View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 81
Which SD-WAN feature can determine whether a WAN path satisfies configured latency, jitter, and packet-loss requirements?
- Security policy
- Performance SLA
- DNS Filter
- Web Application Firewall
Correct Answer: 2
Explanation
Performance SLA is used to evaluate the quality and availability of SD-WAN paths. Depending on the configuration, FortiGate can measure latency, jitter, packet loss, and reachability to a configured target. These measurements can then be compared against defined thresholds. If a member fails the required SLA conditions, SD-WAN rules can select another eligible path. This provides dynamic path selection based on actual network performance rather than simply checking whether an interface is physically connected. Performance SLA is therefore a fundamental component of application-aware and quality-based SD-WAN traffic steering.
Question 82
Which SD-WAN strategy is most appropriate when the administrator wants to distribute traffic among multiple eligible WAN members?
- Best Quality
- Lowest Cost
- Load Balance
- Manual
Correct Answer: 3
Explanation
Load Balance is intended to distribute traffic across multiple eligible SD-WAN members according to the configured load-balancing behavior. This can help make better use of available WAN capacity instead of concentrating all traffic on a single connection. The exact distribution depends on the FortiGate configuration and traffic characteristics. Load balancing can be useful when several links have adequate performance and the organization wants to utilize them concurrently. It is different from a strategy that simply chooses the best-performing or lowest-cost path because its objective is to distribute traffic across available resources.
Question 83
What is the purpose of configuring a gateway or target for an SD-WAN Performance SLA?
- To provide a destination against which path performance can be measured
- To create firewall administrator accounts
- To store FortiAnalyzer reports
- To define antivirus signatures
Correct Answer: 1
Explanation
A Performance SLA requires a meaningful destination or target that FortiGate can use when measuring the quality of an SD-WAN path. FortiGate sends probes toward the target and records measurements such as latency, jitter, packet loss, and availability when supported by the configured health check. The results help determine whether a member satisfies the requirements of an SD-WAN rule. Selecting an appropriate target is important because it should represent the connectivity that the administrator wants to evaluate. This allows path-selection decisions to be based on useful and relevant performance information.
Question 84
Which characteristic describes the underlay in an SD-WAN network?
- It provides the underlying transport connectivity
- It contains only application signatures
- It stores firewall logs
- It replaces all VPN tunnels
Correct Answer: 1
Explanation
The underlay is the underlying transport infrastructure used to provide connectivity between SD-WAN endpoints. It can consist of broadband Internet, MPLS, LTE, 5G, or other WAN services. SD-WAN operates over these available transports and can make forwarding decisions according to policies and path-quality measurements. The underlay should be distinguished from the overlay, which is the logical network built over one or more transports. Understanding this distinction helps administrators troubleshoot SD-WAN problems by determining whether an issue exists in the physical or transport connectivity or in the logical overlay and routing configuration.
Question 85
Which technology commonly provides a secure overlay between FortiGate devices over Internet connections?
- IPsec VPN
- DHCP
- DNS
- FTP
Correct Answer: 1
Explanation
IPsec VPN is commonly used to create secure encrypted overlays between FortiGate devices. In SD-WAN environments, IPsec tunnels can be established over Internet connections and then added as SD-WAN members. This allows organizations to use public WAN services while protecting traffic between branch offices, hubs, and other sites. Multiple IPsec tunnels can also provide path redundancy and support different SD-WAN designs. FortiGate can monitor these tunnel paths through Performance SLA and use SD-WAN rules to determine how traffic should be forwarded over the available secure connections.
Question 86
What is the main advantage of using application-based traffic steering in SD-WAN?
- It allows different applications to use different path-selection policies
- It forces every application through one WAN link
- It removes the need for routing
- It disables security inspection
Correct Answer: 1
Explanation
Application-based traffic steering allows FortiGate to apply different forwarding behavior to different applications. This is valuable because applications have different network requirements. For example, voice and video may require low latency and jitter, while backup traffic may tolerate a slower connection. Administrators can create SD-WAN rules that identify applications and associate them with suitable strategies and SLA requirements. This provides more granular control than simply selecting one WAN connection for all traffic. Application-aware steering can therefore improve the use of available WAN resources while aligning network behavior with business priorities.
Question 87
Which metric indicates how much packet delivery is being lost on an SD-WAN path?
- Jitter
- Latency
- Packet loss
- Throughput
Correct Answer: 3
Explanation
Packet loss indicates the percentage or amount of packets that fail to reach their destination during a measurement period. It is an important indicator of network reliability. Excessive packet loss can negatively affect many applications, particularly real-time services such as voice and video. FortiGate can monitor packet loss through Performance SLA and use the results when determining whether an SD-WAN member meets configured requirements. A WAN path can remain technically connected while experiencing significant packet loss, which is why performance-based monitoring provides more useful information than simply checking interface status.
