B shows the SD-WAN diagnostics output Based on the exhibits, which statement is correct?
- A. Both SD-WAN member interfaces have used separate SLA targets.
- B. Port1 became dead 1ecause no traffic was offload through the egress of port1.
- C. SD-WAN member interfaces are affected by the SLA state of the inactive interface
- D. The SLA state of port1 is dead after five unanswered requests by the SLA servers.
Answer: A
NEW QUESTION 34
Which statement reflects how BGP tags work with SD-WAN rules?
- A. BGP tags match the SD-WAN rule based on the order that these rules were installed.
- B. VPN topologies are formed using only BGP dynamic routing with SD-WAN
- C. Route tags are used for a BGP community and the SD-WAN rules are assigned the same tag
- D. BGP tags require that the adding of static routes be enabled on all ADVPN interfaces
Answer: B
NEW QUESTION 35
What are two reasons why FortiGate would be unable to complete the zero-touch provisioning process? (Choose two.)
- A. FortiDeploy has connected with FortiGate and provided the initial configuration to contact FortiManager
- B. The zero-touch provisioning process has completed internally, behind FortiGate.
- C. A factory reset performed on FortiGate.
- D. The FortiGate cloud key has not been added to the FortiGate cloud portal.
- E. FortiGate has obtained a configuration from the platform template in FortiGate cloud.
Answer: B,D
NEW QUESTION 36
Refer to the exhibit.
Which two statements about the debug output are correct? (Choose two )
- A. The debug output shows per-lP shaper values and real-time readings.
- B. Traffic being controlled by the traffic shaper is under 1 Kbps
- C. FortiGate provides statistics and readings based on historical traffic logs.
- D. This traffic shaper drops traffic that exceeds the set limits.
Answer: A,C
NEW QUESTION 37
Refer to the exhibit.
What must you configure to enable ADVPN?
- A. The protected subnets should be set to address object to all (0.0.0.0/0).
- B. On the hub VPN, only the device needs additional phase one settings.
- C. ADVPN should only be enabled on unmanaged FortiGate devices.
- D. Each VPN device has a unique pre-shared key configured separately on phase one.
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 38
What would best describe the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?
- A. Reverse policy shaping mode
- B. Interface-based shaping mode
- C. Per-IP shaping mode
- D. Shared policy shaping mode
Answer: D
NEW QUESTION 39
Which diagnostic command can you use to show the SD-WAN rules interface information and state?
- A. diagnose sys virtual-wan-link route-tag-list
- B. diagnose sys virtual-wan-link neighbor.
- C. diagnose sys virtual-wan-link member.
- D. diagnose sys virtual-wan-link service
Answer: B
NEW QUESTION 40
An administrator is troubleshooting VoIP quality issues that occur when calling external phone numbers. The SD-WAN interface on the edge FortiGate is configured with the default settings, and is using two upstream links. One link has random jitter and latency issues, and is based on a wireless connection.
Which two actions must the administrator apply simultaneously on the edge FortiGate to improve VoIP quality using SD-WAN rules? (Choose two.)
- A. Select the corresponding SD-WAN balancing strategy in the SD-WAN rule.
- B. Use the performance SLA targets to detect latency and jitter instantly.
- C. Configure an SD-WAN rule to load balance all traffic without VoIP.
- D. Place the troublesome link at the top of the interface preference list.
- E. Choose the suitable interface based on the interface cost and weight.
Answer: A,B
NEW QUESTION 41
......
Fortinet NSE7_SDW-6.4 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
Pass Your Fortinet Exam with NSE7_SDW-6.4 Exam Dumps: https://www.test4engine.com/NSE7_SDW-6.4_exam-latest-braindumps.html
Pass NSE7_SDW-6.4 Exam Info and Free Practice Test : https://drive.google.com/open?id=1NWVr7GpIeXwav7DEkFkmUAhIZFvHfZJ_