[Oct-2021] Pass Fortinet NSE7_SDW-6.4 Exam in First Attempt Guaranteed!
Full NSE7_SDW-6.4 Practice Test and 37 unique questions with explanations waiting just for you, get it now!
NEW QUESTION 14
Which statement about using BGP routes in SD-WAN is true?
- A. VPN topologies must be form using only BGP dynamic routing with SD-WAN
- B. Learned routes can be used as dynamic destinations in SD-WAN rules
- C. Adding static routes must be enabled on all ADVPN interfaces.
- D. Dynamic routing protocols can be used only with non-encrypted traffic
Answer: A
NEW QUESTION 15
Refer to the exhibit.
Based on the output shown in the exhibit, which two criteria on the SD-WAN member configuration can be used to select an outgoing interface in an SD-WAN rule? (Choose two.)
- A. Set cost 15.
- B. Set source 100.64.1.1.
- C. Set load-balance-mode source-ip-ip-based.
- D. Set priority 10.
Answer: B
NEW QUESTION 16
Refer to exhibits.

Exhibit A shows the performance SLA exhibit B shows the SD-WAN diagnostics output.
Based on the exhibits, which statement is correct?
- A. SD-WAN member interfaces are affected by the SLA state of the inactive interface
- B. The SLA state of port1 is dead after five unanswered requests by the SLA servers.
- C. Port1 became dead 1ecause no traffic was offload through the egress of port1.
- D. Both SD-WAN member interfaces have used separate SLA targets.
Answer: B
NEW QUESTION 17
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A shows the source NAT global setting and exhibit B shows the routing table on FortiGate Based on the exhibits, which two statements about increasing the port2 interface priority to 20 are true? (Choose two )
- A. All the existing sessions will continue to use port2 and new sessions will use port1
- B. All the existing sessions will be blocked from using port1 and port2
- C. All the existing sessions with no SNAT will start using port1 as the outgoing interface instead of port2
- D. All the existing sessions using SNAT will start using port1 as the outgoing interface instead of port2.
Answer: C,D
NEW QUESTION 18
Refer to the exhibit.
Which two statements about the status of the VPN tunnel are true? <Choose two )
- A. VPN static routes are prevented from populating the FortiGate routing table.
- B. There are separate virtual interfaces for each dial-up client.
- C. 100.64.3.1 is one of the remote IP address that comes through index interface 1.
- D. FortiGate created a single IPsec virtual interface that is shared by all clients.
Answer: C,D
NEW QUESTION 19
Which diagnostic command you can use to show interface-specific SLA logs for the last 10 minutes?
- A. diagnose sys virtual-wan-link health-check
- B. diagnose sys virtual-wan-link intf-sla-log
- C. diagnose sys virtual-wan-link sla-log
- D. diagnose sys virtual-wan-link log
Answer: C
Explanation:
Explanation/Reference: https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/943037/sla-logging
NEW QUESTION 20
What would best describe the SD-WAN traffic shaping mode that bases itself on a percentage of available bandwidth?
- A. Per-IP shaping mode
- B. Reverse policy shaping mode
- C. Shared policy shaping mode
- D. Interface-based shaping mode
Answer: C
NEW QUESTION 21
Which two statements describe how IPsec phase 1 main mode is different from aggressive mode when performing IKE negotiation? (Choose two )
- A. The use of Diffie Hellman keys is limited by the responderand needs initiator acceptance
- B. A total of six packets are exchanged between an initiator and a responder instead of three packets.
- C. XAuth is enabled as an additional level of authentication which requires a username and password
- D. A peer ID is included in the first packet from the initiator, along with suggested security policies
Answer: C
NEW QUESTION 22
Which components make up the secure SD-WAN solution?
- A. Application, antivirus, and URL, and SSL inspection
- B. Datacenter, branch offices, and public cloud
- C. Telephone, ISDN, and telecom network.
- D. FortiGate, FortiManager, FortiAnalyzer, and FortiDeploy
Answer: D
NEW QUESTION 23
What is the lnkmtd process responsible for?
