View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.
Question 181
Which SD-WAN component is used to define how specific traffic should be forwarded across WAN members?
- FortiAnalyzer
- SD-WAN rule
- DHCP server
- DNS filter
Correct Answer: 2
Explanation
An SD-WAN rule determines how matching traffic should be handled across available SD-WAN members. Administrators can define matching conditions based on factors such as source address, destination address, application, service, and Internet Service Database information. The rule can then use a selected SD-WAN strategy to determine the preferred path. Performance SLA information can also influence member eligibility. This allows different types of traffic to receive different forwarding treatment. For example, business-critical applications can use higher-quality links while less-sensitive traffic can use lower-cost or otherwise available WAN connections.
Question 182
Which Performance SLA measurement indicates how many packets fail to reach their destination?
- Latency
- Jitter
- Throughput
- Packet loss
Correct Answer: 4
Explanation
Packet loss represents packets that fail to reach their intended destination successfully. It is an important indicator of WAN quality because excessive packet loss can cause retransmissions, application delays, poor voice quality, and interrupted sessions. FortiGate can measure packet loss as part of Performance SLA monitoring and compare the result with configured thresholds. If a WAN member exceeds an acceptable loss level, an SD-WAN rule may consider another eligible path. Packet loss is different from latency and jitter because it measures delivery failures rather than packet delay or variation in packet timing.
Question 183
Which Fortinet product provides centralized configuration and device management for FortiGate?
- FortiManager
- FortiAnalyzer
- FortiMail
- FortiWeb
Correct Answer: 1
Explanation
FortiManager provides centralized management and configuration capabilities for FortiGate devices. It is useful in large SD-WAN deployments where many branch firewalls require similar configurations. Administrators can use FortiManager to manage policies, device settings, and standardized configurations from a central platform. This reduces repetitive manual work and can improve configuration consistency. FortiAnalyzer has a different primary purpose, focusing on log collection, analysis, and reporting. Using FortiManager together with FortiAnalyzer can provide both centralized configuration management and centralized visibility across multiple Fortinet devices.
Question 184
Which SD-WAN strategy is designed to prefer a path according to configured cost while considering SLA requirements?
- Load Balance
- Best Quality
- Lowest Cost (SLA)
- Manual
Correct Answer: 3
Explanation
Lowest Cost (SLA) is designed for environments where administrators want to consider WAN member cost while still requiring acceptable network performance. FortiGate can evaluate whether a member satisfies the configured Performance SLA conditions and then use cost information when selecting among eligible paths. This is useful when organizations have different WAN services with different pricing structures. A less expensive path may be preferred when it provides sufficient quality, while another connection can be selected if the cheaper option fails the required SLA. This approach helps balance network cost and application requirements.
Question 185
Which technology can dynamically establish more direct branch-to-branch connectivity in a suitable hub-and-spoke deployment?
- DHCP
- ADVPN
- DNS
- SNMP
Correct Answer: 2
Explanation
ADVPN can provide dynamic shortcut connectivity between branch locations in suitable hub-and-spoke architectures. In a traditional hub-and-spoke design, branch-to-branch traffic may need to pass through a central hub, creating additional traffic flow. ADVPN can allow more direct paths to be established dynamically when the required conditions are satisfied. This can reduce unnecessary traffic hairpinning and potentially improve application performance. Fortinet deployments commonly combine ADVPN with IPsec and dynamic routing. The exact behavior depends on topology, routing configuration, tunnel design, and supported FortiOS functionality.
Question 186
Which metric is most directly associated with variation in packet arrival timing?
- Jitter
- Latency
- Packet loss
- Bandwidth
Correct Answer: 1
Explanation
Jitter measures variation in packet arrival timing. It is particularly important for real-time applications such as voice and video because these applications require packets to arrive at relatively consistent intervals. A path can have acceptable average latency while still suffering from high jitter. FortiGate can measure jitter through Performance SLA and use configured thresholds when evaluating WAN members. If a path develops excessive jitter, an SD-WAN rule can potentially select another suitable member. Monitoring jitter separately from latency provides administrators with more detailed information about the quality of WAN connections.
Question 187
Which Fortinet platform is primarily designed for centralized log analysis and reporting?
- FortiManager
- FortiGate
- FortiAnalyzer
- FortiSwitch
Correct Answer: 3
Explanation
FortiAnalyzer provides centralized log collection, analysis, reporting, and monitoring. FortiGate devices can forward logs to FortiAnalyzer so administrators can investigate events across multiple branches and devices from one platform. In SD-WAN environments, this visibility can help identify connectivity issues, review traffic behavior, and analyze network events. FortiAnalyzer does not replace FortiGate’s SD-WAN forwarding functionality. FortiManager is focused more on centralized device and configuration management. Understanding the distinction between these products is important when designing centralized administration and monitoring for a distributed Fortinet environment.
