Question 6 of 62

Which two performance SLA protocols enable you to verify that the server response contains a specific value? (Choose two.)

    Correct Answer: A, D

    The HTTP protocol allows you to check for specific content in the server’s response, making it suitable for verifying that the response contains a specific value. Similarly, the DNS protocol can be used to verify the presence of specific values in DNS responses. Therefore, both HTTP and DNS protocols enable the verification of specific values in server responses.

Question 7 of 62

Refer to the exhibit.

Which two conclusions for traffic that matches the traffic shaper are true? (Choose two.)

    Correct Answer: B, C

    The measured bandwidth is currently 93 KBps, which is less than 100 KBps. The traffic shaper is configured with a maximum bandwidth limit of 6250 KBps, meaning it will drop packets if the traffic exceeds this limit.

Question 8 of 62

Refer to the exhibit.

Which configuration change is required if the responder FortiGate uses a dynamic routing protocol to exchange routes over IPsec?

    Correct Answer: D

    When a dynamic routing protocol is used to exchange routes over an IPsec connection, the 'add-route' setting must be disabled. This is because dynamic routing protocols handle route management dynamically, and having 'add-route' enabled (which adds static routes) would interfere with the dynamic route management process. Disabling 'add-route' prevents conflicts and allows the dynamic routing protocol to function correctly.

Question 9 of 62

Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?

    Correct Answer: B

    To perform real-time troubleshooting for ADVPN negotiation, you use the CLI command 'diagnose debug application ike'. This command is specifically designed to debug issues related to the Internet Key Exchange (IKE) protocol, which is a critical component in the negotiation and setup of IPsec VPNs, including ADVPNs. Other commands such as 'get router info routing-table all' or 'diagnose vpn tunnel list' provide general routing and VPN tunnel information but do not offer the detailed, real-time debugging capabilities required for troubleshooting ADVPN negotiation specifically.

Question 10 of 62

Refer to the exhibits.

Exhibit A -

Exhibit B -

Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.

Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?

    Correct Answer: B

    To create an SD-WAN zone, the interfaces involved should not be referenced in any firewall policy, static route, or another configuration. Exhibit B shows that port1 is referenced in a firewall policy named 'Internet_Access'. This reference can prevent you from adding port1 to the SD-WAN zone. Therefore, this configuration will indeed cause an issue when attempting to create an SD-WAN zone for port1 and port2.