nse7_sdw-72

Here you have the best Fortinet nse7_sdw-72 practice exam questions

  • You have 60 total questions to study from
  • Each page has 5 questions, making a total of 12 pages
  • You can navigate through the pages using the buttons at the bottom
  • This questions were last updated on November 22, 2024
Question 1 of 60

Refer to the exhibit.

The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.

Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)

    Correct Answer: B, C, D

    To ensure that BGP can properly advertise prefixes from spokes to other spokes over the IPsec overlays and include additional paths, the administrator must configure the following settings inside each BGP neighbor group: Enable route-reflector-client, which is essential for reflecting routes to other BGP neighbors without the need for a full mesh configuration. Set additional-path to send enables the sending of multiple paths for the same prefix, thus allowing additional path advertisements. Set adv-additional-path to the number of additional paths to advertise, ensuring that the BGP router advertises additional paths to its BGP peers. These configurations collectively facilitate the desired routing behavior in the described BGP setup.

Question 2 of 60

What are two advantages of using an IPsec recommended template to configure an IPsec tunnel in an hub-and-spoke topology? (Choose two.)

    Correct Answer: A, B

    Using an IPsec recommended template ensures consistent settings between phase1 and phase2, which helps to maintain uniformity and avoid configuration errors. Additionally, it guides the administrator to use Fortinet recommended settings, providing best practices and reducing the likelihood of misconfiguration.

Question 3 of 60

Refer to the exhibit.

    Correct Answer: A

    When 'preserve-session-route enable' is configured on a FortiGate device, it prevents the reevaluation of session routing information for existing sessions, even after a route change. This means that any sessions already established do not have their routing information changed, and thus continue to use the old route. On the other hand, new sessions created after the route change will use the new routing paths. Therefore, FortiGate does not change the routing information on existing sessions after a route change, which aligns with the correct option.

Question 4 of 60

In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)

    Correct Answer: A, C

    In a hub-and-spoke topology, enabling ADVPN on the IPsec overlays provides the benefits of a full-mesh topology within a hub-and-spoke network, which enhances network efficiency and scalability. Additionally, it allows for direct connectivity between spokes by creating shortcuts, resulting in more efficient data transfer paths and reduced latency.

Question 5 of 60

Refer to the exhibit.

The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.

The administrator wants to know through which interface FortiGate will steer the traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the business application Salesforce located on HQ servers 10.0.0.1.

Based on the exhibits, which two statements are correct? (Choose two.)

    Correct Answer: C, D

    Service rule 1 is configured for the Internet Service categories of Facebook and Twitter, so traffic destined for Salesforce will not match this rule. Since Salesforce is categorized under business applications, service rule 2 applies, which specifies port2. If the application of the flow is not recognized, traffic will default to service rule 3. Therefore, the correct steering will be as per rule 2 for recognized business applications like Salesforce, and as per rule 3 when the application cannot be recognized.