The Fortinet NSE7_SDW-7.2 Questions & Practice Test are Available On-Demand [Q35-Q53]

Share

The Fortinet NSE7_SDW-7.2 Questions & Practice Test are Available On-Demand

Valid NSE7_SDW-7.2 Exam Dumps Ensure you a HIGH SCORE

NEW QUESTION # 35
Refer to the exhibit.

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

  • A. add-route must be disabled.
  • B. mode-cfg must be enabled.
  • C. exchange-interface-ip must be enabled.
  • D. type must be set to static.

Answer: A


NEW QUESTION # 36
Which two statements describe how IPsec phase 1 main mode id different from aggressive mode when performing IKE negotiation? (Choose two.)

  • A. Three packets are exchanged between an initiator and a responder instead of six packets.
  • B. A peer ID is included in the first packet from the initiator, along with suggested security policies.
  • C. XAuth is enabled as an additional level of authentication, which requires a username and password.
  • D. The use of Diffie Hellman keys is limited by the responder and needs initiator acceptance.

Answer: A,B


NEW QUESTION # 37
Refer to the exhibits.
Exhibit A

Exhibit B

Exhibit A shows the source NAT (SNAT) global setting and exhibit B shows the routing table on FortiGate.
Based on the exhibits, which two actions does FortiGate perform on existing sessions established over port2, if the administrator increases the static route priority on port2 to 20? (Choose two.)

  • A. FortiGate continues routing the sessions with no SNAT, over port2.
  • B. FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.
  • C. FortiGate performs a route lookup for the original traffic only.
  • D. FortiGate flags the sessions as dirty.

Answer: A,B


NEW QUESTION # 38
Refer to the exhibit.

Based on the exhibit, which two statements are correct about the health of the selected members? (Choose two.)

  • A. After FortiGate switches to active mode, FortiGate never fails back to passive monitoring.
  • B. During passive monitoring, FortiGate can't detect dead members.
  • C. FortiGate passively monitors the member if TCP traffic is passing through the member.
  • D. FortiGate can offload the traffic that is subject to passive monitoring to hardware.

Answer: B,C


NEW QUESTION # 39
Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?

  • A. diagnose vpn tunnel list
  • B. diagnose debug application ike
  • C. get ipsec tunnel list
  • D. get router info routing-table all

Answer: B

Explanation:
IKE real-time debug - useful when debugging ADVPN shortcut messages and spoke-to-spoke negotiations.
* diagnose debug console timestamp enable
* diagnose vpn ike log filter clear
* diagnose vpn ike log filter mdst-addr4 <ip.of.hub> <ip.of.spoke>
* diagnose debug application ike -1
* diagnose debug enable


NEW QUESTION # 40
Refer to the exhibit.

Which statement about the role of the ADVPN device in handling traffic is true?

  • A. This is a hub that has received a query from a spoke and has forwarded it to another spoke.
  • B. Two spokes, 192.2.0.1 and 10.0.2.101, forward their queries to their hubs.
  • C. This is a spoke that has received a query from a remote hub and has forwarded the response to its hub.
  • D. Two hubs, 10.0.1.101 and 10.0.2.101, are receiving and forwarding queries between each other.

Answer: A


NEW QUESTION # 41
Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

  • A. When T_N1PLS_0 has a latency of 80 ms.
  • B. When T_MPLS_0 has a latency of 100 ms.
  • C. When T_INET_0_0 and T_MPLS_0 have the same latency.
  • D. When T_INET_0_0 has a latency of 250 ms.

Answer: A


NEW QUESTION # 42
Refer to the Exhibits:

Exhibit A, which shows the SD-WAN performance SLA and exhibit B shows the health of the participating SD-WAN members.
Based on the exhibits, which statement is correct?

  • A. FortiGate has not received three consecutive requests from the SLA server configured for port2.
  • B. Port2 needs to wait 500 milliseconds to change the status from alive to dead.
  • C. The dead member interface stays unavailable until an administrator manually brings the interface back.
  • D. Static routes using port2 are active in the routing table.

Answer: D


NEW QUESTION # 43
Refer to the exhibits.
Exhibit A

Exhibit B

Exhibit A shows the source NAT (SNAT) global setting and exhibit B shows the routing table on FortiGate.
Based on the exhibits, which two actions does FortiGate perform on existing sessions established over port2, if
the administrator increases the static route priority on port2 to 20? (Choose two.)

  • A. FortiGate flags the sessions as dirty.
  • B. FortiGate continues routing the sessions with no SNAT, over port2.
  • C. FortiGate updates the gateway information of the sessions with SNAT so that they use port1 instead of port2.
  • D. FortiGate performs a route lookup for the original traffic only.

