Fortinet NSE6_SDW_AD-7.6 Practice Test Questions and Exam Dumps Part14 Q261-280

View Full Fortinet NSE6_SDW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 261

Which SD-WAN component determines whether a monitored WAN path meets configured quality thresholds?

  1. Performance SLA
  2. Firewall Policy
  3. FortiAnalyzer
  4. DHCP Server

Correct Answer: 1

Explanation

Performance SLA evaluates the quality and availability of monitored SD-WAN paths against configured thresholds. Depending on the health-check configuration, FortiGate can measure latency, jitter, packet loss, and reachability. These measurements help determine whether an SD-WAN member is suitable for traffic associated with a particular rule. If a path fails the required conditions, another eligible member may be selected according to the configured strategy. Performance SLA therefore provides an important foundation for dynamic SD-WAN path selection. Administrators should configure thresholds according to actual application requirements rather than choosing unnecessarily strict or overly permissive values.

Question 262

Which SD-WAN strategy is designed to distribute traffic among multiple eligible members?

  1. Manual
  2. Best Quality
  3. Load Balance
  4. Lowest Cost

Correct Answer: 3

Explanation

Load Balance is designed to distribute traffic among multiple eligible SD-WAN members. This can improve utilization when an organization has several WAN connections that are suitable for the same type of traffic. Rather than depending entirely on one preferred link, the strategy allows available paths to participate in forwarding. Eligibility can still depend on configured Performance SLA conditions. Load Balance differs from Best Quality, which focuses on measured path quality, and Manual, which provides an explicit preference order. The appropriate strategy depends on bandwidth availability, application requirements, WAN costs, and the desired traffic-distribution behavior.

Question 263

Which metric specifically indicates variation in packet delivery delay?

  1. Latency
  2. Packet Loss
  3. Jitter
  4. Throughput

Correct Answer: 3

Explanation

Jitter indicates variation in packet delivery delay. Unlike latency, which represents packet delay, jitter describes how consistently that delay occurs from packet to packet. High jitter can be especially problematic for voice and video because these applications depend on consistent packet timing. FortiGate can monitor jitter through Performance SLA health checks and use the result when evaluating SD-WAN members. Administrators can configure thresholds based on application requirements. A WAN path with acceptable latency can still be unsuitable for real-time traffic if its jitter is excessive, which is why multiple SLA metrics should be considered together.

Question 264

Which Fortinet product provides centralized management of FortiGate configurations?

  1. FortiAnalyzer
  2. FortiManager
  3. FortiMail
  4. FortiWeb

Correct Answer: 2

Explanation

FortiManager provides centralized management and configuration capabilities for FortiGate devices. In an SD-WAN environment, it can help administrators manage configurations across many branches from a centralized platform. This can include device settings, policies, routing configurations, and SD-WAN-related configurations. FortiManager helps reduce repetitive administrative work and promotes consistency across managed devices. FortiAnalyzer serves a different primary purpose, focusing on centralized logging, analysis, and reporting. Using both solutions together can provide centralized configuration control through FortiManager and centralized visibility into operational events through FortiAnalyzer.

Question 265

What happens when packet loss on an SD-WAN member exceeds the configured SLA threshold?

  1. The member may become ineligible for the affected rule
  2. All FortiGate interfaces shut down
  3. The firewall configuration is erased
  4. All VPN tunnels are permanently deleted

Correct Answer: 1

Explanation

When packet loss exceeds the configured Performance SLA threshold, the monitored member may become ineligible for traffic governed by that SLA. FortiGate can then evaluate other available members and select an eligible path according to the configured SD-WAN strategy. This behavior helps prevent important traffic from continuing to use a degraded WAN path. The physical interface itself does not necessarily shut down. Instead, its suitability for the particular SD-WAN rule is affected. Correct threshold configuration is important because thresholds that are too strict can cause unnecessary path changes, while thresholds that are too relaxed may allow poor-quality links to remain in use.

Question 266

Which SD-WAN component represents an individual WAN path participating in path selection?

  1. SD-WAN member
  2. FortiAnalyzer report
  3. Firewall address group
  4. User group

Correct Answer: 1

Explanation

An SD-WAN member represents an individual WAN interface or logical path that participates in SD-WAN forwarding decisions. Examples can include Internet, MPLS, LTE, or other WAN connections. FortiGate evaluates members according to SD-WAN rules, configured strategies, and Performance SLA results. Members can also have characteristics such as cost or priority that influence selection. If a member becomes unavailable or fails required SLA conditions, another eligible member can potentially be selected. Understanding the role of members is essential because SD-WAN ultimately uses these paths to forward traffic according to configured policy.

Question 267

Which protocol can dynamically exchange routing information across an SD-WAN overlay?

