Fortinet NSE 7 - SD-WAN 7.2

Here you have the best Fortinet NSE7_SDW-7.2 practice exam questions

  • You have 70 total questions across 14 pages (5 per page)
  • These questions were last updated on March 15, 2026
  • This site is not affiliated with or endorsed by Fortinet.
Question 1 of 70

Refer to the exhibit.
Exam NSE7_SDW-7.2: Question 1 - Image 1
The exhibit shows the BGP configuration on the hub in a hub-and-spoke topology. The administrator wants BGP to advertise prefixes from spokes to other spokes over the IPsec overlays, including additional paths. However, when looking at the spoke routing table, the administrator does not see the prefixes from other spokes and the additional paths.
Based on the exhibit, which three settings must the administrator configure inside each BGP neighbor group so spokes can learn other spokes prefixes and their additional paths? (Choose three.)
Answer

Suggested Answer

The suggested answer is B, C, D.

To ensure that BGP can properly advertise prefixes from spokes to other spokes over the IPsec overlays and include additional paths, the administrator must configure the following settings inside each BGP neighbor group: Enable route-reflector-client, which is essential for reflecting routes to other BGP neighbors without the need for a full mesh configuration. Set additional-path to send enables the sending of multiple paths for the same prefix, thus allowing additional path advertisements. Set adv-additional-path to the number of additional paths to advertise, ensuring that the BGP router advertises additional paths to its BGP peers. These configurations collectively facilitate the desired routing behavior in the described BGP setup.

Community Votes9 votes
BCDSuggested
100%
Question 2 of 70

What are two advantages of using an IPsec recommended template to configure an IPsec tunnel in an hub-and-spoke topology? (Choose two.)
Answer

Suggested Answer

The suggested answer is A, B.

Using an IPsec recommended template ensures consistent settings between phase1 and phase2, which helps to maintain uniformity and avoid configuration errors. Additionally, it guides the administrator to use Fortinet recommended settings, providing best practices and reducing the likelihood of misconfiguration.

Community Votes8 votes
ABSuggested
100%
Question 3 of 70

Refer to the exhibit.
Exam NSE7_SDW-7.2: Question 3 - Image 1
Answer

Suggested Answer

The suggested answer is A.

When 'preserve-session-route enable' is configured on a FortiGate device, it prevents the reevaluation of session routing information for existing sessions, even after a route change. This means that any sessions already established do not have their routing information changed, and thus continue to use the old route. On the other hand, new sessions created after the route change will use the new routing paths. Therefore, FortiGate does not change the routing information on existing sessions after a route change, which aligns with the correct option.

Community Votes15 votes
ASuggested
93%
C
7%
Question 4 of 70

In a hub-and-spoke topology, what are two advantages of enabling ADVPN on the IPsec overlays? (Choose two.)
Answer

Suggested Answer

The suggested answer is A, C.

In a hub-and-spoke topology, enabling ADVPN on the IPsec overlays provides the benefits of a full-mesh topology within a hub-and-spoke network, which enhances network efficiency and scalability. Additionally, it allows for direct connectivity between spokes by creating shortcuts, resulting in more efficient data transfer paths and reduced latency.

Community Votes3 votes
ACSuggested
100%
Question 5 of 70

Refer to the exhibit.
Exam NSE7_SDW-7.2: Question 5 - Image 1
The exhibit shows output of the command diagnose sys sdwan service collected on a FortiGate device.
The administrator wants to know through which interface FortiGate will steer the traffic from local users on subnet 10.0.1.0/255.255.255.192 and with a destination of the business application Salesforce located on HQ servers 10.0.0.1.
Based on the exhibits, which two statements are correct? (Choose two.)
Answer

Suggested Answer

The suggested answer is C, D.

Service rule 1 is configured for the Internet Service categories of Facebook and Twitter, so traffic destined for Salesforce will not match this rule. Since Salesforce is categorized under business applications, service rule 2 applies, which specifies port2. If the application of the flow is not recognized, traffic will default to service rule 3. Therefore, the correct steering will be as per rule 2 for recognized business applications like Salesforce, and as per rule 3 when the application cannot be recognized.

Community Votes36 votes
ACMost voted
53%
CDSuggested
42%
AD
3%
C
3%

About the Fortinet NSE7_SDW-7.2 Certification Exam

About the Exam

The Fortinet NSE7_SDW-7.2 (Fortinet NSE 7 - SD-WAN 7.2) validates your knowledge and skills. Passing demonstrates proficiency and can boost your career prospects in the field.

How to Prepare

Work through all 70 practice questions across 14 pages. Focus on understanding the reasoning behind each answer rather than memorizing responses to be ready for any variation on the real exam.

Why Practice Exams?

Practice exams help you familiarize yourself with the question format, manage your time, and reduce anxiety on the test day. Our NSE7_SDW-7.2 questions are regularly updated to reflect the latest exam objectives.