Question 88
Which Fortinet product provides centralized configuration and device management for multiple FortiGate systems?
- FortiAnalyzer
- FortiManager
- FortiMail
- FortiAP
Correct Answer: 2
Explanation
FortiManager provides centralized management for multiple Fortinet devices, including FortiGate systems. Administrators can use it to organize devices, manage configurations, distribute policies, and maintain consistent settings across branch deployments. This is particularly useful for SD-WAN environments because many sites may require similar VPN, routing, security, and WAN configurations. Centralized management reduces repetitive manual work and can help maintain configuration consistency. FortiAnalyzer has a different primary purpose, focusing on log collection, analysis, and reporting rather than centralized configuration management.
Question 89
Which Fortinet product is designed primarily for centralized log analysis and reporting?
- FortiAnalyzer
- FortiManager
- FortiSwitch
- FortiAP
Correct Answer: 1
Explanation
FortiAnalyzer provides centralized log collection, analysis, monitoring, and reporting capabilities for Fortinet environments. FortiGate devices can send logs to FortiAnalyzer, allowing administrators to investigate security events and network activity from a centralized platform. In SD-WAN deployments, collected logs can help with troubleshooting and operational visibility. FortiManager and FortiAnalyzer have complementary roles: FortiManager is primarily used for device and configuration management, while FortiAnalyzer focuses on log analysis and reporting. Using both platforms can provide centralized management and centralized operational visibility across large Fortinet deployments.
Question 90
What does high latency generally indicate about an SD-WAN path?
- The path has a significant delay
- The path has zero packet loss
- The path has unlimited bandwidth
- The path is automatically encrypted
Correct Answer: 1
Explanation
High latency indicates that packets experience significant delay while traveling between the monitored endpoints. This can affect interactive applications because users must wait longer for responses. Applications such as remote desktop, voice communication, video conferencing, and transactional systems can be sensitive to excessive latency. FortiGate can measure latency through Performance SLA health checks and use the result when evaluating SD-WAN members. If a path exceeds the configured latency threshold, an SD-WAN rule may select another eligible member depending on its strategy and the availability of alternative paths.
Question 91
Which component determines how matching traffic should select among available SD-WAN members?
- SD-WAN rule
- DHCP server
- Antivirus profile
- DNS forwarder
Correct Answer: 1
Explanation
An SD-WAN rule determines how traffic matching specified criteria should be handled across available SD-WAN members. Rules can use traffic characteristics such as source, destination, application, service, or supported Internet service information. After identifying the traffic, the rule applies a configured strategy to determine which member should be selected. The decision can also be influenced by Performance SLA results. This makes SD-WAN rules the policy component that connects traffic classification with dynamic WAN path selection. Proper rule ordering and configuration are important when multiple rules exist for different traffic categories.
Question 92
Which SD-WAN measurement is most closely associated with variation in packet delay?
- Bandwidth
- Jitter
- Packet loss
- Availability
Correct Answer: 2
Explanation
Jitter describes variation in packet delay or packet arrival timing. A network path with high jitter may deliver packets at inconsistent intervals even if its average latency appears acceptable. This can cause problems for real-time applications such as voice and video because those applications depend on relatively consistent packet timing. FortiGate can measure jitter through Performance SLA monitoring and use it in path-selection decisions. Administrators can configure acceptable thresholds so that sensitive traffic can avoid WAN paths whose measured jitter exceeds the desired performance level.
Question 93
What is one benefit of combining multiple WAN transports in SD-WAN?
- It provides additional path choices and resilience
- It removes the requirement for IP addressing
- It disables all routing protocols
- It guarantees zero packet loss
Correct Answer: 1
Explanation
Combining multiple WAN transports gives FortiGate more than one path that can be used for network traffic. This can improve resilience because traffic may be moved to another eligible connection when a preferred path becomes unavailable or fails performance requirements. Multiple transports can also allow organizations to balance cost, quality, and capacity. For example, broadband may provide inexpensive connectivity while MPLS or another transport provides predictable performance. SD-WAN can evaluate these connections and apply configured policies to select appropriate paths. However, redundancy still depends on correct configuration and actual availability of alternative links.
Question 94
Which topology uses a central hub to connect multiple branch locations?
- Full mesh
- Hub-and-spoke
- Linear
- Ring
Correct Answer: 2
Explanation
A hub-and-spoke topology uses one or more central hub devices to connect multiple branch or spoke locations. This model is common in enterprise SD-WAN deployments because it provides a centralized architecture for connecting branches to headquarters, data centers, or shared services. FortiGate can establish IPsec overlays between spokes and hubs and use SD-WAN policies to manage available WAN paths. The architecture can simplify centralized connectivity, although direct spoke-to-spoke communication may require additional mechanisms such as ADVPN. The topology selected should reflect the organization’s traffic patterns, scalability, and redundancy requirements.