  1. DNS
  2. DHCP
  3. BGP
  4. NTP

Correct Answer: 3

Explanation

BGP can dynamically exchange routing information between FortiGate devices or other routing peers across an SD-WAN environment. This is especially useful when a deployment contains many sites and manually maintaining routes would become difficult. BGP can operate over suitable IPsec overlay connections and can advertise reachable networks between locations. Administrators can apply routing policies to control route advertisements and selection. SD-WAN and BGP solve different but complementary problems: BGP can determine which networks are reachable, while SD-WAN can determine which available path should carry matching traffic based on configured rules and performance conditions.

Question 268

Which feature allows FortiGate to identify traffic destined for supported cloud or Internet services using predefined service information?

  1. Internet Service Database
  2. Static ARP
  3. DHCP Relay
  4. DNS Forwarder

Correct Answer: 1

Explanation

The Internet Service Database provides predefined information about supported Internet and cloud services. SD-WAN rules can use ISDB entries to identify traffic destined for recognized services without requiring administrators to manually maintain every destination IP address. This is useful because large Internet services may use many addresses and their infrastructure can change over time. By using ISDB information, administrators can create application or service-specific SD-WAN rules more efficiently. These rules can then apply an appropriate strategy and Performance SLA requirements to determine how the traffic should use available WAN members.

Question 269

Which SD-WAN strategy emphasizes selecting a path based on measured network quality?

  1. Load Balance
  2. Best Quality
  3. Manual
  4. Lowest Cost

Correct Answer: 2

Explanation

Best Quality emphasizes selecting an appropriate SD-WAN member based on measured network performance. Performance SLA can provide information such as latency, jitter, packet loss, and reachability. FortiGate can use these measurements to determine which eligible path provides the required quality. This strategy is useful for applications where network performance is more important than minimizing WAN cost. It is different from Manual, where the administrator specifies a preferred order, and Lowest Cost, where cost is an important selection factor. Realistic SLA thresholds are important to ensure that quality-based decisions reflect actual application needs.

Question 270

Which topology normally connects branch locations through centralized hub devices?

  1. Full Mesh
  2. Hub-and-Spoke
  3. Ring
  4. Broadcast

Correct Answer: 2

Explanation

A hub-and-spoke topology connects multiple branch or spoke sites through centralized hub devices. This design can simplify centralized routing, security inspection, and network management. One limitation is that traffic between two branches may need to pass through the hub, potentially increasing latency and consuming hub resources. Fortinet ADVPN can provide dynamic shortcut connectivity between suitable spoke sites, reducing unnecessary traffic hairpinning. SD-WAN can also operate within hub-and-spoke designs and select appropriate WAN paths based on application requirements, Performance SLA conditions, and configured steering strategies.

Question 271

Which metric is directly associated with the delay experienced by packets across a WAN path?

  1. Latency
  2. Jitter
  3. Packet Loss
  4. Throughput

Correct Answer: 1

Explanation

Latency represents the delay experienced by packets while traveling between endpoints across a network path. It is an important Performance SLA metric because excessive delay can negatively affect interactive applications such as voice, video conferencing, remote desktop, and transactional systems. FortiGate can monitor latency and compare it against configured thresholds. If a member exceeds the required threshold, it may become unsuitable for an SD-WAN rule that depends on that SLA. Latency should be evaluated together with jitter and packet loss because a low-latency path can still provide poor application performance when other quality metrics are degraded.

Question 272

Which Fortinet product is primarily used for centralized collection and analysis of FortiGate logs?

  1. FortiManager
  2. FortiGate
  3. FortiAnalyzer
  4. FortiSwitch

Correct Answer: 3

Explanation

FortiAnalyzer is primarily used for centralized log collection, analysis, reporting, and monitoring. In an SD-WAN deployment, multiple FortiGate devices can send logs to FortiAnalyzer, allowing administrators to investigate events from different branches through a centralized platform. This can help with troubleshooting WAN behavior, security events, connectivity problems, and traffic patterns. FortiManager has a different primary function focused on device and configuration management. Combining both products can provide centralized configuration through FortiManager and centralized operational visibility through FortiAnalyzer, which is useful in large distributed Fortinet deployments.

Question 273

Which SD-WAN strategy allows an administrator to define a specific member preference order?

  1. Best Quality
  2. Lowest Cost
  3. Load Balance
  4. Manual

Correct Answer: 4

Explanation

The Manual strategy allows an administrator to explicitly define the preferred order of SD-WAN members. This is useful when an organization wants a particular WAN link to be preferred and another link to act as a backup. Unlike Best Quality, Manual selection is based on administrator-defined preference rather than primarily ranking paths by measured quality. Performance SLA conditions can still influence member eligibility depending on the configuration. Manual preference is useful when predictable path selection is required, but administrators should understand that fixed preferences may not always reflect changing WAN conditions.

Question 274

Which technology provides encrypted connectivity for an SD-WAN overlay across an untrusted WAN transport?

