Pass NSE7_SDW-7.2 Exam Latest Practice Questions Updated on Feb 28, 2025
Fortinet NSE7_SDW-7.2 Study Guide Archives
NEW QUESTION # 25
Refer to the exhibit.
Which are two expected behaviors of the traffic that matches the traffic shaper? (Choose two.)
- A. The traffic shaper limits the bandwidth of each source IP address to a maximum of 625 KB/sec.
- B. The number of simultaneous connections among all source IP addresses cannot exceed five connections.
- C. The traffic shaper limits the combined bandwidth of all connections to a maximum of 5 MB/sec.
- D. The number of simultaneous connections allowed for each source IP address cannot exceed five
connections.
Answer: A,D
NEW QUESTION # 26
Refer to the exhibit.
FortiGate has multiple dial-up VPN interfaces incoming on port1 that match only FIRST_VPN.
Which two configuration changes must be made to both IPsec VPN interfaces to allow incoming connections to match all possible IPsec dial-up interfaces? (Choose two.)
- A. Specify a unique peer ID for each dial-up VPN interface.
- B. Use different proposals are used between the interfaces.
- C. Configure the IKE mode to be aggressive mode.
- D. Use unique Diffie Hellman groups on each VPN interface.
Answer: A,C
NEW QUESTION # 27 
Exhibit B -
Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.
Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?
- A. port1 is assigned a manual IP address.
- B. port1 is referenced in a firewall policy.
- C. port2 is referenced in a static route.
- D. port1 and port2 are not administratively down.
Answer: B
NEW QUESTION # 28
Refer to the exhibit.
An administrator is troubleshooting SD-WAN on FortiGate. A device behind branch1_fgt generates traffic to
the 10.0.0.0/8 network. The administrator expects the traffic to match SD-WAN rule ID 1 and be routed over
T_INET_0_0. However, the traffic is routed over T_INET_1_0.
Based on the output shown in the exhibit, which two reasons can cause the observed behavior? (Choose two.)
- A. T_INET_1_0 has a higher member configuration priority than T_INET_0_0.
- B. T_INET_0_0 does not have a valid route to the destination.
- C. T_INET_1_0 has a lower route priority value (higher priority) than T_INET_0_0.
- D. The traffic matches a regular policy route configured with T_INET_1_0 as the outgoing device.
Answer: B,D
NEW QUESTION # 29
Which statement about using BGP for ADVPN is true?
- A. IBGP is preferred over EBGP, because IBGP preserves next hop information.
- B. You must use BGP to route traffic for both overlay and underlay links.
- C. You must configure AS path prepending.
- D. You must configure BGP communities.
Answer: A
Explanation:
ADVPN is a technology that allows dynamic creation of IPsec tunnels between branch sites without requiring pre-configured policies or keys. BGP is a routing protocol that can be used to exchange routes between ADVPN peers. IBGP is a type of BGP that runs between routers in the same autonomous system (AS), while EBGP is a type of BGP that runs between routers in different ASes. IBGP is preferred over EBGP for ADVPN, because IBGP preserves the next hop information of the routes, which is needed to establish the IPsec tunnels. EBGP changes the next hop information to the EBGP peer address, which may not be reachable by the ADVPN peers. Therefore, using IBGP for ADVPN avoids the need to configure additional static routes or redistribute routes between BGP and another routing protocol. References = ADVPN with BGP as the routing protocol, ADVPN, SD-WAN self-healing with BGP, Technical Tip: ADVPN with BGP as the routing protocol
NEW QUESTION # 30
Refer to the exhibit.
Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)
- A. Priority
- B. Cost
- C. Gateway IP
- D. Interface member
Answer: C,D
NEW QUESTION # 31
Which two statements are correct when traffic matches the implicit SD-WAN rule? (Choose two.)
- A. The sdwan_service_id flag in the session information is 0.
- B. Traffic does not match any of the entries in the policy route table.
- C. All SD-WAN rules have the default setting enabled.
- D. Traffic is load balanced using the algorithm set for the v4-ecmp-mode setting.
