Summer Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

NSE7_SDW-6.4 Questions and Answers

Note! Following NSE7_SDW-6.4 Exam is Retired now. Please select the alternative replacement for your Exam Certification. The new exam code is NSE7_SDW-7.2

NSE7_SDW-6.4 Questions and Answers

Question # 6

Which two statements about SLA targets and SD-WAN rules are true? (Choose two.)

A.

Member metrics are measured only if an SLA target is configured.

B.

SLA targets are used only by SD-WAN rules that are configured with Lowest Cost (SLA) or Maximize Bandwidth (SLA) as strategy.

C.

When configuring an SD-WAN rule, you can select multiple SLA targets of the same performance SLA.

D.

SD-WAN rules use SLA targets to check if the preferred members meet the SLA requirements.

Full Access
Question # 7

Refer to exhibits

Exhibit A shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate

Based on the FortiGate configuration shown in the exhibits, what are two issues you might encounter when creating an SD-WAN interface on port1 and port2? {Choose two )

A.

Member interfaces that are administratively down

B.

Member interface that have IP address of 0.0.0.0/0.0.0.0

C.

Member interfaces that are physical interfaces as well as VLAN aggregate, and iPsec interfaces

D.

Member interfaces that are referenced by any other configuration element

Full Access
Question # 8

Which CLI command do you use to perform real-time troubleshooting for ADVPN negotiation?

A.

diagnose sys virtual-wan-link service

B.

get router info routing-table

C.

diagnose debug application ike

D.

get ipsec tunnel list

Full Access
Question # 9

Refer to the exhibit.

Which two statements about the debug output are true? (Choose two)

A.

The debug output shows per-IP shaper values and real-time readings.

B.

FortiGate provides statistics and reading based on historical traffic logs.

C.

Traffic being controlled by the traffic shaper is under 100 KB/s.

D.

This traffic shaper drops traffic that exceeds the set limits.

Full Access
Question # 10

Refer to the exhibit.

What must you configure to enable ADVPN?

A.

On the hub VPN, only the device needs additional phase one sett

B.

ADVPN should only be enabled on unmanaged FortiGate devices.

C.

Each VPN device has a unique pre-shared key configured separately on phase one

D.

The protected subnets should be set to address object to all (0.0 .0. 0/0).

Full Access
Question # 11

Refer to the exhibit.

Based on the exhibit, which statement about FortiGate re-evaluating traffic is true?

A.

The type of traffic defined and allowed on firewall policy ID 1 is UDP.

B.

FortiGate has terminated the session after a change on policy ID 1.

C.

Changes have been made on firewall policy ID 1 on FortiGate.

D.

Firewall policy ID 1 has source NAT disabled.

Full Access
Question # 12

Refer to the exhibits.

ExhibitA shows the system interface with the static routes and exhibit B shows the firewall policies on the managed FortiGate.

Based on the FortiGate configuration shown in the exhibits, what issue might you encounter when creating an SD-WAN zone for port1 and port2?

A.

port2 is referenced in a static route.

B.

port1 is assigned a manual IP address.

C.

port1 and port2 are not administratively down.

D.

port1 is referenced in a firewall policy.

Full Access