  1. IPsec VPN
  2. DHCP
  3. ARP
  4. DNS

Correct Answer: 1

Explanation

IPsec VPN provides encrypted connectivity and is commonly used to build secure SD-WAN overlay paths across untrusted WAN transports such as the public Internet. The underlying transport provides connectivity, while IPsec protects the logical communication between FortiGate endpoints. Multiple IPsec tunnels can be used to provide redundancy and additional path choices. SD-WAN can then monitor and steer traffic across these paths according to configured rules and Performance SLA results. This combination allows organizations to use cost-effective WAN services while maintaining encrypted connectivity between branches, data centers, and other network locations.

Question 275

Which Performance SLA metric would be most concerning for an application that requires consistent packet timing?

  1. Jitter
  2. Interface description
  3. MAC address
  4. Administrative distance

Correct Answer: 1

Explanation

Jitter is particularly important for applications that require consistent packet timing, such as voice and video. High jitter means that packet delivery intervals vary significantly, which can cause interruptions or quality degradation in real-time communication. FortiGate can monitor jitter through Performance SLA and compare the result against configured thresholds. If a member exceeds the acceptable threshold, SD-WAN can potentially select another eligible path for the affected traffic. Latency and packet loss also matter, but jitter specifically addresses variation in packet timing, making it an important metric for real-time application traffic.

Question 276

Which SD-WAN feature allows traffic to be matched based on an application’s identity rather than only its IP address?

  1. Application-aware SD-WAN rules
  2. Static routing
  3. DHCP snooping
  4. ARP inspection

Correct Answer: 1

Explanation

Application-aware SD-WAN rules allow FortiGate to identify and steer traffic based on application identity. This provides more granular control than simply matching IP addresses because different applications can receive different WAN treatment even when they use shared infrastructure. Administrators can combine application matching with Performance SLA requirements and SD-WAN strategies. For example, business-critical applications can be assigned strict quality requirements while general traffic uses a different path-selection policy. Application-aware steering is particularly useful in modern environments where cloud applications and services may use changing destination addresses.

Question 277

Which component separates the physical WAN connections from the logical secure tunnels used between sites?

  1. Underlay and Overlay
  2. Application Control and DNS
  3. DHCP and NAT
  4. Policy and Profile

Correct Answer: 1

Explanation

The underlay represents the physical or transport WAN connections, while the overlay represents logical connectivity built across those transports. The underlay may include Internet, MPLS, LTE, or broadband services. The overlay can use IPsec tunnels to provide secure communication between FortiGate devices. SD-WAN operates across these paths and can steer traffic based on configured policies and Performance SLA measurements. This separation allows organizations to change or combine WAN transports without completely redesigning their logical network. It also helps troubleshooting by distinguishing transport problems from overlay tunnel or routing problems.

Question 278

Which SD-WAN rule criterion can identify traffic intended for a specific application category?

  1. Application
  2. Physical temperature
  3. Device serial number
  4. Administrator name

Correct Answer: 1

Explanation

The Application criterion allows an SD-WAN rule to identify traffic according to application information. This makes it possible to apply different steering behavior to different applications. For example, voice or business-critical applications can be associated with strict Performance SLA requirements, while less-sensitive traffic can use another strategy. Application-based rules can also be combined with source, destination, service, or ISDB criteria. Proper application identification is important because FortiGate needs to recognize the traffic before the corresponding rule can be matched. This provides granular control over WAN usage based on business and application requirements.

Question 279

What is a key benefit of using multiple WAN transports in an SD-WAN deployment?

  1. Greater path diversity and resilience
  2. Elimination of all routing protocols
  3. Automatic removal of security policies
  4. Guaranteed unlimited bandwidth

Correct Answer: 1

Explanation

Using multiple WAN transports provides greater path diversity and resilience. An organization may combine Internet, MPLS, LTE, or other connectivity types so that traffic has alternative paths when one service becomes unavailable or degraded. SD-WAN can evaluate these paths using Performance SLA and select appropriate members according to configured rules and strategies. Multiple transports can also help distribute traffic and optimize WAN utilization. However, using multiple links does not automatically guarantee unlimited bandwidth or perfect application performance. Proper configuration, monitoring, routing, and security policies are still required to achieve reliable SD-WAN operation.

Question 280

Which combination can provide secure branch connectivity, dynamic path selection, and quality-based failover?

  1. IPsec VPN, SD-WAN rules, and Performance SLA
  2. DHCP, DNS, and ARP
  3. NTP, SNMP, and SMTP
  4. NAT, FTP, and HTTP

Correct Answer: 1

Explanation

IPsec VPN, SD-WAN rules, and Performance SLA provide complementary capabilities for secure and intelligent WAN connectivity. IPsec can provide encrypted overlay tunnels between branch FortiGates. SD-WAN rules determine how matching traffic should be steered across available members. Performance SLA evaluates the quality and reachability of those paths using metrics such as latency, jitter, packet loss, or availability. When a preferred path becomes degraded, the SD-WAN strategy can select another eligible member. Together, these technologies provide secure connectivity, policy-based traffic steering, and dynamic response to changing WAN conditions.