Answer: A,B
Explanation:
Explanation
sdwan_service_id is 0 = match SD-WAN implicit rule, study guide 7.0 page 120, 7.2 page 149 SD-WAN rules
internally are interpreted as a Policy route, so when the traffic doesn't match with any policy route, it will be
flowing by implict policy.
NEW QUESTION # 32
What are two advantages of using an IPsec recommended template to configure an IPsec tunnel in an hub-and-spoke topology? (Choose two.)
- A. The VPN monitor tool provides additional statistics for tunnels defined with an IPsec recommended template.
- B. It ensures consistent settings between phase1 and phase2.
- C. It automatically install IPsec tunnels to every spoke when they are added to the FortiManager ADOM.
- D. It guides the administrator to use Fortinet recommended settings.
Answer: B,D
Explanation:
The use of an IPsec recommended template offers the advantage of ensuring consistent settings between phase1 and phase2 (A), which is essential for the stability and security of the IPsec tunnel. Additionally, it guides the administrator to use Fortinet's recommended settings (B), which are designed to optimize performance and security based on Fortinet's best practices. References: The benefits of using IPsec recommended templates are outlined in Fortinet's SD-WAN documentation, which emphasizes the importance of consistency and adherence to recommended configurations.
NEW QUESTION # 33
The SD-WAN overlay template helps to prepare SD-WAN deployments. To complete the tasks performed by
the SD-WAN overlay template, the administrator must perform some post-run tasks. What are three
mandatory post-run tasks that must be performed? (Choose three.)
- A. Configure routing through overlay tunnels created by the SD-WAN overlay template.
- B. Assign a branch_id metadata variable to each branch device.
- C. Create policy packages for branch devices.
- D. Configure SD-WAN rules.
- E. Assign an sdwan_id metadata variable to each device (branch and hub}.
Answer: A,C,E
NEW QUESTION # 34
Which best describes the SD-WAN traffic shaping mode that bases itself on a percentage of available
bandwidth?
- A. Shared-policy shaping mode
- B. Per-IP shaping mode
- C. Interface-based shaping mode
- D. Reverse-policy shaping mode
Answer: C
Explanation:
Explanation
Interface-based shaping goes further, enabling traffic controls based on percentage of the interface bandwidth.
NEW QUESTION # 35
Refer to the exhibit.
Which two SD-WAN template member settings support the use of FortiManager meta fields? (Choose two.)
- A. Priority
- B. Cost
- C. Gateway IP
- D. Interface member
Answer: C,D
NEW QUESTION # 36
In the default SD-WAN minimum configuration, which two statements are correct when traffic matches the
default implicit SD-WAN rule? (Choose two )
- A. Traffic has matched none of the FortiGate policy routes.
- B. The FIB lookup resolved interface was the SD-WAN interface.
- C. An absolute SD-WAN rule was defined and matched traffic.
- D. Matched traffic failed RPF and was caught by the rule.
Answer: A,B
NEW QUESTION # 37
Refer to the exhibit.
In a dual-hub hub-and-spoke SD-WAN deployment, which is a benefit of disabling the anti-replay setting on the hubs?
- A. It instructs the hub to skip content inspection on TCP traffic, to improve performance.
- B. It instructs the hub to disable TCP sequence number check, which is required for TCP sessions originated from spokes to fail over back and forth between the hubs.
- C. It instructs the hub to disable the reordering of TCP packets on behalf of the receiver, to improve performance.
- D. It instructs the hub to not check the ESP sequence numbers on IPsec traffic, to improve performance.
Answer: B
NEW QUESTION # 38
Exhibit.
Which conclusion about the packet debug flow output is correct?
- A. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the firewall policy, and the packet was dropped.
- B. The number of concurrent sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
- C. The packet size exceeded the outgoing interface MTU.
- D. The total number of daily sessions for 10.1.10.1 exceeded the maximum number of concurrent sessions configured in the traffic shaper, and the packet was dropped.