Answer: A,C


NEW QUESTION # 44
Refer to the exhibit.

Two hub-and-spoke groups are connected through a site-to-site IPsec VPN between Hub 1 and Hub 2.
Which two configuration settings are required for Toronto and London spokes to establish an ADVPN shortcut? (Choose two.)

  • A. On the spokes, auto-discovery-receiver must be enabled on the IPsec VPN to the hub.
  • B. auto-discovery-forwarder must be enabled on all IPsec VPNs.
  • C. On the hubs, net-device must be enabled on all IPsec VPNs.
  • D. On the hubs, auto-discovery-sender must be enabled on the IPsec VPNs to spokes.

Answer: A,D


NEW QUESTION # 45
Which are three key routing principles in SD-WAN? (Choose three.)

  • A. SD-WAN rules have precedence over ISDB routes.
  • B. By default, SD-WAN members are skipped if they do not have a valid route to the destination.
  • C. FortiGate performs route lookups for new sessions only.
  • D. By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member.
  • E. Regular policy routes have precedence over SD-WAN rules.

Answer: B,D,E

Explanation:
Explanation
Study Guide 7.2, pages 125, 129, 151


NEW QUESTION # 46
Which two interfaces are considered overlay links? (Choose two.)

  • A. LAG
  • B. Physical
  • C. IPsec
  • D. GRE

Answer: A


NEW QUESTION # 47
Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI.

Based on the exhibit, which statement is true?

  • A. You can delete the virtual-wan-link zone because it contains no member.
  • B. The overlay zone contains four members.
  • C. The corporate zone contains no member.
  • D. You can move port1 from the underlay zone to the overlay zone.

Answer: C

Explanation:
Based on the exhibit, the "corporate" zone contains no member (B). In the FortiGate GUI, zones without members do not display any interfaces listed under them, which is the case for the corporate zone in the exhibit. References: This conclusion is based on standard Fortinet GUI interpretation and the operational logic of SD-WAN zones as per Fortinet's guidelines and user interface standards.


NEW QUESTION # 48

Exhibit B -

Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.
Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?

  • A. port2 is referenced in a static route.
  • B. port1 is assigned a manual IP address.
  • C. port1 is referenced in a firewall policy.
  • D. port1 and port2 are not administratively down.

Answer: C


NEW QUESTION # 49
Refer to the exhibit.

Which two statements about the IPsec VPN configuration and the status of the IPsec VPN tunnel are true? (Choose two.)

  • A. Dead peer detection is disabled.
  • B. FortiGate does not install IPsec static routes for remote protected networks in the routing table. Most Voted
  • C. FortiGate facilitated the negotiation of the T_INET_1_0_0 ADVPN shortcut over T_INET_1_0.
  • D. The phase 1 configuration supports the network-overlay setting. Most Voted

Answer: B,D


NEW QUESTION # 50
Refer to the exhibit.

The exhibit shows the SD-WAN rule status and configuration.
Based on the exhibit, which change in the measured latency will make T_MPLS_0 the new preferred member?

  • A. When T_N1PLS_0 has a latency of 80 ms.
  • B. When T_MPLS_0 has a latency of 100 ms.
  • C. When T_INET_0_0 and T_MPLS_0 have the same latency.
  • D. When T_INET_0_0 has a latency of 250 ms.

Answer: A


NEW QUESTION # 51
Refer to the exhibits.
Exhibit A -

Exhibit B -

Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SD-WAN member status, the routing table, and the performance SLA status.
If port2 is detected dead by FortiGate, what is the expected behavior?

  • A. FortiGate removes all static routes for port2.
  • B. Port2 becomes alive after three successful probes are detected.
  • C. Host 8.8.8.8 is reachable through port1 and port2.
  • D. The administrator manually restores the static routes for port2, if port2 becomes alive.

Answer: A

Explanation:
This is due to Update static route is enable which removes the static route entry referencing the interface if the interface is dead


NEW QUESTION # 52
Which two statements about the SD-WAN zone configuration are true? (Choose two.)

  • A. You can delete the default zones.
  • B. An SD-WAN member can belong to two or more zones.
  • C. Theservice-sla-tie-breaksetting enables you to configure preferred member selection based on the best
    route to the destination.
  • D. The default zones are virtual-wan-link and SASE.

Answer: C,D


NEW QUESTION # 53
......

NSE7_SDW-7.2 Exam Practice Questions prepared by Fortinet Professionals: https://examtorrent.dumpsactual.com/NSE7_SDW-7.2-actualtests-dumps.html