Question 95
What is the primary purpose of ADVPN in a Fortinet SD-WAN environment?
- Enable dynamic and more direct VPN connectivity between sites when appropriate
- Disable all VPN encryption
- Replace firewall policies
- Provide centralized log storage
Correct Answer: 1
Explanation
ADVPN can allow FortiGate devices in a hub-and-spoke environment to establish more direct VPN connectivity between spokes when appropriate. Without such mechanisms, branch-to-branch traffic may need to pass through a central hub, creating unnecessary traffic hairpinning. Dynamic shortcuts can improve efficiency and potentially reduce latency for direct communication. ADVPN is commonly used with IPsec and dynamic routing technologies in larger Fortinet deployments. The exact behavior depends on the configured topology and supported FortiOS features. Proper design is required to ensure routing and security policies support the intended direct communication.
Question 96
Which option can be used to identify traffic destined for supported Internet services in an SD-WAN rule?
- Internet Service Database
- DHCP database
- ARP table only
- Local administrator list
Correct Answer: 1
Explanation
The Internet Service Database provides predefined information that can help identify supported Internet services and destinations. SD-WAN rules can use this information to classify traffic and apply appropriate path-selection policies. This can simplify configuration when an administrator wants to steer traffic for specific cloud applications or Internet services without maintaining extensive destination address lists manually. Service definitions can change over time, so administrators should understand how the database is maintained and how supported services are represented in the relevant FortiOS version. Proper traffic identification allows SD-WAN policies to become more application and service aware.
Question 97
What happens when a WAN member fails the required SLA conditions for a rule and another member is eligible?
- The alternative eligible member can be selected
- All SD-WAN rules are deleted
- FortiGate automatically reboots
- The firewall becomes permanently disabled
Correct Answer: 1
Explanation
When an SD-WAN member fails the conditions required by a particular rule, FortiGate can consider another eligible member according to the configured strategy. For example, excessive latency, jitter, or packet loss may cause a member to fail an SLA requirement. If another member satisfies the necessary conditions, traffic can be steered through that path. This behavior provides dynamic resilience and helps applications avoid degraded WAN links. The actual outcome depends on rule configuration, SLA thresholds, member status, and the available alternatives. Proper health checks and backup paths are therefore important in SD-WAN designs.
Question 98
Which statement best describes the relationship between FortiManager and FortiAnalyzer?
- FortiManager focuses on centralized management, while FortiAnalyzer focuses on logs and analysis
- Both products only provide wireless access
- FortiAnalyzer replaces all FortiGate routing
- FortiManager is only an antivirus engine
Correct Answer: 1
Explanation
FortiManager and FortiAnalyzer provide different but complementary functions. FortiManager is primarily used for centralized device and configuration management, allowing administrators to manage multiple FortiGate devices from a central platform. FortiAnalyzer is primarily focused on collecting, analyzing, storing, and reporting on logs and events. In an SD-WAN environment, FortiManager can help deploy consistent configurations across branches, while FortiAnalyzer can provide centralized visibility into activity and events. Understanding these roles helps administrators choose the appropriate Fortinet platform for configuration management versus operational monitoring and analysis.
Question 99
Which factor can make a WAN link unsuitable for latency-sensitive traffic even when the interface remains physically up?
- Excessive latency
- Interface description
- Hostname length
- Administrator username
Correct Answer: 1
Explanation
A WAN interface can remain physically operational while experiencing excessive latency. Physical link status alone does not indicate whether the connection provides suitable performance for a particular application. Latency-sensitive applications may experience slow responses when delay becomes too high. Performance SLA monitoring can measure latency and compare it against configured requirements. If the path no longer meets the relevant SLA, an SD-WAN rule can potentially select another eligible member. This demonstrates why SD-WAN uses performance-based monitoring rather than relying only on whether an interface is technically up or down.
Question 100
What is the main objective of application-aware SD-WAN path selection?
- Match WAN path decisions to application and network requirements
- Eliminate all security policies
- Replace every routing protocol
- Disable WAN redundancy
Correct Answer: 1
Explanation
Application-aware SD-WAN path selection is designed to align WAN forwarding decisions with the requirements of individual applications. Different applications may have different sensitivity to latency, jitter, packet loss, bandwidth, and availability. FortiGate can identify traffic and apply SD-WAN rules that select suitable members according to configured strategies and Performance SLA conditions. This allows critical applications to receive appropriate WAN treatment while less-sensitive traffic can use other available paths. The overall objective is to use WAN resources intelligently while maintaining connectivity and meeting the performance requirements established by the network administrator.