Question 188
What does latency measure in an SD-WAN Performance SLA?
- Variation in packet delay
- Packet delivery delay
- Number of lost packets
- Available bandwidth
Correct Answer: 2
Explanation
Latency measures the delay experienced by packets while traveling across a monitored network path. Low latency is important for interactive applications because excessive delay can make communication feel slow. FortiGate can monitor latency through Performance SLA health checks and compare measured values with configured thresholds. If latency becomes unacceptable, the associated SD-WAN rule may consider another eligible member. Latency should be distinguished from jitter, which measures variation in delay, and packet loss, which measures unsuccessful packet delivery. Monitoring these metrics together provides a more complete understanding of WAN path quality.
Question 189
Which SD-WAN strategy is primarily intended to distribute traffic among suitable WAN members?
- Manual
- Lowest Cost
- Load Balance
- Best Quality
Correct Answer: 3
Explanation
Load Balance is intended to distribute traffic across multiple suitable SD-WAN members. This can help make more efficient use of available WAN capacity when several connections meet the required conditions. The exact behavior depends on the configured SD-WAN rule and member eligibility. Load balancing differs from Best Quality, which focuses on measured path performance, and Lowest Cost, which emphasizes cost-related selection. Administrators should consider bandwidth, application requirements, reliability, and service costs when choosing a suitable strategy. Properly configured load balancing can help avoid unnecessary concentration of traffic on a single WAN link.
Question 190
Which feature allows SD-WAN policies to match traffic destined for predefined Internet services?
- ARP table
- DHCP relay
- Static route
- Internet Service Database
Correct Answer: 4
Explanation
The Internet Service Database provides predefined information about supported Internet services and their associated destinations. SD-WAN rules can use this information to match traffic without requiring administrators to manually maintain every individual IP address. This is especially useful for cloud applications and Internet services that use multiple or changing addresses. ISDB-based matching can simplify policy management and allow specific Internet services to receive different path-selection treatment. Administrators can combine these matches with Performance SLA requirements and appropriate SD-WAN strategies to control how service traffic uses available WAN connections.
Question 191
Which component monitors the quality of an SD-WAN path against configured performance requirements?
- Performance SLA
- FortiManager
- Application Control
- DHCP Server
Correct Answer: 1
Explanation
Performance SLA monitors the quality and availability of SD-WAN paths against configured requirements. FortiGate can measure metrics such as latency, jitter, packet loss, and reachability depending on the health-check configuration. These measurements allow the device to determine whether an SD-WAN member satisfies the conditions required by a particular rule. If a path becomes degraded, another eligible member may be selected according to the configured strategy. Performance SLA is therefore a key component of dynamic SD-WAN path selection because it provides real-time information about the condition of available WAN connections.
Question 192
Which topology connects sites through one or more central hub locations?
- Full Mesh
- Hub-and-Spoke
- Peer-to-Peer
- Ring
Correct Answer: 2
Explanation
A hub-and-spoke topology connects multiple branch or spoke locations through one or more central hubs. This design can simplify centralized security inspection, routing, and network administration. In a traditional hub-and-spoke deployment, traffic between two branches may travel through the hub, which can introduce additional latency and traffic processing. Technologies such as ADVPN can provide more direct connectivity when appropriate. SD-WAN can operate within a hub-and-spoke architecture and select paths based on traffic requirements, WAN quality, routing information, and configured policies.
Question 193
Which protocol can dynamically exchange routing information between FortiGate devices in an SD-WAN environment?
- FTP
- BGP
- SMTP
- DHCP
Correct Answer: 2
Explanation
BGP can dynamically exchange routing information between FortiGate devices and other routing domains. In SD-WAN environments, dynamic routing can reduce the amount of manually configured route information required as the network grows. BGP can advertise reachable networks and update routing information when topology changes. It can operate over suitable VPN overlays and support routing policies that control route advertisements and selection. The appropriate BGP design depends on the organization’s network topology, addressing plan, and routing requirements. Proper filtering and route-policy configuration are important for predictable operation.
Question 194
Which technology provides secure encrypted connectivity over a WAN underlay?