Answer: B
Explanation:
In a Per-IP shaper configuration, if an IP address exceeds the configured concurrent session limit, the message
"Denied by quota check" appears. SD-WAN 7.0 Study Guide page 287
NEW QUESTION # 39
Which statement about using BGP routes in SD-WAN is true?
- A. You must use BGP to route traffic for both overlay and underlay links.
- B. You must configure AS path prepending.
- C. Learned routes can be used as dynamic destinations in SD-WAN rules.
- D. You must use external BGP.
Answer: C
NEW QUESTION # 40
Refer to the exhibit, which shows the IPsec phase 1 configuration of a spoke.
What must you configure on the IPsec phase 1 configuration for ADVPN to work with SD-WAN?
- A. You must enable auto-discovery-sender.
- B. You must set ike-version to 1.
- C. You must enable net-device.
- D. You must disable idle-timeout.
Answer: C
NEW QUESTION # 41
Which action fortigate performs on the traffic that is subject to a per-IP traffic shaper of 10 Mbps?
- A. Fortigate limits each source ip address to a maximum bandwidth of 10 Mbps.
- B. FortiGate guarantees a minimum of 10 Mbps of bandwidth to each source IP address.
- C. FortiGate applies traffic shaping to the original traffic direction only.
- D. FortiGate shares 10 Mbps of bandwidth equally among all source IP addresses.
RIAS
Answer: A
NEW QUESTION # 42
Refer to the exhibit.
Which statement explains the output shown in the exhibit?
- A. FortiGate used192.2.0.1as the gateway for the original direction of the traffic.
- B. FortiGate performed standard FIB routing on the session.
- C. FortiGate must re-evaluate the session due to routing change.
- D. FortiGate will not re-evaluate the session following a firewall policy change.
Answer: C
Explanation:
Explanation
The snat-route-change option is enabled by default. This option enables FortiGate to re-evaluate the routing
table and select a new egress interface if the next hop IP address changes. This option only applies to sessions
in the dirty state. Sessions in the log state are not affected by routing changes.
NEW QUESTION # 43
Refer to the exhibits.
Exhibit A shows a policy package definition Exhibit B shows the install log that the administrator received when he tried to install the policy package on FortiGate devices.
Based on the output shown in the exhibits, what can the administrator do to solve the Issue?
- A. Use a metadata variable instead of a dynamic interface to define the firewall policy.
- B. Policies can refer to only one LAN source interface. Keep only the D-LAN, which is the dynamic LAN interface.
- C. Dynamic mapping should be done automatically. Review the LAN interface configuration for branch2_fgt.
- D. Create dynamic mapping for the LAN interface for all devices in the installation target list.
Answer: D
NEW QUESTION # 44
Which two interfaces are considered overlay links? (Choose two.)
- A. LAG
- B. IPsec
- C. GRE
- D. Physical
Answer: A
NEW QUESTION # 45
Refer to the exhibits.
Exhibit A -
Exhibit B -
Exhibit A shows a site-to-site topology between two FortiGate devices: branch1_fgt and dc1_fgt. Exhibit B shows the system global and system settings configuration on dc1_fgt.
When branch1_client establishes a connection to dc1_host, the administrator observes that, on dc1_fgt, the reply traffic is routed over T_INET_0_0, even though T_INET_1_0 is the preferred member in the matching SD-WAN rule.
Based on the information shown in the exhibits, what configuration change must be made on dc1_fgt so dc1_fgt routes the reply traffic over T_INET_1_0?
- A. Enable snat-route-change under config system global.
- B. Disable allow-subnet-overlap under config system settings.
- C. Disable tp-session-without-syn under config system settings.
- D. Enable auxiliary-session under config system settings.
Answer: D
NEW QUESTION # 46
......
NSE7_SDW-7.2 Questions Prepare with Learning Information: https://www.actual4labs.com/Fortinet/NSE7_SDW-7.2-actual-exam-dumps.html
Download NSE7_SDW-7.2 Mock Test Study Material: https://drive.google.com/open?id=13YZGVHZGN0SydFqEYTG5AMcSQNmWNfZT