Practice on 2024 LATEST NSE7_SDW-7.2 Exam Updated 85 Questions
Download Latest NSE7_SDW-7.2 Dumps with Authentic Real Exam QA's
NEW QUESTION # 29
Which two statements about the SD-WAN zone configuration are true? (Choose two.)
- A. An SD-WAN member can belong to two or more zones.
- B. The default zones are virtual-wan-link and SASE.
- C. The service-sla-tie-break setting enables you to configure preferred member selection based on the best route to the destination.
- D. You can delete the default zones.
Answer: B,C
NEW QUESTION # 30
Refer to the exhibit.
FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections
to match all possible IPsec dial-up interfaces? (Choose two.)
- A. Use unique Diffie Hellman groups on each VPN interface.
- B. Specify a unique peer ID for each dial-up VPN interface.
- C. Configure the IKE mode to be aggressive mode.
- D. Use different proposals are used between the interfaces.
Answer: B,C
NEW QUESTION # 31
Refer to the exhibit.
Which statement explains the output shown in the exhibit?
- A. FortiGate must re-evaluate the session due to routing change.
- B. FortiGate performed standard FIB routing on the session.
- C. FortiGate used 192.2.0.1 as the gateway for the original direction of the traffic.
- D. FortiGate will not re-evaluate the session following a firewall policy change.
Answer: A
Explanation:
The snat-route-change option is enabled by default. This option enables FortiGate to re-evaluate the routing table and select a new egress interface if the next hop IP address changes. This option only applies to sessions in the dirty state. Sessions in the log state are not affected by routing changes.
NEW QUESTION # 32
Which are two benefits of using CLI templates in FortiManager? (Choose two.)
- A. You can configure FortiManager to sync local configuration changes made on the managed device, to
the CLI template. - B. You can configure interfaces as SD-WAN members without having to remove references first.
- C. You can configure advanced CLI settings.
- D. You can reference meta fields.
Answer: C,D
NEW QUESTION # 33
Exhibit.
Which conclusion about the packet debug flow output is correct?
- A. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
- B. The packet size exceeded the outgoing interface MTU.
- C. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
- D. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
Answer: C
Explanation:
In a Per-IP shaper configuration, if an IP address exceeds the configured concurrent session limit, the message "Denied by quota check" appears. SD-WAN 7.0 Study Guide page 287
NEW QUESTION # 34
Refer to the exhibit.
The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate appliance that supports hardware offloading. Based on the information shown in the exhibits, which two statements about the session are true? (Choose two.)
- A. The auxiliary session can be offloaded to hardware.
- B. The reply direction of the asymmetric traffic flows from port2 to port3.
- C. The main session cannot be offloaded to hardware.
- D. The original direction of the symmetric traffic flows from port3 to port2.
Answer: A,B
NEW QUESTION # 35
Refer to the exhibit.
The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured packet loss will make T_INET_1_0 the new preferred member?
- A. When T_INET_1_0 has 4% packet loss.
- B. When all three members have the same packet loss.
- C. When T_INET_0_0 has 4% packet loss.
- D. When T_INET_0_0 has 12% packet loss.
Answer: B
NEW QUESTION # 36
Refer to the exhibit.
Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?
- A. All traffic from a source IP is sent to the same interface.
- B. All traffic from a source IP to a destination IP is sent to the least used interface.
- C. All traffic from a source IP is sent to the most used interface.
- D. All traffic from a source IP to a destination IP is sent to the same interface.
Answer: D
Explanation:
Explanation
Study Guide 7.2, page 176.
NEW QUESTION # 37
Refer to the exhibit.
The exhibit shows the details of a session and the index numbers of some relevant interfaces on a FortiGate
appliance that supports hardware offloading. Based on the information shown in the exhibits, which two
statements about the session are true? (Choose two.)
- A. The auxiliary session can be offloaded to hardware.
- B. The reply direction of the asymmetric traffic flows from port2 to port3.
- C. The main session cannot be offloaded to hardware.
- D. The original direction of the symmetric traffic flows from port3 to port2.