- DNS
- DHCP
- IPsec VPN
- SNMP
Correct Answer: 3
Explanation
IPsec VPN provides secure encrypted connectivity over a WAN underlay. FortiGate devices can establish IPsec tunnels across Internet or other WAN services to create protected logical communication paths. In an SD-WAN deployment, these tunnels can become members or provide overlay connectivity between sites. FortiGate can then monitor the resulting paths through Performance SLA and apply traffic-steering rules. The underlay provides the transport, while IPsec provides encrypted logical connectivity. This architecture allows organizations to use different WAN services while maintaining secure communication between branches, hubs, data centers, and other locations.
Question 195
Which application type is generally most sensitive to jitter?
- Voice and video
- File backup
- Software archive
- Bulk data transfer
Correct Answer: 1
Explanation
Voice and video applications are generally highly sensitive to jitter because they depend on consistent packet timing. Significant variation in packet arrival can cause audio distortion, interruptions, or unstable video. FortiGate can monitor jitter through Performance SLA and compare the measured value against configured thresholds. Administrators can then create SD-WAN rules that prefer paths meeting suitable quality requirements for real-time applications. Less-sensitive applications such as backups may tolerate more variation because they can often use buffering or retransmission mechanisms. Therefore, SD-WAN policies should consider the characteristics of each application.
Question 196
Which FortiManager feature can reduce repetitive configuration work across multiple branch devices?
- Packet Capture
- Configuration Templates
- Traffic Sniffer
- DNS Proxy
Correct Answer: 2
Explanation
Configuration Templates in FortiManager can reduce repetitive configuration work when many FortiGate devices require similar settings. In a branch SD-WAN environment, administrators may need to configure common elements such as VPNs, routing, security policies, interfaces, and SD-WAN rules. Templates can provide a standardized configuration structure that can be applied to multiple devices. Device-specific parameters can still be handled where necessary. This approach improves consistency and can simplify large-scale changes. It is particularly useful when organizations operate many branches and need centralized control over their FortiGate configurations.
Question 197
What can happen when an SD-WAN member no longer satisfies the Performance SLA for a rule?
- It can become ineligible for the affected traffic
- All VPNs are permanently deleted
- The FortiGate shuts down
- All routing protocols are disabled
Correct Answer: 1
Explanation
When an SD-WAN member fails the Performance SLA conditions associated with a rule, that member can become ineligible for the affected traffic. Failure may occur because of excessive latency, jitter, packet loss, or loss of reachability depending on the configured health check. If another member meets the required conditions, FortiGate can select that path according to the configured strategy. This behavior provides dynamic failover and helps applications avoid degraded WAN connections. The member itself is not necessarily physically disabled; its eligibility for particular traffic is affected by the SLA evaluation.
Question 198
Which architecture separates physical WAN connectivity from logical secure connectivity?
- Application and service
- Underlay and overlay
- User and group
- Policy and profile
Correct Answer: 2
Explanation
Underlay and overlay architecture separates physical WAN connectivity from logical network connectivity. The underlay can consist of services such as broadband Internet, MPLS, or LTE. The overlay can use technologies such as IPsec to create logical and encrypted connections between network locations. SD-WAN can evaluate the available paths and steer traffic according to configured policies and Performance SLA results. This separation provides flexibility because multiple transport services can support the same logical architecture. It also allows organizations to introduce or replace WAN transports without completely redesigning their logical network connectivity.
Question 199
Which SD-WAN strategy focuses primarily on selecting paths according to measured quality?
- Best Quality
- Load Balance
- Manual
- Lowest Cost
Correct Answer: 1
Explanation
Best Quality focuses on selecting a path according to measured network performance. FortiGate can evaluate Performance SLA metrics such as latency, jitter, and packet loss when determining which available member provides better quality. This strategy is useful for applications that prioritize consistent network performance. If the preferred path becomes degraded, another eligible member can potentially be selected. Administrators should configure Performance SLA thresholds according to application requirements. A well-designed Best Quality policy can help real-time and interactive applications avoid WAN connections that are experiencing unacceptable performance.
Question 200
What is the primary purpose of combining SD-WAN rules with Performance SLA monitoring?
- To eliminate all firewall policies
- To assign IP addresses automatically
- To steer traffic according to policy and current WAN quality
- To disable routing protocols
Correct Answer: 3
Explanation
Combining SD-WAN rules with Performance SLA monitoring allows FortiGate to make traffic-steering decisions based on both configured policy and current WAN conditions. SD-WAN rules determine which traffic should receive a particular treatment, while Performance SLA provides information about the quality of available paths. Metrics such as latency, jitter, packet loss, and reachability can help determine whether a member is suitable. This combination allows different applications and destinations to use different paths and can provide dynamic failover when a preferred connection becomes degraded. It is a central concept in performance-aware SD-WAN design.