- A. Flushing route tags addresses
- B. Monitoring links for any bandwidth saturation
- C. Logging interface quality information
- D. Processing performance SLA probes
Answer: B
NEW QUESTION 24
What are two benefits of using FortiManager to organize and manage the network for a group of FortiGate devices? (Choose two )
- A. It reduces WAN usage on FortiGate devices by acting as a local FortiGuard server.
- B. It simplifies the deployment and administration of SD-WAN on managed FortiGate devices.
- C. It sends probe signals as health checks to the beacon servers on behalf of FortiGate.
- D. It acts as a policy compliance entity to review all managed FortiGate devices.
- E. It improves SD-WAN performance on the managed FortiGate devices.
Answer: D,E
NEW QUESTION 25
Refer to exhibits.
Exhibit A.
Exhibit B.
Exhibit A shows the SD-WAN performance SLA and exhibit B shows the SO-WAN interface and the static routes configuration.
Port1 and port2 are member interfaces of the SD-WAN, and port2 becomes a dead member after reaching the failure thresholds Which statement about the dead member is correct?
- A. SD-WAN interface becomes disabled and port1 becomes the WAN interface
- B. Dead members require manual administrator access to bring them back alive
- C. Port2 might become alive when a single response is received from an SLA server
- D. Subnets 100 .64-1.0/23 and 172 . 20 . 0. 0/16 are reachable only through port1
Answer: A
NEW QUESTION 26
Which diagnostic command can you use to show the SD-WAN rules interface information and state?
- A. diagnose sys virtual-wan-link neighbor.
- B. diagnose sys virtual-wan-link service
- C. diagnose sys virtual-wan-link member.
- D. diagnose sys virtual-wan-link route-tag-list
Answer: A
NEW QUESTION 27
Refer to the exhibit.
What must you configure to enable ADVPN?
- A. The protected subnets should be set to address object to all (0.0 .0. o/o).
- B. ADVPN should only be enabled on unmanaged FortiGate devices.
- C. On the hub VPN, only the device needs additional phase one sett
- D. Each VPN device has a unique pre-shared key configured separately on phase one
Answer: D
NEW QUESTION 28
What are two roles that SD-WAN orchestrator plays when it works with FortiManager? (Choose two )
- A. It configures and monitors SD-WAN networks on FortiGate devices that are managed by FortiManager.
- B. It acts as a standalone device to assist FortiManager to manage SD-WAN interfaces on the managed FortiGate devices.
- C. It acts as a hub FortiGate with an SD-WAN interface enabled and managed along with other FortiGate devices by FortiManager.
- D. It acts as an application that is released and signed by Fortinet to run as a part of management extensions on FortiManager.
Answer: B,D
NEW QUESTION 29
What are the two minimum configuration requirements for an outgoing interface to be selected once the SD-WAN logical interface is enabled? (Choose two )
- A. Specify incoming interfaces in SD-WAN rules.
- B. Configure SD-WAN rules interface preference.
- C. Select SD-WAN balancing strategy.
- D. Specify outgoing interface routing cost.
Answer: B,D
NEW QUESTION 30
What is the lnkmtd process responsible for?
- A. Logging interface quality information
- B. Monitoring links for any bandwidth saturation
- C. Flushing route tags addresses
- D. Processing performance SLA probes
Answer: A
NEW QUESTION 31
Refer to the exhibit.
Multiple IPsec VPNs are formed between two hub-and-spokes groups, and site-to-site between Hub 1 and Hub 2 The administrator configured ADVPN on the dual regions topology
Which two statements are correct if a user in Toronto sends traffic to London? (Choose two )
- A. Toronto needs to establish a site-to-site tunnel with Hub 2 to bypass Hub 1.
- B. The first packets from Toronto to London are routed through Hub 1 then to Hub 2.
- C. London generates an IKE information message that contains the Toronto public IP address
- D. Traffic from Toronto to London triggers the dynamic negotiation of a direct site-to-site VPN
Answer: A,D
NEW QUESTION 32
......
Prepare for your Fortinet certification with the updated PassLeader NSE7_SDW-6.4 exam questions: https://drive.google.com/open?id=1yulynYPzWYybwkK9GFYsIDjp-KR-zFJM
Get Latest NSE7_SDW-6.4 Dumps Exam Questions in here: https://www.passleader.top/Fortinet/NSE7_SDW-6.4-exam-braindumps.html