Answer: A,B
NEW QUESTION # 38
Refer to the exhibit.
Which are two expected behaviors of the traffic that matches the traffic shaper? (Choose two.)
- A. The number of simultaneous connections among all source IP addresses cannot exceed five connections.
- B. The traffic shaper limits the bandwidth of each source IP address to a maximum of 625 KB/sec.
- C. The traffic shaper limits the combined bandwidth of all connections to a maximum of 5 MB/sec.
- D. The number of simultaneous connections allowed for each source IP address cannot exceed five connections.
Answer: B,D
NEW QUESTION # 39
Refer to the exhibit.
The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths.
However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.
Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)
- A. Set advertisement-interval to the number of additional paths to advertise
- B. Enable soft-reconfiguration
- C. Enable route-reflector-client
- D. Set additional-path to send
- E. Set adv-additional-path to the number of additional paths to advertise
Answer: C,D,E
NEW QUESTION # 40
Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?
- A. diagnose debug application ike
- B. get ipsec tunnel list
- C. get router info routing-table all
- D. diagnose vpn tunnel list
Answer: A
Explanation:
Explanation
IKE real-time debug - useful when debugging ADVPN shortcut messages and spoke-to-spoke negotiations.
* diagnose debug console timestamp enable
* diagnose vpn ike log filter clear
* diagnose vpn ike log filter mdst-addr4 <ip.of.hub> <ip.of.spoke>
* diagnose debug application ike -1
* diagnose debug enable
NEW QUESTION # 41
What is a benefit of using application steering in SD-WAN?
- A. You steer traffic based on the detected application.
- B. You do not need to configure firewall policies that accept the SD-WAN traffic.
- C. You do not need to enable SSL inspection.
- D. The traffic always skips the regular policy routes.
Answer: A
NEW QUESTION # 42
Which two performance SLA protocols enable you to verify that the server response contains a specific value? (Choose two.)
- A. http
- B. twamp
- C. icmp
- D. dns
Answer: A,D
NEW QUESTION # 43
Refer to the exhibit.
Based on the exhibit, which action does FortiGate take?
- A. FortiGate brings down port5 after it detects all SD-WAN members as dead.
- B. FortiGate brings up port5 after it detects all SD-WAN members as alive.
- C. FortiGate fails over to the secondary device after it detects all SD-WAN members as dead.
- D. FortiGate bounces port5 after it detects all SD-WAN members as dead.
Answer: C
NEW QUESTION # 44
Refer to the exhibits.
Exhibit A
Exhibit B -
Exhibit A shows the configuration for an SD-WAN rule and exhibit B shows the respective rule status, the routing table, and the member status.
The administrator wants to understand the expected behavior for traffic matching the SD-WAN rule.
Based on the exhibits, what can the administrator expect for traffic matching the SD-WAN rule?
- A. The traffic will be routed over T_INET_0_0.
- B. The traffic will be load balanced across all three overlays.
- C. The traffic will be routed over T_INET_1_0.
- D. The traffic will be routed over T_MPLS_0.
Answer: C
NEW QUESTION # 45
Refer to the exhibit.
The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?
- A. When T_N1PLS_0 has a latency of 80 ms.
- B. When T_MPLS_0 has a latency of 100 ms.
- C. When T_INET_0_0 and T_MPLS_0 have the same latency.
- D. When T_INET_0_0 has a latency of 250 ms.
Answer: A
NEW QUESTION # 46
Exhibit.
The exhibit shows VPN event logs on FortiGate. In the output shown in the exhibit, which statement is true?
- A. There is one shortcut tunnel built from master tunnel T_MPLS_0.
- B. There are no IPsec tunnel statistics log messages for ADVPN cuts.
- C. The master tunnel T_INET_0 cannot accept the ADVPN shortcut.
- D. The VPN tunnel T_MPLS_0 is a shortcut tunnel.
Answer: A
Explanation:
VPN event logs record the status of VPN tunnels, such as the establishment, termination, or failure of a tunnel.
The output includes the following information:
logid: the log ID number
type: the log type, either traffic or event
subtype: the log subtype, either vpn or ipsec
level: the log level, either error, warning, or notice
vd: the virtual domain name
logdesc: the log description
msg: the log message
action: the log action, such as tunnel-up, tunnel-down, or tunnel-stats remip: the remote IP address locip: the local IP address remport: the remote port number locport: the local port number outintf: the outgoing interface name cookies: the IKE SA cookies user: the user name group: the user group name useralt: the alternative user name xauthuser: the XAuth user name authgroup: the XAuth user group name assignip: the assigned IP address vpntunnel: the VPN tunnel name tunnellip: the tunnel loopback IP address tunnelid: the tunnel ID number tunneltype: the tunnel type, either ipsec or ssl duration: the tunnel duration in seconds sentbyte: the number of bytes sent rcvdbyte: the number of bytes received nextstat: the next statistics interval in seconds advpnsc: the ADVPN shortcut flag, either 0 or 1 Based on the exhibit, the following statement is true:
There is one shortcut tunnel built from master tunnel T_MPLS_0. This means that the VPN tunnel T_MPLS_0 is a master tunnel that can send ADVPN shortcut offers to other spokes, and the VPN tunnel T_MPLS_0_0 is a shortcut tunnel that is built from the master tunnel T_MPLS_01. In the exhibit, the log action for T_MPLS_0 is tunnel-up, and the log action for T_MPLS_0_0 is shortcut-up. The advpnsc flag for T_MPLS_0 is 0, indicating that it is not a shortcut tunnel, while the advpnsc flag for T_MPLS_0_0 is 1, indicating that it is a shortcut tunnel.
NEW QUESTION # 47
Refer to the exhibit.
Which conclusion about the packet debug flow output is correct?
- A. The original traffic exceeded the maximum packets per second of the outgoing interface, and the packet was dropped.
- B. The original traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.
- C. The reply traffic exceeded the maximum bandwidth configured in the traffic shaper, and the packet was dropped.
- D. The original traffic exceeded the maximum bandwidth of the outgoing interface, and the packet was dropped.
Answer: B
NEW QUESTION # 48
Refer to the exhibit.
Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)
- A. auto-discovery-forwarder must be enabled on all IPsec VPNs.
- B. On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.
- C. On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.
- D. On the hubs, net-device must be enabled on all IPsec VPNs.
Answer: B,C
NEW QUESTION # 49
Refer to the exhibits.
Exhibit A shows two IPsec templates to define Branch_IPsec_1 and Branch_IPsec_2. Each template defines a VPN tunnel.
Exhibit B shows the error message that FortiManager displayed when the administrator tried to assign the second template to the FortiGate device.
Which statement best explain the cause for this issue?
- A. You should review the branch1_fgt configuration for the already configured tunnel with the name HUB1-VPN2.
- B. You can define only one IPsec tunnel from branch devices to HUB1.
- C. You can assign only one template with a tunnel of fype static to each FortiGate device
- D. You can assign only one IPsec template to each FortiGate device.
Answer: A
Explanation:
The error message indicates that there is a conflict between the IPsec templates Branch_IPsec_1 and Branch_IPsec_2 for the device branch1_fgt. This means that the device already has an IPsec tunnel with the name HUB1-VPN2 configured, and the second template is trying to assign the same name to another tunnel.
This is not allowed, as each IPsec tunnel must have a unique name. Therefore, the administrator should review the branch1_fgt configuration and either delete or rename the existing tunnel with the name HUB1-VPN2 before assigning the second template. References = IPsec tunnel templates, IPsec VPN template
6.4.3, Understand and Use Debug Commands to Troubleshoot IPsec, L2L VPN TroubleShooting :"IPSec policy invalidated proposal with error ...
NEW QUESTION # 50
......
Authentic NSE7_SDW-7.2 Exam Dumps PDF - Jul-2024 Updated: https://protechtraining.actualtestsit.com/Fortinet/NSE7_SDW-7.2-exam-prep-dumps.html